Seige Privacy Policy
DRAFT — not effective or ready to publish. Prepared September 19, 2026. Resolve bracketed fields and the publication checklist before adoption. Statements below describe the reviewed evaluation implementation or explicitly identified proposed commitments; verify deployment before publishing.
Effective date: [EFFECTIVE DATE].
1. Who is responsible
This policy describes how Seige handles personal information. Operator identification is intentionally deferred in this draft; no registered office or jurisdiction is established here. Contact [PRIVACY EMAIL] for privacy questions or requests. [ADD DATA-PROTECTION OFFICER AND REGIONAL REPRESENTATIVE CONTACTS IF REQUIRED.]
This policy covers our website and current account, notes and email evaluation. It also covers people who send messages to Seige users or contact us without an account. It does not claim that planned storage, AI, OAuth or third-party app features are available. We will explain additional processing before introducing such features. Where we process business-customer content solely on their instructions, any required data-processing agreement will separately identify the parties' roles.
2. Information we process
| Category | Information and source | Purpose |
|---|---|---|
| Account and authentication | Your chosen username, assigned address and account identifier; password-protocol registration data; public keys, encrypted key packages and signatures; optional passkey identifiers, public credential records and encrypted wrappers | Create and authenticate accounts, open supported encrypted data on your device, and prevent unauthorized access |
| Sessions and browser storage | Session identifiers and expiry data; remembered-session token hashes and server wrapping shares; encrypted local account packages and browser-held cryptographic keys | Maintain sign-in, restore access and revoke sessions |
| Stored content | Encrypted notes, drafts, mailbox messages and received originals, including attachments; record identifiers, ownership, sizes, versions, timestamps and mailbox/delivery state | Save, retrieve, synchronize and deliver your information |
| Email delivery | Sender and recipient addresses, routing headers, message identifiers, timestamps, delivery results and readable internet-message content at the mail gateway; supplied by senders, recipients and their providers | Route messages, filter spam locally, handle retries and diagnose delivery failures |
| Connections and operations | IP addresses processed when connecting, connection timing, request and error information, mail-server logs and security signals | Serve requests, apply limits, troubleshoot and protect infrastructure |
| Support and abuse cases | Contact details, correspondence, reports, supplied evidence and action records from you, reporters or authorized authorities | Answer requests, investigate abuse, handle appeals and meet legal duties |
The account protocol does not send your raw password or your content private keys to the account API. Passkey verification occurs through your authenticator; Seige does not receive its fingerprint or face templates. Authentication records and encrypted key packages remain security-sensitive information.
The reviewed web configuration does not enable access logs, advertising trackers or third-party analytics. This does not mean all infrastructure is log-free: mail and operating-system services can record operational information, and IP addresses are processed for connections and abuse controls. [CONFIRM ACTUAL LOG FIELDS, PROVIDER TELEMETRY AND RETENTION BEFORE PUBLICATION.]
3. What encryption does and does not protect
Supported notes, drafts and stored mailbox copies are encrypted for your account. For mail between Seige accounts, the sender's browser encrypts separate copies for the sender and recipient. Account servers store those ciphertexts rather than receiving the corresponding content private keys.
Ordinary internet email has a different boundary. Incoming mail is readable by our mail server, spam filter and gateway before encryption into the mailbox. Outgoing internet mail includes a copy encrypted to the gateway, which decrypts it for delivery. Temporary mail queues may contain readable messages. Administrators can observe this delivery plaintext and routing metadata, and the SMTP boundary can be subject to lawful interception. Stored mailbox encryption does not make ordinary internet delivery end-to-end encrypted.
Encrypted backups include gateway key material and may include pending outbound ciphertext, so they must also be protected against access to pending external messages. They do not include the plaintext SMTP retry queue.
Your device decrypts supported content. Compromised devices or browser code can expose it; first-party browser code supplied by Seige is part of the trust boundary. Recipients can keep or share their copies. Lost credentials may prevent recovery. Seige remains an evaluation service without completed independent security qualification; use test data.
4. Uses and legal bases
We use the information above to provide and secure the requested features, communicate about service issues, respond to support and rights requests, investigate misuse and meet legal obligations. We do not sell personal information, use private content for targeted advertising, or train AI models on private content. These are commitments of this proposed policy and must remain consistent with actual practices.
Where a law requires a legal basis, we rely on performing our agreement for account and service delivery; legitimate interests in security, abuse prevention and support, balanced against affected people's rights; and legal obligations for required records, reports and responses. For correspondence involving non-users, the relevant interest is delivering communications requested by our users. Optional processing requiring consent will be explained separately, and consent can be withdrawn without affecting prior lawful processing. We do not treat acceptance of the Terms as blanket privacy consent.
Account information needed for authentication and delivery is necessary to provide those features. Without it, we cannot operate the account or deliver the message. We do not use personal data for advertising profiles. Technical controls may automatically reject requests or mail; contact [APPEALS EMAIL] to request human review of a restriction affecting you.
5. When information is shared
- Infrastructure providers: Hetzner hosts the documented application, database and mail infrastructure. Cloudflare provides DNS with web proxying disabled in the reviewed deployment; GoDaddy is the domain registrar. DNS and domain administration have different data access from hosting. [VERIFY CONTRACTING PROVIDER ENTITIES, LOCATIONS AND ANY ADDITIONAL SUPPORT OR BACKUP VENDORS.]
- People and providers you communicate with: Messages and routing information go to intended recipients and their email providers. Their processing is outside Seige's control. Passkey synchronization, if selected, is handled by your authenticator provider under its own terms.
- Support and professional assistance: Authorized personnel and contracted advisers may receive the information necessary for support, security or legal work, subject to appropriate confidentiality and access restrictions.
- Law and safety: We may preserve or disclose information when required by valid legal process or a legal reporting duty. Any voluntary disclosure, including an emergency disclosure, must have a specific lawful basis; a suspicion of abuse alone does not authorize unrestricted release of private messages. We assess authority, scope and applicable restrictions, limit responses accordingly, and notify affected users where lawful and practicable. Notice may be delayed when law or a legitimate safety or investigative need requires it. We can provide only information available to us; encrypted content and accessible delivery information have different boundaries.
- Business transfers: Information may transfer in a merger, acquisition or similar transaction subject to applicable law, appropriate confidentiality and continuing privacy obligations. Material changes will be notified.
6. Retention, closure and deletion
We keep data for the purposes described here and applicable legal requirements. Current evaluation limits are important:
| Data | Current behavior or required final detail |
|---|---|
| Account records and encrypted content | Persist in the service database. Self-service account deletion and a complete purge workflow are unfinished. Trash changes mailbox state; it does not erase messages or reclaim quota. Request closure or deletion at [PRIVACY EMAIL]. [DEFINE AND IMPLEMENT ACTIVE-DATA DELETION DEADLINE.] |
| Remembered sign-in | Server grants expire after 60 days without use. Sign-out revokes that browser grant and removes its local remembered cache. Expiry does not necessarily mean immediate removal of every expired database row. |
| SMTP retry queues | Configured retries run for up to two days; bounce queues up to one day. These delivery settings are not a deletion guarantee for logs, mailbox copies or backups. |
| Backups | Documented daily encrypted server archives rotate after 14 days. Separate operator-held off-server copies exist; their deletion schedule is [OFF-SERVER BACKUP RETENTION]. The 14-day rotation is not a universal erasure deadline. |
| Logs, support and abuse records | [SET PERIODS OR SPECIFIC NECESSITY-BASED CRITERIA FOR EACH CATEGORY, INCLUDING PROVIDER LOGS AND CLOSED CASES.] |
| Legal holds | Relevant records may be retained for a required preservation period, legal obligation or necessary legal claim, with access restricted and the hold reviewed before release. |
We will assess deletion requests individually, explain lawful retention exceptions and meet applicable statutory deadlines. Incomplete self-service tooling does not remove your legal rights. Deletion from Seige cannot remove copies retained by recipients or your devices. Restoring backups must preserve previously actioned deletion requests. [IMPLEMENT AND TEST THIS PROCESS BEFORE ADOPTING THIS POLICY.]
7. Cookies and local storage
The prepared service-domain layout uses `account.seige.ai` for sign-in and the trusted app runtime. Mail and Storage pages embed that runtime from the account origin. Account cookies and encrypted local account storage stay on that origin; service pages exchange only readiness and navigation messages with it. Storage currently shows a coming-soon view. [VERIFY DOMAIN CUTOVER AND BROWSER BEHAVIOR BEFORE PUBLICATION.]
Seige uses cookies for authentication and session security. Remembered sign-in stores an encrypted account package and a browser cryptographic key in IndexedDB; the server supplies a separate wrapping share through an authorized session. These mechanisms support account access, not advertising.
The sign-in screen lets you choose whether to stay signed in. Disabling that choice uses a session cookie, though browsers may restore session cookies when reopening a session. Sign-out clears the remembered grant and local cache for that browser. Blocking essential storage can prevent sign-in or restoration. [VERIFY AND LIST OTHER PREFERENCE STORAGE USED BY THE RELEASE.]
8. Locations and international transfers
The documented service uses Hetzner infrastructure. Actual hosting country, operator access countries, backup destinations and any other processing locations are [CONFIRMED COUNTRIES]. We will identify applicable safeguards for transfers requiring them, such as an adequacy decision or appropriate contractual safeguards, and explain how to obtain a copy at [PRIVACY EMAIL]. [INSERT THE ACTUAL TRANSFER MECHANISM AND RELEVANT RECIPIENTS; DO NOT INFER LAWFUL TRANSFERS FROM A PROVIDER'S BRAND.]
9. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction or a portable copy of personal information, object to processing based on legitimate interests, and withdraw consent. Send requests to [PRIVACY EMAIL]. We use proportionate verification and do not ask for your password or private keys. We will explain any legally permitted refusal or limitation and applicable appeal route, and respond within the deadline required by your law.
Encryption may limit what we can retrieve in readable form; it does not eliminate rights over metadata or other information we hold. The current interface does not provide complete export or self-service account deletion. Contact us for available assistance.
You may complain to the competent privacy regulator, including the authority where you live or work when applicable. Our lead or local authority, if applicable, is [AUTHORITY AND COMPLAINT LINK]. We will not retaliate against you for exercising privacy rights. [ADD REQUIRED REGIONAL NOTICES, AGENT REQUEST METHODS AND APPEALS AFTER JURISDICTION REVIEW.]
10. Children and updates
Account registration is intended for adults aged 18 and over. If you believe an underage person registered, contact [PRIVACY EMAIL] so we can investigate and take appropriate action. An age restriction does not mean incoming correspondence can never contain information about minors.
We will publish revisions with an effective date and notify users of material changes through the Service or an available account contact. Where required, we will obtain separate consent before introducing new processing. Contact [PRIVACY EMAIL] with questions.