Seal
Log inSign up

Contents

  1. 1. WHO THIS POLICY COVERS, AND OUR ROLE
  2. 2. INFORMATION WE COLLECT
  3. 3. GOOGLE USER DATA
  4. 4. ARTIFICIAL INTELLIGENCE PROCESSING
  5. 5. HOW WE USE INFORMATION
  6. 6. HOW WE DISCLOSE INFORMATION
  7. 7. RETENTION AND DELETION
  8. 8. SECURITY
  9. 9. YOUR CHOICES AND RIGHTS
  10. 10. ADDITIONAL DISCLOSURES
  11. 11. CHANGES TO THIS POLICY
  12. 12. CONTACT US

Version 1.0 · Effective September 10, 2026 · Permanent archive

Seal Privacy Policy

The Harbor Seal Corporation · Version 1.0 · Effective September 10, 2026

This Privacy Policy explains how The Harbor Seal Corporation ("Seal", "we", "us", "our") collects, uses, discloses, retains, and protects information in connection with the Seal platform, the website at https://www.tryseal.co, and related services (the "Services"). It forms part of our Terms of Service at https://www.tryseal.co/terms.

1. WHO THIS POLICY COVERS, AND OUR ROLE

1.1 Our customers. Our customers are businesses and business professionals ("Customers"). This policy applies to Customers and their authorized users, to visitors to our website, and to the information about other people that Customers bring into the Services.

1.2 Two different roles. We handle two categories of information in two different capacities, and the distinction matters:

  • Account and website information. Information we collect about our Customers and website visitors directly, such as registration details and usage analytics. We determine how this information is used, and we act as a controller (or, under some state laws, a business) with respect to it.

  • Customer Data. Information a Customer submits to the Services or that we retrieve from a Customer's connected account at that Customer's direction, including email content, documents, and information about the Customer's own clients and counterparties. We process this information on the Customer's behalf and under the Customer's instructions. We act as a processor (or service provider) with respect to it.

1.3 If your information is in a Customer's account. If you are a client, counterparty, or contact of one of our Customers, that Customer, not Seal, controls the information about you in the Services and is responsible for the notices and consents required to place it there. Requests about that information should go to the Customer. If you contact us directly, we will refer you to the relevant Customer or assist that Customer in responding. See Section 9.

2. INFORMATION WE COLLECT

2.1 Information you provide to us. Account registration details, including name, business email address, company name, job title, and password credentials. Billing information if and when we charge for the Services, which is processed by our payment processor and not stored by us in full. Communications you send us, including support requests.

2.2 Information you upload. Documents and files you submit to the Services, which in our market may include financial statements, tax returns, profit and loss statements, balance sheets, contracts, and similar business records, and which may contain personal and financial information about individuals other than you.

2.3 Information from connected accounts. If you authorize a connection to your email or another third-party service, we may access and process message content, message metadata (including sender, recipient, subject, timestamps, and labels), attachments, and contact records. Section 3 describes this in detail for Google accounts.

2.4 Information generated by the Services. Records, summaries, drafted communications, extracted fields, and calculated or derived figures the Services produce from the above.

2.5 Technical and usage information. IP address, browser and device type, pages and features accessed, timestamps, referring URLs, and diagnostic and error data. We use cookies and similar technologies for authentication, session management, security, and product analytics. We do not use advertising cookies and we do not permit third parties to use cookies on our Services for advertising.

2.6 Information we do not intentionally collect. We do not seek government identification numbers, payment card numbers, health information, or other special categories of personal information. Such information may nonetheless appear inside documents or messages a Customer submits or connects. We treat any such information as Customer Data under this policy and handle it under Section 6.

3. GOOGLE USER DATA

This section applies if you connect a Google account to the Services. Before each connection, we present a separate connection consent, distinct from your acceptance of our Terms of Service, describing what will be accessed and asking you to confirm you are authorized to connect that account. We keep a record of that consent.

3.1 What we access. With your explicit authorization through Google's OAuth consent flow, we request the following scopes and use them only as described:

  • gmail.readonly, to read message content, headers, and attachments so the Services can extract contacts, companies, transaction details, and activity into your workspace;

  • gmail.compose, to create draft messages in your mailbox for your review. The Services do not send messages on your behalf;

  • gmail.settings.basic, to help you create a mail filter or label that limits which messages the Services retrieve, if you choose to use that feature; and

  • userinfo.email and userinfo.profile, to identify your account.

3.2 What we retrieve and retain. A Google authorization may technically grant access broader than what we retrieve. We retrieve and retain only what is necessary to provide the Services. Where you have configured a label or filter, we retrieve only messages matching it. We store the structured fields we extract, and message content where it is necessary to provide the Services, and we delete raw message content on the schedule in Section 7.

3.3 LIMITED USE COMMITMENT. SEAL'S USE AND TRANSFER TO ANY OTHER APP OF INFORMATION RECEIVED FROM GOOGLE APIS WILL ADHERE TO THE GOOGLE API SERVICES USER DATA POLICY, INCLUDING THE LIMITED USE REQUIREMENTS.

3.4 What we will not do with Google user data. We will not:

  • use it to create, train, or improve any generalized artificial intelligence or machine learning model. Any personalization is limited to your own use of the Services;

  • transfer or sell it to advertising platforms, data brokers, or information resellers;

  • use it for advertising of any kind, including retargeting, personalized, or interest-based advertising;

  • use it to determine credit-worthiness or for lending purposes;

  • retain it in any internal analytical environment after deletion, as described in Section 7; or

  • allow humans to read it, except where you have given documented explicit consent for specific messages, where the data is aggregated and anonymized and used for internal operations, where access is necessary for security purposes such as investigating a bug or abuse, or where required to comply with applicable law.

3.5 Revoking access. You may disconnect your Google account at any time within the Services, or through the Google account permissions page at https://myaccount.google.com/permissions. Revoking access stops future retrieval. Information already retrieved is handled under Section 7.

4. ARTIFICIAL INTELLIGENCE PROCESSING

4.1 How the Services use AI. The Services send Customer Data to third-party large language models to generate summaries, extract information, and draft communications. This processing occurs to deliver the features you are using.

4.2 How we reach models. We access large language models through an inference routing provider, OpenRouter, rather than contracting with each model provider directly. We configure that routing so that Customer Data is sent only to models and providers whose terms prohibit retaining it beyond what is necessary to return a response and prohibit using it to train models. The set of underlying providers may change as we tune the product; the retention and training restriction does not.

4.3 No training on your data. We do not use Customer Data to train, fine-tune, or otherwise develop or improve any generalized artificial intelligence or machine learning model.

4.4 Human review of outputs. The Services produce drafts and working materials that a qualified person at the Customer must review. Outputs may be inaccurate. Our Terms of Service set out the responsibilities this creates.

5. HOW WE USE INFORMATION

We use information to:

  • provide, operate, maintain, and support the Services, including generating the outputs you request;

  • authenticate users and secure accounts;

  • detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms;

  • communicate with you about the Services, including service, security, and administrative messages, which you cannot opt out of while you hold an account;

  • improve reliability and performance using technical and usage information and aggregated, de-identified statistics that do not derive from the substantive content of Customer Data;

  • with your separate consent, send you marketing communications, which you may opt out of at any time; and

  • comply with legal obligations and enforce our agreements.

WE DO NOT SELL PERSONAL INFORMATION, AND WE DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING. WE DO NOT DISCLOSE CUSTOMER DATA TO ADVERTISING PLATFORMS, DATA BROKERS, OR INFORMATION RESELLERS. WE DO NOT USE CUSTOMER DATA TO TRAIN GENERALIZED AI MODELS.

6. HOW WE DISCLOSE INFORMATION

6.1 Service providers. We disclose information to vendors that perform services for us, under written contracts that limit them to processing on our instructions and require appropriate confidentiality and security. These vendors fall into the following categories:

  • cloud hosting and storage;

  • artificial intelligence model routing and processing, described in Section 4;

  • authentication;

  • error monitoring and product analytics;

  • transactional email delivery; and

  • payment processing, if and when we charge for the Services.

6.2 At your direction. We disclose information as you instruct, including when you export or share it.

6.3 Legal and safety. We may disclose information where we believe in good faith it is reasonably necessary to comply with law or valid legal process, to enforce our Terms, or to protect the rights, property, or safety of Seal, our Customers, or others. Where legally permitted, we will give the affected Customer notice before disclosing Customer Data.

6.4 Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to the acquirer continuing to handle it in a manner consistent with this policy. We will notify Customers of any such transfer affecting Customer Data. We will not transfer data obtained through the Google Workspace APIs in connection with such a transaction without first obtaining the explicit prior consent of the user whose data it is; absent that consent, we will delete it.

6.5 No other disclosure. We do not otherwise disclose Customer Data to third parties.

7. RETENTION AND DELETION

7.1 Retention principle. We retain information only as long as necessary for the purposes described in this policy, and we design for the shortest retention the Services can operate on.

7.2 While your account is active. Raw content retrieved from a connected account is retained for 30 days and then deleted. Structured records extracted from that content, and documents you upload, are retained while your account is active or until you delete them. Technical and usage logs are retained for 90 days. Account information is retained while your account is active and for 12 months afterwards.

7.3 On termination or deletion request. Following the export period described in our Terms of Service, we delete Customer Data within 30 days from the Services and from every system through which it is made available to you or to any other customer, and within 90 days from routine backups. You may request deletion of specific Customer Data at any time through the Services or by writing to g@tryseal.co. On written request, we will confirm in writing that Customer Data has been deleted in accordance with this Section.

7.4 Internal analytical environment. We may retain a copy of Customer Data in an internal analytical environment that does not form part of the Services, for no longer than 12 months after the deletion date, solely to operate, secure, troubleshoot, and improve the Services. Any such copy is access-restricted, is not made available to any other customer, is not used to provide the Services to any other customer, and is not used to train, fine-tune, or improve any artificial intelligence or machine learning model. Data obtained through the Google Workspace APIs is never retained in that environment and is deleted on the schedule in Section 7.3 without exception.

7.5 Backups. Deleted data may persist in encrypted backups until those backups expire on the schedule above. Backup data is not returned to production use.

7.6 Records we keep. We retain aggregated, de-identified data that does not derive from the substantive content of Customer Data, records required for billing, tax, or legal compliance, security and abuse logs, and records of the consents you have given, including your acceptance of these terms and your connection consents.

8. SECURITY

8.1 Safeguards. We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and destruction, appropriate to the sensitivity of the information and the size and complexity of our business. These include encryption of data in transit using TLS and encryption at rest, role-based access controls, multi-factor authentication for administrative access, logical separation of each Customer's data, logging and monitoring, least-privilege access provisioning, security review of vendors before we engage them, and periodic review of who has access to what.

8.2 Our program. We maintain a written information security program consistent with the requirements of the New York SHIELD Act and comparable state laws, which apply to us regardless of our size or revenue.

8.3 Incident notification. If we determine that a security incident has compromised Customer Data, we will notify the affected Customer without undue delay and will cooperate reasonably in that Customer's own notification obligations to its clients and to regulators.

8.4 No guarantee. No system is perfectly secure. We cannot guarantee that our safeguards will prevent every unauthorized access, and you are responsible for protecting your credentials and for the scope of what you connect to the Services.

9. YOUR CHOICES AND RIGHTS

9.1 Access, correction, and deletion. Customers may access and correct account information in the Services, export Customer Data, and request deletion as described in Section 7.

9.2 Connected accounts. You may disconnect any connected account at any time. See Section 3.5.

9.3 Marketing. You may opt out of marketing emails using the unsubscribe link in any such message or by writing to us. Service and administrative messages continue while you hold an account.

9.4 State privacy rights. Depending on your state of residence, you may have rights to know what personal information we hold about you, to obtain a copy, to correct it, to delete it, and to be free from discrimination for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of in that respect. To exercise a right, write to g@tryseal.co. We will verify your identity before responding and will respond within the period required by applicable law. We honor these rights as a matter of practice whether or not a particular state law currently applies to us.

9.5 If your data is in a Customer's account. If you are not a Seal Customer and believe a Customer has placed information about you in the Services, contact that Customer, who controls it. If you write to us at g@tryseal.co, we will forward your request to the relevant Customer and assist them in responding, but we cannot delete or disclose a Customer's data without that Customer's instruction except where the law requires otherwise.

10. ADDITIONAL DISCLOSURES

10.1 Age. The Services are for business use by individuals 18 or older. We do not knowingly collect personal information directly from anyone under 18. If we learn we have done so, we will delete it.

10.2 Location of processing. We operate in the United States and process information there. The Services are offered to customers in the United States. If we begin serving customers in other jurisdictions, we will update this policy and put the additional terms those jurisdictions require in place before doing so.

10.3 Third-party sites. The Services may link to third-party websites and services we do not control. This policy does not cover their practices.

10.4 Browser signals. We do not respond to Do Not Track browser signals, which have no agreed standard. Where a state law applicable to us requires us to honor Global Privacy Control or a similar opt-out preference signal, we will honor it.

11. CHANGES TO THIS POLICY

We may update this policy. If a change is material, we will notify Customers by email to the address associated with the account or by prominent notice in the Services at least 30 days before it takes effect. We will update the effective date above and keep prior versions available on request. Continued use after the effective date constitutes acceptance.

12. CONTACT US

Questions, requests, or complaints about this policy or our handling of information:

The Harbor Seal Corporation

Attn: Privacy

155 Water St, Office 4-4

Brooklyn, NY 11201

Email: g@tryseal.co

Last revised: September 10, 2026 • Version 1.0

Seal

The operating system for small-business acquisitions.

Seal is a CRM for business brokers. It reads the email and documents on a deal, keeps the record current, and drafts the follow-ups and marketing documents a broker would otherwise write by hand.

Made in Brooklyn, New York.

Legal
TermsPrivacy
© 2026 Seal