Trust & security

What we actually do with your work.

We make serialized video ourselves, so unreleased scripts and cuts are exactly the thing we would not want leaking either. Here is plainly how yours are handled — including the parts that are not finished.

Report a vulnerability
Mail contact@seedagent.ai with enough detail to reproduce it. Tell us before you tell the internet and we will work with you on the fix.
OWNERSHIP
You keep what you upload
Your uploads stay yours. Once you have paid in full, our Terms give you a perpetual, worldwide license to the AI-generated videos from your projects — other outputs are not covered by that clause yet. The same clause reserves our right to use anonymized outputs to improve our models and to show what the product can do, unless you opt out in writing.
GENERATION
The models are not ours
We do not run model inference. Your prompt and the references you attach go to the provider behind the model you picked, for some models via an API aggregator in front of it. Separately, whichever model you pick, OpenAI sees any prompt you send through Polish and any reference image our real-person detector checks.
ACCESS
Personal work stays personal
A canvas belongs to whoever made it: nobody else opens it unless you invite them or share a link. Team workspaces are deliberately more open than that, and the section below says exactly how much.
MEDIA LINKS
A link is the permission
Uploaded and generated files alike sit at hard-to-guess URLs on our media domain. They do not expire and are not individually access-checked, so anyone holding one can open it.

Your content and your data

What we store
Your scripts and canvases, including every prompt and the settings behind each generation. The images, video and audio you upload as references, and everything the models hand back. Plus 3D characters, review uploads and comments, your chats with the in-app assistant, support tickets and their screenshots, and the account, usage and billing records needed to run your plan.
Where it lives
Account and project data in a managed Postgres database; uploaded and generated media in Cloudflare R2, served from our own media domain over HTTPS. Both platforms encrypt what they hold at rest by default. We have not layered customer-managed keys on top of that, and we would rather say so than name a cipher we never configured.
Who else sees it
The provider behind whatever model you generate with, and for some models an API aggregator in front of that provider. Payments run through Stripe, and through Alipay on the China storefront. Our marketing pages and the signed-in app load Vercel Analytics and advertising tags from Google, Reddit and TikTok; when you sign up we also send Reddit's and TikTok's conversion APIs a hashed copy of your email or phone number along with your IP address and user agent, so the ad click and the sign-up match up.
Which countries
One storage region, plus wherever your chosen model's provider runs. Several of the video providers we route to are hosted in mainland China and Singapore. There is no EU-residency option today, and no way to pin a workspace to a region.
Retention
Content stays until you delete it. A deleted canvas sits in trash for 7 days, after which a nightly job removes the record and purges the generated video files it referenced. That same job also retires videos one at a time: once a clip or a merged cut is no longer referenced by any canvas, share link or asset, its file is deleted 7 days later — so removing a video node or re-merging a chain retires the old file too. Generated images and audio are not swept at all. Billing and credit records are kept indefinitely, including after an account closes.
Getting it out
Any video you generate can be downloaded from the canvas's generation history and starred panels, one at a time or in bulk, along with generated music and final cuts. Script and image export are not built yet.
Closing an account
Account deletion is self-serve in the iOS app; on the web, mail us and we run the same thing by hand. It bans the login on every device and blanks your profile, the customer name and email on your generation records, and your canvas-access row. It does not erase your project content, and an address on an invitation you sent or a support ticket you filed stays on that row until we remove it — ask and we will.

Infrastructure

In transit

Every connection between your browser and SeedAgent, including every media URL we hand out, is HTTPS. One internal hop is not yet: the cache holding short-lived copies of asset lists and account settings connects without TLS today.

At rest

Our database and object storage encrypt what they hold at rest as a platform default. No customer-managed keys, and no per-object key scheme.

Media URLs

Hard-to-guess paths — an account id, a timestamp and a short random suffix — that we never list anywhere. They are not access-controlled and do not expire, so the path is the only thing protecting the file.

What we run ourselves

Generation happens at the provider over their authenticated API. Our own compute on your media is mechanical: pulling frames, joining clips, compositing reference images, and stripping the audio off a video so a speech vendor can transcribe it — in short-lived serverless functions that delete their working files before the request returns.

Payments

Card details never reach us. We create a checkout session and hand you to the provider's own hosted page; what returns is an outcome on a callback whose signature we verify before crediting anything.

Ledgers

Credit purchases, grants, refunds and every workspace pool movement land in append-only ledgers, and pricing changes record which administrator made them. We do not log who opened which asset.

Access control

Ownership sits with the person who made the thing, and workspaces layer roles on top. Everything below is checked in our API routes, not just hidden in the interface.

A canvas belongs to the person who made it. Someone else opens it only if the owner invites them or shares a link — being in the same workspace is not enough, and neither is being its admin.
Scripts in a team workspace are more open than that. The workspace's owner and admins can read any script in it, and once a script is approved for production every video creator in that workspace can read it. Workspace owners and admins can also see every render's prompt and finished video.
Team workspaces have three tiers — owner, admin and member — plus four functional roles: script writing, video creation, script review and video review. Owners and admins hold all four.
Those roles are checked on our servers: creating a workspace canvas or running one as a member needs video creation, and creating a workspace script needs script writing. The matching review role is always enough to sign off on submitted work — and with content isolation off, which is the default, a workspace member holding a review invitation can sign off too.
Review invitations on workspace content are limited to people in that workspace. Switch content isolation on and they narrow to the reviewers assigned to that content type, re-checked on every approve or reject, so an older invitation stops working.
Workspace admins can set an optional monthly credit ceiling per member. Where one is set it is applied inside the same locked transaction that deducts the credits, so an over-budget run is refused before the job exists and before any provider is called. Ceilings are off by default.
Handing over ownership can only be started by the current owner, and only an existing admin can receive it. Both rules are enforced server-side.
Dissolving a workspace returns every canvas and script to its author and pays leftover purchased pool credits to the owner. It archives the workspace rather than erasing it.
Two things we would rather state than imply: these checks live in our application layer rather than in database row-level security, and a small allowlist of SeedAgent operators can open and act on any account's canvases, scripts and workspaces — personal ones included — for support and incident response.
No SSO and no SCIM provisioning today. Members join by invitation.

Where we stand

We would rather show the real state than a wall of badges. Some of these rows say no, and they will say something else when that is true rather than before.

SOC 2 Type II

No audit under way. This row changes the day one starts.
Not yet

Privacy requests

No DPA template yet. Deleting your account is self-serve in the iOS app; a copy of your data, a correction, or erasing project content is handled by hand — mail us and we will do it.
By request

Data residency

Not offered. One storage region, and generation providers in several countries.
Not offered

Penetration testing

No third-party test commissioned yet.
Not yet

Sub-processor list

Our privacy policy lists only Stripe, Alipay, Supabase, Cloudflare R2 and Vercel. It does not yet name any model provider, any API aggregator, or the advertising tags described above — so until it catches up, the sections above are the fuller list.
Partial

Responsible disclosure

If you find something, tell us before you tell the internet and we will work with you. No legal action from us against good-faith research that stays inside your own account, leaves other people's content alone, and gives us reasonable time to fix before you publish. We are happy to credit you once it is closed.

Keep it to seedagent.ai and creator.seedagent.ai — no denial-of-service or load testing, no automated scanning, no social engineering, and nothing aimed at our vendors' own systems, which are not ours to authorize. Anything on this page you want in writing for a procurement review, or a question it does not answer, goes to the same address.

Written August 2, 2026. Our privacy policy and terms are the binding versions of anything summarized here — except the disclosure commitment above, which is a promise we make in addition to them rather than a summary of them. Privacy and data requests can go to the address on this page or the one in the privacy policy; both reach us.