Back to Seamix Legal centre
Legal // Data Protection Notice

Privacy
Policy.

What personal data Seamix AI collects, why we are allowed to process it, who it is shared with, where it is stored, how long we keep it, and the rights you can exercise.

Last updated: 14 August 2026 // Version 1.0 // Governing law: the laws of England and Wales

1. Who Is Responsible for Your Data

2. What We Collect

Data you give us

  • Account data: email address, display name, and a password that is stored only as a salted hash by Google Firebase Authentication. If you sign in with Google we receive your name, email address, profile photo URL and Google account identifier.
  • Profile data: optional brand, studio or company name and role.
  • Design content: written briefs and prompts, answers to refinement questions, uploaded sketches, reference photographs and artwork, and edits you make to generated documents.
  • Measurement data: body or block measurements you choose to enter for fit and grading. We use these only to compute grading logic for your document. We do not use them to identify anyone and we do not treat them as biometric identifiers.
  • Support data: the content of emails and messages you send us.

Data we generate about your use

  • Generated Output: technical flats, callouts, specification tables, bills of materials, colourways and related assets produced from your briefs, together with version history.
  • Usage and metering records: generation counts, plan allowance, per-request usage receipts, an append-only credit ledger, and short-window API call counters used to enforce quotas and detect abuse.
  • Technical and security logs: IP address, browser and device type, request paths, timestamps, error traces and rate-limit events.
  • Analytics: aggregated product analytics collected through Google Analytics for Firebase, which we only load if you consent to analytics cookies.

Data we receive from others

  • Payment data from Stripe: your Stripe customer and subscription identifiers, plan, currency, billing status, invoice history, the country of your card and the last four digits and brand of the card. We never receive or store your full card number, expiry date or security code.
  • Authentication data from Google if you use Google sign-in.

We do not intentionally collect special category data such as health, ethnicity, religion, political opinion, sexual orientation or genetic or biometric data, and you should not submit it. Please do not upload photographs of identifiable people unless you have their permission.

3. Why We Process It and Our Legal Basis

PurposeData usedLegal basis
Create and operate your account, authenticate you, and provide the StudioAccount, profile, design content, OutputPerformance of a contract
Generate technical documents by sending your brief and references to our AI providerDesign content, measurement dataPerformance of a contract
Take payment, manage subscriptions, meter allowances and issue invoicesPayment, usage and metering recordsPerformance of a contract
Keep the Service secure: authentication checks, quota and rate limiting, abuse and fraud prevention, incident investigationTechnical and security logs, usage records, account dataLegitimate interests in protecting the Service and our users
Provide support and respond to your messagesSupport data, account dataPerformance of a contract and legitimate interests
Understand which features are used so we can improve the productAnalytics identifiers and eventsConsent
Send product or marketing emailEmail addressConsent, which you may withdraw at any time
Keep accounting, tax and transaction records, and respond to lawful requestsPayment records, account dataCompliance with a legal obligation
Establish, exercise or defend legal claimsAny relevant dataLegitimate interests and legal obligation

4. How Your Content Is Used by AI Providers

  • We do not use your briefs, uploads or Output to train any model of our own.
  • Under the paid Gemini API terms, Google does not use the prompts or responses passed through the API to train or improve its general models. Google may retain limited data for a short period for abuse monitoring and to meet legal obligations.
  • We do not sell your design content, and we do not license it to any third party for their own purposes.
  • Requests are authenticated and metered per account so that content cannot be attributed to, or accessed by, another user.

5. Who We Share Data With

  • Service providers acting on our instructions, being Google Cloud and Firebase for hosting, authentication, database, file storage and analytics, Google for AI inference, and Stripe for payment processing. The current list, with roles and locations, is published on the Sub-processors page.
  • Professional advisers such as accountants, auditors and lawyers, under a duty of confidence.
  • Authorities, courts or regulators where we are legally required to disclose, or where disclosure is necessary to protect our rights or someone's safety. We will tell you unless we are prohibited from doing so.
  • A buyer or successor if we sell or reorganise the business, subject to this notice continuing to apply.

6. Where Your Data Is Stored and International Transfers

  • the UK International Data Transfer Addendum and the European Commission Standard Contractual Clauses, as incorporated into the Google Cloud and Stripe data processing terms;
  • the EU-US Data Privacy Framework and the UK Extension, where the receiving entity is certified under it; and
  • additional technical measures including encryption in transit and at rest and strict per-account access controls.

7. How Long We Keep It

CategoryRetention
Account and profile dataFor as long as your account is open, then deleted when you delete the account
Design content, uploads and generated OutputUntil you delete the item or the account; removed from live systems on deletion
Routine encrypted backupsOverwritten on our providers' standard cycle, normally within 30 to 90 days of deletion
Usage, metering and credit ledger recordsUp to 24 months, for billing accuracy, dispute handling and abuse prevention
Technical and security logsNormally 30 days, longer only where an incident is under investigation
Payment, invoice and tax records6 years after the end of the relevant financial year, as required by tax law
Support correspondence24 months from the last message
Records of consent and of privacy requestsAs long as needed to evidence compliance, normally 3 years

8. How We Protect It

  • HTTPS everywhere with HTTP Strict Transport Security, and a strict Content Security Policy enforced by the browser.
  • Encryption of data at rest by default on Google Cloud storage and database services, and encryption in transit between all components.
  • Passwords never stored by us in readable form; authentication is handled by Google Firebase Authentication.
  • Every AI, media and metering endpoint requires a verified account identity token before it will run, and requests are attributed and rate limited per account.
  • Database and file storage rules that allow each account to read and write only its own records and files.
  • Application secrets held in Google Secret Manager rather than in source code, with least-privilege service credentials.

Seamix AI does not itself hold an ISO 27001 certificate or a SOC 2 report. Our infrastructure providers hold their own certifications, which do not transfer to us. No internet service can be guaranteed to be completely secure.

9. Your Rights (UK and EEA)

  • Access: ask for a copy of the personal data we hold about you.
  • Rectification: have inaccurate data corrected.
  • Erasure: ask us to delete your data where there is no overriding reason to keep it.
  • Restriction: ask us to pause processing while a dispute is resolved.
  • Portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another controller. You can export your document library from the dashboard at any time.
  • Objection: object to processing based on legitimate interests, and object to direct marketing at any time.
  • Withdraw consent: withdraw analytics or marketing consent at any time, without affecting processing already carried out.
  • Automated decisions: we do not make decisions about you by solely automated means that produce legal effects. Quota and abuse controls are automated but only limit or pause access to the Service, and you can ask us to review any block.

10. United States State Privacy Rights

  • Categories collected in the last 12 months: identifiers such as name and email; commercial information such as subscription and transaction records; internet and network activity such as usage and log data; and your own uploaded content and generated Output.
  • We collect this from you directly, automatically through the Service, and from Stripe and Google as described above.
  • We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not sold or shared the personal information of minors under 16.
  • We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit its use.
  • Your rights: to know and access, to correct, to delete, to obtain a portable copy, to opt out of sale or targeted advertising (which we do not carry out), and not to be discriminated against for exercising a right.
  • You may use an authorised agent, and we may ask for proof of authorisation. Where a state law provides an appeal route, you may appeal a refused request by replying to our decision email, and we will respond within the statutory period.

11. Cookies and Local Storage

12. Children

13. Changes to This Notice

Summary

We collect what we need to run the Studio, bill you accurately and keep the platform secure. Your design content is sent to Google only to generate your documents, is not used to train models, and is never sold. Data is hosted in the United States under recognised transfer safeguards, and you can access, export or delete it at any time.