Legal

Privacy Policy

We respect your privacy. This policy explains what data we collect, why we collect it, and how you can control it.

Last updated: June 1, 2026

1. Introduction

Seraph, Inc. ("Seraph", "we", "our", or "us") operates the Seraph platform at seraph.ai (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service. Please read this policy carefully. If you do not agree with its terms, please discontinue use of the Service.

We may update this policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date, and, where appropriate, by sending an email notification to the address associated with your account.

2. Information We Collect

Account Information

When you register for a Seraph account, we collect your email address, password (stored as a cryptographic hash), and optional company name. If you sign in with a third-party provider such as Google, we receive your name and email address from that provider.

Usage Data

We automatically collect information about how you interact with the Service, including pages visited, features used, audit URLs submitted, report views, session duration, and click paths. This data helps us understand how the product is being used so we can improve it.

Log Data and Device Information

Our servers automatically record certain information whenever you access the Service, including your IP address, browser type and version, operating system, referring URL, and timestamps. This information is used for security monitoring, debugging, and aggregate analytics.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to maintain your session, remember your preferences, and measure the performance of our marketing campaigns. See our Cookie Policy for a full breakdown of the cookies we set and how to manage them.

Payment Information

If you subscribe to a paid plan, payment information (card number, expiry, CVV) is processed directly by our payment processor, Stripe. Seraph never stores raw payment card data on our servers.

3. How We Use Your Information

We use the information we collect for the following purposes:

4. Data Sharing and Disclosure

We do not sell your personal information. We share your information only in the following limited circumstances:

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. If you close your account, we will delete or anonymize your personal data within 90 days, except where we are required to retain it for legal, tax, or audit purposes. Aggregated, anonymized data may be retained indefinitely for product analytics.

6. Security

We implement industry-standard technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These include TLS 1.3 encryption for all data in transit, AES-256 encryption for data at rest, role-based access controls, and regular third-party security audits. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

7. Cookies

We use essential cookies to operate the Service (session management, CSRF protection) and optional analytics and marketing cookies to understand and improve your experience. You can control cookie preferences through your browser settings or our cookie consent manager. Disabling certain cookies may limit the functionality of the Service. See our Cookie Policy for the full list and instructions for managing your preferences.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

GDPR (EU/EEA residents): You have all the rights listed above under the General Data Protection Regulation. Our legal basis for processing is typically contract performance (to deliver the Service), legitimate interests (security, product improvement), and consent (marketing). You have the right to lodge a complaint with your local supervisory authority.

CCPA (California residents): You have the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at privacy@seraph.ai.

To submit a data rights request, email us at privacy@seraph.ai. We will respond within 30 days.

9. Children's Privacy

The Service is not directed at children under the age of 16, and we do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will delete that information promptly. If you believe we have collected such information, please contact us at privacy@seraph.ai.

10. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or the Service. We will indicate the revision date at the top of this page. For material changes that affect your rights or how we process your data, we will provide prominent notice (such as a banner in the dashboard or an email notification) at least 14 days before the change takes effect.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: