Privacy policy
Last updated 26 September 2026
Every claim here is one we can point to in our own code. Where something is narrower than it sounds, it says so. The section What we do not claim exists for that reason.
Who we are
Seturos is operated by Seturos, Inc., a Wyoming corporation, 1810 E Sahara Ave STE 75057, Las Vegas, NV 89104, United States. We are the controller of the account data described below, and we process your organisation's content on your behalf to provide the service.
Seturos is in early access. The product is changing, and this policy will change with it; the date above tells you when it last did.
What Seturos is
Seturos is a shared memory for work that moves between AI tools. It carries what was settled in one tool (a conversation, a coding session, a document) into the next one, through a browser extension, a desktop app, a web app and an MCP server, and keeps it where you and the people you work with can find it.
What we hold
- Your account: name, email and organisation membership, through our identity provider. We do not store passwords.
- Your organisation’s map: the people, teams and projects you enter or import, and the records of work done against them.
- Conversations and sessions you carry: a distilled brief of each, and a capped excerpt as supporting evidence. Before anything is stored, recognised secrets such as keys and connection strings are removed.
- Documents you upload: held in encrypted object storage and readable only through short-lived, signed links issued to your session. The storage is not public.
- Connector tokens: OAuth tokens for the tools you connect, encrypted with AES-256-GCM before they are stored, and decrypted only to do something you asked for.
- Operational records: the shape of a run (which tools, what it cost, how long it took) and an audit log of authorisation-sensitive actions.
What only happens when you ask
Reading another tool’s content is always an explicit act, never a background one. This is enforced in the code rather than promised in a policy.
- The browser extension reads the page you are on only when you run a capture, or while you have chosen to follow a project. Its passive layers record which tool you are in, never what is on the screen, and redact typed values at the point of capture.
- The desktop app never reads your screen. It reads what you highlighted, at the moment you pressed the shortcut, through the operating system clipboard, and it knows the name of the foreground application.
- Coding sessions are recorded only where you installed Seturos’s hooks or plugin, and a session is filed only under the repository it ran in.
Personal data in prompts
Before a prompt leaves your browser, the extension replaces recognised personal data (emails, phone numbers, national identifiers, payment card numbers and named people) with placeholders. The map back stays in your browser session, expires after fifteen minutes, and is discarded once the response is shown. Model providers receive the placeholders.
This is a real reduction and it is not total. See “What we do not claim”.
Model keys and running a model on your machine
Seturos works without a model key: capture, briefs and resume are produced without calling a model. When your organisation adds its own Anthropic, OpenAI or Google key, calls are made with that key and billed to and governed by your account with that provider.
Where you have a local model available, Seturos can summarise a captured conversation on your own machine and send only the summary. The conversation itself is then never transmitted.
Who else processes your data
Each provider processes only what its function requires. A named list of subprocessors is available on request.
- Hosting and database: our application host and managed Postgres provider.
- Identity: our authentication provider, which holds your sign-in credentials so that we do not.
- Model providers: Anthropic, Google and OpenAI, only when your organisation has added its own key: calls are made with that key, and billed to and governed by your own account with that provider. Seturos makes no model calls on its own account.
- Object storage: for documents you upload.
- Transactional email: for invitations and notifications.
- Tools you connect yourself: these are your accounts; we act on them only with the access you grant and only to do what you asked.
What we do not do
- We do not sell your data, and we do not use it for advertising.
- We do not train models on your data.
- We do not use one customer’s data to answer another customer’s question. Every read is scoped to the asking person’s own organisation and their own level of access within it.
What we do not claim
The placeholder substitution described above reduces what model providers see. It does not make us blind to your content: we hold briefs, documents and organisational records in a form we can read, and we could be lawfully compelled to produce them. This is not zero-knowledge encryption and we do not describe it as such.
Detection of personal data and of secrets is pattern-based and imperfect. It will not catch everything.
SOC 2 Type II is in progress and not complete. We will not claim a certification before we hold it.
This website
seturos.com sets no cookies, runs no analytics and loads nothing from third parties: its fonts are self-hosted and its content security policy allows only its own origin. The web app at app.seturos.com uses the cookies sign-in needs, and no advertising or tracking cookies.
Your controls and rights
- Archive, move or delete any carried conversation, or export all of them, from the web app.
- Disconnect any tool from Settings. Disconnecting deletes the stored encrypted token.
- Delete your account, which removes your personal records and reassigns work that belongs to your organisation rather than to you.
- Ask for a copy of your data, a correction, or a full deletion of your organisation’s data. Deletion requests are completed within 30 days.
- Depending on where you live you may have further rights, including to object to processing or to complain to a data protection authority.
Retention
Account records, organisational records and carried briefs are kept until you delete them or close your organisation.
By default, the conversation excerpt stored beside a brief is removed after 90 days, and a conversation nobody has touched for 180 days is archived. It is still findable by name, but no longer offered automatically. Archived conversations are deleted only if your organisation turns that on. An administrator can change all three periods in Settings.
The browser-side placeholder map expires after fifteen minutes.
Children
Seturos is a workplace product and is not directed at anyone under 16.
Changes
When this policy changes materially we will update the date at the top and tell account holders by email.
Contact
Privacy questions, export and deletion requests: [email protected]. Security reports: [email protected]. How the product is secured is on the security page.