The short version
- Your content is yours. We use it to run seed for you and the people you share it with. That’s it.
- No selling, no ads, no tracking. We don’t sell or rent personal information, show ads, or use analytics or advertising trackers in the app or on this website.
- We don’t train AI on your data. seed doesn’t train models. When you use AI features, the text needed for that request goes to an AI provider (see AI features, including one setting you should know about).
- Connected accounts do only what you ask. seed reads or writes your Google or Slack data only to do something you or your agent settings requested.
- You can leave with your data. Ask for an export or full deletion any time.
Who we are
seed (“seed”, “we”, “us”) is operated by Cash Flow Crescendo Inc., a company based in Ontario, Canada. We are responsible for the personal information described here. Questions, requests and complaints go to our privacy contact at support@getcashflow.co.
This policy covers the seed website, the seed web app, the seed iOS app and our related services. When you’re a member of someone else’s workspace, the workspace owner decides who can see the content in it. We process that content on their behalf and on yours.
What we collect
Information you give us
- Account details. When you sign in with Google we receive your name, email address and Google account ID. We don’t store your profile picture. You can change your display name and colour in seed.
- Your content. Workspaces, folders, items, notes, subtasks, due dates, reminders, locations, chat messages, reactions, Library links, notes and contacts, and anything else you type into seed.
- Files. Images, PDFs and videos you upload, and the names and links of Google Drive files you choose to attach (the Drive files themselves stay in your Drive).
- Financial entries. If you use Financials: payees, amounts, taxes, categories, dates, notes, and the receipts and invoices you scan.
- Agent settings. Agent roles, the knowledge base you write for it, and which abilities you’ve switched on.
- People you invite. The email address of anyone you invite to a folder or workspace.
- Messages to us. Anything you send to support.
Information from services you connect
- Google (Calendar, Drive, Gmail, Sheets). This is only if you connect them. We store an encrypted access token, and the Drive folder you pick if you choose one. See Google user data.
- Slack. This is only if you connect it. We store an encrypted bot token, your Slack workspace ID and the channel you link to a folder. When someone pins a message in a linked channel, we receive that message’s text to create an item.
- Stripe (Pro only). We receive your Stripe customer ID, subscription status, plan, renewal date and billing email. We never receive or store your card number.
Information collected automatically
- Activity history. seed keeps a history of changes in each folder (who created, edited, completed or deleted what) so collaborators can see what happened.
- Usage counters. Monthly counts of agent requests, agent sends and document reads, your trial end date, and which people you invited have joined seed (for invite bonuses). We use these to apply plan limits.
- Read state. Which chats and threads you’ve read, used for unread counts and badges.
- App presence (iOS app). Whether the app is open on your phone right now. We use this to avoid sending you notifications while you’re using seed, and keep it for about a minute.
- Technical data. Our hosting provider, Cloudflare, processes your IP address, browser or device type and request details to deliver the service and protect it from abuse. We keep error logs to fix problems. They may contain request details, but we don’t use them to profile you.
Cookies and similar storage
seed uses one essential cookie to keep you signed in (nm_session, up to 30 days), and a short-lived cookie that protects sign-in from forgery. In your browser we also store small preferences locally, such as theme, panel widths and your last location in the app. We keep a local cache of documents you’ve already scanned so they aren’t read twice. We use no advertising, analytics or cross-site tracking cookies, so there’s no cookie banner to click through.
How we use it
- To provide seed: store and sync your content, show it to the people you’ve shared it with, send reminders and notifications, and run the features you use.
- To run AI features you ask for (see below).
- To act in connected services when you or your agent settings ask us to.
- To bill Pro subscriptions and apply plan limits.
- To keep seed secure, prevent abuse and fix problems.
- To contact you about your account, security, billing or important changes. We don’t send marketing email without your consent, and you can unsubscribe from any we do send.
- To meet legal obligations.
What we don’t do: sell or rent personal information, share it for cross-context behavioural advertising, build advertising profiles, or use your content to train AI models. We don’t look at your content except to do what you ask, like support. We also look when we must, to investigate abuse or security problems or to comply with the law.
AI features and your data
seed’s AI features are the agent (when you type @agent, or an outside system triggers it) and document reading (receipts and invoices in Financials). They run only when you use them. For each request, seed sends the AI provider only what that request needs. That can include:
- your message and recent messages in that chat or thread
- the folder’s items, notes and subtasks the agent looks up
- the folder’s agent role and your workspace knowledge base
- names of the people in the folder
- the text or image of a document being read
AI requests go through one of two routes:
| Route | Used when | What the provider may do with it |
|---|---|---|
| Google Gemini API, free tier | By default, first, if the workspace owner has “Use Google’s free AI tier” turned on. It’s never used when anyone involved has Google services connected (see below). | Under Google’s terms for its free tier, Google may use these requests and responses to improve its products, and human reviewers may read them. Don’t send information you consider sensitive while this is on. |
| OpenRouter, routed to the model’s provider | When the free tier is off, busy or unavailable, and for web searches. | seed requires zero data retention and no training on every request. OpenRouter only routes them to providers that commit to both. |
You can turn the free tier off. Workspace owners can switch off Settings › Agent › Use Google’s free AI tier. From then on, every AI request for the folders and financials they own goes only through the no-retention, no-training route.
When the agent searches the web, your search query is sent through OpenRouter to a search provider. You control which abilities the agent has in Settings › Agent, and whether it asks before acting in connected services. AI output can be wrong; please review what it does.
Google user data
seed’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Sign-in uses your basic profile (name and email) only to create and secure your account.
- Google Calendar (
calendar.events): create events you or your agent ask for. - Google Drive (
drive.file): open only the files you pick in Google’s picker, and files seed creates. seed can’t see the rest of your Drive. - Gmail (
gmail.send): send emails you or your agent ask for. seed cannot read your inbox. - Google Sheets (
spreadsheets): read or add rows to the spreadsheets you point the agent at.
We use Google user data only to provide these user-facing features. We don’t use it for advertising. We don’t sell it, and we don’t transfer it except as needed to provide the features, for security, or to comply with law. We don’t use Google Workspace data to develop, improve or train generalized AI or machine-learning models. Nothing obtained through Google APIs is sent to the free Gemini tier. Whenever you or the workspace owner has Google services connected, seed uses the no-retention, no-training route. Humans at seed don’t read your Google data unless you ask us to, it’s needed for security or legal reasons, or it has been aggregated and anonymized. You can disconnect any Google service in Settings › Integrations or at myaccount.google.com/permissions. Disconnecting deletes the stored token.
The iOS app
- Camera and photos are used only when you choose to photograph or pick a receipt or file. We never access them in the background.
- Push notifications are optional and controlled in the app’s notification settings. To deliver them we store your device’s push token and send the notification through Apple Push Notification service (APNs). If “Show message text” is on, the text of the message passes through Apple. Turn it off to receive a generic notice instead.
- App presence (whether the app is open) is used only to hold back notifications while you’re using seed.
- Your session is kept in the iPhone’s secure keychain.
- The app contains no advertising, analytics or tracking SDKs, and does not track you across other companies’ apps or websites.
Who we share it with
People you share with. Content in a folder or workspace is visible to the people given access to it, at the level the owner chose. Your name, colour and messages are visible to collaborators in folders you’re in.
Service providers who process data for us under contracts that limit its use:
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | Hosting, database, file storage, network security | All account data, content and files; IP addresses |
| Sign-in; Calendar, Drive, Gmail and Sheets actions you request; Gemini free-tier AI (if on); web fonts on this website | Profile; data for requested actions; AI request content as described above; IP address (fonts) | |
| OpenRouter and the model providers it routes to | AI requests and web search, with zero retention and no training | AI request content, search queries |
| Stripe | Payments for Pro | Billing email, payment details (collected by Stripe directly) |
| Apple | Push notifications to the iOS app | Push token, notification content |
| Slack | Posting to and receiving pins from a channel you link | Messages the agent posts; pinned message text |
| OpenStreetMap (Nominatim) | Finding an address when you add a location | The address text you type (sent from our servers, not your device) |
| jsDelivr | Delivers the on-device text reader used as a fallback for scanning | Your IP address when the reader downloads (your document stays in your browser) |
Legal and safety. We may disclose information if required by law, or to protect the rights, safety or property of our users, the public or seed. When the law allows, we’ll tell you first.
Business transfers. If seed is involved in a merger, acquisition or sale of assets, personal information may transfer as part of it. It would remain protected by this policy, and we’d give notice before it becomes subject to a different one.
Where data is stored
seed runs on Cloudflare’s global network, and our providers operate in the United States and other countries. Your information may be stored or processed outside Canada or your own country, including the United States, where it may be accessible to local authorities under local law. Where required, we use appropriate safeguards for international transfers, such as standard contractual clauses.
How long we keep it
- Your content stays until you or the workspace owner delete it. Deleted items go to Trash for 7 or 30 days (your setting), then are permanently deleted.
- Database backups may keep deleted data for up to 30 days more before it’s gone for good.
- Sessions expire after 30 days. Sign-in forgery tokens expire in minutes. App presence lasts about a minute.
- Connected-service tokens are deleted when you disconnect, or when the service tells us they’ve been revoked. Push tokens are deleted when Apple reports them invalid.
- AI requests: seed doesn’t store prompts separately from your chat. What the provider keeps depends on the route described in AI features.
- Billing records are kept as long as tax and accounting law requires, even after you close your account.
- If you delete your account, your personal information and the content you own are erased immediately, including uploaded files, and backups age out within 30 days. Exceptions are anything we must keep by law, and messages you posted in other people’s folders. Those are removed or anonymized.
Security
All traffic uses encrypted connections (TLS), and data is encrypted at rest by our hosting provider. Google and Slack tokens are additionally encrypted with our own key (AES-GCM). Sessions use secure, HTTP-only cookies. Access to every folder is checked on every request, including requests the agent makes on your behalf. We ask Google and Slack for the narrowest permissions that make each feature work. No system is perfectly secure. If a breach affecting your personal information creates a real risk of significant harm, we’ll notify you and the relevant regulators as the law requires.
Your choices and rights
Whatever the law where you live, you can:
- Access and export your information. Email us and we’ll send a machine-readable export.
- Correct it. Edit your name and content in the app, or ask us.
- Delete content in the app, or your whole account in Settings › General › Delete account. This works on the web and in the iOS app, and it cancels Pro and takes effect immediately. You can also ask us to do it.
- Withdraw consent: disconnect Google or Slack, turn off agent abilities, switch off the free AI tier, or turn off notifications.
- Complain to us, and to your privacy regulator. In Canada that’s the Office of the Privacy Commissioner of Canada (priv.gc.ca).
EEA, UK and Switzerland. We process your data to perform our contract with you (running seed). We rely on our legitimate interests for security, fixing problems and improving the service, and on your consent for optional connections and notifications. You have the rights of access, rectification, erasure, restriction, portability and objection, and can lodge a complaint with your local supervisory authority.
California and other US states. We don’t sell or share personal information for cross-context behavioural advertising, and we don’t use sensitive personal information for purposes that would need a right to limit. You can request to know, delete or correct your information, and we won’t discriminate against you for doing so.
We’ll respond within 30 days and may need to verify your identity first. Send requests to support@getcashflow.co.
Children
seed isn’t directed to children under 13 (or under 16 in the EEA and UK), and we don’t knowingly collect their personal information. If you believe a child has given us information, contact us and we’ll delete it.
Changes to this policy
We’ll update this page when our practices change, and change the effective date at the top. If a change is significant, such as a new kind of data or a new use of it, we’ll tell you in the app or by email before it takes effect.
Contact
Cash Flow Crescendo Inc., Ontario, Canada. Privacy questions and requests: support@getcashflow.co.