Privacy Policy
Sequesign Inc. (“Sequesign,” “we,” “us,” or “our”) provides a cryptographic receipt, witness, and audit-trail platform for AI agent actions. This Privacy Policy explains what information we collect, how we use it, when we disclose it, how long we retain it, and what choices and rights may be available to you.
This Privacy Policy applies to Sequesign websites, applications, dashboards, APIs, software development kits when they communicate with our hosted services, and related services (collectively, the “Services”).
1. Our privacy posture
Sequesign is designed to minimize the data we hold.
Our default hash-only mode means that Sequesign does not receive or store the underlying evidence content your agents act on. In that mode, we store only cryptographic hashes and associated metadata needed to verify receipts and operate the witness service.
If you choose hosted evidence storage, Sequesign stores evidence bytes for you under your configured retention policy. We do not use evidence content to train AI models, sell advertising, build user profiles for advertising, or analyze your evidence content for our own commercial purposes.
2. Roles under privacy laws
For account data, website data, billing data, authentication data, service administration data, security data, and our own business records, Sequesign generally acts as an independent controller or business.
For customer content submitted to the hosted evidence storage service, Sequesign generally acts as a processor or service provider on behalf of the customer, except where we process limited information for our own security, legal compliance, billing, fraud prevention, service integrity, and other legitimate business purposes.
For hash-only mode, Sequesign generally acts as a processor or service provider for customer-controlled receipt metadata, and as an independent controller or business for limited operational, security, billing, and witness-log metadata that Sequesign determines for the integrity of the Services.
If you use Sequesign on behalf of an organization, your organization may be the controller or business responsible for deciding what evidence content is submitted to the Services and how it is used. Where Sequesign acts as a processor or service provider, the applicable Data Processing Addendum governs that processing.
3. Information we collect
3.1 Account and authentication information
When you create an account, sign in, or administer an organization, we may collect:
- Email address
- Name
- Organization name and role, if provided
- Authentication identifiers and session metadata provided by WorkOS
- IP address, device information, browser type, and user agent at authentication
- Security events, such as login attempts, session creation, account changes, and access failures
We do not receive or store your password when authentication is handled by WorkOS or an identity provider.
3.2 Billing and subscription information
When you subscribe to a paid tier or use metered services, we may collect:
- Billing email
- Customer and subscription identifiers from Stripe
- Subscription tier, pricing model, billing status, and invoice history
- Aggregate usage counters, such as signatures per month and bytes stored per month
- Tax, payment status, and transaction records needed for accounting and compliance
We do not store complete credit card numbers or bank account credentials. Stripe processes payment instruments on our behalf.
3.3 Receipt metadata
For receipts produced through the Services, we may store metadata needed to operate and verify the receipt and witness system, including:
- Cryptographic hash or content-addressed identifier of a receipt envelope
- Chain identifier
- Schema, protocol, or profile identifier
- Witness signature and related verification data
- Retention policy applied to the receipt
- Finalization, witnessing, and verification timestamps
- Agent identity, signing key identifier, organization identifier, or workspace identifier associated with the receipt
- Identifiers of attestation participants, such as approver or counterparty names, email addresses, or public keys, where the customer includes them in a receipt or attestation
- Status and integrity information associated with receipt verification
Receipt metadata is used to operate the witness log, support independent verification, enforce retention policies, detect abuse, and provide customer dashboards and audit tooling.
3.4 Evidence content in hash-only mode
In hash-only mode, Sequesign does not store the underlying evidence content your agents produce, observe, or act on. You retain the underlying evidence bytes. Sequesign stores only the hash and limited metadata required for verification.
If a hash-only receipt is later challenged or verified, the party seeking verification must supply the underlying bytes. Sequesign cannot produce evidence content that it does not have.
3.5 Evidence content in hosted storage mode
If you choose hosted evidence storage, Sequesign stores the evidence bytes you submit to the Services. Hosted evidence is stored in object storage operated by Cloudflare R2 on our behalf. Hosted evidence may be stored using content-addressed keys derived from cryptographic hashes.
We process hosted evidence content only as needed to provide the Services, including storage, retrieval, verification, export, deletion, retention enforcement, security, troubleshooting, and compliance with applicable law and contractual obligations.
We do not use hosted evidence content to train AI models. We do not use hosted evidence content for advertising. We do not sell hosted evidence content.
The hosted verifier at verify.sequesign.com runs entirely in your browser. Receipt content evaluated by the hosted verifier is not transmitted to Sequesign.
3.6 Operational and usage information
We collect technical information needed to operate, secure, debug, and operationally improve the Services, including:
- API request logs, including timestamps, endpoints, response codes, request sizes, latency, and account or organization identifiers
- Error logs and diagnostic events
- Security logs and abuse-prevention signals
- Aggregate reliability, capacity, and usage metrics
- Witness log entries and verification events
We do not intentionally include evidence content or receipt bodies in operational logs. Customers should not place secrets, regulated information, or evidence content in fields intended for identifiers, labels, names, descriptions, or support messages unless they intend for that information to be processed as account, support, or operational data.
3.7 Communications and support information
If you contact us, request support, participate in sales discussions, or subscribe to updates, we may collect:
- Contact information
- Communications with us
- Support tickets and related diagnostic information
- Preferences for product, security, billing, and marketing communications
You may opt out of non-transactional marketing emails. We may still send transactional or service-related messages.
3.8 Cookies and similar technologies
We use first-party cookies and similar technologies that are necessary for authentication, session management, security, preferences, and operation of our websites and dashboard.
As of the effective date above, Sequesign does not use third-party advertising cookies or cross-context behavioral advertising technologies on its websites. If we add analytics, advertising, or tracking technologies later, we will update this Privacy Policy and provide any required choices or notices before or when those technologies are deployed. See our Cookie Notice at sequesign.com/cookies for more detail.
3.9 Categories of personal information under U.S. state law
The following table summarizes the categories of personal information we collect, using the category framework of the California Consumer Privacy Act, together with the sources of that information.
| Category | What we collect | Sources |
|---|---|---|
| Identifiers | Name, email, organization and user identifiers, IP address, authentication and session identifiers, and identifiers associated with receipts, agents, and attestation participants such as approvers and counterparties | You and your organization; WorkOS; automatically through your use of the Services |
| Commercial information | Subscription tier, billing status, invoice and transaction records, and aggregate usage counters | You; Stripe; automatically through your use of the Services |
| Internet or network activity | API request logs, device and browser information, error and security logs, and aggregate usage metrics | Automatically through your use of the Services |
| Professional or employment information | Organization name and your role, where provided | You and your organization |
| Geolocation | Coarse location inferred from IP address only; we do not collect precise geolocation | Automatically through your use of the Services |
| Sensitive personal information | Account log-in and authentication credentials used to access your account | You; WorkOS |
| Communications | Support tickets, sales and support correspondence, and communication preferences | You |
We do not create profiles or inferences about individuals for advertising or to predict personal characteristics. We disclose these categories only to the service providers listed in Section 6.1, for the purposes described in Section 4, and as otherwise permitted or required by law. The sensitive personal information we collect is limited to account log-in and authentication credentials, which we use only to provide and secure the Services.
4. How we use information
| Purpose | Examples |
|---|---|
| Provide and administer the Services | Create accounts, operate APIs, run the witness service, store hosted evidence, serve receipts, verify receipts, enforce retention policies |
| Authenticate users and secure accounts | Login, session management, access control, security alerts |
| Process payments and manage subscriptions | Billing, invoices, taxes, payment status, usage metering |
| Operate and improve infrastructure | Monitoring, debugging, reliability, capacity planning, product quality |
| Protect the Services and users | Fraud prevention, abuse detection, incident response, vulnerability response |
| Communicate with you | Security notices, billing notices, support responses, service updates, product announcements where permitted |
| Comply with law | Legal requests, tax records, regulatory obligations, dispute handling |
Our purposes for processing include operating, securing, improving, and protecting the Services; preventing fraud and abuse; enforcing our agreements; complying with law; and supporting customer use of cryptographic receipt and audit-trail infrastructure.
Sequesign does not use personal information to engage in automated decision-making that produces legal or similarly significant effects concerning individuals.
5. What we do not do
Sequesign does not:
- Sell personal information
- Share personal information for cross-context behavioral advertising
- Use evidence content to train AI models
- Use evidence content to build advertising profiles
- Authorize sub-processors to use customer data for their own marketing or advertising purposes
- Intentionally log evidence content in operational logs
6. How we disclose information
We disclose information only as described in this Privacy Policy, with your direction, or as otherwise permitted or required by law.
6.1 Service providers and sub-processors
We use service providers and sub-processors to operate the Services. They may process information only as needed to provide services to Sequesign and under contractual restrictions.
Current core providers include:
| Provider | Role | Categories of information |
|---|---|---|
| Cloudflare | Object storage, CDN, security, and related infrastructure | Hosted evidence content when enabled, website and infrastructure data |
| Fly.io | Application hosting | Account, receipt metadata, operational, and service data processed by backend services |
| Railway | Landing page and marketing website hosting | Website visitor and request data, and information submitted through website forms such as contact requests |
| Neon | Managed PostgreSQL hosting | Account data, receipt metadata, billing references, operational data |
| Stripe | Payment processing | Billing, payment status, subscription, invoice, and tax-related data |
| WorkOS | Authentication and single sign-on | Authentication identifiers, session metadata, organization and user login data |
| Resend | Transactional and notification email delivery | Recipient email address and the contents of service, security, and account emails |
| Microsoft | Business email and productivity | Email and communications sent to or from Sequesign, including support and sales correspondence |
When Sequesign acts as a processor or service provider, we will provide advance notice of new sub-processors and an opportunity to object, as set out in the applicable Data Processing Addendum. We may otherwise update our provider list as the Services evolve, and material changes will be reflected in this Privacy Policy or a sub-processor notice, where applicable.
6.2 Customers, organizations, and administrators
If you use the Services through an organization account, organization administrators may be able to access information associated with that organization, including users, roles, receipt metadata, hosted evidence configured for that organization, retention policies, usage, and audit activity.
6.3 Legal, safety, and compliance disclosures
We may disclose information if we believe disclosure is necessary to comply with a subpoena, court order, legal process, regulatory request, or applicable law. We may also disclose information to protect the rights, property, or safety of Sequesign, our users, our providers, or others.
Where legally permitted and reasonably practicable, we will notify affected customers before disclosing their data in response to legal process. We may challenge requests that we believe are unlawful, overbroad, or inappropriate.
For hash-only mode, Sequesign does not have the underlying evidence content to disclose. We may still disclose account information, receipt metadata, operational records, billing records, or other information we hold if legally required.
6.4 Business transfers
If Sequesign is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be disclosed to or transferred as part of that transaction, subject to appropriate confidentiality protections. Any successor will be required to honor this Privacy Policy or provide notice of any material changes.
7. Retention
We retain information only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law, contract, security needs, or dispute resolution.
| Category | Typical retention |
|---|---|
| Account data | For the life of the account, plus a reasonable period after closure for security, audit, billing reconciliation, and dispute handling |
| Billing and tax records | As required by tax, accounting, and financial laws, commonly up to 7 years |
| Receipt metadata | For the lifetime of the receipt or witness log entry, subject to applicable retention settings and service design |
| Hosted evidence content | According to the configured retention policy, subject to any minimum retention floor, legal hold, export window, or contractual requirement |
| Free-tier hosted evidence | Subject to any minimum retention floor stated for the applicable free tier |
| Operational logs | Typically 30 to 90 days, depending on log type, unless retained longer for security, fraud prevention, debugging, legal, or audit reasons |
| Support communications | For the period needed to resolve and document the matter and maintain account history, then deleted or de-identified unless a longer period is required for legal, audit, or dispute purposes |
Retention extensions may be available through customer settings. Reductions to already-committed hosted evidence retention windows may require operator review to protect audit integrity, contractual expectations, legal holds, and system consistency.
When information is no longer needed, we delete it, de-identify it, aggregate it, or retain it only where permitted or required by law.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including:
- TLS encryption in transit for API and web traffic
- Storage-layer encryption at rest provided by infrastructure providers
- Authentication-required access to customer-facing systems
- Role-based access controls for internal systems
- Logging and review of internal access where appropriate
- Tamper-evident witness log design using cryptographic signatures and chaining
- Security monitoring, incident response, and periodic security reviews
- Vulnerability reporting and remediation processes
No method of transmission, storage, or processing is perfectly secure. We cannot guarantee absolute security. If we determine that a security incident has affected personal information, we will notify affected customers or users as required by applicable law and any applicable written agreement. Where Sequesign acts as a processor or service provider, breach-notification timing and process are governed by the applicable Data Processing Addendum.
Security reports may be sent to security@sequesign.com.
9. International transfers
Sequesign is based in the United States, and the Services are operated from the United States and other locations where we or our providers process information. As described in our Terms of Service, Sequesign does not currently target or localize the Services for the European Economic Area, the United Kingdom, or Switzerland.
Hosted evidence content and other customer data are stored and processed in the United States. Sequesign does not currently offer regional data residency options or in-region storage for any particular jurisdiction. Receipt metadata and registration and attestation records may include personal information, such as approver and counterparty email addresses, names, and public keys, in addition to any personal information contained in hosted evidence content.
If we begin offering the Services in those jurisdictions, or if personal information is transferred from a jurisdiction with cross-border transfer restrictions, we will implement the appropriate safeguards required at that time, such as Standard Contractual Clauses, an adequacy mechanism, or a data processing agreement.
10. Your choices and rights
Depending on your location and how you use the Services, you may have rights to:
- Request access to personal information we hold about you
- Request correction of inaccurate personal information
- Request deletion of personal information, subject to legal, contractual, security, billing, and audit-retention exceptions
- Request export or portability of personal information
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Opt out of certain marketing communications
- Appeal a privacy-rights decision where applicable law provides an appeal right
To exercise rights, email privacy@sequesign.com or use any rights-request form we make available. We may verify your identity before responding. If you use the Services through an organization, we may direct your request to that organization or coordinate with that organization where appropriate.
11. European, UK, and Swiss users
The Services are operated from the United States and, as described in our Terms of Service, are not currently targeted at or localized for the European Economic Area, the United Kingdom, or Switzerland.
If the GDPR, UK GDPR, or a similar law becomes applicable to our processing, we will provide the disclosures those laws require, including the identity of the controller, the purposes and legal bases of processing, the recipients of personal information, retention periods, data subject rights, international-transfer safeguards, and the right to lodge a complaint with a supervisory authority.
Where Sequesign processes customer content as a processor, the customer organization is generally responsible for responding to data subject requests concerning that content, and Sequesign will assist as required by the applicable Data Processing Addendum.
12. United States state privacy rights
12.1 California
California residents may have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including rights to:
- Know the categories and specific pieces of personal information collected
- Know the categories of sources, purposes, and third parties involved
- Request deletion of personal information, subject to exceptions
- Request correction of inaccurate personal information
- Opt out of sale or sharing of personal information
- Limit certain uses or disclosures of sensitive personal information, where applicable
- Not be discriminated against for exercising privacy rights
Sequesign does not sell personal information and does not share personal information for cross-context behavioral advertising. Sequesign does not use sensitive personal information for purposes that require a right to limit under California law unless we provide an additional notice and choice. The categories of personal information we collect, their sources, and the categories of recipients are described in Sections 3.9 and 6.1.
To exercise California rights, contact privacy@sequesign.com. Authorized agents may submit requests by contacting the same address. We may require proof of authorization and identity verification before fulfilling a request. See also our Do Not Sell or Share page at sequesign.com/do-not-sell.
12.2 Other U.S. states
Residents of other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, and a growing number of others, may have similar rights to access, correct, delete, and obtain a portable copy of their personal information, to opt out of targeted advertising, sale, and certain profiling, and, where provided by law, to appeal a decision on a privacy request. You may exercise these rights using the contact methods in Section 10.
Where required by applicable state law, Sequesign honors recognized opt-out preference signals, such as the Global Privacy Control, for opt-outs of sale, sharing, or targeted advertising. As noted above, Sequesign does not sell or share personal information or engage in targeted advertising.
13. Children
The Services are intended for business and organizational use by adults and are not directed to children under 13 years old, or under 16 years old where a higher minimum age applies under applicable law. We do not knowingly collect personal information from children. If you believe a child has provided personal information to Sequesign, contact privacy@sequesign.com and we will take appropriate steps to delete it.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by email, in-product notice, or posting on our website, as appropriate. The updated policy will be effective as of the date stated in the policy unless a later effective date is provided.
Archived versions are available in our policy changelog at sequesign.com/changelog.
15. Contact us
For privacy questions, rights requests, or concerns, contact:
Sequesign Inc.
Email: privacy@sequesign.com
Security reports: security@sequesign.com
Mailing address: 8 The Green, Suite B, Dover, DE 19901