Privacy Policy

Effective: March 1, 2026

Version 1.1 — Last updated May 8, 2026

At seashellOS, we take your privacy seriously. This Privacy Policy outlines how we collect, use, store, and protect your personal information when you use our mobile application (seashellOS for iOS) and our web application (seashell-os.com).

By using our platforms, you agree to the collection and use of information in accordance with this Privacy Policy.

1. Information We Collect

We collect several different types of information to provide and improve our services to you.

A. Personal Identification Data

  • Account Information: Name (first and last), email address, phone number, company name, nickname, and profile photos (stored as encoded image data in our database).
  • Mailing Address: Street address, city, state, and ZIP code (optional, for invoicing and business correspondence).
  • Event & Relationship Data: For event-based industries (e.g., weddings), we may collect event dates, venue names, partner names, partner contact information, and wedding planner contact details.
  • Terms of Service Acceptance: We record when you accepted our Terms of Service, the version accepted, and the IP address at the time of acceptance.

B. Authentication & Security Data

  • Passwords: Stored using bcrypt one-way hashing (never in plaintext). We never have access to your actual password.
  • Passkeys (WebAuthn): If you register a passkey, we store your public key, credential ID, device name, and usage counter. Your private key never leaves your device.
  • Sign in with Apple: If you authenticate via Apple, we receive your Apple identity token and authorization code. Apple may share your name and email on first sign-in per your Apple ID settings.
  • Biometric Preferences: If you enable Face ID, Touch ID, or Optic ID on iOS, biometric data is processed entirely on your device by Apple's Secure Enclave and is never transmitted to our servers. We only store a preference flag indicating that you enabled biometric unlock.

C. Financial and Transactional Data

  • Invoicing: Invoice amounts, due dates, payment status, payment method type (card, ACH, check, cash, Zelle, Venmo, wire transfer), and payment references.
  • Card Information: We store only the card brand (e.g., Visa, Mastercard) and last 4 digits. We never store full credit card numbers on our servers. Full payment processing is handled by Stripe or Square.
  • Bank Account Data (Plaid): If you link a bank account, Plaid securely connects to your financial institution. We store your Plaid access token encrypted at rest using AES-256-GCM encryption, along with institution name, account name, account type, last 4 digits of the account, and current balances.
  • Bank Transactions (Plaid): When you sync transactions, we store transaction amounts, merchant names, dates, categories, payment channels, and enrichment data provided by Plaid (including merchant logos, websites, and counterparty details).
  • Payment Consent: We record the timestamp and IP address when you consent to be charged.
  • Stripe Connect: If you are a studio owner (tenant), your Stripe Connected Account ID, payout schedule, and payout bank last 4 digits are stored for payment processing.

D. Usage and Device Data

  • IP Addresses: We collect your IP address at account signup, Terms of Service acceptance, payment consent, and during administrative actions for our audit log.
  • Login Activity: We record the timestamp of your last login.
  • Audit Logging: All administrative actions (e.g., creating clients, updating invoices, modifying settings) are logged with the actor's email, IP address, action type, and timestamp. These logs are retained for compliance and security purposes.
  • Device Tokens: On iOS, if you enable push notifications, we store your Apple Push Notification service (APNs) device token to deliver notifications.

E. User-Generated Content

  • Galleries and Media: Photos uploaded to galleries, cover photos, logo files, and gear photos.
  • Videos: Video deliverables and associated metadata, including Frame.io asset references if the Frame.io integration is enabled.
  • Messages: Messages sent via the platform, including subject lines, content, and attachments.
  • Contracts and E-Signatures: Digital contracts (e.g., Photography Agreements), including HTML content and captured e-signature images (stored as encoded image data).
  • Documents: Uploaded files and linked documents shared between studio owners and clients.
  • AI Conversations: If you use Shello (our AI assistant), your conversation history (prompts and responses) is stored in our database.

F. Location Data

  • Transaction Locations: When you sync bank transactions via Plaid, merchant location data may be included — specifically city, region, country, and in some cases latitude and longitude coordinates. This data originates from Plaid's merchant enrichment, not from your device's GPS.
  • Shoot/Event Locations: Booking requests and projects may include text-based location descriptions (venue names, shoot locations) that you provide.
  • Mailing Addresses: Client addresses stored for invoicing purposes.

We do not request GPS or geolocation permissions on any platform. The seashellOS iOS app does not access your device's location services.

G. Notification Preferences

We store your preferences for receiving notifications across categories including: invoices, payments, project status updates, messages, video deliverables, revision completions, event reminders, and general updates. We also store your preferred contact method, best time to reach you, and timezone.

2. How We Use Your Information

seashellOS uses the collected data for the following purposes:

  • To Provide and Maintain Our Service: Ensuring the iOS app and web platform function correctly, handling client portals, managing multi-tenant studio isolation, and securing your accounts.
  • To Process Payments: Handling Stripe invoices, Square payments, Plaid bank account linking, and ACH transfers securely.
  • To Personalize AI Experiences: Providing AI-assisted features through our Shello assistant (detailed in Section 3).
  • To Communicate with You: Sending automated emails including invoice notifications, payment reminders, booking confirmations, password resets, invitation links, video-ready alerts, contract updates, and message digests.
  • To Maintain Security and Compliance: Logging administrative actions, tracking consent, and maintaining audit trails for regulatory compliance.
  • To Sync Calendars: If you connect Google Calendar, syncing project dates and invoice due dates to your calendar.

3. Artificial Intelligence (AI) and Machine Learning

Our platform integrates AI technologies to assist users through our AI assistant, Shello. Shello can help with drafting messages, parsing financial insights, generating contract content, and managing workflow.

AI Providers We Use

  • Anthropic Claude (primary) — Our default AI model for conversation, drafting, and business intelligence.
  • Perplexity Sonar Pro (supplementary) — Used when your query requires live, real-time web information.
  • Google Gemini (supplementary) — Used when the conversation context is exceptionally large.

The AI model is selected automatically based on your request.

Data Shared with AI Providers

When you use Shello, relevant business context may be sent to the AI provider processing your request. This context is configurable by studio owners through data access settings and may include:

  • Studio name, business type, and AI persona settings (always included)
  • Active project titles, statuses, and event dates (if enabled)
  • Client names, emails, and company names (if enabled)
  • Overdue invoice summaries — invoice number, amount, and days overdue (if enabled)
  • Upcoming calendar events for the next 7 days (if enabled)
  • Recent message activity from the last 48 hours (if enabled)
  • Connected integration names (if enabled)
  • Monthly revenue summaries and payout history (only if explicitly enabled by the studio owner — disabled by default)

You can change these settings at any time in Settings → Shello. When a toggle is turned off, the corresponding database query is never executed — that data is never retrieved, transmitted, or processed by any AI provider.

Data Never Shared with AI

  • Passwords or authentication credentials
  • Full credit card or bank account numbers
  • Individual bank transaction details
  • Raw customer financial data
  • Gallery photos or uploaded media files

No Training on Your Data: Our agreements with AI providers prohibit them from using your data to train their foundational models. Only data strictly necessary for fulfilling your specific prompt is transmitted over encrypted connections.

4. Third-Party Services and Data Sharing

We do not sell your personal data. We share necessary information with the following trusted third-party services to operate our platform:

  • Stripe — PCI DSS Level 1 certified payment processor. Handles invoice processing, connected accounts, and payouts. Card details are entered directly into Stripe's secure elements; we never see or store full card numbers, CVVs, or expiration dates. Stripe receives customer name, email, and transaction amounts.
  • Plaid — Secure bank account linking and transaction synchronization. You authenticate directly with Plaid's interface; we store encrypted access tokens.
  • Square — Optional payment processing for studios that connect their Square account via OAuth.
  • Helcim — Optional PCI-compliant payment processing for studios that connect their Helcim merchant account. Like Stripe Connect, funds flow directly to the studio's bank account.
  • Resend — Email delivery service. Receives recipient email addresses and email content for all automated platform emails (invoices, reminders, notifications, etc.).
  • Google Calendar — Optional calendar sync via OAuth. Receives project/event details (titles, dates) to create calendar entries. Requires read/write calendar access.
  • Frame.io (Adobe) — Optional video collaboration integration via Adobe IMS OAuth. Receives video metadata and asset references.
  • Anthropic (Claude) — AI assistant processing. Receives business context as described in Section 3.
  • Perplexity — Supplementary AI for live web queries. Receives the same context as Claude when invoked.
  • Google (Gemini) — Supplementary AI for large-context processing. Receives the same context as Claude when invoked.
  • Apple — Sign in with Apple authentication (iOS app). Apple processes your authentication per their privacy policy.

These third parties have access to your personal data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

5. Data Storage and Security

  • Database: Data is stored in PostgreSQL with Row-Level Security (RLS) enforcing strict multi-tenant isolation. Each studio's data is logically separated at the database level.
  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using HTTPS/TLS.
  • Encryption at Rest: Plaid access tokens are encrypted using AES-256-GCM before storage. Passwords are hashed with bcrypt (10 rounds).
  • Security Headers: We employ HTTP security headers including Content-Security-Policy, Strict-Transport-Security (HSTS), X-Content-Type-Options, and X-Frame-Options.
  • Rate Limiting: Login attempts are limited to 10 per 15 minutes (per IP and email). Registration attempts are limited to 5 per hour.
  • iOS App Security: Authentication tokens and user credentials are stored in Apple's Keychain (not in app preferences). Biometric data is processed by Apple's Secure Enclave and never leaves your device.
  • Access Controls: Profile photos and media assets are protected with rate limiting and CORS restrictions.
  • Infrastructure: Backend services run on Google Cloud Platform (Google Kubernetes Engine) in US data centers. The frontend is hosted on Vercel. Both providers maintain SOC 2 compliance and industry-standard physical and network security.
  • Platform Operations Access: Designated SeashellOS staff (SuperAdmins) may access platform infrastructure to provide support, investigate security or billing issues, and ensure reliability. SuperAdmin access is recorded in an immutable audit log capturing the actor's email, IP address, action type, and timestamp. SuperAdmins do not access tenant data outside the scope of these operational responsibilities.

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

6. Data Retention and Deletion

Retention

  • Account data is retained for the duration of your account.
  • Financial transaction data (from Plaid) and invoice records are retained indefinitely for tax reporting and compliance purposes, unless you request deletion.
  • Audit logs (administrative actions, IP addresses) are retained permanently for security and compliance.
  • AI conversation history is retained until account deletion.

Account Deletion

  • Individual Users: Can request account deletion. Deletion removes all associated invoices, projects, messages, videos, and contracts.
  • Studio Owners (Tenants): Can submit an account closure request. Upon approval, a 30-day grace period begins during which you may cancel the request. After the grace period, all tenant data is permanently purged — including all users, projects, invoices, messages, integrations, and linked financial data. Stripe Connected Accounts are preserved separately by Stripe.

Deletion is permanent and cannot be reversed after the purge is completed.

7. Your Data Rights

Depending on your geographic location (e.g., GDPR in the European Union, CCPA in California), you may have the right to:

  • Access the personal information we hold about you.
  • Update or correct inaccurate information.
  • Request deletion of your personal data (subject to the process described in Section 6).
  • Request a copy of your personal data in a standard format.
  • Withdraw consent for specific data processing.
  • Object to or restrict certain processing activities.
  • Manage your notification preferences and opt out of non-essential communications through your account settings.

To exercise these rights, please contact us at support@seashell-os.com.

8. iOS App Specifics

If you use the seashellOS iOS app:

  • No Device Tracking: The app does not collect your device's Advertising Identifier (IDFA), does not use App Tracking Transparency (ATT), and does not track you across other apps or websites.
  • No Location Access: The app does not request access to your device's location services.
  • No Photo Library Access: The app does not request access to your device's photo library or camera. Media is displayed from server URLs only.
  • Push Notifications: If you grant permission, the app registers for push notifications and stores your device token to deliver alerts for messages, invoices, and project updates. You can disable notifications at any time through iOS Settings.
  • Face ID / Touch ID: If you enable biometric unlock, authentication is handled entirely on your device by Apple's Secure Enclave. Your biometric data is never transmitted to or stored on our servers.
  • Offline Caching: The app caches limited project, invoice, and message data locally on your device (via Apple's SwiftData framework) for offline access. This cache is cleared upon logout.

Apple's Privacy Policy also applies to your App Store interactions, including your Apple ID and Apple Pay.

9. Communications and Email

We send automated emails through our email service provider (Resend) for essential platform functions including:

  • Account invitations and signup confirmations
  • Password reset links
  • Invoice delivery and payment reminders
  • Booking confirmations and rejections
  • Video-ready and revision-complete notifications
  • Message digests
  • Account closure notices

You can manage your notification preferences in your account settings to control which categories of email you receive. To opt out of all non-essential communications, update your notification preferences or contact us.

10. Children's Privacy

seashellOS is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected data from a minor, please contact us immediately.

11. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top. We encourage you to review this Privacy Policy periodically.

12. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or need to report a privacy concern, please contact us at: