This Privacy Policy explains how Aqili, Inc. (“Aqili”, “we”, “us”) collects, uses, shares and keeps personal information when you use Seben, our document platform at app.seben.io, its desktop apps and its MCP server at api.seben.io, and when you visit our website, www.seben.io. Aqili, Inc. is a Delaware corporation at 131 Continental Dr, Suite 305, Newark, DE 19713.
What we collect
Account information. Your name, your email address and the identifiers your sign-in provider gives us. You sign in with Microsoft 365, through Microsoft Entra ID, or with email, through Microsoft Entra External ID. We do not receive your password.
Workspace information. The workspaces you belong to, your role in each, and the invitations you send or accept.
Your documents and what Seben derives from them. The PDFs you or your workspace upload, every version of them, and the data Seben creates from them: text recognized by OCR, layout data used for Office export, extraction results, and your conversations with the agent, including the steps it took.
Connected apps and API keys. The address of each app a workspace connects, and the credentials needed to call it, which Seben keeps on its servers and never shows back to you. For each workspace API key, a salted hash of the key, its name, who created it and when it was last used.
Billing information. Payments are processed by Stripe. You enter card details on Stripe’s pages, and we do not receive or store your full card number. We keep the plan, the subscription status and the Stripe identifiers we need to run a workspace’s billing.
Feedback. What you send with Send feedback: your message, its kind and the page you sent it from, stored with your name and email address.
Error reports. When the app hits an unexpected error while you are signed in, it sends us an error report automatically, without any action from you, and at most three each time the app loads. A report holds the error message, a technical trace of where in the app the error happened (up to 1,500 characters), the app’s build, the user agent of your browser or desktop app, and the path of the page you were on. We store it with your name and email address, as we do feedback.
Feedback and error reports are kept in Seben’s own database. We do not pass them to any other service.
Technical logs. Our servers record technical events, such as requests, errors and timings, which can include IP addresses and device details.
This website. It sets no cookies and loads no trackers or third-party scripts.
How we use information
- To provide Seben: store and show your documents, apply the changes you and the agent make, and keep each version.
- To run the features you use. The agent, extraction, OCR and Office export send the document content and instructions they need to the AI and document-analysis services described below.
- To keep Seben secure: check sign-in, enforce workspace membership, prevent abuse and investigate problems.
- To bill organization workspaces and manage their subscriptions.
- To answer your support requests and feedback, and to find and fix errors in Seben.
We do not sell personal information, and we do not use it for advertising.
AI processing
When you use the agent, extraction or another AI feature, Seben sends the parts of your documents and conversation that the request needs to an AI model and returns the result to you. The agent shows each step it takes.
Seben offers three AI models, all running on Microsoft Azure. GPT-5.4 mini is the default; you can choose GPT-5.6 Terra or Claude Sonnet 5 instead, in the agent panel or in Seben’s settings. The models come from two providers, whose terms differ.
GPT models. GPT-5.4 mini and GPT-5.6 Terra are OpenAI models that Microsoft hosts in its Azure cloud, through Azure OpenAI in Microsoft Foundry. Microsoft processes what Seben sends to these models as our service provider, under Microsoft’s data protection terms. Under those terms, the content Seben sends and the output it gets back are not available to OpenAI or to other Microsoft customers. They are not used to train generative AI foundation models without our permission, and we have not given it. Nor are they used to improve Microsoft’s or third parties’ products or services without our permission. Microsoft checks prompts and outputs automatically for abuse of its services, and content its systems flag can be stored by Microsoft in the United States and reviewed by authorized Microsoft employees. Microsoft does not state how long it keeps flagged content.
Claude. Claude Sonnet 5 is Anthropic’s model. Anthropic operates it on Microsoft Azure in the United States: Seben uses Claude in Microsoft Foundry, hosted on Azure. Anthropic processes what Seben sends it as our service provider, under Anthropic’s commercial terms and data processing addendum, and under those terms Anthropic may not train models on it. Claude’s prompts and outputs are processed in Azure in the United States. Only usage information, and content that Anthropic’s safety systems flag, leave Azure for Anthropic, which can keep flagged content for up to two years; anything else Anthropic stores stays in Azure in the United States.
Aqili does not use your documents or your conversations with the agent to train AI models. Apart from the apps and AI clients that you or your workspace’s owner connect or authorize (see “Who can see your information”), Seben sends your content only to the AI services named in this policy.
Where information is stored and processed
Documents are stored on Microsoft Azure in the United States.
Account and workspace records, document records, extraction results, agent conversations, feedback and error reports are stored in a Microsoft Azure database in the United States.
Seben’s servers, OCR and layout analysis run on Microsoft Azure in the United States. Each AI model runs as follows. Apart from content Anthropic’s safety systems flag (see below), only GPT-5.6 Terra’s prompts and outputs can be processed outside the United States:
- GPT-5.4 mini, the default, runs in Microsoft’s United States data zone, so its prompts and outputs are processed in the United States.
- Claude Sonnet 5 runs on Azure in the United States, where its prompts and outputs are processed. Usage information and content that Anthropic’s safety systems flag go to Anthropic; anything else Anthropic stores stays in Azure in the United States.
- GPT-5.6 Terra runs on Microsoft’s global deployment: Microsoft may process its prompts and outputs in any Azure region where it is available, while what Microsoft stores stays in the United States.
Some of Seben runs on global networks, so a request can pass through a data center near you: Azure Static Web Apps serves the web app’s files, Azure Front Door the email sign-in page, and Cloudflare this website.
If you use Seben from outside the United States, your information is transferred to the United States and processed there. Some of it can also be processed in other countries, for example: the prompts and outputs of GPT-5.6 Terra; requests that pass through the global networks above; what Microsoft Entra processes to sign you in and what Stripe processes for payments, under their own terms; and content Anthropic’s safety systems flag, once it leaves Azure for Anthropic.
Service providers
We use these companies to run Seben. Each processes information for us under its own terms.
- Microsoft Azure: hosting for Seben’s servers, document storage, databases, OCR and layout analysis, and logs, in the United States; and two global networks: Azure Static Web Apps for the web app’s files and Azure Front Door for the email sign-in page.
- Azure OpenAI in Microsoft Foundry: Microsoft’s service that runs the GPT models, GPT-5.4 mini and GPT-5.6 Terra.
- Anthropic: the Claude model, Claude Sonnet 5, which Anthropic operates on Microsoft Azure in the United States.
- Microsoft Entra: sign-in with Microsoft 365 and with email.
- Stripe: payments and subscriptions.
- Cloudflare: hosting of this website and DNS for seben.io.
Who can see your information
- Your workspace. In an organization workspace, its members can open the workspace’s documents and their versions. Your personal workspace is private to you.
- Apps connected to your workspace. A workspace’s owner can connect other apps to it. When you approve a call to a connected app, Seben sends that app what the approval shows, and the app’s own terms then apply.
- AI clients your workspace’s owner authorizes. The owner of an organization workspace can create workspace API keys. A key lets the client holding it, such as an AI assistant, read and edit that workspace’s documents, including ones other members uploaded, and that client’s own terms then apply.
- Service providers, as listed above.
- Legal reasons. We may disclose information when the law requires it, or to protect the rights, property or safety of Aqili, our users or others.
- Business transfers. If Aqili is part of a merger, acquisition or sale of assets, information may transfer as part of that deal, and this policy keeps applying to it.
How long we keep information
- Your documents and every version of them, including the version from before any redaction, stay until the document or its workspace is deleted.
- Deleting a document removes its files and layout data. Its extraction results and the agent conversations about it remain until the workspace is deleted, and a conversation can quote up to 2,000 characters of document text.
- Deleted files can be recovered for 7 days.
- Technical logs are kept for up to 90 days.
- Account and workspace records stay while the account or workspace exists, and are deleted when we delete it at your request.
- Feedback and error reports stay while your account exists and are deleted with it.
- Records we delete can stay in our database backups until those backups expire.
- There is no self-serve way to delete an account or a workspace yet. To delete either, email [email protected] and we will do it for you.
- Aqili keeps its own billing records for as long as tax and accounting law requires, generally up to seven years. Stripe keeps its billing records under its own terms.
- Microsoft and Anthropic keep what their safety systems flag as described in “AI processing”.
Security
Seben takes who you are from a validated sign-in token and what you can open from your workspace memberships, so documents in other workspaces are not visible to you. app.seben.io and api.seben.io accept only TLS 1.2 or newer. Workspace API keys are stored as salted hashes. The Security page has more, and you can report a vulnerability to [email protected].
Your choices and rights
You can download your documents at any time. To ask for a copy of your personal information, to correct it, or to have it deleted, write to [email protected]. Your name and email address come from your sign-in account. We answer every request, wherever you live, and we may need to confirm that the request comes from you, for example by replying to the email address on your account.
If you are in the European Economic Area or the United Kingdom
Aqili, Inc. is the controller of the personal information this policy describes. We use it on these legal bases:
- To perform our contract with you, or with the organization whose workspace you use: providing Seben, running the features you use, and billing.
- For our legitimate interests in running a secure and reliable service: keeping Seben secure, preventing abuse, finding and fixing errors, and answering feedback and support requests.
- To meet legal obligations, such as keeping billing records.
You have the right to access your personal information, to correct it, to have it deleted, to restrict or object to how we use it, and to receive it in a portable format. To use any of these rights, write to [email protected]; we answer within one month. You can also complain to the data protection authority where you live or work, or, in the United Kingdom, to the Information Commissioner’s Office.
Seben stores and processes information in the United States, and in other countries as described above, so using Seben from the European Economic Area or the United Kingdom means your information is transferred to the United States, where data protection law differs from yours. Our service providers protect the information they process for us with safeguards such as the European Commission’s standard contractual clauses and, for the United Kingdom, the International Data Transfer Addendum.
If you are a California resident
In the past 12 months we have collected these categories of personal information, from you, from your organization, from your sign-in provider and from Stripe: identifiers, such as your name, email address, account identifiers and IP address; commercial information, such as a workspace’s plan and subscription; internet and other electronic network activity, such as technical logs and error reports; and the content of the documents and messages you put into Seben, which may contain any kind of information. We use them for the purposes in “How we use information”, and we disclose them for those purposes to the service providers listed above. We keep them for the periods in “How long we keep information”.
We do not sell or share personal information, as California law defines those terms, and we have not done so in the past 12 months. We do not knowingly sell or share the personal information of anyone under 16. We use sensitive personal information, such as any in your documents, only to provide Seben to you.
You have the right to know what personal information we collect, use and disclose, and to ask us to delete or correct it. You will not be treated differently for using these rights. To use them, write to [email protected]. We confirm the request comes from you by replying to the email address on your account. An authorized agent can make a request for you with your signed permission, and we may ask you to confirm it directly.
Children
Seben is not meant for anyone under 18. You must be at least 18 to create an account. If we learn that we hold personal information from someone under 18, we will delete it.
Cookies and browser storage
Seben uses no advertising or analytics cookies and no trackers. The web app keeps your sign-in session and your settings in your browser’s storage; the desktop app keeps your settings the same way and your sign-in session in an encrypted file on your device. The Microsoft sign-in pages use the cookies they need to sign you in. This website sets no cookies; it remembers your theme choice in your browser’s local storage.
Changes to this policy
When we change this policy, we will post the new version on this page and update the date at the top.
Contact
Privacy questions and requests: [email protected]. Security reports: [email protected]. Everything else: [email protected]. By post: Aqili, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713.