SeaOtter / Privacy
Privacy Policy
In plain words, first
You choose what to send. We use it to run your job.
SeaOtter is a web service. You can describe work by typing, speaking, or attaching files. We use that material to write the list you confirm, send the job to a worker team, check the delivery, and settle the job. We do not collect work from unrelated apps or files.
When you describe the job
We receive the words you type, the transcript of speech you send, links, and files you choose to attach. Voice audio is streamed for transcription; SeaOtter does not save it as a job attachment unless you choose to upload a recording.
When you confirm what done means
We store the confirmed list, attached references, quoted price, and confirmation record. That contract guides the work, the checks, payment, and any dispute.
While the work is done and checked
The assigned worker team receives the job material it needs. We store job messages, progress, submitted work, check results, evidence, and receipts.
When money moves
Stripe processes top-ups and payouts. We keep the related account, balance, hold, invoice, transaction, and reconciliation records needed to run the service and meet legal obligations.
Your controls at a glance
Running a job and training our systems are separate
Submitting a job allows SeaOtter and the assigned worker team to use the material needed to contract, complete, check, support, and settle that job. It does not by itself place the job in a training corpus.
Job use
Limited to delivering the service
We use job material to create the contract, do the work, check the result, handle support or disputes, and keep required records.
Training
Off unless people grant it
A job episode is eligible only when every affected party has an explicit grant covering every modality in that episode. No grant means no training use.
By modality
The grant states what it covers
A grant can cover text, image, video, audio, document, spreadsheet, code, archive, or other submitted material. Missing coverage keeps the whole episode out.
Revoke or erase
Future training use stops
Revocation makes covered episodes ineligible. A later grant applies only to future collection. Erasure removes covered capture records and returns deletion receipts.
For access, export, revocation, or erasure requests, contact: privacy@seaotter.ai
We state what was removed and identify anything that must remain for legal, tax, security, fraud-prevention, or dispute purposes.
Deletion path
Deletion is carried out and receipted
A request identifies the job, account, or training-consent subject in scope. The service then uses the deletion path for those records instead of treating a hidden row as deletion.
Request: identify the records
For a closed job, use the job's artifact-delete control. For account-wide or cross-system requests, email privacy@seaotter.ai from the address connected with the work.
Remove: erase controlled content
Managed job files are physically deleted and their rows are tombstoned. Training grants are revoked, captured episode content rows are removed, and a deletion receipt and non-trainable tombstone remain.
Receipt: record what happened
Deletion receipts name the records or artifacts removed, when and why they were removed, and the requester. A deletion that cannot be verified is not reported as complete.
1. What this page covers
SeaOtter is a web service for describing work, agreeing what done means, assigning work to people and their agents, checking delivered artifacts, and settling payment through a prepaid balance and Stripe.
This policy covers the public website, buyer and worker accounts, job intake by text or voice, uploaded references, confirmed contracts, job messages and progress, delivered artifacts, check evidence, support and dispute records, training-consent records, and billing or payout records.
2. What we collect
- Intent and contract material: the words you type, speech transcripts, links, questions and answers, files or recordings you attach, the list you confirm, reference anchors, quoted price, and confirmation record.
- Work and delivery records: assignment and status events, job messages, milestones, worker submissions, interim previews, delivered files, check results, evidence, receipts, escalation records, and closing feedback.
- Account and contact records: email address, name or organization details you provide, account role, authentication and session records, notification choices, and security events.
- Money records: balance movements, holds, top-ups, credit, draws, refunds, payouts, invoices, tax facts, and Stripe account, status, and transaction references.
- Consent and rights records: terms acceptance, training choices and their scope or modality, grant and revocation times, exports, erasure requests, and deletion receipts.
- Technical and usage records: IP address and request metadata used for security and regional policy, service logs, cookie choices, and consented analytics or minimized performance events described below.
3. How we use your data
- Turn your request into a contract you can review and confirm.
- Assign the work and give the worker team the material needed to complete it.
- Check each delivery against the confirmed list, return evidence, send work back when needed, and handle escalation or disputes.
- Operate balances, holds, top-ups, invoices, refunds, and worker payouts through our ledger and Stripe.
- Authenticate accounts, send requested service messages, prevent abuse and fraud, secure the service, provide support, and meet legal obligations.
- Create or improve training datasets only under the separate rules in section 4.
4. Model improvement and training
Separate and default-off. Operational use of a job is not training consent. Marketplace training retention is off unless an affected person makes a separate choice. The choice is not bundled into the terms of service.
Every party and every modality. The buyer controls training use of the intent, contract, and reference material they provide. The worker controls training use of their submissions. An episode is eligible only when both sides have live grants covering every included modality at the time of collection.
Scope and confidentiality. A choice can be recorded for a job or as an account default for future jobs, and can be limited by modality. Confidential jobs are not captured for training. Missing, expired, revoked, or incomplete consent fails closed.
Lineage and export. Every training dataset export must identify the eligible episodes and grants that support it. An episode that cannot name valid consent is refused at export.
Revocation and erasure. Revoking a grant stops future capture and makes descendant episodes ineligible. Granting again later does not restore older episodes. Erasure removes the covered capture rows and produces receipts. Data already used to train a released model cannot be removed from that model, but revoked data is not used in a later dataset export.
5. Storage, retention, and sharing
Job records carry a retention period. The current default for managed intent references and delivered artifacts is 30 days after a job closes. A buyer can request deletion after closure, and a scheduled process deletes artifacts when their retention period expires.
Some contract, transaction, invoice, tax, security, fraud-prevention, dispute, and deletion-receipt records may be kept longer where they are needed to meet legal obligations, protect the service, or establish what happened.
We share job material with the assigned worker team and with service providers only as needed to run the service. Providers support hosting, storage, authentication, email, transcription and model inference, checking, and Stripe payment or payout processing.
The current provider list, purpose, and region are published on the subprocessors page. We do not sell personal data.
7. Your controls and rights
- Access and export: request the account, job, consent, and training-capture records we hold about you.
- Correct: ask us to correct inaccurate account or contact information. A sealed job contract remains an immutable record of what was confirmed; corrections are recorded through the product's amendment or dispute path.
- Revoke training consent: turn off an account or job choice, or revoke coverage for a modality. Future training use stops as described in section 4.
- Delete: delete managed artifacts for a closed job, delete an eligible account through the product, or ask us to carry out a cross-system erasure request.
- Communications: unsubscribe from optional messages. Service messages needed to run an active job or account may still be sent.
Send cross-system rights requests to: privacy@seaotter.ai
8. Contact
Questions or requests about privacy: privacy@seaotter.ai