Privacy Policy
Last updated 18 August 2026
1. Who is responsible
The data controller for Seed (seed.superseeds.io) is Superseeds (Emil Mogensen), a sole proprietorship (enskild firma) registered in Sweden, org. nr 980604-XXXX (partially masked; full number available on request), emil@superseeds.io. Contact us at that address for anything in this policy, including exercising your rights.
2. What we process
- Account data — your email address, name, and optional profile photo, used to sign you in and show who did what in a shared workspace.
- Client workspace data — the client company name and the contact details of invited members, used to scope portal access.
- Content — the product, prop, and backdrop photos you upload, brand assets, prompts, and the images and video generated from them. Uploading photos of real people is not permitted (see the Terms), so what you upload is not intended to contain personal data. Posts read from a connected Instagram account are the exception: those are your own published posts and may show people, and they are covered in the next point but one.
- Connected advertising accounts — if you connect a Meta or Google advertising account, we store the access tokens that connection returns (encrypted at rest), the identifiers of the ad account and page you select, and the delivery statistics we read back for campaigns Seed created.
- Connected Instagram accounts — if you connect a Meta account to a client and pin an Instagram business account to it, Seed reads that account's ID and username, and, for the 24 most recent posts on it, the post's ID, media type, caption, publish date, permalink, and a temporary link to the picture or video. We use this for one thing: to draw the posts you have already published behind the posts you are planning, so a photograph that does not exist yet can be composed against the account it is going into. Those published posts are read-only in Seed. The only thing you can do with one is copy its caption into the brief for a new render.
- We never copy those pictures or video into our storage. The temporary link is only trusted for 45 minutes and is then fetched again from Meta, so the images you see always load directly from Meta rather than from us. We do not publish, schedule, comment, send messages, or read followers, likes or any engagement figures — Seed has no feature that would use them. If you delete a post on Instagram, it disappears from Seed at the next refresh.
- Websites you ask us to scan — when you use the brand scanner, our server fetches the public web address you enter and passes its text, colours, fonts, and logos to our AI provider so it can suggest brand settings. The address is saved with the brand and used as the landing link for ads published through Seed.
- Purchase data — token purchases and balances. Card details are handled entirely by Stripe; we never see or store them.
- Technical data — sign-in and security logs kept by our hosting providers.
3. Why we process it
We process this data to provide the service you or your studio agreed to (contract, GDPR art. 6(1)(b)), to keep the service secure and improve it (legitimate interest, art. 6(1)(f)), and to meet legal obligations such as bookkeeping (art. 6(1)(c)). We do not sell data, run advertising, or use your content to train AI models.
4. Who processes it for us
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Stripe — payment processing.
- fal.ai — AI image, video, and text generation. Your uploaded reference photos and prompts are sent to fal.ai to fulfil the generations you request, along with the finished renders, brand settings, and any website content you ask us to scan when it writes ad copy or plans a campaign for you.
These providers act as our processors under data processing agreements. Some are located in, or may process data in, the United States; transfers rely on the EU–US Data Privacy Framework or the EU standard contractual clauses.
In addition, when you connect an advertising account and ask Seed to publish an ad set, we send the finished creative, its ad copy, and the landing link to that platform and read back the campaign's delivery statistics. These platforms act as independent controllers for the advertising account itself, under their own terms and privacy policies:
- Meta — publishing to Facebook and Instagram advertising, if you connect it, and reading the Instagram account you pin so Seed can plan against it.
- Google — publishing to Google Ads, if you connect it.
5. How long we keep it
Account and workspace data is kept while the account or client relationship is active. Uploaded and generated content is kept so your reference bank stays useful, and is deleted when you delete it in the app or when the client relationship ends and deletion is requested. Advertising-account tokens are deleted as soon as you disconnect that account. Details of your Instagram posts are kept only while the Meta connection is live: disconnecting Meta on a client deletes that client's stored token and every stored post record for it immediately, in the same action. Purchase records are kept for 7 years as required by Swedish bookkeeping law.
6. Your rights
You can ask for access to, correction of, deletion of, or a copy of your personal data, and you can object to or ask us to restrict processing. Write to emil@superseeds.io and we will respond within a month. You can also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, www.imy.se).
7. Cookies and analytics
Seed sets only the strictly necessary cookies used to keep you signed in — there are no advertising or tracking cookies, so there is no cookie banner. We measure page visits and loading speed with Vercel Analytics and Speed Insights, which are cookie-free and give us only aggregated numbers. Details are in the Cookie Policy.
8. Changes
If this policy changes materially, we will notify account holders by email or in the app. The date above shows the latest revision.