Skip to main content
Sealens logo Sealens
Privacy Terms DPA Homepage Request Early Access

Legal

Privacy Policy

Effective date: July 8, 2026. This policy explains how Sealens handles data for the early access service operated directly by the founder.

On this page

  • 1. Operator
  • 2. Scope
  • 3. Data We Collect
  • 4. How We Use Data
  • 5. Legal Bases
  • 6. Processors and Sharing
  • 7. International Transfers
  • 8. Retention
  • 9. Your Rights
  • 10. Security
  • 11. Children
  • 12. Changes
  • 13. Contact

1. Operator

Sealens is currently operated by Mathurin Bourgouin, a web developer based in France. Until a company is formally incorporated, the data controller for this service is the founder operating Sealens.

2. Scope

This policy applies to the Sealens website, early-access product, and related communications. It is designed for business teams evaluating incident investigation workflows.

3. Data We Collect

  • Contact data : name, work email, company, role, and outreach context.
  • Product usage data : events, logs, and operational telemetry needed to run and improve the service.
  • Repository analysis data : metadata and technical artifacts required to generate incident investigation insights.
  • Support communications : messages sent by email or support channels.
Current position : Sealens is not intended to train general-purpose AI models on customer private source code.

4. How We Use Data

  • Deliver, secure, and maintain the service.
  • Provide onboarding and customer support.
  • Monitor reliability, investigate abuse, and prevent fraud.
  • Improve product quality and roadmap decisions.
  • Communicate service updates and legal notices.
  • Process a closed beta application and send related communications (confirmation, acceptance, or decision) — applies to every applicant, regardless of the newsletter choice below.
  • Send an occasional product newsletter, only to visitors who explicitly opt in on the closed beta application form — never bundled with the application itself.

5. Legal Bases (EEA/UK)

  • Contract necessity for delivering the service, and for processing a closed beta application submitted to us.
  • Legitimate interests for security and product operations.
  • Consent where legally required (for example, optional cookies, and the optional product newsletter — withdrawable at any time via the unsubscribe link in every message).
  • Legal obligations when compliance duties apply.

6. Processors and Sharing

Sealens uses a small number of named service providers to operate the service: cloud infrastructure and hosting (Scaleway, a French provider — chosen deliberately over a US-headquartered cloud so that infrastructure data stays outside the reach of foreign extraterritorial access regimes such as the US CLOUD Act), an AI language model provider used only to turn analysis Sealens has already computed into readable text (Anthropic's Claude API — the underlying commits, diffs, and raw code are not sent to this provider, and it is not used to train Anthropic's models on Sealens data), notification delivery (Slack, Microsoft Teams, only when a customer configures that integration), a transactional email provider for account notices, and a contact and email platform (Brevo) used to process closed beta applications for every applicant and, only for visitors who explicitly opt in, to send the optional product newsletter. Data is shared only when needed to operate the service, under confidentiality and data processing commitments. The complete, current list of sub-processors is maintained in the Data Processing Agreement.

Sealens does not sell personal data.

Business customers that need a signed Data Processing Agreement for their own compliance review can find our standard DPA at sealens.io/dpa.html, or request a countersigned or negotiated copy at hello@sealens.io.

7. International Transfers

Sealens hosts data in the EU by default. Because the AI language model provider named above is located outside the EU/EEA, the structured analysis payload sent to it for summarization involves an international transfer. Where required, Sealens relies on appropriate safeguards such as Standard Contractual Clauses for this and any other transfer outside your region — see the Data Processing Agreement for detail.

8. Retention

Data is retained only as long as necessary for the stated purposes, legal obligations, and security requirements. Upon request and where applicable, Sealens will delete or anonymize data within a reasonable timeframe.

9. Your Rights

Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing activities.

To exercise your rights, contact hello@sealens.io.

10. Security

Sealens applies reasonable technical and organizational safeguards designed to protect data against unauthorized access, misuse, or loss. No system can guarantee absolute security.

11. Children

Sealens is intended for professional use and is not directed to children.

12. Changes

Sealens may update this policy as the product and legal structure evolve. Material changes will be posted on this page with a new effective date.

13. Contact

Privacy questions and requests can be sent to hello@sealens.io.

Read Terms of Service Read Data Processing Agreement Back to Homepage
Sealens logo Sealens

Incident Investigation Workspace

Product

  • How It Works
  • Features
  • Pricing
  • Early Access

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement

Connect

  • Email

© Sealens. All rights reserved.