Privacy Policy

Last updated 4 October 2026

Seisaku Studio is operated by Mentis Vision LLC ("we", "us"). It turns recorded video and audio into an edited master cut and related written assets, and can publish those assets to social accounts you connect. This policy explains what we collect, why, who we share it with, and how you remove it.

What we collect

DataWhy we hold it
Name, email address, and optionally your role and business nameTo create your account and identify you as the author of content you publish.
Authentication identifier from your sign-in providerTo sign you in. We never receive or store your password.
Recordings you upload, and transcripts derived from themTo produce the master cut, captions, clips and written assets you asked for.
Your brand kit — tone of voice, colours, positioning, banned wordsTo shape generated content to your brand.
Access tokens for social accounts you connectTo publish on your behalf, only when you ask us to.
A record of what was published, where, and whenTo show you your publishing history.
Diagnostic error reportsTo find and fix faults. Reports are stripped of credentials before they leave our systems.

We do not collect special category data, we do not use your recordings for advertising, and we do not sell personal information.

Who processes your data

We use the following providers. Each receives only what its function requires.

ProviderWhat it receives
Google Firebase AuthenticationYour email address and sign-in identifier.
Google Gemini APIAudio, video, text and photos you submit for transcription, analysis, writing and pictures. Seisaku asks Google not to store its picture and transcription requests. Google keeps requests for up to 55 days to detect abuse and does not use them to train its models.
OpenAI APIText you submit for writing and script review; and, as Seisaku makes pictures with OpenAI by default, the words for each new picture and the photo and instruction for each picture you ask it to change. OpenAI keeps API requests for up to 30 days to detect abuse and does not use them to train its models.
Anthropic APIText and project details you send to the studio agent and to writing work.
Amazon Web Services (S3)Media files you upload. Stored in a private bucket in the US West (Oregon) region.
Neon (PostgreSQL)Account details, brand kit, publishing history and encrypted access tokens.
SliplaneApplication hosting.
LinkedIn, Meta, Google/YouTube, Canva, BeehiivOnly the content you explicitly choose to publish or sync, and only to accounts you have connected.
Descript, OpusClip, HeyGen, ElevenLabs, VizardOptional. Used only if you supply credentials for them, and only for the files you send to them.
SentryError diagnostics, with credentials and request bodies redacted.

Connected social accounts

When you connect an account, the provider issues us an access token scoped to the permissions shown on their consent screen. We use those permissions only to publish content you have composed and confirmed. We do not read your feed, message your contacts, or post without an explicit action from you.

Access tokens are encrypted with AES-256-GCM before being written to our database, so a copy of the database alone does not grant access to your accounts. You can disconnect any account at any time, which deletes the stored token.

Google user data

Where you grant Google Drive or YouTube permissions, we use them solely to read media files you select, to upload videos you choose to publish, and to read back from YouTube only what the app shows you about your own channel: your own YouTube channel's name and picture, the visibility YouTube kept for a video right after you publish it, and the view, like and comment counts of videos you published through Seisaku Studio. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, and we do not allow humans to read it except where required for security, to comply with law, or with your explicit consent.

Who we share, transfer, or disclose Google user data with

Google user data means the media files you select from Google Drive, your Google account email address, and your YouTube channel identity. We share it only as follows, and only to provide the service you asked for:

RecipientWhat Google user data it receives, and why
Amazon Web Services (S3)Copies of the Drive media files you select, stored in our private bucket so the app can edit and publish them.
Neon (PostgreSQL)File names and metadata of the Drive files you import, your Google account email, and your encrypted Google access tokens.
Sliplane (hosting)Processes all application traffic, including Google user data in transit, as our hosting provider.
Google Gemini APIThe audio, video, text or frames of media you submit for transcription, analysis, writing and pictures, which may include files that originated in your Drive. Gemini is a Google service.
OpenAI APIText drawn from media you submit, such as a transcript, for writing and script review, which may come from a file that originated in your Drive; and, as Seisaku makes pictures with OpenAI by default, a frame or photo you choose to change, with its instruction.
Anthropic APIText drawn from media you submit, such as a transcript, when you use the studio agent or writing work, which may come from a file that originated in your Drive.
Editing vendors you connect (for example Descript or OpusClip)Only a specific media file, only when you explicitly send that file to that vendor, and only using credentials for your own vendor account. A file you imported from Drive is included only if you choose to send it.
Social platforms you publish toOnly the finished content you explicitly choose to publish, to accounts you connected.

We do not sell Google user data, we do not transfer it to data brokers or advertising networks, and we do not share it with any party not listed above. We may disclose it if required by law, or as part of a merger or sale of the business, in which case this policy continues to apply to it and we will notify you. Transfers of information from Google APIs to any other app are not made; tokens stay encrypted in our database and are deleted when you disconnect.

How long we keep it

Your rights

You can access, correct, export or delete your data. Under the GDPR you may also object to or restrict processing, and lodge a complaint with your supervisory authority. Under the CCPA you may request disclosure and deletion, and we do not sell or share personal information as those terms are defined there.

To exercise any of these, use the deletion page or email sang@mentisvision.com. We respond within 30 days.

Security

Traffic is encrypted in transit. Access tokens are encrypted at rest at the application layer, separately from the database's own encryption. Every API route requires an authenticated session, and your data is scoped to your account.

International transfers

We process data in the United States. If you are in the UK, EEA or Switzerland, your data is transferred there under appropriate safeguards.

Children

The service is not directed to anyone under 16, and we do not knowingly collect their data.

Changes

We will update this page and change the date above when this policy changes. Material changes will be notified by email.

Contact

sang@mentisvision.com