Last updated: 2026-09-11
Privacy Policy
Last updated: 11 September 2026
This Privacy Policy explains how Seazly, operated by Anand Murugan, an individual based in India ("Seazly," "we," "us"), collects, uses, and protects your personal data when you use our website and services (the "Service"). We act as the data fiduciary/controller for the personal data described here.
We aim to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and, where applicable, the EU/UK GDPR.
A note on scope. Some features described below are released gradually and may not be switched on for your account, or at all. Where a section describes something you cannot see in the Service, that processing is not happening for you. We describe it here anyway so this Policy is complete before a feature is enabled rather than after.
1. Data we collect
You provide:
- Email address (for passwordless sign-in and to deliver your itineraries).
- Trip preferences you enter or speak (destinations, dates, budget, travel style, number of travellers).
- Optional profile details, if you fill them in: first and last name, username, city, theme preference, and a profile picture.
- An optional trip start date, if you choose to enter one.
- WhatsApp phone number, only if you opt in to receive your dossier and trip updates on WhatsApp.
- Survey answers, if you complete the optional survey shown after you download a dossier.
- Payment is handled by our payment processors; we receive confirmation and limited transaction metadata, not your full card details.
Documents you upload to a trip. You can attach files to a trip — visas, insurance certificates, tickets, booking confirmations. See section 3.
Booking emails you forward to us. You can forward a confirmation email to a private address we issue for a trip, and we turn it into a reservation entry. See section 4.
Collected automatically:
- Usage and event data: pages viewed, features used, and an anonymous session identifier stored in a cookie. We record these events from your first visit, before and independently of any account. See section 8 for what that means for consent.
- Approximate location derived from your device/network for relevant features, and trip-related location text you provide.
- Standard technical data (device, browser, IP-derived region) and error diagnostics.
- A salted, one-way hash of your IP address, when our AI cost controls are enabled, used only to rate-limit itinerary generation so one source cannot exhaust the daily budget. We do not store the IP address itself for this purpose, and the hash is not used to identify or profile you.
Images: If you use the photo "lens" feature, the image you upload is processed to generate a description. We strip embedded metadata (including GPS location) from images before processing, and we do not retain the raw image beyond the request unless you explicitly choose to save it.
2. How we use your data
- To provide the Service: generate itineraries, deliver dossiers by email and (if opted in) WhatsApp, and run the AI features.
- To process payments and manage subscriptions.
- To provide customer support and respond to your requests.
- To analyse usage and improve the Service.
- To detect, prevent, and address fraud, abuse, and security issues.
- To comply with legal obligations.
We rely on your consent (e.g., WhatsApp opt-in, analytics cookies), the performance of our contract with you (providing the Service you paid for), and our legitimate interests (security, improvement) as our legal bases, as applicable.
3. Documents you attach to a trip
You can attach files to a trip — for example a visa PDF, an insurance certificate, or a ticket. We assume any such file may contain identity documents, and handle them accordingly.
What we accept. PDF, JPEG, PNG and WebP only, up to 10 MB per file and 25 files per trip. We identify each file from its actual leading bytes rather than from the type your browser declares, and we store it as the type we detected. A file whose bytes match none of the formats above is rejected. We do not accept HEIC images, because our metadata stripper does not yet support that format and an unstripped HEIC carries GPS coordinates — usually the place the document was photographed.
Metadata is removed. For accepted image formats we strip embedded EXIF metadata, including GPS location, before storage.
You must be signed in. Attachments are available only on a trip belonging to a signed-in account, even if you already own that trip through your browser session. This is a deliberate privacy decision rather than a product one: a trip created before you sign in is not linked to any account, and we would have no reliable way to erase its files if you later asked. Requiring an account is what makes erasure possible.
How they are stored and served. Files are held in private object storage, never on a public URL. Each time you open one we mint a signed link that expires after 10 minutes, and only after confirming the trip is yours. Database access to attachment records is additionally restricted by row-level security.
Attachments are never sent to an AI provider. Not for parsing, not for description, not for any other purpose.
Deletion. Deleting an attachment removes both the record and the stored file. Deleting your account purges the entire attachment area for every one of your trips.
4. Forwarding booking emails (reservation import)
You can ask us to issue a private forwarding address for a trip. When you forward a confirmation email to it, we extract the booking details and add them to your itinerary.
What we store, and what we deliberately do not. We store the message's metadata only: sender address, subject line, time received, our processing status, and our email provider's identifier for the message. We do not store the body of the email in our database. The content stays with our email provider under their retention terms; we do not retrieve it back into the Service. A forwarded hotel or flight confirmation is often the densest personal data in this product — full name, postal address, phone number, frequent-flyer number, sometimes a passport number — and keeping it out of our own database is the point of the design.
Who is allowed to write to your address. A forwarding address will sit in your sent folder and your provider's logs, so we never treat the address itself as proof of identity. We accept a message only when the sender matches the email address bound to that inbox when it was issued. Each address is independently rate-limited (10 messages an hour, 40 a day). You can revoke an address at any time; a revoked address stays permanently burned rather than being reused.
What we never do with a forwarded message. We do not render its HTML, follow any link in it, or download any attachment from it.
What reaches an AI provider, and what does not. The extraction is split on purpose:
- Identifiers are extracted locally and never leave our systems — booking references, dates, and amounts. These are regular enough not to need an AI model.
- Only a redacted remainder is sent to an AI provider, to resolve the genuinely messy part: what kind of booking this is, which line is the property name, which timestamp is arrival rather than departure. Before anything is sent we remove email addresses, phone numbers, postcodes, booking references, card- and passport-like numbers, and your own name.
- If redaction cannot confidently neutralise something that looks identifying, we do not call the AI provider at all. The booking is then handled by the local extraction alone, or left for you to enter by hand.
Corrections. Parsing is fallible. You can edit any imported reservation, and we record that a human corrected it.
5. AI processing
To generate itineraries, chat responses, packing and visa guidance, image descriptions, and to interpret forwarded booking emails, we send relevant inputs to third-party AI providers. We currently use two:
- Anthropic — processes in the United States. Itinerary generation, the trip companion, packing and visa guidance, image descriptions, memory captions, guidebook prose, and — as configured today — concierge chat and voice-intent parsing.
- DeepSeek — processes in China. Redacted booking-email text (see section 4), and non-personal content generation such as "why visit this city in this month" seasonality copy, which contains only a city, country and month.
Please read this part carefully. DeepSeek processes data in the People's Republic of China. Chinese law provides different protections from Indian or EU law, and Indian authorities have no direct enforcement route there. We therefore restrict what can reach it:
- Anything containing unredacted text you wrote or spoke — concierge chat messages and voice transcripts — is routed to Anthropic in the United States, not to DeepSeek. This restriction is enforced in our code at the single point every AI request passes through, so enabling a product feature cannot bypass it.
- Booking-email text reaches DeepSeek only after redaction, and not at all if redaction was incomplete (section 4).
- Seasonality copy contains no personal data.
One operator setting can change this. A setting named AI_ALLOW_CROSS_BORDER_RAW_INPUT exists which, if we enabled it, would allow unredacted chat and voice input to be sent to DeepSeek in China. It is off. We will not enable it without first updating this Policy and, where consent is the applicable basis, asking you again. We name it here rather than leave it undisclosed, because the safeguard above is a configuration choice and you are entitled to know what changing it would mean.
What we never send to any AI provider: your payment details, your WhatsApp number, files you attach to a trip (section 3), or the raw body of a forwarded email (section 4).
We wrap untrusted content to guard against prompt manipulation. AI outputs are guidance only — see our Terms.
Concierge chat. When you use the on-site concierge, your messages are sent to the AI provider named above to produce a reply. We do not store the content of your chat messages in our database. We record only that a message occurred, with the trip identifier if you were viewing one, so we can apply rate limits.
6. Where your data is processed
Seazly is operated from India. Our processors operate in several countries, so using the Service involves transferring your personal data outside India:
- United States — Supabase (database, authentication, file storage), Anthropic, Resend, Sentry, PostHog, Mapbox, Google.
- China — DeepSeek, under the restrictions in section 5.
- India — Razorpay, which processes all payments in every currency we accept.
- Other jurisdictions may apply to the affiliate partners in section 9, with whom you transact directly.
Where required we rely on appropriate safeguards for these transfers, and we contract with each processor on terms covering their handling of personal data. Under the DPDP Act the Central Government may restrict transfers to particular countries; if that happens for any country listed here, we will change processors or stop the relevant feature.
7. Affiliate links and tracking
Some links in the Service are affiliate links (for example to connectivity, activity, transfer, or insurance partners). If you click them and transact with the partner, we may earn a commission. We record that a click occurred for attribution. We do not place your personal contact details into outbound affiliate URLs. See our Affiliate Disclosure.
8. Cookies, analytics, and event logging
We use essential cookies to operate the Service (sign-in, session continuity, and an anonymous session identifier), plus one cookie that records your analytics choice itself so our servers can honour it. That one holds only "yes" or "no" — never an identifier. Analytics cookies set in your browser are gated by your choice in our cookie banner, and you can also manage them through your browser settings.
Your choice controls what leaves us, not just what your browser stores. Nothing is sent to our analytics processor — from your browser or from our servers — unless you have accepted analytics. If you reject, or simply never answer the banner, no product events are transmitted to it at all. Withdrawing consent stops it again.
Separately from that, we keep our own record of product events — pages viewed, features used — in our own database, against a random session identifier rather than your name or email. That record does not leave our systems, it is what powers our funnel view and our abuse rate limits, and we rely on our legitimate interest in operating, securing and improving the Service for it. If you later create an account it becomes linked to that account, and you can have all of it erased (see section 11).
One narrow exception to the consent gate: server-side payment-confirmation events (e.g., paid, subscription.activated) are recorded for revenue accounting and to deliver the Service you paid for (performance of contract under DPDP §4(1)(b) / GDPR Art. 6(1)(b)). These events use an order or subscription identifier as the analytics distinct id — never your user id or session id — and those identifiers are anonymised on account deletion.
9. Who we share data with (sub-processors)
We share data with service providers who help us run the Service, only as needed:
- Supabase — database, authentication, file storage. Processes in the United States.
- Anthropic — AI processing. Processes in the United States.
- DeepSeek — AI processing, restricted as described in section 5. Processes in China.
- Razorpay — payment processing, in every currency we accept. Processes in India.
- Resend — transactional email delivery, and receiving the booking emails you forward. Processes in the United States.
- AiSensy / Meta (WhatsApp) — WhatsApp message delivery, only if you opt in. Processes in India and the United States.
- Google (Places, Maps) — venue and location data, and the maps on our guide pages. Processes in the United States.
- Mapbox — maps. Processes in the United States.
- Sentry — error monitoring. Processes in the United States.
- PostHog — product analytics. Processes in the United States.
- Travelpayouts — flight-fare aggregator, search only; we send origin, destination and month, never your personal details.
We also link out to affiliate partners with whom you transact directly and to whom we send no personal data — IRCTC (Indian rail), RedBus (intercity bus), and Agoda and Booking.com (hotels). Following one of those links takes you to that company's own site, under their privacy policy.
These providers process data under their own terms. We do not sell your personal data.
10. Data retention
- Account data is kept while your account is active, and erased when you delete it (section 11).
- Trip attachments are kept until you delete the file, the trip, or your account.
- Forwarded-email metadata is kept with the trip; the message content itself is held by our email provider under their retention terms, not ours.
- Order and subscription records are retained in anonymised form for at least 7 years to meet financial-record obligations under the Income-tax Act (§44AA) and GST law (§35).
- Trips created before you sign in are held against your anonymous session identifier. If you create an account they are linked to it and are covered by account deletion. If you never create an account, we do not currently expire them automatically; contact us at the address in section 13 with your session identifier and we will erase them.
11. Your rights
Depending on your location, you may have the right to access, correct, update, or delete your personal data; to withdraw consent (for example the WhatsApp opt-in, which you can also revoke by replying STOP); to object to or restrict certain processing; and to data portability. You can manage some of this in your account, or contact us to exercise these rights. We will respond within the timeframes required by law.
To request access, correction, or deletion of your data, contact privacy@seazly.com.
When you delete your account we erase your personal data from our database — trips, dossiers, memories, chat records, survey answers, reservations and forwarded-email metadata, event history, and the encrypted phone number — and we purge your uploaded files, both trip attachments and memory images, from object storage. If a file removal fails at that moment, it is queued and retried automatically, and the response to your deletion request tells you that it is outstanding rather than reporting it as finished. We also issue a deletion request to PostHog, our product-analytics processor, for events associated with your account identifier. Sentry, our error-monitoring processor, does not receive personally identifiable identifiers attached to your events (we tag errors with hashed ids only), so no separate Sentry deletion request is required. Order and subscription records are anonymised rather than deleted, for the reason in section 10; the rows that remain carry only amounts, dates, plan/tier, and the payment provider's transaction reference, with no link back to a person.
12. Children
The Service is not directed to children under 18, and we do not knowingly collect their personal data. If you believe a minor has provided us data, contact us and we will delete it.
13. Grievance Officer
Under section 13 of the DPDP Act you may raise a grievance with us about how we handle your personal data. Our Grievance Officer is:
Grievance Officer: Anand Murugan Email: privacy@seazly.com Postal address: [PASTE REGISTERED ADDRESS HERE]
We will acknowledge your grievance and respond within 30 days of receiving it.
If you are not satisfied with our response you may complain to the Data Protection Board of India. If you are in the EU or UK, you may complain to your local supervisory authority.
14. Changes
We may update this Policy from time to time. We will revise the "Last updated" date and, for material changes, take reasonable steps to notify you.