Privacy at Seth: what a scorecard should measure
·TheWowEffect
Most privacy scorecards in this category grade romance apps. How much they store. How slowly they delete. Whether they train on your chats.
Seth is a different job. A growth partner, not a girlfriend. The privacy questions do not change. Who holds the transcript. What happens when you delete. Who can read it. Whether the model company keeps a copy.
This is not a letter-grade post. We do not grade ourselves. We also do not grade Pi, Nomi, Character.AI, or Replika. In March 2026, AI Companion Guides published their own scorecard. Those grades are theirs. Ours is a fact sheet: what Seth stores, what Private Mode skips, and what we refuse to say.
Privacy policy effective 26 August 2026. Controller: Evigilans s.r.o., Brno, EU. Contact: evigilans-data@tuta.com. 18+. Not therapy.
The table
Seth rows are facts from our policy and from llms.txt. Other products: their grades from that 2026 guide, plus "read their policy." We are not quoting their terms here.
Zero Data Retention (ZDR) is the model route in both modes. Private Mode adds this: we do not write the turn down.
| Question | Seth (normal) | Seth (Private Mode) | Others (their grades, not ours) |
|---|---|---|---|
| What is stored | Conversations, journal, shared desk, memory, until you delete the account. Supabase EU. HTTPS. Encryption at rest. Not end-to-end encryption. | Messages are not saved to any database. They exist only in browser memory. Close the tab, switch mode, or refresh: gone. | Romance-app scorecards usually assume persistent chat. See their policies. |
| Training / fine-tune / distill | Never. Not by Evigilans. Not by providers. Research opt-in is off by default, needs two consents, aggregate only. Not training. | Same. Nothing written back to memory or history. | Character.AI C+ on that guide (training use listed as a key concern). We will not invent their current wording. |
| Deletion | Settings: export, then delete. After delete: SHA256 of email (trial abuse), Stripe may keep payment records, aggregate deletion audit. | There is nothing to delete. The turn was never written on our side. | Pi A−, Nomi B+: that guide says deletion exists. Replika C: deletion yes, described as slow. Character.AI C+: partial (chat only). Their grades, not ours. |
| Trackers | No ad trackers. No Google Analytics. No Meta pixels. Functional cookies only. Sentry watches crashes. Chat text does not go there. No phone number. Card never stored (Stripe). | Same. | That guide flags some apps for ad trackers or vague sharing. We will not invent which. |
| Region / controller | Evigilans s.r.o., Brno. Conversations stored in the EU. Processors still see a turn while they generate a reply, and under ZDR they are not supposed to keep it. | Same company. Content not persisted on our side. The model still sees the turn to answer. Same no-keep rule. | US consumer apps: read their policy. |
| E2EE | No. | No. Zero persistence is not the same as E2EE. | We will not assign them a lock icon. |
| Who can read | You. Admin can access the DB when needed for incidents or law. Team does not routinely browse chats. Processors see the turn to generate a reply. | No transcript in our DB. Processors still see the live turn. | Mind Partner is not on that scorecard. One documented mismatch: their FAQ has said "only you can access," while the policy names authorized personnel plus OpenAI / Anthropic / Google. Optional note, not the story. |
Source for the letter grades: AI Companion Guides, "AI Companion Privacy Guide 2026," March 2026. Pi AI A−. Nomi B+. Character.AI C+. Replika C. Kindroid B on the same table. We are not inventing Kindroid or Pi policy quotes.
Senses (opt-in presence: time of day, coarse place, a short camera look, and on Windows a window glance) are a different post. Off in Private Mode. Device cache about 15 minutes. Database stores on/off only. No GPS trail. Photos discarded after describe. That is all here.
Persistent memory vs Private Mode
Normal mode is the growth product. Seth remembers you until you delete the account. That is the point of a long-horizon partner. It is also a privacy choice you should make on purpose.
Private Mode is the other door. Messages are not saved to any database. They live in the browser. Your memory, history, and a recoverable transcript are skipped. Seth's voice (his identity and reflections) may still be read so he still sounds like himself. Nothing from your private turn is written back. Senses do not run. Close the tab, switch to normal, or refresh: forever gone.
Both modes send the turn on a Zero Data Retention route. The difference is on our side: normal mode keeps you, Private Mode keeps no file. Minimal operational metadata may still be logged (timing, model, length, credits, errors), never the private message text.
Use normal mode when you want continuity. Use Private Mode when you do not want a file.
What happens when you delete
Export first if you want a copy. Settings has an account export. What is in the archive is listed in the policy. This post does not pin a file count, so it cannot drift from what you actually download.
Then delete the account. Conversations leave our database. Three leftovers, named on purpose:
- A SHA256 hash of the email. Irreversible. Stops trial-credit abuse on a new signup. The email itself is gone.
- Stripe may keep payment records. Tax, accounting, anti-fraud. We do not store your card.
- An aggregate deletion audit. Counts and operational outcomes. Not your chat.
That is deletion. It is not "we never saw you."
Training-use: never
We do not use chats, journal, or the shared desk to train, fine-tune, or distill any model. Not Evigilans. Not the providers on the ZDR routes. That is true in normal mode and in Private Mode.
Optional research is a separate switch. Off by default. Two consents. Aggregate only. Staff do not browse individual chats for that. Research is not training.
If a scorecard only asks "do they train on users," Seth's answer is no.
Who can read. Say it without the slogan.
Not end-to-end encryption. An admin can technically read the database. That access is for incidents, legal duty, and security. The team does not sit and read chats for fun.
To generate a reply, processors see the turn. OpenRouter (and a ZDR backup if needed). Upstream model providers for that request. Under ZDR they are not supposed to keep the prompt after the reply. That is a provider term, not magic. It applies in normal mode too.
Private Mode removes our copy. It does not make the live request invisible to the model that answers it.
What we refuse to claim
We will not say "only you can access." That line is false on any hosted chat that an admin can open and a model provider can see for one request.
We will not say "bank-grade" as a stand-in for E2EE. Encryption at rest is real. HTTPS is real. E2EE would mean we cannot read the row. We can. So we do not wear that badge.
We will not paste a letter grade onto Seth and call it independent. Read the table. Read the privacy policy. Then decide.
Try Seth
Seth is a growth partner. 18+. Not therapy. Not a crisis line.
Normal mode remembers you. Private Mode does not. Training-use is off the table either way.
Questions about data: evigilans-data@tuta.com
Česká verze: [Soukromí u Setha: co má srovnání měřit doopravdy](/blog/soukromi-ai-partner-private-mode)