PRIVACY NOTICE

Collect only what the validation job needs.

Effective September 25, 2026. This notice explains what SeenRelay processes, why it is processed, how long application data is retained, and which infrastructure providers may process service traffic.

SCOPE

Local scanner and hosted service are different.

Local scannernpx seenrelay scan reads supported project files locally. It does not contact SeenRelay, upload source code, create an account, or enable reuse.
Hosted CHECK / OBSERVENetwork use is optional. CHECK compares a caller-known value with recent evidence for the same deterministic fact. OBSERVE accepts evidence only after the caller independently obtained it.
No account or payment profileSeenRelay currently requires no SeenRelay account or API key and billing is disabled.
No conversation harvestingSeenRelay is not designed to read Claude memory, chat history, conversation summaries, or unrelated user files.
APPLICATION DATA

What the hosted service processes.

The hosted service processes only data needed for deterministic fact matching, freshness evidence, abuse controls, and bounded operational measurement.

Fact identitySubject, predicate, qualifiers, canonicalized source URL, and optional source-native locator.
Observation processingThe submitted value may exist in request memory long enough to compute a deterministic fingerprint. Active Production stores the fingerprint and bounded evidence metadata rather than another caller's raw submitted value.
Pseudonymous provenanceObserver/client continuity uses privacy-salted identifiers. Raw IP address, raw user-agent, raw Ed25519 public key, and raw self-asserted observer ID are not used as application database identity.
Operational metricsAggregate CHECK/OBSERVE outcomes, reuse accounting, lease state, and aggregate MCP protocol-interest events may be measured for reliability, abuse prevention, and product evaluation.

Do not submit passwords, API keys, access tokens, private cryptographic keys, signed URLs, or unnecessary sensitive personal data.

PURPOSE

Why SeenRelay processes this data.

The purpose is to operate a validation-reuse service that can compare recent observations without treating them as universal truth, preserve authoritative fallback, prevent unsafe or abusive reuse, and measure whether the service is useful. SeenRelay does not sell personal data and does not use submitted values to train an AI model.

RETENTION

Application retention is bounded where operational state permits.

Observation evidence
7d
configured evidence horizon
Observer/fact state
7d
aligned pseudonymous state
Hive leases
30d
operational retention
Reuse events
90d
utility evidence

Fact summaries and aggregate operational measurements may be retained longer where needed for STALE/latest-observed semantics, abuse controls, or historical measurement. Infrastructure-provider backups and security logs follow the providers' own retention practices.

INFRASTRUCTURE

Service providers.

VercelHosts the web/API runtime and may process network/security/operational data under its terms and privacy notice. Vercel Privacy Notice.
NeonProvides PostgreSQL infrastructure for application state and may process service data under its terms and privacy practices. Neon Privacy Policy.
CHOICES & CONTACT

Use the local path when you do not want hosted processing.

You can use the local scanner without sending project source to SeenRelay. If you use the hosted service, submit only eligible public or legitimately accessible source-backed facts under your own policy. For product or privacy questions, contact the repository owner through GitHub. Do not post secrets or sensitive personal data in a public issue. For security vulnerabilities, use the repository's private vulnerability-reporting channel described in SECURITY.md.

Because SeenRelay has no user accounts and application identifiers are pseudonymous, locating data associated with a particular person may require enough information to identify the relevant pseudonymous record without exposing additional sensitive data.

TECHNICAL DETAIL

Need the exact application-level fields?