Privacy Policy
Effective 2026-10-08
1. Who we are
AiSeek (aiseek.dev, the "Service") is operated by WU Yuanchao, an individual resident in Japan ("AiSeek", "we", "us"). We are the business operator responsible for personal information under Japan's Act on the Protection of Personal Information (APPI) and the controller of personal data under the EU and UK General Data Protection Regulations (GDPR).
Contact for anything in this policy: [email protected]. Our postal address is disclosed without delay on request.
2. What this policy covers
This policy explains what personal data we handle when you visit aiseek.dev, create an account, subscribe, use features such as following, alerts, briefs, research and Ask AiSeek, or contact us. It also explains how we handle information about people that appears in public sources we analyse (section 9).
3. Information we collect
Account information. Your email address, display name and, if you sign up with a password, a salted hash of it (we never store the password itself). If you sign in with GitHub, Google or Microsoft, we receive your name, email address, profile picture (not from Microsoft) and account identifier from that provider. If you enable two-factor authentication, we store the secret needed to verify your codes. If you add a passkey, we store its public key, the name you give it, when it was added, its signature counter and the kind of authenticator; your fingerprint, face or screen lock is checked on your device and never reaches us. If you ask for a sign-in code by email, we keep only a hash of the code until it is used or expires after 10 minutes.
Sessions and security. When you are signed in we keep a session record with the time, IP address and browser user agent, so we can keep you signed in and detect misuse.
What you do in the Service. The companies, topics and other items you follow, your alerts and saved filters, your brief and email preferences, your private research runs and their results, and your Ask AiSeek questions and answers. Private research and Ask AiSeek threads are visible only to you and are never published.
Your own model key (Ask AiSeek). If you add an API key for a model provider, we store it encrypted (AES-256-GCM) and use it only to send your Ask AiSeek requests to the provider you chose. After you save it we never show it again; you see only its last four characters.
Subscriptions and payments. Payments are handled by Polar, which acts as the merchant of record. Polar collects your payment details; we never receive your card number. We receive your plan, subscription status, renewal date and a customer identifier.
Comments. A comment you post on the Discover page is shown publicly with your account's display name once the team has reviewed it, never with your email address. We keep its text, language, time and the review decision.
Messages to us. When you use the contact form, report a problem with content or send a takedown request, we keep what you send: your email address, your name if you give it, the category, your message and the item it concerns. To limit abuse we keep a salted hash of your network address, never the address itself.
Newsletter. If you subscribe to the newsletter, we keep your email address, the language and how often you chose, when and on which page you subscribed and confirmed, your referral code and, if you came through someone's link, whose. We send a confirmation email first and add the address to the mailing list only after you confirm. The emails are sent through our email delivery provider (Resend). Unsubscribing, from the link in any email, stops them at once; we keep the address marked as unsubscribed so it is not mailed again, and delete it on request.
Your account's first week. When you sign up, your browser sends where that visit came from: the referring website's domain (never the full address), the labels of the link you followed (utm_source, utm_medium, utm_campaign) and, if you came through a friend's link, their invite code. We keep these with your account, together with when you last used the site, how many days you have used it, whether you finished or skipped the welcome step and when you claimed a Pro pass. To give one Pro pass per person, we keep a one-way hash of your normalised email address (not the address itself), also after your account is deleted. If you were invited, the friend who invited you can see that an invite succeeded, never which account it was; to tell invites from duplicate accounts we compare, inside our systems, the network address and browser recorded for the two accounts' sign-ins. Each account also gets a welcome email once and, if you claim a Pro pass, one reminder the day before it ends; both can be turned off with the link in them.
Usage analytics. We use a self-hosted instance of Umami to understand how the site is used. It does not use cookies, does not track you across other websites and does not store your IP address. It also counts a few steps without anything that identifies you: a newsletter subscription, the start and the completion of a checkout (with the plan and billing period), copying an embed, which version of a page you saw, the welcome step, claiming a Pro pass, and sharing a page or copying an invite link (with where it was shared to). It records the page visited, the referring page, browser, operating system, device type and the country derived from your IP address at the time of the visit.
Location for the weather card. The weather card on the home page needs to know roughly where you are. By default we use the city and coordinates Cloudflare derives from your IP address; only if you press the location button and allow it in your browser do we use the position your browser provides. Either way, the coordinates are rounded to about 10 km before they are used to look up the weather, and they are neither stored nor logged.
Your country for SeekMap. The SeekMap card opens on a region near you: a country you follow on SeekMap, or else the country Cloudflare derives from your IP address for that request. Only the two-letter country code is used, to choose what the card shows; it is neither stored nor logged, and the pages themselves are the same for every visitor.
Server logs. Our servers and our network provider record technical data for each request, such as IP address, time, requested address, status and user agent, to operate and protect the Service.
We do not ask for sensitive data (such as health, beliefs or biometric data) and ask you not to send it to us.
4. Cookies and similar storage
We use only cookies that the Service needs to work:
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookie | Keeps you signed in | Up to 30 days, or until you sign out |
aiseek_locale | Remembers the language you chose | 1 year |
| Passkey check cookie | Holds the one-time challenge while you add or use a passkey | 5 minutes |
aiseek_pk_offer | Remembers that you chose "Not now" when offered a passkey after signing in | 1 year |
aiseek_pet | Set only when you put the little ball away from the footer, to remember that choice | 1 year |
aiseek_theme | Set only when you switch between light and dark, to remember that choice | 1 year |
aiseek_visit | When you were last on the site, so the home page can say what arrived since (the time only, to the minute) | 1 year |
aiseek_read | The changes you opened from the home page (the first 8 characters of each change's id, the latest 60), so they show as read | 1 year |
aiseek_ab | "a" or "b": which of two versions of a page you see while we compare them (for example monthly or yearly prices shown first). It identifies no one | 180 days |
aiseek_src | Where this visit came from (the referring site's domain, the link's labels and an invite code), until you sign up and your browser sends it once | Until you close the browser |
Cloudflare security cookies (for example __cf_bm) and Turnstile | Tell people from bots and protect sign-in and forms | Minutes to hours |
We do not use advertising or cross-site tracking cookies. Your browser may also store small preferences locally (such as a collapsed panel); these never leave your device.
5. Why we use your information
| Purpose | Information used | Legal basis (GDPR) |
|---|---|---|
| Create and run your account, sign you in, keep it secure | Account, session and security data | Contract; legitimate interest in security |
| Provide follows, alerts, briefs, research and Ask AiSeek | What you do in the Service, your model key | Contract |
| Send emails you asked for (verification, password reset, alerts, briefs) | Email address, preferences | Contract; consent where required for optional emails |
| Manage subscriptions and plan limits | Subscription data from Polar | Contract; legal obligation (tax and accounting) |
| Answer messages, fix reported errors, handle takedown requests | Messages to us | Legitimate interest in support and content quality; legal obligation |
| Understand and improve the Service | Cookieless analytics, aggregated usage | Legitimate interest |
| Prevent abuse, fraud and attacks | Server logs, session data, security cookies | Legitimate interest; legal obligation |
Under APPI, these are our purposes of use. We will not use personal information beyond them without your consent unless the law permits.
We do not sell your personal data, do not use it for advertising and do not use your private research, Ask AiSeek questions or account data to train AI models.
6. Who we share it with
We share personal data only with service providers who process it for us under contract, or where the law requires:
- Hosting providers that run our servers and store our databases.
- Cloudflare for content delivery, DNS, security, bot protection (including Turnstile), email forwarding and encrypted off-site backups.
- Polar for checkout, payments, taxes, invoices and the customer portal.
- Sentry for error reports from our servers: when something fails on our side, the error, where in our code it happened and the page address without its query. Request headers, cookies, form contents and IP addresses are removed before a report leaves our servers; the browser loads no error-reporting script.
- GitHub, Google or Microsoft, only if you choose to sign in with them.
- MET Norway (the Norwegian Meteorological Institute) for weather forecasts. Our server sends it only the rounded coordinates, never your IP address or account details.
- An email delivery provider to send account emails, alerts and briefs.
- The model provider you choose for Ask AiSeek. When you ask a question, we send your question and the AiSeek content selected to answer it (public content, and your own private research where it is relevant) to that provider with your key. That provider handles the request under its own terms and privacy policy, and bills you for it.
- Google Cloud (Vertex AI) for the SeekMap assistant (Intelligence). When you ask it about a country, we send your question and the public AiSeek content selected to answer it, under our own account; we pay for it, and nothing about your account is sent.
AiSeek also uses AI model providers to analyse public sources (for example, to summarise news or extract relations). Those requests contain public content, not your account data.
We may disclose information if required by law, court order or a competent authority, or to protect the rights, safety and security of our users, the public or AiSeek.
7. International transfers
We are based in Japan, and our servers and service providers may be located in other countries, including the European Union, the United Kingdom and the United States. When personal data moves between countries we rely on appropriate safeguards, such as the EU adequacy decision for Japan, standard contractual clauses or the provider's equivalent commitments. Under APPI, you may ask us for information about the protections in place for a specific foreign recipient.
8. How long we keep it
| Information | Kept for |
|---|---|
| Account, follows, preferences and research | While your account exists; deleted at once when you delete your account |
| Comments | Until you delete the comment or your account |
| Ask AiSeek threads | One year after the last message, or until you delete them or your account |
| Newsletter subscription | While you are subscribed; after you unsubscribe, the address is kept only as unsubscribed so it is never mailed again, unless you ask us to delete it. An unconfirmed address is deleted after 30 days |
| First-week records (where you came from, last use, welcome step, Pro pass, invites) | While the account exists; the hash used for one Pro pass per person is kept after deletion |
| Your model key | Until you remove it or delete your account; deleted when it has not been used for 90 days after your subscription ended |
| Session records | Until the session ends or expires, then deleted |
| Passkeys | Until you remove them or delete your account |
| Sign-in codes (as a hash) | Until used, or 10 minutes |
| Subscription status | While your account exists; Polar keeps invoice records as merchant of record for as long as tax law requires |
| Contact messages and content reports | 2 years after we receive them |
| Takedown requests | 2 years after the decision |
| Server logs | Rotated automatically, usually no longer than 30 days |
| Encrypted backups | Overwritten on a rolling schedule, within about 6 months |
9. People mentioned in public sources
AiSeek analyses public information about companies, markets, institutions and public figures, for example that a founder holds shares in a company. Where this includes personal data about public figures, we process it in our legitimate interest in providing verified public information, show where each statement comes from and distinguish facts from inferences. If information about you is wrong, out of date or should not be shown, write to [email protected] or use the report option on the page, and we will review it.
10. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy in a portable format;
- correct inaccurate data;
- delete your data or your account;
- object to or restrict certain processing, including processing based on legitimate interest;
- withdraw consent at any time, without affecting earlier processing;
- under APPI, request disclosure, correction, suspension of use or deletion of retained personal data.
In your account settings you can change your details, download a copy of your data and delete your account. For anything else, write to [email protected]. We may need to verify your identity, and we answer within 30 days (or the time the applicable law sets). You may also complain to a data protection authority, such as Japan's Personal Information Protection Commission or the authority in your country.
11. Security
We encrypt connections with TLS, encrypt stored model keys and off-site backups, limit access to personal data to what is needed to run the Service, and monitor for misuse. No system is perfectly secure; if a breach affects your personal data, we will inform you and the authorities as the law requires.
12. Children
The Service is not intended for anyone under 16, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy. If a change is significant, we will tell you by email or on the site before it takes effect. The change history at the end of this page lists every version.
14. Contact
WU Yuanchao, operator of AiSeek. Email: [email protected]
Change history
- 2026-10-08 Added the Pro pass and invites: what an account keeps about where it came from and its first week, and the cookie that holds it until sign-up.
- 2026-10-08 Added the newsletter, the steps counted by usage analytics and the cookie that splits visitors between two versions of a page.
- 2026-10-08 Added Sentry, which receives error reports from our servers without personal data.
- 2026-10-07 Added how SeekMap uses your country, where the SeekMap assistant's questions go, and the cookies behind the dark theme, your last visit and read marks.
- 2026-10-07 Added the cookie that remembers you put the little ball away. Liking now needs an account, so visitors no longer get a like cookie.
- 2026-10-07 Added comments on the Discover page and their rules.
- 2026-10-06 Added sign-in with Microsoft, passkeys and emailed codes, and the cookies they use.
- 2026-10-06 Added the cookie behind likes from visitors who are not signed in.
- 2026-10-06 Added the weather card and how it uses your approximate location.
- 2026-10-05 Added Ask AiSeek and your own model key.
- 2026-10-05 First published version.