Privacy Policy
Last updated: August 8, 2026
This policy explains what DealSeal ("the Service") collects, how it is used, and who it is shared with. It applies to dealseal.io and its APIs. By using the Service you agree to this policy and to the Terms of Service.
1. Information You Provide
- Party details - your name and email address, and the email address of the counterparty you invite.
- Deal details - title, description, asking price or opening offer, additional terms, and any equipment fields (make, model, year, hours, serial, location, condition).
- Private negotiation inputs - your bottom line, BATNA, ROI notes, and pitch. See section 3; these are treated differently from everything else.
- Uploads - any image you attach to a negotiation.
- Support requests - anything you send through the support form.
2. Information Collected Automatically
We record your IP address and email address as rate-limiting keys, to stop abuse of the creation and email endpoints. We keep server logs of requests and errors. The Service uses no analytics, tracking pixels, advertising trackers, or third-party cookies. Browser local storage is used only to hold an administrator session token on administrator devices.
3. Your Sealed Values - What We Actually Do
Confidentiality between the two parties is the product, so we state this precisely rather than generally.
Your bottom line, BATNA, ROI notes and pitch are never disclosed to the other party. They are excluded from every party-facing API response, every email, every transcript, and every certificate. Outcome bands in a Meet Report are deliberately coarse so a counterparty cannot reverse-engineer your number from them. These exclusions are enforced in code, not by policy alone.
DealSeal's own operators can see these values through an administrative interface protected by a separate password, in order to support and debug the Service. That is access by us as the operator of the Service; it is not disclosure to the other party.
They are, however, sent to the AI provider that operates your own advocate, because your advocate cannot represent your interests without knowing your limits. They are not sent to the content-moderation layer at all. If you do not want a value processed by a third-party AI provider, do not enter it.
4. How We Use Information
- To run the negotiation you asked us to run, and to notify both parties by email.
- To screen public-facing text and uploaded images for prohibited content before they are stored.
- To operate, secure, debug and improve the Service, including rate limiting and abuse prevention.
- To process payments, when paid plans are enabled.
- To comply with law, enforce our Terms, and respond to legal process.
We do not sell your personal information, and we do not use your negotiation content to train our own models.
5. Service Providers
The Service cannot function without sending certain data to the following processors:
- AI model providers (Anthropic, and OpenRouter for moderation and image generation) - receive negotiation content, including the private inputs described in section 3 for your own advocate. Their handling of that data is governed by their own terms and privacy policies.
- Mailgun - delivers transactional email, and therefore receives recipient addresses and message contents.
- Stripe - processes payments when paid plans are enabled. Card details go to Stripe directly; we never receive or store them.
- Hosting and infrastructure providers - store the database, uploads and logs.
We share information with these providers only as needed to deliver the Service, and otherwise only where required by law or to protect our rights.
6. Access Links
Dashboard and invitation links contain a secret access token in the URL. Anyone holding such a link can act as that party, and these tokens do not currently expire. Treat those links as credentials: do not forward them, and do not post them anywhere public. We are not responsible for access obtained through a link you shared.
7. Retention
Negotiation records, messages and uploads are retained indefinitely so that both parties keep access to their deal history, unless you ask us to delete them. An invitation that is never accepted is cancelled once the record is next accessed more than 72 hours after it was created; a record nobody opens can remain pending beyond that. Cancellation changes the status of the record and does not by itself erase it. Rate-limit counters and moderation logs are retained as operational records; moderation logs store decision metadata only, never your content.
8. Your Choices
You may request access to, correction of, or deletion of your personal information by contacting us through the support form. We will respond within a reasonable period. Note that we may be unable to delete information that forms part of a counterparty's record of a completed deal, or that we are required to keep.
9. Security
We take reasonable technical measures to protect your information, including code-level isolation of the sealed values described in section 3. No system is perfectly secure, and we do not guarantee absolute security. To the fullest extent permitted by law, we are not liable for unauthorised access, disclosure, or loss of data.
10. International Users
The Service is operated from the United States and information is processed there and wherever our providers operate. If you use the Service from another country, you consent to that transfer and processing.
11. Children
The Service is not directed to anyone under 18, and we do not knowingly collect information from them.
12. Changes
We may update this policy at any time. Material changes will be reflected in the "last updated" date above, and continued use of the Service after a change constitutes acceptance of the revised policy.
13. Contact
Questions about this policy go through the support form.