Privacy Policy
Last updated: 4 September 2026
1. Operator
SeyDit is operated by:
- Lukáš Hrnčíř
- Business ID: 07783485
- Business address: Ostravská 216, 261 01 Příbram, CZ
- Email: info@hrncirovistudio.cz
2. Privacy by Design
SeyDit is designed to minimise the processing of personal data. Whenever technically possible, information is processed directly on the user's device.
SeyDit does not maintain its own database of users' voice commands, emails, calendars, reminders or notes unless explicitly stated for a particular feature.
3. OpenAI
SeyDit uses OpenAI services to provide artificial intelligence functionality.
OpenAI is the only third-party AI/ML provider to which SeyDit transfers Google Workspace user data. SeyDit connects directly to the OpenAI API and does not use an AI aggregator, gateway or model hub.
SeyDit uses the OpenAI API with the user's own API account and API billing tier; a ChatGPT Free, Plus, Pro, Business or Enterprise subscription is not used by SeyDit. The application currently uses the OpenAI Realtime API model gpt-realtime-2.1 and the gpt-4o-mini-transcribe transcription model.
Users provide their own OpenAI API key. The key is stored using Apple Keychain on the user's device.
When an AI feature is used, information required to fulfil the user's request may be transmitted to OpenAI. This may include a voice command, transcript, text entered by the user or content the user explicitly requests SeyDit to process.
Before such information is shared for the first time, the user is informed about the use of OpenAI and asked to provide the appropriate consent.
Data submitted through the OpenAI API is not used by OpenAI to train or improve generalized models by default. OpenAI may retain API data for abuse monitoring for up to 30 days under its standard API data controls. SeyDit does not claim or require Zero Data Retention.
SeyDit does not enable, request or rely on OpenAI's optional API data-sharing programmes, feedback sharing, evaluation sharing or fine-tuning. Google Workspace user data is sent only through the standard API request needed to fulfil the user's instruction.
4. Voice Data
SeyDit may process the user's voice in order to understand requests, generate responses and perform requested actions.
Voice data is not used for advertising profiling.
5. Connected Services
SeyDit may interact with device features and external services, including email, calendars, reminders, notes, location, maps and services provided by Apple, Microsoft and Google.
Access is limited to permissions granted by the user.
6. Google User Data
SeyDit accesses Google user data only after the user explicitly connects a Google account and grants the requested permissions.
Direct Google account connection may be temporarily unavailable in the current app version. These rules apply if the feature is made available and the user enables it.
SeyDit requests access to Gmail data to provide the following user-facing features:
- displaying and reading email messages requested by the user;
- finding and summarising email messages requested by the user;
- preparing email replies requested by the user; and
- sending email messages after an explicit user request and confirmation.
Google user data is used solely to provide these user-requested features. It is not used for advertising, profiling, marketing, analytics, sale of data, creation of user databases, or training or improving general-purpose artificial intelligence or machine-learning models.
SeyDit does not delete, archive, move or otherwise modify Gmail messages using its Gmail read-only access.
When the user asks SeyDit to read, summarise or otherwise process an email using its voice and artificial-intelligence features, the information required to fulfil that request is transmitted from the user’s device to the configured AI service provider. This transfer is performed solely to provide the requested SeyDit functionality and only after the user has consented to AI processing.
SeyDit’s use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Storage and Retention of Google User Data
SeyDit does not operate a server-side database containing users’ Gmail messages.
Gmail content is retrieved on demand when required to fulfil a user request. The application does not independently create a permanent copy of the user’s mailbox or Gmail messages.
If the user enables SeyDit’s conversation-memory feature, content spoken or generated during a conversation may form part of a conversation transcript stored locally on the user’s device. This may include text derived from an email that the user asked SeyDit to read or summarise. The user can delete locally stored conversation history and disable the memory feature.
Basic Google account information required to maintain the connection, such as the account identifier, email address, user-assigned account name and granted permissions, is stored locally on the user’s device.
8. Protection of Google User Data
SeyDit applies technical and organisational safeguards designed to protect personal and sensitive information.
Google OAuth refresh tokens are stored on the user’s device using Apple Keychain. Short-lived access tokens are held only as required to communicate with Google APIs.
Data transmitted between SeyDit, Google APIs and the AI service required to fulfil a user-requested feature is protected in transit using encrypted HTTPS/TLS connections.
SeyDit requests only the minimum Google permissions required for its Gmail functionality. Access is limited to the Google account and permissions selected by the user.
Users can disconnect a Google account from SeyDit at any time. SeyDit then removes its locally stored authorization credentials and requests revocation of the associated Google authorization token.
9. Analytics and Google User Data
SeyDit may process aggregated technical diagnostics to identify errors and improve application reliability.
Google user data, Gmail message content and information derived from Google Workspace APIs are not used for analytics, advertising, profiling or marketing.
10. Microsoft User Data and Microsoft 365
SeyDit accesses Microsoft user data only after the user explicitly connects a Microsoft account and grants delegated permissions through Microsoft. SeyDit acts as the signed-in user and does not use application-wide unattended access.
Depending on the features selected by the user, SeyDit may request User.Read, Mail.Read, Mail.ReadWrite, Mail.Send, Chat.Read, Chat.ReadWrite, ChatMessage.Send, Files.Read or Files.ReadWrite. These permissions are used only to identify the connected account and to read, search, summarise, prepare, send or modify the specific email, Teams or OneDrive content requested by the user. Sending a message or email requires explicit confirmation in SeyDit.
Microsoft 365 content is retrieved on demand through Microsoft Graph. SeyDit does not operate a server-side database containing users' Microsoft email, Teams messages or OneDrive files. Basic account details, user-assigned account names and granted permissions are stored locally on the device.
Microsoft OAuth refresh tokens are stored on the device using Apple Keychain. Short-lived access tokens are retained only as required to communicate with Microsoft Graph. Data is protected in transit using encrypted HTTPS/TLS connections.
When the user explicitly asks SeyDit to process Microsoft 365 content using voice or AI, only the information required to fulfil that request may be transmitted to OpenAI. Microsoft user data is not used for advertising, marketing, analytics, profiling, sale of data or general-purpose AI model training.
Users can disconnect a Microsoft account at any time. SeyDit then removes the locally stored authorization credential for that account. Access may also be revoked from the user's Microsoft account or by the relevant organisation administrator.
11. User Content
At the user's request, SeyDit may work with emails, calendar events, reminders, notes and other content.
Where AI processing is required, the relevant portion of that content may be transmitted to the AI provider.
12. Location
Location may be used for functions such as navigation, place searches and location-based reminders.
Location permission can be changed at any time through iOS settings.
13. App Purchases
SeyDit is distributed through the Apple App Store.
Payments are processed by Apple. The SeyDit operator does not receive the payment card details used for App Store purchases.
14. Analytics
The current SeyDit iOS app contains no third-party advertising or analytics SDK and does not track users. Apple may independently provide aggregate App Store information and diagnostics under the user's settings and Apple's rules.
SeyDit website analytics is separate, and optional analytics technologies are activated only after cookie consent.
15. Briefings, meeting recordings, web and custom apps
A scheduled briefing uses only sources explicitly selected by the user. Required content is sent to OpenAI to create the briefing, and the result is stored locally until the user deletes it.
The user starts meeting recording and must inform participants and obtain their consent. After confirmation, audio is sent to OpenAI for transcription and summarization; the transcript and summary are stored locally in SeyDit Notes. Audio can be retained or deleted according to the user's choice.
For web search, the user's query is sent to OpenAI. SeyDit does not automatically add email content, location or other data unless required for the explicitly requested task.
For a custom connected app, the user defines the service address, credentials and instructions. The access secret is stored in Apple Keychain. Data is fetched only on request or for a user-selected briefing and the necessary portion may be sent to OpenAI. The connection can be removed at any time.
16. Data Retention and Deletion
Personal data is retained only for as long as necessary for the relevant purpose or as required by applicable law.
Conversations can be deleted in Memory, briefings in Scheduled Briefings, notes in SeyDit Notes, and accounts in the relevant service settings. Uninstalling removes remaining local data from that device; copies created by an external service follow that service's rules.
External service providers may apply their own retention policies.
17. Your Rights
Where applicable under GDPR, users may have rights including access, correction, deletion, restriction, portability, objection and withdrawal of consent.
Requests may be submitted to: info@hrncirovistudio.cz
18. Third Parties
Depending on the features used, SeyDit may interact with services provided by Apple, OpenAI, Microsoft, Google, Higgsfield and Magnific.
The operator selects providers that are required to protect personal data at least to the level described in this policy and required by applicable law. If such protection cannot be ensured, data will not be shared with that provider or its use will be discontinued.
19. Higgsfield and Magnific MCP Services
Users may optionally connect their Higgsfield or Magnific account using OAuth. The access token is stored in Apple Keychain on the device. SeyDit does not request or store the password for either service.
SeyDit sends the selected service an instruction, parameters and any media selected by the user only after an explicit request and confirmation. Processing, retention of inputs and outputs, and credit usage are then governed by the provider's account, plan and policies.
The account can be disconnected at any time in Settings → MCP; this removes the local OAuth token and ends SeyDit's access. Fully revoking access or deleting data retained by the provider may require using the Higgsfield or Magnific account settings.
Provider policies are available at https://higgsfield.ai/privacy-policy and https://www.magnific.com/legal/privacy.
20. Contact
- Lukáš Hrnčíř
- Email: info@hrncirovistudio.cz
- Ostravská 216, 261 01 Příbram, CZ