SemSwitch Privacy Policy
Version: 2.0
Last updated: September 4, 2026
SemSwitch, Inc. ("SemSwitch," "we," "us," or "our") develops software and computing infrastructure, including Setsuna. This Policy explains how we handle personal information in connection with our websites, business communications, account and preview-access services, and products that link to this Policy (together, the "Services"). Personal information means information that identifies, relates to, or can reasonably be linked to an individual.
1. When this Policy applies
We are responsible as a controller for personal information we use to manage our websites, business relationships, accounts, communications, and our own security and legal obligations.
When we process information in a customer's workloads on that customer's behalf, the customer generally determines the purposes of that processing, and we act as its processor or service provider. Workload information can include code, commands, files, environment variables, inputs, outputs, and content-bearing logs ("Customer Content"). Our agreement with the customer, including an applicable Data Processing Addendum, governs that processing. Calling information "telemetry" or "metadata" does not remove protections that apply to it as personal information or Customer Content.
A customer's own privacy notice applies to its relationship with its users. This Policy does not govern independent third-party websites, applications, or services, or a separately identified SemSwitch service with its own notice. It does not authorize a new use of information contrary to an existing agreement or applicable law.
2. Information we collect and receive
The information involved depends on the features you actually use. Visiting a public page does not, by itself, give us access to your private repositories or local files.
| Category | Examples and sources |
|---|---|
| Inquiries and business relationships | Name, email, organization, role, and information you provide in a contact, research-preview, partnership, support, or investor inquiry; correspondence and attachments; information supplied by an authorized colleague or professional introduction. |
| Meeting requests | Name, email, company, selected meeting time, time zone, notes, and booking or cancellation records you submit. |
| Accounts and access | Identifiers supplied by you, your organization, or an identity provider; email, organization membership, permissions, account status, authentication events, and access-credential records such as key identifiers, hashes, expiry, revocation, and use history. Client software may also store authentication material on your device for sign-in. |
| Website and service activity | IP address, browser and device information, requested pages or API operations, timestamps, referring pages, approximate location or network information, performance measurements, errors, and security or abuse signals. Infrastructure providers receive connection information when they handle requests. |
| Benchmark and document downloads | The requested resource, request time, referring page, browser information, and approximate country or network information. Such records are not necessarily anonymous merely because they omit a name or a full IP address. |
| Website assistant interactions | Messages, replies, conversation identifiers, and information you include in an interaction with our website assistant. Optional voice features are described in Section 4. |
| Customer workloads and support | Customer Content submitted or generated through use of a service, associated sandbox or process identifiers, execution status, resource use, and troubleshooting information. Logs and command output may contain personal information or secrets supplied by a customer. |
| Communications and transactions | Subscription choices, confirmation and unsubscribe records, message delivery and interaction information where enabled, and business contact, invoice, payment-status, or transaction records when you enter a commercial relationship with us. |
We also receive relevant professional contact information from public business sources or people making an introduction, where lawful. We do not need sensitive personal documents to answer a general product inquiry. Do not send identity documents, financial account credentials, health records, or other sensitive information through public forms or the website assistant.
3. How we use information
We use personal information to provide requested functionality; review and administer access; communicate about evaluations and commercial relationships; operate and troubleshoot the Services; measure website and service performance; prevent fraud and abuse; manage subscriptions and transactions; meet legal obligations; and establish, exercise, or defend legal claims. We limit processing to what is reasonably necessary for these purposes.
We use Customer Content to deliver the customer's requested service and to secure, maintain, and support that service within the customer's instructions and our agreement. We do not use Customer Content to train general-purpose AI models, sell it, or make it available to other customers. A customer may separately instruct us to support its own model-training or evaluation workload; that is different from using its information to train models for our own or another party's purposes.
We may use service measurements that do not disclose Customer Content or identify a person or customer to understand reliability, capacity, and performance. Where we de-identify personal information, we take reasonable measures against re-identification, do not attempt to re-identify it except as permitted by law to assess those measures, and require recipients to respect applicable restrictions. Anonymization is not a substitute for permission to reuse confidential material.
We send newsletters following the applicable subscription process. A meeting request, preview application, support request, or investor inquiry is not, by itself, newsletter consent. You can unsubscribe from marketing using the message's instructions or by contacting us. Necessary account, security, contractual, and requested communications may continue.
4. Website assistant and voice features
Our website assistant is separate from the workloads customers run using Setsuna. Messages sent to the assistant are processed through our website infrastructure and Microsoft Azure AI services. Retrieval used to answer questions may also process a search query through our knowledge-search provider. Conversations can be stored by the provider to maintain context; they do not exist only in your browser.
We use assistant interactions to deliver responses, investigate failures or abuse, and improve the usefulness of our website assistance. We do not use website assistant conversations to train general-purpose AI models. Do not use this public assistant to submit confidential customer workloads, credentials, regulated records, or investment-verification documents. It is not a confidential diligence or support-upload channel.
When you request spoken replies, the text to be spoken is processed by Microsoft's speech service. When you enable browser dictation, microphone permission and speech recognition are controlled by your browser and its speech provider; audio may be processed by that provider, and the resulting text is submitted to the assistant. You can decline or disable microphone access and use text instead.
Closing the chat, clearing a browser cookie, or allowing a session token to expire does not necessarily delete a stored provider conversation. Contact us about access or deletion using Section 10.
5. Cookies, browser storage, and measurement
Our website and authentication providers use cookies or comparable session technologies for functions such as sign-in, access control, abuse prevention, and maintaining a requested assistant session. These technologies may be set by SemSwitch or by the provider operating the relevant feature.
We use Cloudflare Web Analytics to measure page use and performance. Cloudflare describes that analytics product as not using cookies, local storage, or individual fingerprinting for analytics. This does not mean that all features on our website are cookie-free, that infrastructure providers never receive an IP address, or that no personal information is processed.
You can manage browser storage and microphone permissions through your browser and use the sign-out controls supplied with an authenticated service. Blocking essential technologies can prevent the requested feature from working. Where applicable law requires consent for a technology or use, we obtain that consent before enabling it; browser settings alone are not a substitute for required consent.
We do not sell personal information or share it for cross-context behavioral advertising, and we do not use personal information for targeted advertising as those activities are defined by applicable U.S. state privacy laws. We do not respond separately to the older, non-standardized "Do Not Track" browser signal. We honor legally required opt-out preference signals, such as Global Privacy Control, for processing to which those signals apply. Our no-sale, no-sharing, and no-targeted-advertising practices apply whether or not you send such a signal.
6. When we disclose information
Service providers. We use providers for hosting and delivery, databases and storage, authentication, security and bot prevention, website measurement, AI-assisted website responses and speech, email delivery, business communications, and business-record and website-content management. Current examples include Cloudflare for website infrastructure and related services; Microsoft Azure for computing and website AI or speech features; Auth0 and Clerk for the respective authentication experiences; Amazon Web Services for transactional email; Customer.io for subscription communications; and Airtable for business records such as meeting requests and for managing published website content. A provider receives information relevant to its function, not automatically every category in Section 2.
These examples are not a list of subprocessors authorized for every customer workload. For customer processing covered by a DPA, the applicable service schedule identifies the authorized subprocessors, their purposes, and processing locations, and the DPA governs changes. We require appropriate contractual protections from providers processing personal information on our behalf.
Your organization and instructions. We disclose information to authorized customer administrators as needed to administer organizational access and services, and to recipients you or your organization instruct us to use. A workload that connects to an external repository, model API, storage service, or other destination can send information to that destination under the customer's control.
Professional and legal purposes. We may disclose information to professional advisers under appropriate confidentiality duties; where required by law or valid legal process; or where reasonably necessary and lawful to protect rights, safety, and the security of the Services. We assess requests and limit disclosures to their lawful scope.
Corporate transactions. We may disclose information where necessary to evaluate or complete a financing, merger, acquisition, reorganization, or transfer of business assets, subject to appropriate confidentiality and data-protection safeguards. This is not permission to disclose customer workloads indiscriminately to prospective investors or buyers or to disregard an existing customer agreement.
Your choice. We may disclose information with your direction or legally valid consent. We do not make a customer's name, logo, confidential workload, or non-public evaluation results public merely because that customer uses our Services.
7. Retention and deletion
We keep personal information for no longer than reasonably necessary for the applicable purpose, subject to customer instructions, contractual commitments, and legal requirements. The relevant criteria differ by record:
| Record | Retention criteria |
|---|---|
| Inquiries, bookings, and business correspondence | Resolving the request, maintaining an active or reasonably anticipated business relationship, and applicable recordkeeping or claims requirements. |
| Accounts, identity links, and access records | Providing and administering authorized access, detecting or investigating misuse, and preserving necessary security or contractual records after access ends. |
| Website, download, and operational records | The period reasonably needed to measure performance, diagnose an issue, investigate security events, or support service administration; information no longer needed for these purposes is deleted or de-identified. |
| Website assistant conversations and support submissions | Continuity of the interaction, support and quality review, security investigation, and relevant provider storage settings; a session-expiry time is not a transcript-retention period. |
| Marketing records | Maintaining an active subscription and evidence of preferences; a limited suppression record may be retained after unsubscribe to avoid contacting you again. |
| Customer Content | The instructed workload lifecycle and any storage, return, and deletion arrangements in the applicable agreement. A short-lived execution environment is not a general-purpose archive. |
| Financial, legal, and compliance records | Applicable accounting, tax, corporate, regulatory, and limitation periods, and any particular legal hold. |
Ending or destroying a sandbox does not necessarily delete related account records, operational logs, support copies, or information exported to another system. It is not a promise that every underlying storage block or external copy has been physically overwritten. Keep any outputs you need through the methods supported by your service.
Where a deletion request applies, we delete or de-identify the relevant information unless retention is lawfully required or permitted. Information awaiting removal from backups or protected archives remains restricted and is removed through the applicable deletion cycle. We do not restore it to ordinary use to avoid a deletion request. Customer-specific return and deletion obligations are governed by the applicable DPA and service schedule.
You can ask us for information about retention applicable to your interaction or service. If a request cannot be fully fulfilled, we explain the applicable reason to the extent required and permitted by law.
8. Security and international processing
We use technical and organizational safeguards appropriate to the information and processing involved. No internet service or execution environment can guarantee absolute security. Authentication, workload isolation, and environment cleanup are different controls; none alone establishes a guarantee of confidentiality from every infrastructure operator, complete data erasure, or suitability for regulated data.
SemSwitch is a U.S. company. Information may be processed in the United States and other countries in which the applicable providers or authorized personnel operate. A website domain, cloud-provider brand, or selected compute region is not by itself a commitment that all identity, logging, support, or other processing remains in that region.
Where international-transfer restrictions apply, the relevant transfer must be supported by a lawful mechanism, such as an applicable adequacy determination or appropriate contractual safeguards, together with any required assessment and supplementary measures. Customer-specific restrictions and safeguards are recorded in the applicable agreement. Contact us for information about applicable safeguards or a copy, subject to necessary redactions. This Policy does not claim that SemSwitch holds a certification or participates in a transfer framework merely because a provider does.
9. Legal grounds for processing
Where a law requires a legal basis, we rely on the basis appropriate to the particular processing. This includes performing or taking requested steps toward a contract with you; legitimate interests in running a business, administering organizational accounts, answering relevant inquiries, improving service reliability, and protecting our systems, balanced against individuals' rights; complying with legal obligations; and consent when required, including for applicable optional communications or technologies.
An employer's contract with SemSwitch is not automatically a contract with each individual employee. We generally rely on the appropriate legitimate interest or other lawful basis for business-representative information. For Customer Content processed on instructions, the customer is responsible for identifying its lawful basis, and our processor obligations remain applicable.
Providing some information is necessary to answer a request, authenticate you, or deliver a requested service. Without it, we may be unable to do so. Optional marketing choices are not required to obtain unrelated services.
10. Your rights and how to contact us
Depending on the law that applies, you may have rights to confirm processing; access or obtain a portable copy; correct or delete information; restrict or object to processing; withdraw consent; opt out of sale, advertising-related sharing, targeted advertising, or qualifying profiling; limit certain uses of sensitive information; and appeal a decision about your request. These rights are subject to applicable conditions and exceptions. Withdrawing consent does not invalidate earlier lawful processing.
Send a request to privacy@semswitch.com. Describe the request and the account, organization, or interaction involved. Do not include a password, API key, or unnecessary identity document. We use proportionate identity and authority checks and respond within the applicable legal deadline. Authorized agents may submit requests where permitted, subject to verification. We do not unlawfully discriminate or retaliate for exercising privacy rights.
For an appeal where available, reply to our decision or email privacy@semswitch.com with "Privacy appeal" in the subject. You may also complain to the supervisory authority, attorney general, or other regulator responsible in your jurisdiction, including an EEA supervisory authority or the UK Information Commissioner's Office where applicable.
For information controlled by a customer, direct your request to that customer first. If you contact us, we will help identify the appropriate route where possible and assist the customer as required by law and our agreement. This does not limit rights you can lawfully exercise directly against SemSwitch.
For California residents, the table in Section 2 describes our collection categories and sources, Section 3 the purposes, Section 6 the recipient categories, and Section 7 retention criteria. Depending on the interaction, these include identifiers, customer-record and commercial information, internet or network activity, approximate location, professional information, and communications. Workloads may contain other categories selected by the customer. We do not use sensitive personal information to infer characteristics about you; account credentials are used to provide and secure access.
11. Children
Our Services are intended for adult professional and business use, not directed to children. We do not knowingly collect personal information from children under 13 through our own websites and account services. If you believe a child has provided such information, contact privacy@semswitch.com so we can investigate and take appropriate action. Customers remain responsible for the information they lawfully control and for complying with restrictions on their use of the Services.
12. Changes and contact details
We update this Policy when our practices or legal requirements change and identify the current revision above. We provide additional notice of material changes, and obtain consent where required. Posting a revised Policy does not retroactively authorize a materially incompatible use of previously collected information or amend an executed customer DPA.
Privacy requests: privacy@semswitch.com
Security reports: security@semswitch.com
Legal notices: legal@semswitch.com
Support: support@semswitch.com
SemSwitch, Inc.
8 The Green, Suite B
Dover, DE 19901
United States