Privacy Policy
Last updated: 24 July 2026
This policy explains what personal data Sequo collects, why, who else sees it, and what you can do about it.
Who is responsible for your data
The controller of your personal data is:
Artem Horobchenko
Warsaw, Poland
Contact for anything in this policy, including requests about your data:
privacy@sequo.app
Sequo is operated from Poland. The EU General Data Protection Regulation (GDPR) applies.
What Sequo does, in one paragraph
Sequo turns a description of a software project into a build plan, a set of project documents, and one prompt per step that you paste into your own AI coding agent. Sequo does not write or run your code. It stores your project description and everything generated from it.
What we collect
When you use Sequo without an account. We create a random identifier and store it in a cookie on your device so we can show you your own project when you come back. We do not know who you are. If you later create an account, that project is linked to your account and the anonymous identifier stops being used for it.
When you create an account. Your email address, and either a password (stored by our authentication provider as a hash, never as text we can read) or the email address and basic profile information your Google account returns if you sign in with Google.
What you type into Sequo. The project description you enter, your answers to the clarifying questions, and any revisions you request. Everything generated from that: the structured version of your idea, the technology choices, the build plan, the project documents, and the step prompts.
Technical data. Your IP address and request timestamps, used to limit how often the same visitor can trigger expensive operations and to block automated abuse. Your browser user agent when you send feedback.
Feedback. If you use the feedback widget: the message you write, the page you sent it from, the project it relates to, your account email if you are signed in, and an email address if you choose to give one.
Payments. If you subscribe, the payment is handled by Polar, which acts as the seller of record. Polar collects and processes your payment details. We never see or store your card number. We receive confirmation that a subscription is active, and the identifiers needed to link it to your account.
Please do not paste secrets
Treat the idea field as you would a message to a colleague. Do not paste passwords, API keys, access tokens, or personal data about other people. Your text is sent to an external AI provider (see below) and stored in our database.
Why we process it, and on what legal basis
| What | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account data | To create your account, sign you in, and let you return to your projects | Performance of a contract, Art. 6(1)(b) |
| Anonymous identifier | To show you your own project before you register | Performance of a contract, Art. 6(1)(b) |
| Your project content | To generate the plan, documents, and prompts you asked for, and to show them back to you | Performance of a contract, Art. 6(1)(b) |
| IP address, request timestamps | To rate-limit and block automated abuse that would otherwise exhaust our costs | Legitimate interests, Art. 6(1)(f) |
| Feedback | To understand problems and improve the product | Legitimate interests, Art. 6(1)(f) |
| Subscription status | To give you access to paid features | Performance of a contract, Art. 6(1)(b) |
| Invoice and tax records | Because tax law requires us to keep them | Legal obligation, Art. 6(1)(c) |
Our legitimate interest in the abuse-prevention case is keeping a small service financially viable and available. We use the smallest amount of data that achieves that.
Who else processes your data
We use the following providers. Each one only receives what it needs.
| Provider | What it does | What it receives |
|---|---|---|
| xAI (Grok) | Generates your plan, documents, and step prompts | Your project description, your clarifying answers, and the previously generated content for that project |
| Supabase | Database and authentication | All stored data: account, projects, generated content, feedback |
| Vercel | Hosting | Request data, including IP address |
| Resend | Sends account emails and feedback notifications | Your email address and the email content |
| Cloudflare | Turnstile, which distinguishes people from bots | IP address and browser signals at the moment you submit a form |
| Sign-in, only if you choose "Sign in with Google" | The sign-in exchange; Google tells us your email address | |
| Polar | Payments and subscription billing | Your payment details, which it collects directly |
Read that first row carefully. Sending your project description to xAI is how Sequo works. There is no version of the product where that does not happen.
We do not sell your data. We do not share it with advertisers. We run no advertising and no third-party analytics.
Where your data is stored, and when it leaves the EU
Our database sits in Frankfurt, Germany. Your account, your projects, and everything Sequo generates for you are stored inside the European Union. Supabase, which operates that database, is a US company, so its staff may access the infrastructure for support and maintenance.
Some processing happens outside the European Economic Area. xAI generates your content in the United States. Vercel serves the site, Resend sends the email, Cloudflare runs the bot check, Google handles sign-in if you use it, and Polar processes payments, all from outside the EEA.
These transfers rely on the safeguards in Chapter V of the GDPR, which in practice means the European Commission's Standard Contractual Clauses, the EU-US Data Privacy Framework where the provider is certified, or both. Ask us and we will tell you which mechanism covers a specific provider.
How long we keep it
Your account and project data stay until you ask us to delete them, or until you delete your account. We do not expire inactive projects.
Rate-limiting records hold an identifier and a counter for the length of the limit window, measured in hours, then stop being used.
Feedback is kept for two years so we can track recurring problems.
Invoices and payment records are kept for as long as tax law requires, which in Poland is generally five years from the end of the tax year.
Your rights
Under the GDPR you can ask us to:
- give you a copy of the personal data we hold about you
- correct anything inaccurate
- delete your data
- restrict how we process it
- send you your data in a portable format
- stop processing based on legitimate interests, by objecting
Write to privacy@sequo.app. We answer within one month.
On deletion, one honest note. Sequo has no self-service delete button yet. Email us and we remove your account and your projects manually. We are building the button.
If you think we are handling your data wrongly, you can complain to the Polish supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa
uodo.gov.pl
You can also complain to the authority in the EU country where you live.
Cookies
Sequo sets a small number of cookies, all of them necessary for the service to work:
- an identifier that links you to a project you started without an account
- session cookies that keep you signed in, set by our authentication provider
- a cookie set by Cloudflare Turnstile when it checks that a form submission comes from a person
We run no analytics cookies, no advertising cookies, and no tracking pixels. Because every cookie we set is strictly necessary to deliver a service you asked for, we do not show a consent banner. If we ever add analytics, we will ask first.
Automated processing
Sequo uses an AI model to produce your plan and documents. That is the product working as intended, and you decide what to do with the output. We make no automated decisions that produce legal effects for you or similarly significantly affect you within the meaning of Article 22 of the GDPR.
Treat generated content as a draft. Review it before acting on it.
Children
Sequo is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
Security
Access to your data is restricted at the database level, so one user cannot read another user's projects. Traffic runs over HTTPS. Passwords are hashed by our authentication provider. No system is perfectly secure, and we do not claim otherwise. If a breach puts your rights at risk, we will notify you and the supervisory authority as the GDPR requires.
Changes to this policy
When this policy changes we update the date at the top and post the new version here. For changes that affect your rights, we email account holders.
Contact
privacy@sequo.app
Artem Horobchenko, Warsaw, Poland