Legal
Privacy Policy
This policy explains what Sedgemark does with personal data: ours to answer for, and yours that we hold on your behalf. It covers sedgemark.app, this website, our APIs and our MCP server.
Effective 23 August 2026 · Last updated 23 August 2026
1. Scope, and our two different roles
Sedgemark handles personal data in two distinct capacities, and almost everything below follows from which one applies.
| Role | Applies to | What it means |
|---|---|---|
| Controller | Your account, your billing record, our emails to you, our server logs, and anything submitted through this website | We decide why and how it is processed. This policy is our commitment to you about it. |
| Processor | Everything inside your workspace: content entries, media, form submissions, and the personal data of your visitors and customers | You decide why and how; we act on your instructions. Your own privacy notice governs it, not this one. |
If you submitted a form on someone else’s website that runs on Sedgemark, we hold your data for them, not for ourselves. Contact the operator of that website to exercise your rights. If you reach us instead, we will pass your request to them.
Where we act as your processor, the terms governing that processing are set out in our Data Processing Addendum, which forms part of your agreement with us automatically and needs no signature.
2. What we collect as controller
When you create a workspace
Your name, the workspace name and address you choose, and your email address. Your password is
never stored: we keep only a salted scrypt hash of it,
which cannot be reversed into your password.
Before verification, this sits in a pending record for up to 24 hours. If you never click the link, it expires and is deleted, and no workspace or database is ever created.
When you subscribe
A Stripe customer reference, your subscription and plan status, your invoice history, and your card’s brand, last four digits and expiry month and year. We never receive or store your full card number. Card fields belong to Stripe and are entered directly into Stripe’s own form.
When you use the service
Our web server writes an access log for each request: the workspace hostname, the client IP address, the HTTP method, the path, the response status and how long it took. Authorization and Cookie headers are redacted before they are written, so API keys and session tokens do not reach the log.
We also count requests per IP address in memory to enforce rate limits and to bound signup abuse. These counters are transient, are never written to a database, and disappear when the process restarts.
When you contact us or use this website
Whatever you put in your email to us, kept as long as needed to handle the matter and keep a record of it. If you join a waiting list or submit a form here, we collect the details you enter along with your IP address, browser user-agent and originating page, the same anti-abuse fields any Sedgemark form records.
3. What we process on your behalf
Inside your workspace we store and process, as your processor, whatever you put there:
- Content and media: entries, uploaded files and images, and any personal data you choose to put in them.
- Form submissions: the fields you defined, plus each submitter’s IP address, browser user-agent and originating page, and any files they attached.
- Team members: the email addresses, password hashes and permission grants of people you invite.
- Credentials you store: API key hashes, webhook signing secrets and AI provider keys. The last two are encrypted at rest; API keys are stored only as hashes and shown to you once.
- Hosted sites: if you use
sedgemark deploy, the static build output you publish. It is stored and served by Cloudflare’s edge rather than by our servers, and it is public by design. Do not deploy anything you would not put on a public website.
Each workspace lives in its own isolated PostgreSQL database. Media sits in object storage under a per-workspace key prefix. Workspaces do not share tables.
We do not use anything in your workspace to train AI models, to build profiles, or for our own marketing. We access it only to operate the service, to fix a fault you have reported, or where the law requires it.
Note that media served through the delivery API is designed to be publicly reachable. Do not store confidential files in the media library and rely on obscurity to protect them.
4. Why we use it, and our legal bases
Under UK and EU data protection law, we rely on the following bases for the data we control:
| Purpose | Data | Legal basis |
|---|---|---|
| Create and run your workspace | Account details | Performance of a contract |
| Verify your email before provisioning | Email, pending signup | Performance of a contract; legitimate interest in preventing abuse |
| Take payment and issue invoices | Billing record | Performance of a contract; legal obligation (tax records) |
| Service email: verification, password reset, security notices | Email address | Performance of a contract |
| Keep the platform secure, debug faults, enforce rate limits | Access logs, IP addresses | Legitimate interest in security and reliability |
| Answer your support requests | Correspondence | Legitimate interest in supporting customers |
| Product news and marketing email | Email address | Consent: you can withdraw it at any time |
| Comply with law and defend legal claims | As required | Legal obligation; legitimate interest |
We do not sell personal information, and we do not share it for cross-context behavioural advertising, under the CCPA/CPRA or otherwise. We have never done so.
5. Cookies and tracking
Sedgemark uses one cookie, on the app: a session cookie set when you sign in.
It is httpOnly,
SameSite=Strict, scoped to your workspace’s own
hostname, sent only over HTTPS, and it expires after an hour. It is strictly necessary: without
it you cannot stay signed in.
We run no analytics, no advertising trackers, no session recording and no third-party scripts, not in the app, and not on this website. There is nothing to opt out of and no consent banner, because there is nothing non-essential to consent to. Your work inside Sedgemark is not measured by anyone.
Your light or dark theme preference is kept in your browser’s local storage. It never leaves your device and we never see it.
If we ever add analytics to this website, we will update this section and the provider table in section 6 before it starts collecting anything, and we will ask for your consent first where the law requires it.
6. Who else touches your data
We do not sell data. We share it only with the service providers below, each under contract and only as needed to run the platform.
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Akamai (Linode) | Servers, databases and file storage | Everything stored on the platform | USA |
| Cloudflare | DNS and TLS for every domain, hosting for this website, and, where you use site hosting, storage and serving of the static site files you deploy | Traffic metadata, IP addresses, and the static site files you choose to deploy | Global edge |
| Stripe | Payments and subscriptions | Your name, email, card and billing details | USA |
| Resend | Sends our service email | Your email address and message contents | USA |
| Better Stack | Uptime and job monitoring | Whether our systems responded (no customer data) | USA |
| Anthropic / OpenAI | AI field generation (only if you enable it with your own key) | The content your prompt names | USA |
We may also disclose data if legally required, to enforce our terms, or to protect the rights and safety of our users. If the business is sold or merged, data may transfer as part of it; we will tell you before that happens and your rights travel with it.
Changes to this list. We will update this table before adding a provider that handles personal data, and will notify workspace owners by email if the change is material.
7. Where your data lives
Sedgemark runs in the United States. Application servers, databases and file storage are in Miami, Florida. This website, and any site you deploy through Sedgemark, is served from Cloudflare’s global edge network.
Sedgemark is operated from the United States for a United States market. We do not target, advertise to, or specifically offer the service in the EEA, the UK or Switzerland, and prices are in US dollars only. The service is reachable from anywhere, however, so people in those regions can and do sign up.
If you are one of them, using Sedgemark means your data is transferred to and stored in the United States, which does not have a data protection adequacy decision covering every recipient. Where a transfer of data we control requires a safeguard, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum with the providers listed above, alongside encryption in transit and at rest. We honour the rights in section 11 for everyone who asks, wherever they live, whether or not the law obliges us to.
Because we do not target those regions, we have not appointed a representative in the EU or UK under Article 27 of the GDPR. Requests should come to support@getsedgemark.com, which reaches us directly.
8. How long we keep it
| Data | Kept for |
|---|---|
| Workspace content, media and account records | As long as your workspace exists |
| Unverified signup requests | 24 hours, then deleted |
| Password reset links | Single use, short expiry; stored only as a hash |
| Invoices and payment records | 7 years (tax and accounting) |
| Payment event records | 90 days |
| AI run history (status and token counts, no content) | At least 30 days; pruned periodically |
| AI monthly spend totals | Kept: they are your cost history |
| Unclaimed form file uploads | Deleted within hours of being abandoned |
| Server access logs | Rolling window, bounded by size rather than a fixed period |
| Database backups | 30 days, with the 7 most recent runs always retained |
Form submissions are kept until you delete them, or until the form or workspace is deleted. As their controller, setting a retention period for them is your responsibility.
9. How we protect it
- Isolation. Each workspace has its own database with its own credentials. A query for one workspace cannot reach another’s tables.
- Passwords. Stored as salted
scrypthashes and compared in constant time. We cannot see or recover your password. - API keys. Stored as SHA-256 hashes. We can tell you a key exists; we cannot show it to you again.
- Encryption at rest. Database credentials, webhook signing secrets and AI provider keys are encrypted with AES-256. Server disks are encrypted.
- Encryption in transit. HTTPS everywhere, with certificates renewed automatically.
- Administrative access. Our internal admin panel requires a hardware-backed passkey. There is no password login for it.
- Log hygiene. Credentials are redacted from access logs, and error messages from AI providers are redacted before they are stored.
- Backups. Databases are dumped nightly to storage separate from the media bucket, reachable by a credential with no access to the other.
What we do not claim. Sedgemark is a small, independently operated product. We hold no SOC 2, ISO 27001 or comparable certification, and we do not undergo third-party security audits. No system is perfectly secure, and we cannot guarantee absolute security. We tell you this plainly so you can judge whether Sedgemark suits the sensitivity of your data.
If a breach affects your personal data, we will notify you and any regulator we are required to notify, without undue delay and within any deadline the law sets.
10. Deleting your data
You can delete individual entries, media and submissions at any time from the dashboard. To delete an entire workspace, contact us at support@getsedgemark.com.
Deletion is immediate and permanent. Deleting a workspace cancels its subscription, erases its files from object storage and drops its database. There is no undo, no grace period, and no way for us to bring it back. Export first.
Two things survive a deletion, and both are limited:
- Backups, for up to 30 days, after which they age out on their own. They are for disaster recovery and are not accessible to you or searchable by us in the ordinary course.
- Billing records, which we keep for the tax and accounting period above because the law requires it.
11. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and get a copy;
- correct it if it is wrong;
- delete it;
- restrict or object to how we use it, including profiling (we do none);
- receive it in a portable format;
- withdraw consent where consent is the basis, without affecting what came before;
- not be discriminated against for exercising these rights.
How to exercise them. Email support@getsedgemark.com. We will respond within 30 days, and will tell you if we need longer. We may ask you to verify your identity, which for a workspace owner normally means writing from the address on the account.
Much of this is self-serve: the dashboard lets you edit your account, change your password, export content through the API, and delete anything in the workspace.
If you are an end user of a site built on Sedgemark (you filled in a form, or your details are in someone’s content), direct your request to that site’s operator. They are the controller. We will forward requests that reach us and assist them in answering.
If you are in California
In the twelve months before this policy’s effective date we collected these categories of personal information, each for the purposes in section 4 and each disclosed only to the service providers in section 6:
- Identifiers: name, email address, IP address, and account and session identifiers.
- Commercial information: your plan, subscription status and invoice history.
- Financial information: card brand, last four digits and expiry. Full card numbers go to Stripe and never reach us.
- Internet activity: requests recorded in our server logs.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising. We do not use or disclose sensitive personal information beyond what the CCPA permits without a right to limit. Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” link to offer. We will not discriminate against you for exercising any right, and you may use an authorised agent to make a request on your behalf.
If you are in the EEA or the UK you may also complain to your local supervisory authority. We would rather you came to us first.
12. Children
Sedgemark is not for children. We do not knowingly collect personal data from anyone under 18, and workspaces may only be created by adults. If you believe a child has given us personal data, contact us and we will delete it.
If you collect data from children through a Sedgemark form, that is your responsibility as controller, including any obligations under COPPA or equivalent laws.
13. Changes to this policy
We will update this policy as the product changes. The effective date at the top always reflects the current version. For material changes we will email workspace owners at least 14 days before they take effect.
14. Contact us
CodeCube Ventures LLC, doing business as Sedgemark
382 NE 191st St #788543
Miami, FL 33179
United States
support@getsedgemark.com
Privacy questions, data requests and legal notices all go to that address. It is read by a person, not a queue.