Privacy Policy
Undercurrents · operated by Seedling Systems LLC (seedlingsystemsllc.com)
Effective date: May 28, 2026 · Last updated: May 28, 2026
This Privacy Policy describes how Seedling Systems LLC (“Seedling,” “we,” “us”) collects, uses, discloses, and protects information when you use Undercurrents (the “Service”).
Our privacy commitments
- We do not sell your personal information. We do not sell, rent, or trade your data to data brokers, advertisers, or list vendors.
- We do not serve third-party advertising in the Service. We do not use ad networks that profile you across other sites.
- We minimize access. Our internal admin tools are designed to show operational metadata—not decrypted health journal content.
- We use opt-in research aggregates only after sustained use, and only in coarse, anonymized form (see Research).
1. Who is responsible
Controller: Seedling Systems LLC
Website: seedlingsystemsllc.com
Product: Undercurrents at https://undercurrents.tech
Privacy inquiries: Support (please do not include detailed health information in email subject lines)
2. Information we collect
Account and identity
- Name, email address, password (stored hashed), timezone, authentication session data
- Subscription and billing status (payment details are handled by Stripe; we receive tokens and status, not full card numbers)
Wellness profile and logs
Depending on how you use the Service, we may collect:
- Goals, conditions, medications, allergies, lifestyle habits, environment and exposure-area answers
- Daily mood, energy, sleep, symptoms, food and exercise tags, optional notes, and time-coded event entries (food, symptom, activity, stress, period)
- Plans, insights, experiments, and feedback you provide on suggestions
- AI run metadata and prompts/responses needed to generate insights
Technical and security data
- IP address, browser type, device information, and logs needed for security, abuse prevention, and debugging
- Admin audit logs (actions by authorized staff on non-content admin functions)
- Optional marketing attribution identifiers if you arrive via a campaign link (see product integration docs)
3. How we use information
- Provide, maintain, and secure the Service
- Generate personalized insights, plans, and AI-assisted observations you request
- Process payments and manage subscriptions
- Send transactional messages and optional reminder or insight emails you enable
- Comply with law and enforce our Terms
- With your opt-in only: contribute anonymized aggregate research to improve the product
4. Legal bases (EEA/UK users)
Where GDPR or UK GDPR applies, we rely on:
- Contract — to provide the Service you signed up for
- Consent — for optional research contribution and non-essential emails where required
- Legitimate interests — security, fraud prevention, product improvement using aggregated or de-identified data, and communicating about your account
- Legal obligation — when we must retain or disclose data under law
5. Encryption and security
We use administrative, technical, and organizational measures appropriate to the sensitivity of wellness data. These include access controls, encrypted transport (HTTPS/TLS), and application-layer encryption for many high-sensitivity fields using Laravel’s encryption (keyed by our server APP_KEY).
Fields typically encrypted at rest in our database
Including, without limitation:
- Health conditions, medications, allergies, family history, and dietary restrictions
- Recreational substance entries, encrypted goal and experiment notes
- Daily log free-text notes, symptom lists, time-coded event payloads, and saved meal templates
- Insight titles and bodies, plan revision content, AI prompt snapshots and outputs
- Feedback notes and selected sensitive exposure-area answers (e.g., stress-related responses)
Fields that may be stored without application-layer encryption
Some lower-sensitivity or structural fields may be stored in plaintext in our database while still protected by access controls and TLS—for example: mood/energy numeric scores, sleep hours, country/region, home age band, water source category, work-hazard tags, and similar categorical profile answers. A database backup leak without our encryption key could expose those fields more readily than encrypted columns.
Important: Encryption at rest does not mean “zero risk.” Anyone with access to the live application and valid keys, or a compromised server, could decrypt protected fields. Losing APP_KEY makes encrypted data unrecoverable.
Staff access
We design administrative interfaces to avoid displaying decrypted health journal content. Operational staff may see account metadata (e.g., subscription status, log counts, AI job status). Access is limited to personnel who need it and is subject to confidentiality obligations.
6. AI processing (Anthropic)
When AI features are enabled, we send relevant portions of your profile and recent logs to Anthropic, P.C. to generate observations. This may include condition labels, goals, environment summaries, and recent mood/sleep data. We instruct models to use wellness framing, not medical diagnosis. Anthropic processes data under its own terms and privacy policy as an independent processor.
AI outputs may be inaccurate. Do not rely on them for medical decisions. You can review our Legal & safety disclaimers.
7. Subprocessors and disclosures
We share information only as needed with:
- Stripe — payment processing
- Anthropic — AI inference (when enabled)
- Hosting and infrastructure providers — to run the application and databases
- Email delivery providers — for account and optional insight emails
- Professional advisors or authorities — when required by law or to protect rights and safety
We do not disclose your personal information to advertisers or data brokers.
8. Optional anonymized research
If you opt in during consent or settings, we may later contribute anonymized aggregate records after you have been actively logging for at least four (4) weeks. Contributions include coarse data such as:
- Age band, sex at birth category, broad region, hashed condition fingerprint (not a list of diagnoses)
- Medication categories (e.g., “SSRI”), not drug names
- Exposure-area bands (e.g., indoor air: moderate), not individual product answers
- Outcome labels from voluntary feedback (better / no change / worse)
We apply a minimum group size (k-anonymity floor of 50 similar profiles) before using aggregates in product features. Once written, anonymized research rows are not linked back to your account and cannot be deleted on request. You may opt out of future contributions at any time in settings.
9. Retention
- Active account data is retained while your account exists and as needed to provide the Service.
- When you delete your account, we delete or de-identify personal data within a reasonable period, subject to backups, legal holds, and billing records we must keep.
- Anonymized research records may be retained indefinitely in aggregate form.
- Security and audit logs may be retained for a limited period for investigation.
10. Your rights and choices
Depending on where you live, you may have rights to:
- Access and export your data (available in Settings)
- Correct profile information through the health profile and exposure areas
- Delete your account and all associated data at https://www.undercurrents.tech/account/delete (requires sign-in and password confirmation). You can also delete from Settings once subscribed.
- Withdraw consent for research or marketing emails
- Object or restrict certain processing where GDPR applies
California residents may have additional rights under the CCPA/CPRA (access, delete, correct, know categories, non-discrimination). We do not “sell” or “share” personal information for cross-context behavioral advertising. Submit requests via Support. We may verify your identity before responding.
11. Children
The Service is not directed to children under 18. We do not knowingly collect personal information from children. Contact us if you believe a child has provided data and we will delete it.
12. International transfers
We are based in the United States. If you access the Service from other countries, your information may be processed in the U.S. or where our subprocessors operate. We use appropriate safeguards where required for cross-border transfers.
13. HIPAA and health laws
Undercurrents is a consumer wellness journal, not a covered entity or business associate under HIPAA in the manner a hospital or insurer would be. Do not use the Service to store records you are legally required to keep only in a certified medical record system unless you have made appropriate arrangements.
14. Changes to this policy
We may update this Privacy Policy. We will post the new version with an updated effective date and provide additional notice for material changes where appropriate.
15. Contact
Seedling Systems LLC
seedlingsystemsllc.com
Support