Seatext library / BotRefund evidence

Does SeaText AI Use Your Personal Data for Training Its AI Models?

No, SeaText AI does not use your personal data to train its models unless you give explicit consent. The platform holds ISO 27001, ISO 27017, and ISO 27018 certifications, which require strict controls on...

Built for advertisers who need clear, refund-ready traffic evidence.

SeaText AI does not use your personal data to train its models unless you give explicit consent. This is not just a policy statement—it is a requirement built into the platform's core operations through internationally recognized security standards. The platform operates under ISO 27001, ISO 27017, and ISO 27018 certifications, which mandate strict handling of personally identifiable information and restrict data processing to the purposes you agree to.

What SeaText AI Actually Does

SeaText AI is described as the first AI that enhances websites without requiring changes to their original design. It dynamically adapts the experience for each visitor: translating content for international visitors, optimizing copy to increase engagement, and making pages more concise and mobile-friendly for users on smaller screens. The AI analyzes each visitor to predict the ideal content—tailoring language, length, and messaging to create a more engaging experience.

This processing happens in real time during a visit. The system adjusts what the visitor sees based on signals like device, location, and behavior. The goal is a better experience for that visitor, not to collect a training corpus for future model updates. Each session is processed independently, with no persistent storage of personal identifiers used for model improvement.

The platform's core function is session-level personalization. When a visitor from Germany lands on an English page, the AI detects the browser language setting and automatically serves translated content. When a mobile user visits, the system shortens paragraphs and adjusts layout. These adaptations happen without storing personal data in a way that could be used for training purposes.

How the Certifications Constrain Data Use

ISO 27001 is the international standard for information security management systems. ISO 27017 adds cloud-specific security controls. ISO 27018 specifically addresses protection of personally identifiable information (PII) in public cloud environments. Together, these certifications mean:

  • Data processing purposes must be defined and documented.
  • PII cannot be repurposed for model training without explicit consent.
  • Access controls, encryption, and audit trails are required.
  • Third-party subprocessors are bound by the same obligations.

The certification scope covers the platform that powers SeaText AI and the related BotRefund service. The certifications are independently audited and must be maintained through regular surveillance audits. This means that every year, external auditors verify that the system continues to meet these strict requirements.

ISO 27018 is particularly relevant here. It specifically requires that PII collected in cloud environments can only be used for the purposes specified at the time of collection. Using visitor data for AI model training would constitute a new purpose that requires explicit consent from each data subject.

What Data Is Processed During a Visit

When a visitor lands on a site using SeaText AI, the system may process:

  • Browser language and locale settings to serve translations.
  • Device type and screen size to adjust layout and copy length.
  • Behavioral signals such as scroll depth, dwell time, and click patterns to optimize content.
  • IP address for geographic routing and bot detection (shared with the BotRefund layer).

This data is used to personalize the current session. The ISO 27018 controls require that PII—such as IP addresses when combined with other identifiers—is protected and not reused for unrelated purposes like model training.

The processing is designed to be minimal and purpose-limited. IP addresses are used only for geographic routing and security purposes, not for building user profiles. Behavioral data is aggregated in real-time to optimize the current visit, then discarded rather than stored for future model training.

Consent and Control Mechanisms

Because the certifications require purpose limitation, any use of personal data beyond the immediate personalization function would need a separate lawful basis—typically explicit consent. The platform does not include a default opt-in for training data collection.

If a future feature were to use aggregated, anonymized interaction data for model improvement, the certification framework would require:

  • Clear notice to data controllers (the website owners).
  • An opt-out mechanism that does not degrade the core service.
  • Documentation of the new processing purpose in the Record of Processing Activities.

Website owners act as data controllers under GDPR and similar laws. SeaText AI operates as a data processor. The data processing agreement (DPA) that accompanies the service defines the permitted purposes and the processor's obligations. This legal framework ensures that data usage stays within agreed boundaries.

The DPA is a critical document that website owners should review carefully. It spells out exactly what data is processed, for what purposes, and under what conditions. Any deviation from these terms would constitute a breach of contract and potentially a violation of data protection laws.

How Bot Detection Intersects With Personal Data

SeaText AI is part of a suite that includes BotRefund, which detects automated traffic on advertising clicks. BotRefund uses 106 independent browser, network, device, and behavioral signals—such as impossible tab speed, window.open tampering, ghost clicks, and robotic mouse movements—to score each visit. These signals are analyzed in real time to distinguish bots from humans.

The bot detection layer processes some of the same technical data (IP, browser fingerprint, behavioral timing). However, its purpose is fraud prevention and ad spend recovery, not model training. The ISO 27018 certification covers this processing as well, requiring the same purpose limitation and PII protections.

This dual functionality is important to understand. The same technical infrastructure that personalizes website content also identifies fraudulent bot traffic. Both functions are covered by the same security certifications, ensuring consistent data protection across all platform features.

The bot detection system uses behavioral biometrics—subtle patterns in how humans interact with web pages. These include mouse movement patterns, typing rhythms, and navigation sequences. Bots struggle to replicate these micro-behaviors, making them identifiable even when they use sophisticated techniques like residential proxies or human-in-the-loop CAPTCHA solving services.

Limitations and What the Certifications Do Not Guarantee

Certifications demonstrate that a management system exists and has been audited. They do not guarantee that no data breach will ever occur, nor do they replace the data controller's own compliance obligations. Specific limitations include:

  • The certifications cover the platform infrastructure and core services. Custom integrations or third-party plugins added by the website owner are outside the scope.
  • Anonymization claims depend on implementation. IP addresses combined with behavioral profiles can sometimes be re-identified.
  • The certifications do not dictate product roadmap. A future feature could introduce training data collection, but it would require a new DPA amendment and consent flow.

If you are a website owner evaluating SeaText AI, request the current DPA and the ISO 27018 statement of applicability. Verify that the permitted purposes align with your privacy notice to visitors.

Certifications are a baseline, not a ceiling. They ensure minimum security standards but do not protect against all possible risks. Website owners must maintain their own compliance programs, including privacy notices, cookie consent mechanisms, and data subject request processes.

Key Facts

FactDetailSource
Core functionDynamically adapts website experience per visitor: translation, copy optimization, mobile concisenessS1
Security certificationsISO 27001, ISO 27017, ISO 27018S1
ISO 27018 scopeProtecting personally identifiable information (PII) in public cloud environmentsS1
Data roleProcessor (website owner is controller)S1
Bot detection signals106 independent browser, network, device, and behavioral checksS5, S7
Bot detection accuracy claim99% accuracy via AI prediction across corroborated signalsS5, S7

Frequently Asked Questions

Can SeaText AI see my visitors' personal data?

It processes technical data (IP, browser language, device info) and behavioral signals (scrolls, clicks, timing) to personalize the visit. Under ISO 27018, this data is treated as PII when it can be linked to an individual. The platform does not collect names, emails, or CRM data unless the website owner explicitly passes it through a configured integration.

Does the AI learn from my specific site's visitors?

The real-time personalization uses per-visit signals to adjust content for that visitor. The certifications require that this processing stay within the agreed purpose. Aggregated learning across sites would be a new purpose requiring consent and DPA updates.

What happens if I want to delete visitor data?

As the data controller, you can request deletion. The processor must comply within the timeframes defined in the DPA. The ISO 27001 framework includes procedures for data retention and secure disposal.

Is my ad spend data used for training?

BotRefund processes click IDs (GCLID, FBCLID) and behavioral proof logs to build refund cases for Google and Meta. This data is used for fraud detection and dispute evidence, not for training the SeaText AI personalization models.

How do I verify the certifications are current?

Ask for the latest surveillance audit report or the certificate with an expiry date. Reputable vendors provide these on request. You can also check the certification body's public register using the certificate number.

What if regulations change (e.g., EU AI Act)?

The ISO 27001 management system includes a process for monitoring legal and regulatory changes. The vendor must assess new requirements and update controls. As a controller, you should include a regulatory change clause in your DPA.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more