Seatext library / BotRefund evidence

How SeaText AI Ensures Data Minimization: Practices, Certifications, and What Advertisers Should Know

SeaText AI limits data collection to what is required for bot detection and refund processing, backed by ISO 27001, 27017, and 27018 certifications that mandate strict PII handling and cloud security controls. The platform...

Built for advertisers who need clear, refund-ready traffic evidence.

SeaText AI applies data minimization by collecting only the signals necessary to identify automated traffic and build refund-ready evidence dossiers for Google and Meta. Its ISO 27001, 27017, and 27018 certifications require documented controls for personally identifiable information (PII) in cloud environments, which include limiting data scope, retention, and access. In practice, the script gathers browser, network, hardware, and behavioral signals — such as pointer movement, click timing, and session duration — but does not capture form content, keystrokes, or personal identifiers beyond what the ad platforms already provide.

What data minimization means for an ad-fraud platform

Data minimization is the principle that a system should collect, process, and retain only the minimum personal data needed to achieve its stated purpose. For a bot-detection and refund service, the purpose is twofold: (1) distinguish human from automated visits with high confidence, and (2) produce evidence that ad platforms accept for billing disputes. Any data point that does not directly support one of those goals is out of scope.

This matters because advertisers already share extensive data with Google and Meta. Adding a third-party script that vacuums up extra PII — emails, names, CRM IDs — would expand the attack surface without improving detection. SeaText's approach is to treat each signal as a single, independent fact (e.g., "pointer path snapped to grid") and feed it into an AI model that weighs the full pattern. The raw signals are not linked to a person's identity; they are linked to a session ID that the advertiser already controls.

Security certifications that enforce minimization

SeaText holds three ISO certifications that collectively require data-minimization controls:

  • ISO 27001 — Information security management system. Mandates asset classification, access control, and regular risk assessments that include data-volume reviews.
  • ISO 27017 — Cloud security controls. Extends 27001 to virtual server infrastructure, requiring providers to define what customer data is processed in the cloud and for how long.
  • ISO 27018 — PII protection in public clouds. Explicitly requires data minimization, purpose limitation, and retention schedules for personally identifiable information.

These certifications are audited annually. The audit scope covers the SeaText AI platform that powers BotRefund, meaning the same controls apply to the bot-detection script, the evidence dossier generator, and the refund-negotiation workflow.

Data collected for bot detection and refund evidence

The BotRefund script runs 106 independent checks grouped into browser, network, device, and behavioral categories. Each check produces a single boolean or numeric signal — for example, "impossible tab speed" flags a timing mismatch that a real browser does not normally create. The signals listed in the public reference include:

  • Click behavior: ghost clicks, honeypot trap interactions
  • Pointer behavior: robotic linear movements, absence of humanlike tremor
  • Speed behavior: superhuman input speed (<1 ms)
  • Path behavior: grid-aligned movement patterns
  • Engagement behavior: absence of clicks or scrolling
  • Session behavior: unnatural session durations

None of these signals capture form field values, typed text, or authentication tokens. The script does not record screenshots of page content; it records only the behavioral telemetry needed to score the session. The evidence dossier that BotRefund compiles for a refund claim aggregates these scores per campaign, placement, and time window — not per individual visitor identity.

How data flows from script to refund claim

  1. Collection — The lightweight script loads on the advertiser's landing page. It captures the 106 signals in the visitor's browser and sends a compact payload to SeaText's cloud infrastructure.
  2. Scoring — The prediction AI evaluates the complete pattern across all signals. A single anomaly is never a verdict; the model requires corroboration across independent categories.
  3. Evidence packaging — Flagged sessions are grouped by ad-platform click ID (gclid, fbclid), campaign, and timestamp. The dossier shows aggregate bot rates, signal breakdowns, and video replays of representative sessions.
  4. Refund submission — The advertiser (or BotRefund on their behalf) submits the dossier to Google or Meta. The platforms review the evidence and issue credits when the claim meets their invalid-traffic policies.
  5. Retention cleanup — After the dispute window closes (typically 60–90 days for Google, 90–120 days for Meta), session-level raw signals are purged. Aggregated reports remain for the advertiser's historical analysis.

Retention, review, and deletion practices

ISO 27018 requires a defined retention schedule. SeaText's practice aligns with the ad platforms' dispute windows:

  • Raw signal logs — Retained for the maximum dispute period plus a 30-day buffer, then automatically deleted.
  • Scored session records — Kept in pseudonymized form (session ID + scores) for up to 12 months to support trend analysis and model improvement.
  • Evidence dossiers — Stored as long as the advertiser's account is active, because they represent the audit trail for past refunds.
  • Account-level aggregates — Retained indefinitely unless the advertiser requests deletion.

An internal review runs quarterly. The security team verifies that no fields outside the documented signal schema have been added, that deletion jobs executed on schedule, and that access logs show only authorized personnel viewed raw data. Any deviation triggers a corrective-action record under the ISO 27001 management system.

Limitations and what the certifications do not guarantee

  • No absolute guarantee against breaches. Certifications confirm that controls exist and are audited; they do not eliminate risk.
  • Ad-platform data is outside SeaText's control. Google and Meta already collect extensive user data. SeaText minimizes its additional collection, but the combined dataset remains large.
  • Model improvement uses pseudonymized scores. The AI retrains on aggregated patterns, not raw visitor data. However, advertisers who require zero secondary use should confirm the current model-training policy in their contract.
  • Enterprise contracts may extend retention. Custom SLAs can override the default schedule. Check the signed agreement.

Key facts

AspectDetailSource
Certifications heldISO 27001, ISO 27017, ISO 27018S1
PII protection scopePublic cloud environments, personally identifiable informationS1
Bot detection signals106 independent checks across browser, network, device, behaviorS1, S4, S6, S8
Signal examplesGhost clicks, honeypot traps, linear mouse paths, superhuman input speed, grid-aligned movement, unnatural session durationsS2, S8
Accuracy claim99% bot/human classification via corroborated AI predictionS4, S6
Refund lookbackGoogle Ads spend dating back to 2017S2, S8
Setup timeAbout one minute, no credit card requiredS2, S8
Refund approval rate83% across client claims submitted to ad platformsS2

Frequently asked questions

Does SeaText collect my visitors' personal information?

No. The script collects behavioral telemetry — mouse movements, click timing, scroll depth, browser fingerprint attributes — that cannot be reverse-engineered into names, emails, or CRM IDs. The only identifier passed through is the ad-platform click ID (gclid/fbclid), which the advertiser already shares with Google or Meta.

Can I delete my data before the standard retention window?

Yes. Account administrators can request immediate deletion of raw signal logs and scored session records via the dashboard or by emailing support. Evidence dossiers for already-submitted refund claims are retained as financial records unless the advertiser withdraws the claim.

How does the AI model improve without storing raw visitor data?

The model retrains on aggregated, pseudonymized score distributions — e.g., "sessions with signal X and Y present were confirmed bot 99.2% of the time." No raw payloads, IP addresses, or click IDs are used in training batches.

What happens if a new signal is added to the 106 checks?

Any new signal goes through the ISO 27001 change-management process: risk assessment, data-minimization review, documentation update, and auditor notification. The signal is not deployed to production until the review confirms it serves the stated purpose and collects no excess data.

Does SeaText share data with third parties?

Only with the advertiser's explicit consent when submitting a refund dossier to Google or Meta. The dossier contains aggregated evidence, not individual session payloads. SeaText does not sell, license, or share behavioral data for advertising, analytics, or any other purpose.

How can I verify the certifications are current?

Request the latest ISO 27001, 27017, and 27018 certificates from SeaText's security team. The certificates list the scope, expiration date, and accredited registrar. You can also verify the registrar's accreditation on the relevant national accreditation body website.

What if my legal team requires a Data Processing Addendum (DPA)?

SeaText provides a standard DPA that incorporates the ISO 27018 commitments, retention schedules, and data-subject rights procedures. Enterprise customers can negotiate custom clauses; the baseline DPA is available on request during the demo or audit booking flow.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more