Your context is yours.
This policy explains what Segue collects, why, and what control you have. It's written to be read.
Effective July 20, 2026
Segue is a personal context store: it lets AI assistants you connect save blocks of text and load them back by a short handle. Segue is operated by CSA Intelligence Inc., based in Toronto, Ontario, Canada ("we," "us"). It applies to segue.ai, the Segue web app, and the Segue MCP server.
What we collect
Account information. Your email address and a password. Passwords are stored only as cryptographic hashes using bcrypt; we cannot read them.
Your content. The contexts you (or your connected AIs) save: Markdown text, optional titles, handles, project names, and timestamps. This is the point of the product, and it is private to your account by construction — every read is scoped to your user ID at the service layer.
Connected AI clients. When you connect an AI tool, we store its OAuth client registration, the scopes you approved, hashed access and refresh tokens, and when it was last active. We never see or store your credentials for those AI tools.
Billing. Purchases are processed by Polar Software Inc. as merchant of record. Polar — not Segue — collects your payment details; we never see your card number. From Polar we receive and store your subscription status, plan, billing period, and a Polar customer reference.
Technical data. Standard server logs (IP address, user agent, request timestamps) kept for security, debugging, and rate limiting, and retained for 30 days.
How we use it
To provide the service: storing and serving your contexts, authenticating you and your connected clients, and enforcing plan limits. To keep the service safe: rate limiting, abuse prevention, and detecting token misuse. To bill you, via Polar. To email you transactional messages (password resets, billing notices) — delivered through Resend. To understand aggregate product health, using metrics derived from service activity (for example, how many contexts are saved or loaded per week).
We do not sell your data. We do not show ads. We do not use your contexts to train AI models — ours or anyone else's. We read individual account content only if you ask us to (support) or the law requires it.
Your connected AI clients
This part is unusual and worth understanding. When an AI you connected loads a context, that content is transferred to that AI's service — for example, loading a handle in ChatGPT sends that context to OpenAI, under OpenAI's terms and privacy policy. Segue only ever hands your content to clients you authorized on our consent screen, with the scopes you approved, and you can revoke any client in Settings at any time. But once a context is loaded into another vendor's tool, that copy is governed by your relationship with that vendor, not by this policy. You carry the baton; mind where you pass it.
Who we share data with
We share data only with the processors needed to run the service:
| Processor | Purpose | What they receive |
|---|---|---|
| Railway | Hosting and database (the United States) | All service data |
| Polar Software Inc. | Payments, merchant of record | Email, purchase and subscription data |
| Resend | Transactional email | Your email address, message content |
| Google Fonts | Web font delivery | Your IP address and browser metadata when pages load |
No third-party analytics, tracking pixels, or advertising SDKs run on Segue.
We may disclose data if required by law, or as part of a merger or acquisition — in which case this policy continues to apply to data collected under it and we will notify you.
Cookies
Segue sets only essential cookies: a session cookie to keep you signed in and a CSRF token to protect forms. No tracking cookies, no cookie banner theater.
Retention and deletion
Your contexts stay until you delete them. Deleting a context is immediate and permanent — there is no version history or trash. Edits overwrite. Revoking a client invalidates its tokens immediately.
To delete your account entirely, email us at support@segue.ai; we will remove your account, contexts, client registrations, and instruct Polar to delete your customer record, within 30 days. Backups age out within 30 days after that. We retain billing records as long as tax law requires.
Your rights
You can access and export everything without asking us: every context is viewable, editable, and downloadable as Markdown in the web app. You can correct data by editing it, and delete it yourself as described above.
If you're in Canada, we handle personal information in accordance with PIPEDA; you may request access to or correction of your personal information, or complain to the Office of the Privacy Commissioner of Canada. If you're in the EU/EEA or UK, you have the rights the GDPR grants — access, rectification, erasure, portability, restriction, and objection — and our legal bases are performance of a contract (running the service you signed up for) and legitimate interest (security and abuse prevention). We don't do automated decision-making or profiling.
To exercise any right, email support@segue.ai. We'll respond within 30 days.
Security
Everything in transit is encrypted with TLS. Access, refresh, and password-reset tokens are stored only as SHA-256 hashes. Connected clients get narrow scopes and short-lived tokens (access tokens last 1 hour), and detected reuse of an authorization code revokes the whole token chain. Every content read is isolated to its owner's account at the service layer. No system is perfectly secure, but if we learn of a breach affecting your data, we will notify you and the relevant authorities as the law requires.
Children
Segue is not directed at children and requires users to be 16 or older. We don't knowingly collect data from anyone younger; if you believe we have, email us and we'll delete it.
International transfers
Segue is operated from Canada and hosted in the United States. Canada holds an EU adequacy decision for commercial organizations under PIPEDA; where data leaves your jurisdiction, we rely on that adequacy and our processors' standard contractual clauses.
Changes
If this policy changes materially, we'll email account holders and post the new version with a fresh effective date. Continued use after that date means the new version applies.