Privacy

What Seston does with your data

Short version: almost nothing, because almost nothing leaves your computer. This page says exactly what does, and there is not much of it.

Last updated 28 August 2026.

There is no account and no collection

Seston has no sign-up, no licence key and no user identity. It does not send telemetry, usage statistics, crash reports or analytics of any kind. Nobody — including us — can tell that you have installed it, opened it, or what you did with it.

Your recordings, session files, generated audio and everything you do to them stay on your own machine. They are never uploaded, and there is no server to upload them to.

The three things that reach the internet

1. The update check

Unless you switch it off in Preferences, Seston asks GitHub once a day what the latest published version number is. The request goes to api.github.com and carries nothing but the fact that a copy of Seston of a given version is asking — which, like any web request, means GitHub sees the IP address it came from. No identifier of you or of your installation is sent.

Copies installed from the Microsoft Store do not do this at all: the Store updates them itself.

2. The sound pack catalogue

The Browse tab in the Library panel reads one file — content.seston.app/index.json — and only at the moment you open that tab. Nothing is read on start-up, and if you never open it nothing is ever contacted. The request carries nothing but itself: no identifier, no account, nothing about your session. Downloading a pack fetches it from the same place. As with any web request, the server sees the IP address it came from.

Every address Seston follows there comes out of that file rather than out of the program, and only https addresses are followed at all.

3. Generate Speech

This feature is the exception to everything above, and it only does anything while you are using it. When you generate a voice, the text you typed and your own ElevenLabs API key are sent to ElevenLabs, over HTTPS, and nowhere else. What ElevenLabs then does with them is governed by their privacy policy and your account with them. Seston has no account there and no part in the transaction.

If you never use Generate Speech, nothing about it ever runs and nothing is ever sent.

Your API key

The ElevenLabs key you enter is encrypted with Windows' own data protection under your user account, so the file that holds it cannot be read from another account on the same machine and is worthless on any other. It is not kept in settings.json, it is never written to a session file, a log or the status bar, and it is never shown again after you enter it. Remove the key deletes it.

It is sent to ElevenLabs and to nowhere else. There is nowhere else for Seston to send it.

This website

seston.app counts page views, using Umami on our own server at stats.notfm.com. It sets no cookies, builds no fingerprint, follows nobody between sites and records nothing that identifies a person: a page address, a referrer, a country, and whether the screen was large or small. Nothing is sent to Google or to any advertising company, because none is involved. There is no advertising on this site. Your browser also stores two things locally — whether you chose the light or the dark theme, and your answer to the notice below — and neither ever leaves your browser.

You can decline the counting. A notice appears on your first visit with an Accept and a Decline. Declining means the counter is never loaded on any page you open, not that the notice stops appearing while the counting carries on. The answer is remembered in your browser, so you are asked once; clearing your browser's storage for this site asks again.

The download links point at GitHub, and the version number shown on the home page is read from GitHub by your browser, so GitHub sees that request the way it sees any other. The site is hosted on Cloudflare Pages, which keeps ordinary server logs of requests made to it.

The account, and only for packs

Adding a sound pack from the catalogue needs an account. Everything else in Seston works without one, and nothing else in the program asks for it.

An account is an email address. There is no password. Signing in sends a six digit code to the address, and what is stored is the address, the date you joined, the country the request came from, and a token for the machine you signed in on. The code itself is stored only as a hash and only for ten minutes.

Signing in with Google is the other way, and it is there so that nobody has to wait for a message to arrive. It opens your browser, you choose an account, and Google tells us one thing: the address, and whether Google has verified it. The permission asked for is that and nothing more, so there is no access to your mail, your files, your contacts, or anything else in the account. Google's answer is read once and thrown away, and what is kept afterwards is exactly what the six digit code would have left behind. You never type a Google password into Seston, because Seston never sees one.

When you add a pack, that is recorded: which pack, when, and which account. It is how we know which packs are worth making more of. It is not sold, not shared, and not used to build a profile of anything else, because nothing else is collected.

Signing out from the Account menu removes the token from this machine and from the server. To have the account itself deleted, with everything recorded against it, ask and it will be.

Children

Seston is a tool for making radio and podcast programmes. It is not directed at children and collects nothing from anybody, of any age.

Changes, and how to ask

If any of this changes, this page changes with it and the date at the top moves. A change that means more data leaving your machine would also be written in the release notes, because it is the kind of thing somebody should not have to discover.

Questions about any of it: open an issue.