Principle
Creator-owned relationship
Subscribers join a specific creator, not a generic Seamline marketing list. The list belongs to the creator — not to us.
Trust infrastructure
Seamline helps creators build a direct thread with their audience. That only works if visitors know what they are joining, who will email them, and where their data will not go.
Boundary promise
Creator content can power AI. Subscriber identity cannot.
This is enforced as a product design rule, not a marketing footnote.
Principle
Subscribers join a specific creator, not a generic Seamline marketing list. The list belongs to the creator — not to us.
Principle
Lead emails, names, and subscriber-identifying data stay out of model prompts. Only creator-authored project descriptions go to Claude.
Principle
Capture surfaces and email flows must keep exit paths visible and honest. No buried opt-outs, no dark-pattern re-subscriptions.
Principle
Seamline optimizes for trust and clarity — not pressure mechanics, fake urgency, or hidden consent. We build trust infrastructure.
Data boundaries
Exactly what goes where.
Used for creator intelligence
Never sent to AI
Used only after explicit setup
Executable guardrails
Build checks block subscriber identifiers, raw lead rows, and unsafe policy metadata from artificial intelligence (AI) prompt surfaces.
scripts/check-privacy-boundaries.mjs
Quota and plan claims are checked in API routes from server-owned records. Client-side tier claims are never trusted.
lib/tiers.ts + authenticated API routes
First-thread milestones write aggregate proof receipts without storing subscriber identity in the public progress ledger.
activation_proof_ledger
Live proof rollup
The rollup is generated from local proof artifacts only. It never includes subscriber personally identifiable information, secrets, or live billing actions.
Rollup status
12/14
needs-attention
Generated Jul 29, 2026
Direct deploy receipt
needs-attention
Worker 893cc1bd-3a24-4bc0-a9f5-35113c8dabd9
Commit 048670b · health pass · live proof pass
Generated Jul 29, 2026
First-thread proof
pass
Sequence dispatch proof
pass
Webhook replay proof
pass
Notification lifecycle proof
pass
Remote production proof
pass
Direct deploy receipt
needs-attention
Live performance proof
pass
Local DB proof
pass
Worker heat-map regression guard
pass
OpenNext proxy canary
blocked-on-opennext-adapter (stale)
Release gate evidence
fail
Contact reachability proof
mailbox-proof-needed
Responsive readiness proof
pass
Doctor snapshot
pass
Refresh OpenNext proxy canary while it is stale: OPENNEXT_BLOCKED · restored=true · next=pass · opennext=fail · proxy.ts still passes Next build but fails the OpenNext Cloudflare build as Node.js middleware. · 2026-07-18T20:01:10.408Z · freshness stale (10d old)
Subscriber promise
They are joining a creator-specific relationship, not a platform newsletter.
The creator controls the message and the list relationship; Seamline supplies infrastructure and measurement.
Preference signals are optional, consented, and aggregate-first — they help the creator improve the thread without turning the subscriber into a data product.