---
title: "Seal AI vs Bring-Your-Own-Key: When to Use Each"
description: "Seal AI: nothing to configure, EU-only inference, zero retention. Bring-your-own-key: model choice, plus the transfer analysis and cost. How to pick."
canonical_url: "https://sealmetrics.com/blog/seal-ai-vs-bring-your-own-key/"
lang: "en"
date_modified: 2026-07-28
content_type: "blog"
owner: "content"
llm_priority: "useful"
last_verified: "2026-07-28"
source: https://sealmetrics.com/blog/seal-ai-vs-bring-your-own-key/
publisher: SealMetrics
---

Product

# Seal AI vs Bring-Your-Own-Key: When to Use Each

July 24, 2026 5 min read By [Rafa Jiménez](https://sealmetrics.com/authors/rafa-jimenez/)

Seal AI is the default because privacy should not depend on a checkbox. But you can bring your own OpenAI, Anthropic, Gemini or DeepSeek key if you need a specific model — you just take on the terms, the cost and the transfer analysis that come with it.

## Key Takeaways

- **Seal AI** is the default: no key, no AI vendor account, EU-only inference, zero retention, no training, covered by your plan quota.
- **Bring-your-own-key** buys model choice. In exchange, your prompts run under your provider's terms and jurisdiction, and the usage is not metered by us.
- A US-parent provider means CLOUD Act exposure even with an EU region — with your own key, that assessment becomes yours to run and document.
- It is a setting, not a migration. Switch either way at any time; the assistant behaves the same, only the model and the terms change.

Most products that offer both a managed AI and a bring-your-own-key option quietly push you towards whichever one is cheaper for them. This post does the opposite: here is what each option genuinely costs you, so you can pick once and stop thinking about it.

## Seal AI: the default, and why it is the default

Seal AI is the private AI layer inside SealMetrics. It powers the natural-language assistant and the automated insights, and there is nothing to configure — no API key, no AI vendor account, no onboarding step where you paste a secret into a settings page. The platform holds the key; you never see it.

What that gets you, specifically:

- **Inference in Paris, France only**, on Scaleway's Generative APIs. Scaleway is a French company in the Iliad group with no US ownership, and states explicitly that its AI services are not subject to extraterritorial laws such as the American CLOUD Act.
- **Zero data retention by default** and no training on your data. The documented exception is narrow: on a severe service error, the failing request may be kept for up to two weeks for root-cause analysis.
- **No international transfer at all**, so GDPR Chapter V — Article 44 onward — is not triggered. No Standard Contractual Clauses, no Transfer Impact Assessment, no reliance on the EU-US Data Privacy Framework.
- **Only token counters persist.** Organisation, model, input and output token counts, for quota and billing. Prompt and response content is never persisted by the metering layer.
- **Covered by your plan.** Usage draws on your organisation's token quota, with non-expiring token packs available if you need more headroom.

There is one more property worth naming, because it is upstream of everything above. SealMetrics is consentless analytics: it never collects IP addresses, cookies, fingerprints or visitor identifiers at all. There is no personal identifier in the dataset to send to a model in the first place. The prompt is born clean.

The default is gpt-oss-120b on Scaleway Paris, no training on your data. BYOK adds Anthropic, OpenAI, Gemini or DeepSeek under your own keys.

[Book a demo](https://sealmetrics.com/demo/)[See pricing](https://sealmetrics.com/pricing/)

## Bring-your-own-key: what you gain, what you take on

You can connect your own **OpenAI, Anthropic, Gemini or DeepSeek** key instead. The assistant works the same way — same questions, same tool inventory, same interface — but the inference goes to your provider on your account.

What you gain is real: **model choice**. If your team has standardised on a particular model, if you have already negotiated pricing with a provider, or if internal policy requires AI spend to run through your own contracts, this is the option that fits.

What you take on is also real:

- **The data-transfer analysis.** Your prompts go to that provider under that provider's terms, including its jurisdiction. If the provider has a US parent, an EU region gives you residency but not sovereignty — CLOUD Act exposure follows the corporate parent, not the datacenter. Documenting that position becomes your job, not ours.
- **The cost.** You are billed directly by the provider. Bring-your-own-key usage is not metered by SealMetrics, which means no quota ceiling from us and no visibility from us either.
- **The key management.** Rotation, scope, revocation, and knowing who in your organisation can see it.
- **The provider's retention and training defaults.** These vary considerably. Worth reading closely before connecting: DeepSeek's official API, for example, states in its privacy policy that it stores personal data in the People's Republic of China and uses data to train and improve its models, with an opt-out exercised by email. Italy's data protection authority imposed an urgent processing block on it in January 2025. The open weights are a separate matter — it is the official API that carries these terms.

None of that makes bring-your-own-key a bad option. It makes it an option with homework.

## Side by side

| Aspect | Seal AI (default) | Bring-your-own-key |
| --- | --- | --- |
| Setup | None — no API key, no AI vendor account | You create and manage a provider key |
| Model choice | The model we ship and test (gpt-oss-120b) | Yours — OpenAI, Anthropic, Gemini or DeepSeek |
| Where inference runs | Paris, France only. No US parent | Wherever your provider processes it |
| Retention & training | Zero retention by default, no training on your data | Whatever your provider's terms say |
| Who you pay | Nobody extra — covered by your plan quota | Your provider, directly, at their prices |
| Metering | Token counters per organisation, for quota only | Not metered by SealMetrics |
| Transfer analysis | Not triggered — no international transfer | Yours to run and document |

## How to choose in one minute

**Choose Seal AI if** you want the assistant to work the moment you open it; if you operate in the EU and would rather not run a transfer assessment for an analytics feature; if you have no strong opinion about which model answers your questions; if you want AI usage to sit inside your existing plan rather than a separate vendor bill; or if you simply do not want another API key in your organisation.

**Choose bring-your-own-key if** you need a specific model for a specific reason; if your organisation already has a provider contract that AI spend must flow through; if an internal policy requires inference on your own account; or if you want to evaluate a model against your own data before standardising on it.

If neither list is decisive, the answer is Seal AI. The default exists so that the privacy-preserving path is the one you get without doing anything — a guarantee that depends on a customer finding the right setting is not much of a guarantee.

## You are not locked into either

This is a setting, not an architecture decision you live with forever. Start on Seal AI, connect your own key later if a requirement appears, disconnect it and fall back to the default if it does not work out. The assistant, the 63-tool inventory and the way you phrase questions do not change — only the model behind them and the terms it runs under.

The full processing detail, subprocessor listing and compliance position are documented in the [Seal AI architecture and privacy documentation](https://docs.sealmetrics.com/lens/seal-ai/private-ai-architecture). For the jurisdiction question behind the bring-your-own-key trade-off, see [Residency Is Not Sovereignty](https://sealmetrics.com/blog/residency-is-not-sovereignty/).

You can start on the default and move to your own keys later. Walk through both routes in a demo with your actual constraints on the table.

[Book a demo](https://sealmetrics.com/demo/)[See pricing](https://sealmetrics.com/pricing/)

## Frequently asked questions

### What is BYOK in an analytics AI tool?

Bring-your-own-key means you connect your own AI provider account — an OpenAI, Anthropic, Gemini or DeepSeek key — and the analytics tool calls that provider on your behalf. You choose the model, you pay the provider directly, and your prompts are processed under that provider's terms, retention policy and jurisdiction rather than the analytics vendor's.

### Should I use a managed AI or bring my own API key?

Use the managed option unless you have a specific reason not to. Seal AI needs no configuration, runs inference in the EU only with zero retention and no training on your data, and is covered by your plan quota. Bring-your-own-key is the right choice when you need a specific model, must route AI spend through an existing provider contract, or have internal policy requiring your own account.

### Does using my own OpenAI or Anthropic key create a GDPR transfer issue?

It can, and the analysis becomes yours. A provider with a US parent remains within reach of the US CLOUD Act even when processing in an EU region, so you may need a transfer basis and an assessment. Seal AI avoids the question by design: inference stays in Paris on a provider with no US parent, so GDPR Chapter V is not triggered at all. With your own key, you decide and document that position.

### Is my AI usage metered if I bring my own key?

No. Bring-your-own-key usage is not metered by SealMetrics — you are billed by your chosen provider on their terms, at their prices. Seal AI usage, by contrast, is covered by your plan's token quota, with additional non-expiring token packs available for organisations that need more headroom.

### Can I switch between Seal AI and my own key later?

Yes. The choice is a setting, not a migration. You can start on Seal AI, connect your own key when a specific requirement appears, and disconnect it again to fall back to the default. The assistant, the tool inventory and the way you ask questions are identical either way — only the model and the processing terms change.

## Related reading

[Meet Seal AI: The Analytics Assistant That Never Sends Your Data to the US](https://sealmetrics.com/blog/meet-seal-ai/)

5 min read

[Residency Is Not Sovereignty: The Question to Ask Your AI Analytics Vendor](https://sealmetrics.com/blog/residency-is-not-sovereignty/)

6 min read

[Three Questions to Ask Your Analytics AI Today](https://sealmetrics.com/blog/three-questions-to-ask-seal-ai/)

4 min read
