Privacy policy
Version
Seluno helps adults connect through conversations, activities and shared memories. This notice explains what we process, what your partner can see and the choices available to you. It applies to the Seluno app and website. OpenAI provides the AI service through its API.
1. Who is responsible
Seluno is the product name. The operators responsible for your personal data are:
- Legal name of the operator(s)
- Nando Wyrsch and Daniel Schmidli
- Contact address
- Nidfelstrasse 2E 6010 Kriens Switzerland
- Privacy contact
- privacy@seluno.io
You can direct a privacy request to either operator using the contact above.
Seluno is available in the European Economic Area. We have not yet appointed a representative under Article 27 GDPR. We will appoint one as soon as Seluno has its first users there and will name them here. Until then, please use the privacy contact above. Both operators answer privacy requests themselves, and not having a representative yet does not limit any of your rights below.
2. What we process and why
- Account and preferences: your email, login credentials managed by our authentication provider, display name, avatar, time zone and preferences let us create and secure your account.
- Relationship and activities: invitations, partner membership, optional relationship details, city/country, questions and answers, conversations, plans, game turns, reactions and uploaded photos enable the features you choose. Online and typing indicators share limited activity status with your connected partner. We also receive information your partner supplies about your relationship.
- AI guidance: selected text and relevant context are used to generate reflections, conversation support and date suggestions. Separate memory preferences control reuse of saved summaries.
- Safety and operation: technical request information, authentication events, limited safety flags, reports, related content references, review notes and consent records help us protect accounts and respond to misuse. A report contains the information the reporting person chooses to include, which may be sensitive.
- Purchases: Apple supplies purchase and renewal information, including transaction identifiers, product, purchase and expiry dates, refund or revocation status, and an account token linking the purchase to your Seluno account. We use this for access, restoration, billing questions and fraud prevention. Seluno does not receive your full payment card details from Apple.
- Support: if you contact us, we use your contact details and the information you provide to respond. Please include only the personal information needed for your request.
We receive data from you, your connected partner, people who submit a report, your device and the providers involved in sign-in or purchase verification. We do not buy relationship profiles from data brokers.
For ordinary personal data needed to provide a feature you request, our basis is performance of the service contract (GDPR Article 6(1)(b)). This includes account access, requested shared features, purchase verification and support for the service. Security, fraud prevention and necessary incident handling use legitimate interests (Article 6(1)(f)), subject to necessity and your rights. Where a specific legal duty requires processing, Article 6(1)(c) applies. Optional personal sharing and AI processing rely on consent (Article 6(1)(a)). The Swiss Federal Act on Data Protection also applies to our processing where applicable.
Conversations can reveal health, sex life, sexual orientation or other specially protected information. Contract necessity alone does not authorize that processing. Before collecting personal answers, conversations, photos, memories or free-text plans, we ask for separate explicit personal-sharing consent (Article 9(2)(a)). This covers the selected features and their hosting and database processing, including non-AI content. AI requires another permission. Neither choice is included in acceptance of the Terms.
Personal sharing is off until you choose it. You can decline, skip the personal onboarding questions and use basic games without personal stakes, account settings and privacy controls. Adding private content requires its owner’s permission; adding new shared content or newly revealing private answers requires the applicable permission of both partners. You cannot consent on another person’s behalf. Do not include intimate details about other people who have not agreed.
Change or withdraw personal-sharing consent in Profile → Data & privacy → Personal sharing. Withdrawal blocks new covered content and its use for new AI requests. It does not automatically erase existing history or partner copies. Use the deletion and rights controls described below for those records.
Safety reporting and requests to exercise your rights remain available without these permissions. Include only the information needed, preferably a reference to the incident rather than intimate details. Our review procedure requires unnecessary sensitive details to be removed. Retaining sensitive evidence requires a specific applicable exception, such as necessity for a legal claim under Article 9(2)(f); ordinary legitimate interests alone are insufficient.
3. AI consent and saved context
AI is optional from the start, including when joining by invitation. Before using it, you must explicitly enable OpenAI processing with an initially unchecked choice. Personal-sharing permission is also required for the content involved. Declining AI does not prevent account setup or non-AI features. Saved AI memory stays off for new choices and can be enabled separately in Settings. You can change or withdraw these choices in Profile → Data & privacy → AI privacy. Withdrawing later stops future AI processing; existing accounts retain access to permitted non-AI features and account controls. Shared AI processing that includes both partners’ context requires each person’s current consent. Memory for future conversations is a separate, optional choice.
When authorized, relevant conversation text, profile or relationship context and permitted saved summaries are sent to OpenAI. Photo files, passwords and authentication tokens are not included in these text requests. Text can itself identify you, so this is not anonymous processing. Private input may be processed by AI even when it is hidden from your partner.
OpenAI does not use API content to train its models by default. Seluno requests no stored Responses history (store: false). This is not Zero Data Retention: default abuse-monitoring logs may retain content for up to 30 days, with longer retention in stated legal or safety circumstances; model-dependent prompt caching can also retain temporary state. Special retention or regional settings require separate configuration. See OpenAI’s API data controls.
Withdrawal stops new authorized AI processing; it cannot recall a request already sent. It does not automatically erase conversation history or copies already shared. You can review and delete saved context under “What Seluno remembers”, delete your account or contact us for an erasure request. AI suggestions may be inaccurate. They do not make decisions with legal or similarly significant effects about you and are not medical treatment.
5. Where data is processed
Google Cloud Run for the app and website; Vercel remains the domain registrar and DNS provider, with earlier deployments retained for rollback.
Website processing locations: Belgium (europe-west1); application hosting region
Supabase project location: Ireland (eu-west-1); primary database region
International transfer arrangements: Supabase stores the database in Ireland and Google Cloud Run hosts the app and website in Belgium, both inside the EU. For customers in Switzerland, OpenAI contracts through OpenAI Ireland Ltd. Resend keeps stored email and log data in the United States. Where a provider processes data outside Switzerland and the EEA, that transfer relies on the provider data processing agreement together with the EU standard contractual clauses, and for Google additionally on the EU-US Data Privacy Framework.
Resend states that its stored email and log data is in the United States, even when a European sending region is selected. OpenAI, Google and the other providers can also involve processing or access outside Switzerland and the EEA. We do not claim that all Seluno data stays in Europe.
A database region alone does not establish that all support, logs, backups or subprocessors remain in that region. Where applicable, transfers require an adequacy decision or appropriate safeguards such as standard contractual clauses and additional measures. A provider’s general contract is not proof of the settings or safeguards for every Seluno data flow. You can request information or a copy of applicable safeguards from our privacy contact.
6. Retention and deletion
When you use Apple subscriptions, Seluno verifies purchase records with Apple and retains transaction and ownership records for access, recovery and fraud prevention. Deleting your Seluno account does not cancel Apple billing. You can manage subscriptions in your Apple account.
- Account details, activities and saved conversations are kept to provide your account and history until you remove them where a feature permits, delete your account, or an applicable erasure request is completed.
- Account deletion removes your login, profile, avatar, private answers, Solo reflections, authored conversation messages and share links you created. Your partner keeps shared photos, memories, plans, already revealed answers and shared AI reflections in an archive they can view but cannot edit. This content may still mention you; it is not automatically anonymized. Contact us to request review of personal information remaining there.
- The shared archive remains while a member keeps it. Removing it in Profile → Data & privacy → Archive removes your access. When the last member removes it, Seluno deletes its data and stored photos. Either partner can also delete an individual shared memory photo in an active relationship. Previously issued temporary photo links may work until they expire.
- Saved AI context remains until it is forgotten or deleted under the account/archive rules. Withdrawing memory permission prevents its future use and new memory generation. Consent records are retained with the account to demonstrate your choices.
- Purchase and renewal records can remain after account deletion, including transaction identifiers and the Seluno identifiers linking the purchase to its original account. Old notification UUIDs are removed once expiry and the last ledger receipt or update are more than 12 months old. The remaining typed purchase and ownership records preserve restoration and prevent replay or reassignment of old purchases. They contain no full payment card details or raw Apple notification payload. Their time limit still requires a separate necessity assessment before release approval; indefinite retention is not automatically justified.
- Safety reports and review notes can remain after account deletion. Account links may be removed while the report text still identifies people. Reports and review notes are removed at the earlier of 180 days after closure and 365 days after receipt. A specifically documented preservation hold lasts at most 90 days per authorization and requires a new review to extend it. Removing a report does not lift an active safety block. Requests for access or erasure protect the reporter and other people concerned.
- Earlier product-measurement events exclude conversation text but can be linked to your account. They are removed after 90 days from the original event, or earlier with the associated account. This release stops sending new optional product and onboarding events.
- Online and typing indicators stop being displayed after a short interval, but the last stored status is removed after 24 hours, or earlier under the account, relationship or safety controls.
- Unfinished server-side preparation previews expire for reuse after 24 hours. Expired preview rows are removed by scheduled cleanup even if you never return. Approved text already saved in a conversation follows that conversation’s retention rules.
- Signup protection stores a pseudonymous network identifier, not the raw network address in its limiter table. Cleanup removes it after more than 48 hours without an accepted signup, normally within 72 hours. Limited crisis events have a 30-day retention period with scheduled cleanup.
The prepared cleanup runs hourly. A time limit makes data due for deletion; physical removal takes place on the next successful run. A failed run must be investigated and retried. Earlier applicable erasure rights still apply.
Hosting logs, backups and their deletion cycle: Automatic daily database backups and a separate backup of uploaded files are not set up yet. We will add both as Seluno grows and will update this notice when we do. Server logs record technical events only, never your messages, answers or AI content. One effect of this is that deleting your account removes your data from the live service without a backup copy left behind.
Provider defaults are not a single retention period for Seluno. For example, Resend publishes a standard 30-day period for email and log content and a 7-day backup period, with exceptions for particular plans and account closure. Our operating rule for ordinary support emails is 90 days after case closure, with minimal evidence for rights requests or a specific legal claim handled separately. The Google Cloud target is 30 days for application logs; Google’s required audit-log categories have a 400-day period. Daily database and separate file backups are planned with a rolling seven-day window. These account settings and backup jobs still need verification. A database backup does not include uploaded photo files, and a provider offering backups does not prove one exists.
Deleting live data does not necessarily remove it immediately from provider backups or legal/safety records. Copies already downloaded by another person cannot be recalled.
7. Cookies and storage on your device
Authentication cookies keep you signed in. Browser storage holds preferences and feature state such as theme, dismissed notices and unfinished drafts. Private preparation drafts expire after seven days when next read; closing a tab does not necessarily remove local storage. Signing out clears identified private drafts. On a shared device, sign out and clear browser data when finished.
Optional onboarding and product analytics are paused in this prepared release. No advertising pixel or third-party marketing analytics is included. Operational records needed for sign-in, purchases, security and a feature you request are separate from optional measurement. Future optional tracking requires an appropriate notice and your consent where required; agreeing to the Terms does not authorize it.
8. Your choices and rights
Depending on the applicable law, you can request access, correction, erasure, restriction and a portable copy of your data, object to processing based on legitimate interests, and withdraw consent without affecting the lawfulness of earlier processing. These rights can be subject to limits, including the rights of your partner and legal obligations.
Use Profile → Data & privacy for an account export, saved-context controls and archives, or the account deletion control under Account. The self-service export contains supported structured records, not every support, safety, purchase or historical measurement record, provider log, or the photo files themselves. Contact us for a complete access request, photo copies or a review of shared information that concerns you.
We may need proportionate identity verification. Under the GDPR we normally respond within one month; if a lawful extension is needed, we explain it within that month. You may complain to a supervisory authority, including in your EU country of residence, work or the alleged infringement, or to the Swiss Federal Data Protection and Information Commissioner. You do not have to contact us first.
Use the privacy contact in section 1 for these requests. You can also use the Swiss commissioner’s website or find an EU supervisory authority. Privacy rights, withdrawal of consent and account deletion do not require acceptance of updated Terms.
9. Adults and changes to this notice
Seluno is intended for adults aged 18 and over. If you believe a child has submitted personal data, contact us. If we materially change a purpose, provider or consent-based use, we will update this notice and obtain a new choice where required. The version date above identifies this notice. Reading or acknowledging a new notice does not automatically renew AI consent or enable saved memory.