Seramel Opna appið

← Back to Seramel

Privacy Policy

Effective Date: January 28, 2026 · Last Revised: October 2, 2026

At Seramel, we believe that privacy is the foundation of trust, and trust is the foundation of meaningful support. This document outlines exactly how we protect the deeply personal information you entrust to us.

1. Introduction

This Privacy Policy describes how Seramel ("we," "us," or "our") collects, uses, and discloses your information when you use our AI emotional support website, mobile application, and related services (collectively, the "Service"). By using the Service, you consent to the practices described in this policy. If you do not agree with this Privacy Policy, you must discontinue use of the Service immediately.

This Policy applies to all users of the Service worldwide, including users in the European Economic Area (EEA), the United Kingdom (UK), California (USA), and any other jurisdiction with applicable data protection legislation.

2. Data Controller

For the purposes of applicable data protection laws (including the GDPR), the data controller of your personal data is:

Seramel — operated by Hüseyin Can Bayram, sole proprietorship
Mithatpaşa Cd. No: 7, 41001 İzmit / Kocaeli, Türkiye
Email: [email protected] (one mailbox for support and privacy requests)

3. Information We Collect

We collect information in three primary categories:

A. Information You Provide Directly

B. Information Collected Automatically

C. Information From Third Parties

4. Sensitive Personal Data (Special Category Data)

Because of the nature of our Service, you may provide data that is considered "sensitive" or "special category" data under applicable laws, including but not limited to data revealing:

We handle ALL Session Content and Wellbeing Inputs with the highest level of security and confidentiality available. We process this sensitive data solely on the basis of your explicit consent (GDPR Art. 9(2)(a)) and for the purpose of providing the Service. We do not use sensitive data for marketing, advertising, profiling for commercial purposes, or sale to third parties.

5. Legal Basis for Processing (GDPR Art. 6)

If you are located in the EEA or UK, we process your personal data only when we have a valid legal basis:

6. How We Use Your Information

We use your information strictly for the following purposes:

7. AI Processing & Third-Party AI Providers

Our Service utilizes advanced Large Language Models (LLMs) provided by third-party partners to generate responses. Your conversation data is transmitted to these providers solely for real-time response generation.

Our AI Data Promise

8. Third-Party Services & Sub-Processors

We use the following third-party services to operate the platform. Each operates under a Data Processing Agreement (DPA) or equivalent contractual safeguard:

ProviderPurposeData Processed
Google (Gemini API, USA)AI response generation, safety classification, summariesConversation text as you write it (not redacted), your structured memory (patterns, experiments, life facts), a short journal excerpt and mood when relevant. No name, e-mail or birth year is sent.
Anthropic (Claude API, USA) — only if enabledFallback AI provider when Google's models are unreachableThe same content as for Gemini, only for the turns it serves
Netcup GmbH (Germany)Server and database hostingAll account data, conversation text (turns deleted 90 days after a conversation ends), memory, journal, backups
Brevo (France)Transactional e-mailE-mail address and the e-mail's content: verification, password reset, step reminders
Push services (Google, Mozilla, Apple; Firebase Cloud Messaging on Android)Notifications you turned onPush token and the notification text
Sentry (USA) — only if enabledError monitoringTechnical error summaries; request bodies, cookies, IP address and user details are removed before sending
Whop (web) · Apple App Store / Google Play (mobile)Payment processingBilling information, transaction records — we never see your card number
Google / Apple sign-in — only if you choose itIdentity verificationName, e-mail and profile picture from the provider

9. How We Share Your Information

We DO NOT sell, rent, or trade your personal data. Ever. We only share information in these limited scenarios:

10. Cookies & Tracking Technologies

We use the following categories of cookies:

We do not use third-party advertising cookies or retargeting pixels. We do not serve ads within the Service.

Analytics

We do not use analytics cookies, third-party tracking scripts or advertising pixels. Fonts are served from our own servers.

11. Data Retention & Deletion

We retain your personal information only for as long as your account is active or as needed to provide you the Service, and for the period necessary to fulfill the purposes outlined in this Policy.

12. Security Measures

We protect your data with the following measures:

While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

13. Automated Decision-Making & Profiling

The Service uses AI-based automated processing to generate supportive responses and monitor for safety risks. Specifically:

No automated decision-making produces legal or similarly significant effects on you. All AI outputs are informational and advisory only. Under GDPR Art. 22, you have the right to request human review of any automated decision. Contact [email protected] to exercise this right.

14. Your Rights Under GDPR (EEA & UK Residents)

If you are located in the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation:

To exercise any of these rights, contact us at [email protected]. We will respond to all requests within 30 days as required by law. We may request identity verification before processing your request.

15. Your Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

To exercise your rights, email [email protected] or use the in-app data controls. We will respond within 45 days as required by California law.

California Shine the Light: Under California Civil Code § 1798.83, California residents may request information about personal data disclosed to third parties for direct marketing. We do not disclose personal data to third parties for their direct marketing purposes.

16. Consent & Withdrawal

By creating an account and using the Service, you provide explicit consent to the collection and processing of your data as described in this Policy, including the processing of sensitive/special category data.

You may withdraw your consent at any time by:

Consequences of Withdrawal: Withdrawing consent for core data processing will result in the inability to use the Service, as the AI requires your conversation data to function. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

17. Data Breach Notification

In the unlikely event of a personal data breach that poses a risk to your rights and freedoms:

18. Children's Privacy

The Service is for adults (18+). We do not knowingly collect personal information from anyone under 18; we ask for a birth year at registration and delete accounts we identify as belonging to minors.

If we become aware that a child under the applicable minimum age has provided us with personal information without proper parental consent, we will take immediate steps to delete such information and terminate the associated account.

19. International Data Transfers

Your information, including Personal Data, may be transferred to — and maintained on — servers located outside of your country of residence, including in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers from the EEA/UK, we rely on the following safeguards:

By using the Service, you acknowledge and consent to the transfer, processing, and storage of your data in countries outside your jurisdiction.

20. Data Anonymization & Aggregation

We may create anonymized and aggregated datasets derived from your data for research and service improvement purposes. Such datasets:

21. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Revised" date. For material changes (changes that affect your rights, the types of data collected, or how data is shared), we will provide at least 30 days' notice via email and/or a prominent in-app notification before the changes take effect. Your continued use of the Service after the effective date of changes constitutes acceptance of the revised Policy.

22. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We aim to respond to all privacy-related inquiries within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.