Privacy Policy
Effective Date: January 28, 2026 · Last Revised: October 2, 2026
- Encrypted in transit and at rest Your journal and chat data travel over TLS and sit in a database with provider-managed encryption at rest; chat turns are deleted 90 days after a conversation ends.
- No AI Training We strictly prohibit our AI partners from using your data to train their models.
- Your Data, Your Rights Correct or permanently delete your data at any time from your profile; ask us for a copy by e-mail.
At Seramel, we believe that privacy is the foundation of trust, and trust is the foundation of meaningful support. This document outlines exactly how we protect the deeply personal information you entrust to us.
1. Introduction
This Privacy Policy describes how Seramel ("we," "us," or "our") collects, uses, and discloses your information when you use our AI emotional support website, mobile application, and related services (collectively, the "Service"). By using the Service, you consent to the practices described in this policy. If you do not agree with this Privacy Policy, you must discontinue use of the Service immediately.
This Policy applies to all users of the Service worldwide, including users in the European Economic Area (EEA), the United Kingdom (UK), California (USA), and any other jurisdiction with applicable data protection legislation.
2. Data Controller
For the purposes of applicable data protection laws (including the GDPR), the data controller of your personal data is:
Seramel — operated by Hüseyin Can Bayram, sole proprietorship
Mithatpaşa Cd. No: 7, 41001 İzmit / Kocaeli, Türkiye
Email: [email protected] (one mailbox for support and privacy requests)
3. Information We Collect
We collect information in three primary categories:
A. Information You Provide Directly
- Account Data: Your name, email address, password (hashed — we never store plaintext passwords), and date of birth/age.
- Profile Data: Personal preferences, wellbeing goals, and any biographical information you choose to share with your AI companion.
- Session Content: The text of your conversations and your written journal entries. Seramel has no voice feature and records no audio. This constitutes "Special Category Data" under GDPR.
- Wellbeing Inputs: Self-reported data such as mood ratings, anxiety levels, sleep quality, and feedback on your wellbeing progress.
- Payment Information: Billing details processed by our third-party payment processor (Whop on the web, Apple/Google on mobile). We do not store your full credit card number on our servers.
- Support Communications: Any messages you send to our support team.
B. Information Collected Automatically
- Usage Data: Information about how you interact with the Service, such as session duration, feature usage, navigation paths, and interaction timestamps.
- Device Data: IP address (anonymized where possible), browser type and version, device model, operating system, screen resolution, and timezone to ensure service compatibility and security.
- Log Data: Server logs including access times, pages viewed, referring URLs, and crash reports for troubleshooting.
C. Information From Third Parties
- Authentication Providers: If you sign in via Google or Apple, we receive your name, email address, and avatar from those providers. We do not receive or store your passwords from these providers.
4. Sensitive Personal Data (Special Category Data)
Because of the nature of our Service, you may provide data that is considered "sensitive" or "special category" data under applicable laws, including but not limited to data revealing:
- Mental health status and conditions
- Emotional state and wellbeing
- Sexual orientation or identity
- Religious or philosophical beliefs
- Information about substance use or addiction
- Experiences of abuse, trauma, or self-harm
We handle ALL Session Content and Wellbeing Inputs with the highest level of security and confidentiality available. We process this sensitive data solely on the basis of your explicit consent (GDPR Art. 9(2)(a)) and for the purpose of providing the Service. We do not use sensitive data for marketing, advertising, profiling for commercial purposes, or sale to third parties.
5. Legal Basis for Processing (GDPR Art. 6)
If you are located in the EEA or UK, we process your personal data only when we have a valid legal basis:
- Consent (Art. 6(1)(a)): For processing sensitive/special category data, sending marketing communications, and placing non-essential cookies. You may withdraw consent at any time (see Section 16).
- Contractual Necessity (Art. 6(1)(b)): To perform our contract with you — i.e., to provide the AI emotional support service, manage your account, and process payments.
- Legitimate Interest (Art. 6(1)(f)): For service improvement via aggregated analytics, fraud prevention, security monitoring, and providing customer support. We balance these interests against your rights and freedoms.
- Legal Obligation (Art. 6(1)(c)): To comply with applicable tax, accounting, and other legal requirements.
- Vital Interest (Art. 6(1)(d)): In rare cases where we detect imminent risk of self-harm, to provide emergency resources and, where legally required, to contact emergency services.
6. How We Use Your Information
We use your information strictly for the following purposes:
- Service Delivery: To provide personalized AI conversations, generating responsive and context-aware emotional support.
- Memory & Context: To maintain a continuous conversation history so the AI "remembers" past details, creating a consistent supportive relationship.
- Safety Monitoring: To algorithmically detect indications of immediate self-harm or danger to others, solely for the purpose of providing emergency resources.
- Service Improvement: To analyze aggregated, anonymized usage patterns to improve the quality of our service (e.g., "users find this module helpful"). Individual session content is never reviewed by human employees for this purpose.
- Communication: To send you transactional notifications (password resets, subscription confirmations) and, with your consent, product updates.
- Security & Fraud Prevention: To detect, investigate, and prevent fraudulent transactions, unauthorized access, and other illegal activities.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
7. AI Processing & Third-Party AI Providers
Our Service utilizes advanced Large Language Models (LLMs) provided by third-party partners to generate responses. Your conversation data is transmitted to these providers solely for real-time response generation.
Our AI Data Promise
- Zero Training: Your data is NOT used to train the base models of our providers. We use API configurations that explicitly opt out of training.
- Ephemeral Processing: Data sent to AI models is processed in memory for the purpose of generating a response and is not stored permanently on their servers.
- Data Processing Agreements: We maintain Data Processing Agreements (DPAs) with all AI providers.
8. Third-Party Services & Sub-Processors
We use the following third-party services to operate the platform. Each operates under a Data Processing Agreement (DPA) or equivalent contractual safeguard:
| Provider | Purpose | Data Processed |
|---|---|---|
| Google (Gemini API, USA) | AI response generation, safety classification, summaries | Conversation text as you write it (not redacted), your structured memory (patterns, experiments, life facts), a short journal excerpt and mood when relevant. No name, e-mail or birth year is sent. |
| Anthropic (Claude API, USA) — only if enabled | Fallback AI provider when Google's models are unreachable | The same content as for Gemini, only for the turns it serves |
| Netcup GmbH (Germany) | Server and database hosting | All account data, conversation text (turns deleted 90 days after a conversation ends), memory, journal, backups |
| Brevo (France) | Transactional e-mail | E-mail address and the e-mail's content: verification, password reset, step reminders |
| Push services (Google, Mozilla, Apple; Firebase Cloud Messaging on Android) | Notifications you turned on | Push token and the notification text |
| Sentry (USA) — only if enabled | Error monitoring | Technical error summaries; request bodies, cookies, IP address and user details are removed before sending |
| Whop (web) · Apple App Store / Google Play (mobile) | Payment processing | Billing information, transaction records — we never see your card number |
| Google / Apple sign-in — only if you choose it | Identity verification | Name, e-mail and profile picture from the provider |
9. How We Share Your Information
We DO NOT sell, rent, or trade your personal data. Ever. We only share information in these limited scenarios:
- Service Providers & Sub-Processors: With the trusted vendors listed in Section 8, under strict Data Processing Agreements, solely for the purpose of operating the Service.
- Legal Requirements: If required by a valid subpoena, court order, or other enforceable legal process, or to prevent imminent physical harm. We will attempt to notify you of such requests unless legally prohibited from doing so.
- Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your data may be transferred as part of the transaction. The successor entity will remain bound by this Privacy Policy. We will notify you before your data is transferred and becomes subject to a different privacy policy.
- With Your Consent: In any other circumstances, we will share your information only with your explicit prior consent.
10. Cookies & Tracking Technologies
We use the following categories of cookies:
- Strictly Necessary Cookies: Required for authentication, security, and core Service functionality. These cannot be disabled.
- Preference Cookies: Remember your settings such as language preference, theme (dark/light mode), and notification preferences.
We do not use third-party advertising cookies or retargeting pixels. We do not serve ads within the Service.
Analytics
We do not use analytics cookies, third-party tracking scripts or advertising pixels. Fonts are served from our own servers.
11. Data Retention & Deletion
We retain your personal information only for as long as your account is active or as needed to provide you the Service, and for the period necessary to fulfill the purposes outlined in this Policy.
- Active Account Data: Retained for the duration of your active account.
- Session Content & Wellbeing Inputs: The turns of a conversation are deleted 90 days after it ends; its title, summary and what Seramel remembers stay for the duration of your account. You may delete individual sessions and remembered items at any time from within the Service.
- Account Deletion: You may request full account deletion at any time via your Profile settings or by contacting [email protected]. Upon deletion, your account and all data linked to it are removed from our live database immediately.
- Backups: Database backups may retain residual data for a limited period (up to 30 days) for disaster recovery purposes before being deleted.
- Legal Obligations: Certain financial records (transaction history, invoices) may be retained for up to 7 years as required by tax and accounting regulations.
- Anonymized Data: Aggregated, fully anonymized data that cannot be re-identified may be retained indefinitely for statistical and service improvement purposes.
12. Security Measures
We protect your data with the following measures:
- Encryption at Rest: we do not apply a separate application-level encryption layer to conversation text; instead we minimise it (turns deleted 90 days after a conversation ends). Off-site backups are encrypted.
- Encryption in Transit: TLS (HTTPS) for all data transmission between your device, our servers, and third-party providers.
- Access Control: Production server and database access is limited to the operator and protected by SSH keys.
- Password Security: User passwords are hashed with scrypt and are never stored in plaintext.
- Security Reviews: Code security reviews and dependency vulnerability checks before releases.
- Incident Response: If a breach affects your personal data, we notify the competent authority and you as required by law.
While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
13. Automated Decision-Making & Profiling
The Service uses AI-based automated processing to generate supportive responses and monitor for safety risks. Specifically:
- AI Response Generation: Our AI system processes your conversation history to generate contextually relevant supportive responses. This is core to the Service you have consented to use.
- Safety Detection: Automated algorithms monitor conversations for indicators of immediate self-harm or crisis situations, solely to surface emergency resources.
- Mood Tracking: If you use mood tracking features, the system may identify patterns in your self-reported data to provide insights. These are informational only and are not a medical assessment.
No automated decision-making produces legal or similarly significant effects on you. All AI outputs are informational and advisory only. Under GDPR Art. 22, you have the right to request human review of any automated decision. Contact [email protected] to exercise this right.
14. Your Rights Under GDPR (EEA & UK Residents)
If you are located in the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation:
- Right of Access (Art. 15): Request a copy of all personal data we hold about you, in a structured, commonly used format.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to be Forgotten" (Art. 17): Request permanent deletion of your personal data. This can be exercised via Profile settings or by contacting us at [email protected].
- Right to Restriction of Processing (Art. 18): Request that we limit the processing of your data in certain circumstances (e.g., while verifying accuracy).
- Right to Data Portability (Art. 20): Receive your personal data in a machine-readable format (JSON/CSV) and transmit it to another service provider.
- Right to Object (Art. 21): Object to the processing of your personal data based on legitimate interests, including profiling.
- Right Related to Automated Decision-Making (Art. 22): Request human review of any solely automated decision that significantly affects you.
- Right to Withdraw Consent (Art. 7(3)): Withdraw your consent for data processing at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local Data Protection Authority (DPA) if you believe your rights have been violated.
To exercise any of these rights, contact us at [email protected]. We will respond to all requests within 30 days as required by law. We may request identity verification before processing your request.
15. Your Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, our purposes for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions (e.g., legal compliance, completing a transaction).
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. Therefore, there is no need to opt out. If this ever changes, we will provide a clear "Do Not Sell My Personal Information" link.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights. You will not receive different service quality or pricing for exercising your rights.
- Right to Limit Use of Sensitive Personal Information: You may request that we limit our use and disclosure of sensitive personal information to what is necessary to provide the Service.
To exercise your rights, email [email protected] or use the in-app data controls. We will respond within 45 days as required by California law.
California Shine the Light: Under California Civil Code § 1798.83, California residents may request information about personal data disclosed to third parties for direct marketing. We do not disclose personal data to third parties for their direct marketing purposes.
16. Consent & Withdrawal
By creating an account and using the Service, you provide explicit consent to the collection and processing of your data as described in this Policy, including the processing of sensitive/special category data.
You may withdraw your consent at any time by:
- Deleting your account through Profile settings
- Contacting us at [email protected]
- Adjusting cookie preferences in your browser settings
Consequences of Withdrawal: Withdrawing consent for core data processing will result in the inability to use the Service, as the AI requires your conversation data to function. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
17. Data Breach Notification
In the unlikely event of a personal data breach that poses a risk to your rights and freedoms:
- We will notify the relevant Data Protection Authority within 72 hours of becoming aware of the breach, as required by GDPR Art. 33.
- If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly via email and in-app notification without undue delay (GDPR Art. 34).
- Our notification will include: the nature of the breach, categories of data affected, likely consequences, and the measures taken or proposed to address the breach.
18. Children's Privacy
The Service is for adults (18+). We do not knowingly collect personal information from anyone under 18; we ask for a birth year at registration and delete accounts we identify as belonging to minors.
If we become aware that a child under the applicable minimum age has provided us with personal information without proper parental consent, we will take immediate steps to delete such information and terminate the associated account.
19. International Data Transfers
Your information, including Personal Data, may be transferred to — and maintained on — servers located outside of your country of residence, including in the United States, where data protection laws may differ from those in your jurisdiction.
For transfers from the EEA/UK, we rely on the following safeguards:
- Adequacy Decisions: Where the European Commission has determined that a third country provides an adequate level of data protection.
- Standard Contractual Clauses (SCCs): We use EU-approved Standard Contractual Clauses with all sub-processors located outside the EEA to ensure equivalent data protection.
- EU-US Data Privacy Framework: Where applicable, we rely on certifications under the EU-US Data Privacy Framework.
By using the Service, you acknowledge and consent to the transfer, processing, and storage of your data in countries outside your jurisdiction.
20. Data Anonymization & Aggregation
We may create anonymized and aggregated datasets derived from your data for research and service improvement purposes. Such datasets:
- Have all direct identifiers (name, email, IP address) permanently and irreversibly removed
- Cannot be re-identified or linked back to any individual user
- May be used for internal analytics, academic research collaborations, and public statistical reports
- Are not subject to the data deletion provisions of this Policy, as they are no longer "personal data" under applicable law
21. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Revised" date. For material changes (changes that affect your rights, the types of data collected, or how data is shared), we will provide at least 30 days' notice via email and/or a prominent in-app notification before the changes take effect. Your continued use of the Service after the effective date of changes constitutes acceptance of the revised Policy.
22. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- General Privacy Inquiries: [email protected]
- General Support: [email protected]
We aim to respond to all privacy-related inquiries within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.