Privacy Policy
1. Our approach
Selah is a ministry tool. We collect as little as possible, we don't sell your data, and we don't use your reflections to train AI models. This policy explains what we collect, why, who processes it, and the choices you have.
If you have questions, email privacy@selahapp.app.
2. Who is responsible for your data
The data controller is The Selah App, LLC, the same Florida entity named in the Terms (see Terms §1). Our service providers ("processors") who handle data on our behalf are listed in Section 6.
3. What we collect
You can use Selah anonymously. On first launch we create an anonymous account so your progress can be saved. You are not asked for your name, email, or any identifier to begin.
| Category | Examples | Do we have it? |
|---|---|---|
| Account identifiers | Anonymous user ID; email address only if you choose to back up across devices. | Email: only if you opt in. |
| Your reflections | Journal entries and drafts, mood check-ins, which paths/days you've walked, your saved companion persona settings. | Yes — to provide the Service. |
| AI Companion messages | The messages you send the AI Companion and its responses. | See Section 5 — handled specially. |
| Notification settings | If you opt in to reminders: your chosen reminder time, time zone, and a push subscription token. | Only if you opt in. |
| Technical/operational data | IP address and basic request metadata used transiently for security and rate limiting. | Yes — minimal, for protection. |
We do not collect: precise location, contacts, advertising identifiers, biometrics, or payment card numbers (any subscription payments are handled by a third-party payment processor — see Subscription & Support Terms).
4. Why we use it (and our legal basis)
We use your data only to:
- Provide the Service — save your progress, sync across your devices, generate AI Companion responses, send reminders you asked for.
- Keep Selah safe and available — rate limiting and abuse prevention (IP/request metadata).
- Improve Selah — understand, in aggregate, what's working. We do not need your identity to do this.
For users in regions where it applies (e.g., the EU/UK), our legal bases are performance of a contract (to run the app you asked to use), consent (for optional things like email backup and notifications), and legitimate interests (security and keeping the Service running).
5. The AI Companion and Scripture-based reflection
When you message the AI Companion, your message (and limited context such as your chosen path and companion persona) is sent to our AI provider, Anthropic, using the Claude API, which processes it to generate a response and returns it to you.
- We do not use your conversations to train any AI model. Our AI provider processes the data under our commercial API agreement and applicable data-processing terms. Under Anthropic's commercial terms, Anthropic does not train its models on the content we submit through the Service. We will update this Policy if our provider, plan, settings, or agreement changes.
- Crisis-detection runs on the server to surface emergency resources; see the Crisis & Safety Disclaimer.
- AI Companion chat history is currently stored only on your device, not on our servers. Journal entries and mood data, by contrast, are backed up to our servers so you don't lose them.
6. Who we share data with
We do not sell your data and we do not share it for advertising. We use a small set of processors:
- Supabase — database, authentication, and storage (your reflections and account).
- Anthropic — AI Companion responses (your messages, transiently).
- Vercel — hosting and serverless functions (transient request handling, logs).
- Google Firebase Cloud Messaging (FCM) — delivering reminder notifications, if you opt in.
- Stripe — payment processing if you choose to subscribe (we do not receive your card number).
We may also disclose data if required by law, to protect the safety of a person, or to protect the Service from abuse.
7. How long we keep it
We keep your reflections for as long as your account exists. Transient security data (like IP in rate-limit windows) is short-lived. If you ask us to delete your account, we will delete or de-identify your active stored reflections, profile, mood history, path progress, push subscriptions, and related account data within 30 days after verification, unless we must retain limited information for legal, security, fraud-prevention, or payment-record purposes. Our database is currently hosted on a plan that does not include scheduled backups or point-in-time recovery, so removing your data from our live database is the operative deletion; we do not retain your data in customer-restorable backups. Our hosting provider may keep short-lived, infrastructure-level backups for disaster recovery that are outside our control and age out on the provider's own cycle.
8. Your choices and rights
- Use anonymously — don't attach an email and your data isn't tied to a personal identifier.
- Access / export / correction / deletion — email us at privacy@selahapp.app to request access to, a copy of, correction of, or deletion of your data. We may need to verify control of the email-linked account or another account identifier before acting. Anonymous, local-only data that is not backed up to our servers may be unavailable to export and can be deleted only by clearing your local browser/app data.
- Notifications — opt in/out anytime in Settings.
- Local data — clearing your browser/app data removes locally stored data on that device (note: if you have not backed up via email, clearing data can permanently orphan an anonymous account).
Depending on where you live (e.g., California, EU/UK), you may have additional rights such as to object to or restrict processing, or to lodge a complaint with a regulator. We honor these where they apply.
9. Security
We protect your data with industry-standard measures, including database row-level security so each user can access only their own rows, encrypted transport (HTTPS), secret keys kept on the server (never exposed to the browser), and rate limiting against abuse. No system is perfectly secure, and we cannot guarantee absolute security.
10. Children
Selah is intended for adults 18 and older and is not directed to children. We do not market Selah to anyone under 18.
Ages 13–17 (Parental Access). A parent or legal guardian who is 18 or older may enable a parent-administered profile for their own child aged 13 to 17 through the Parental Access option. The parent completes the consent screen, accepts these terms and the disclaimers on the minor's behalf, supervises the minor's use of the AI Companion, and can review, disable, export, and request deletion of the minor profile through their own account. Selah does not permit independent teen accounts. Any data associated with a minor's use is treated the same as other user data under this policy.
Under 13. Selah is not available to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us personal information, contact us and we will delete it.
11. International users
Selah is intended for users in the United States. It is operated from the U.S., your data is processed in the U.S. and by our processors, and Selah is not marketed to or directed at users outside the United States. If you choose to use Selah from outside the U.S., you do so on your own initiative and you consent to this transfer to and processing in the U.S. We do not currently offer Selah to users in the EU/UK or other regulated regions; if that posture ever changes, additional terms and safeguards (e.g., standard contractual clauses, a fuller GDPR rights section) will apply.
12. Changes
We'll update the "Effective date" when this policy changes and, for material changes, may prompt you in the app.
Contact for privacy requests: privacy@selahapp.app
← All policies