Selaro
How it worksPricingAbout
Sign inGet started

Privacy Policy

Last updated: 26 June 2026

In plain English: we collect the minimum we need to run Selaro, your conversations are private and never used to train AI models, we use a small set of trusted processors (database, AI, payments, email, privacy-friendly analytics), and you can access, export, or delete your data at any time. The full policy below governs.

1. Who we are

Selaro ("Selaro", "we", "us") is an AI thinking partner for personal decisions, available at selaro.ai. Selaro is operated by a two-person team of developers based in Denmark, and is subject to EU law, including the General Data Protection Regulation (GDPR). For the purposes of the GDPR, the operator of Selaro is the data controller for the personal data described in this policy.

For any privacy question or to exercise your rights, contact us at support@selaro.ai.

2. The data we collect

Account data

Your email address, your display name (if you provide one), and authentication data needed to create and secure your account. We use this to identify you, keep you signed in, and send essential account communications.

Conversation content

The messages you write to Selaro and the responses generated for you. This content is stored so you can return to your conversations. It is never used to train AI models (see "AI processing" below).

Derived data (memory, patterns, principles, insights)

On paid plans, and only when memory is enabled, Selaro derives a private profile from your conversations — themes, values, recurring patterns, personal principles, and similar insights — so future conversations are more relevant. Memory is optional and you control it: you can turn it off, and view, edit, or delete this derived data at any time from your settings.

Payment data

Payments are processed by Stripe. We do not see or store your full card number — Stripe handles card data under its own security standards. We retain limited billing metadata (such as your subscription tier, status, and renewal date) needed to provide the paid service.

Usage and analytics data

With your consent, we collect privacy-friendly product analytics through PostHog (EU-hosted) — pseudonymous behavioural events (for example, which features are used and pages visited), identified only by a random user id. We do not record your screen, and we never send your conversation content, memory, or message text to analytics. Analytics is off until you accept it in the cookie banner.

Technical and security data

To operate the service securely we process technical data such as your IP address and basic device/browser information. We use this for security, abuse prevention, and rate-limiting (for example, we record the IP address used at sign-up to detect fraud and abuse). We do not use this data to track you across other websites.

3. How we use your data and our legal basis

Under the GDPR we rely on the following legal bases for each purpose:

  • Creating your account and providing the service (including storing and displaying your conversations) — Contract (Art. 6(1)(b)).
  • Processing payments and managing your subscription — Contract (Art. 6(1)(b)).
  • Building your private memory profile (paid, opt-in) — Contract (Art. 6(1)(b)) for the feature you signed up for, applied only when you enable memory.
  • Product analytics — Consent (Art. 6(1)(a)), off by default and withdrawable at any time via "Cookie preferences".
  • Marketing emails (only if you opt in) — Consent (Art. 6(1)(a)), withdrawable at any time.
  • Optional product-improvement feedback (the "Help improve Selaro" setting — for example thumbs ratings and feedback you choose to send) — Consent (Art. 6(1)(a)), off by default and withdrawable at any time in Settings.
  • Security, abuse prevention, and protecting the service and our users — Legitimate interest (Art. 6(1)(f)).
  • Meeting legal, tax, and accounting obligations — Legal obligation (Art. 6(1)(c)).

Reporting a genuine problem — a bug or a billing error — is always handled to provide and fix the service (Contract / legitimate interest) and does not depend on the optional "Help improve Selaro" choice: we will always receive and act on a problem report so we can support you and put the issue right.

We do not sell your personal data, and we do not use it for advertising or to profile you across other websites.

4. AI processing

To generate responses, your messages are sent to Anthropic's API. Anthropic processes this content to return a response and, under its API terms and our data processing agreement, does not use it to train its models. We do not use your conversations or memory profile to train any AI model. Memory is optional and under your control, as described above.

5. Processors and who we share data with

We share personal data only with the processors needed to run Selaro, each under a data processing agreement and only for the purposes below:

  • Supabase — our database and authentication, hosted in the EU. Stores account data, conversations, and derived memory.
  • Anthropic — AI processing of your messages to generate responses. Does not train on API data. See anthropic.com/privacy.
  • Stripe — payment processing, billing, and invoices (including VAT where applicable). Stripe is GDPR-compliant and handles card data under its own standards.
  • Resend — sends transactional and (where you opt in) occasional product emails on our behalf, using your email address.
  • PostHog — privacy-friendly product analytics, hosted in the EU. Receives only pseudonymous usage events (random user id), never your email, name, or any conversation/memory content. Consent-based, no session recording, Do-Not-Track respected.
  • Vercel — hosting and content delivery for the application.
  • Better Stack — error monitoring (used only when enabled). Receives technical error reports — an error message, the code location/stack, and a route tag — so we can detect and fix problems. We strip personal data: no IP address, account identifiers, cookies, or any conversation or memory content are sent.

We may engage additional sub-processors from time to time; an up-to-date list is available on request at support@selaro.ai. We do not use advertising networks or data brokers.

6. International data transfers

We keep data in the EU where we can (our database and analytics are EU-hosted). Some processors — in particular Anthropic, which provides the AI processing — operate outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses (SCCs), to protect it.

7. Data retention

  • While your account is active, your account data, conversations, and (if enabled) memory profile are retained so you can use the service.
  • When you delete your account, your personal data is permanently deleted within 30 days. Residual copies in encrypted backups are purged within 90 days.
  • We may retain limited billing and transaction records for as long as required by law (for example, tax and accounting obligations).
  • Limited security records (such as abuse and fraud signals) may be kept for as long as needed to protect the service, then deleted.

8. Your rights under the GDPR

You have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten");
  • Restrict processing in certain circumstances;
  • Receive your data in a portable format (data portability);
  • Object to processing based on our legitimate interests;
  • Withdraw consent at any time (without affecting prior processing);
  • Lodge a complaint with a supervisory authority — in Denmark, the Danish Data Protection Agency (Datatilsynet), datatilsynet.dk.

To exercise these rights, go to Settings → Profile → Data and Privacy (where you can export or delete your data), or email support@selaro.ai. We respond to requests within the timeframes required by law (normally within one month).

9. Cookies and consent

We use necessary cookies to keep you signed in — these are essential and always on. Our product analytics (PostHog, EU-hosted) run only with your consent and use no tracking cookies; analytics stays off until you accept it in the cookie banner. You can change or withdraw your choice at any time via "Cookie preferences" in the footer.

10. Security

We protect your data with encryption in transit (HTTPS) and at rest, database-level row security so each account can only access its own data, and access controls that restrict production data to essential personnel. No system is perfectly secure, but we take reasonable, industry-standard measures and review them regularly.

11. Children

Selaro is not directed at children. You must be at least 16 years old to use Selaro, and we do not knowingly collect personal data from anyone under that age. If you believe a minor has provided us personal data, contact support@selaro.ai and we will delete it.

12. Changes to this policy

We may update this policy as the service evolves. For material changes, we will give reasonable notice — for example, by email or an in-app notice — before they take effect, and we will update the "Last updated" date above.

13. Contact and complaints

Questions, requests, or complaints: support@selaro.ai. You also have the right to complain to your local supervisory authority — in Denmark, the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).

Selaro

The AI thinking partner for your biggest decisions. Think clearly, decide for yourself.

Product

  • How it works
  • Pricing
  • Blog

Company

  • About
  • Help & FAQ
  • Sitemap
  • Contact
  • Status

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy

© 2026 Selaro. Built in Europe.

Not a therapist. Not a life coach. A thinking partner.