Privacy Policy
Last updated: 26 July 2026
Sera is designed around one short reset and a simple rule: memory of what helps, not memory of everything. A first private or Incognito reset does not require an account, email, name, card, trial, or subscription. This policy explains what Real Product LLC processes and why under UK data-protection law.
1. Your account identity
A guest reset uses a high-entropy, short-lived browser credential and session-only consent; it does not create a durable wellbeing account or profile. If you later choose to register, no legal name is required: you may use a first name or nickname. Sera asks for an email address and password so you can sign in from another browser; the password is stored only as a one-way password hash. A short-lived one-time code confirms the email address and supports password reset.
2. What we process, and why
- Raw reset data. Audio you choose to record, its transcript or the thought you type, Sera's reflection, and the temporary generation context needed to complete the reset. Private and Incognito raw data is transient by default and is not written to the durable conversation store. Audio is discarded immediately after transcription or failure.
- Approved memory and causal evidence. Only when you choose Save or Edit and save, Sera keeps the minimised practical note, the versioned approach offered, what you chose, whether it felt lighter, and the source and approval details needed to avoid repeating an unhelpful approach. Saving a memory does not save the raw thought or thread.
- Saved threads. A signed-in user can separately opt one thread into raw retention for up to 30 days. This is distinct from memory approval and can be revoked sooner.
- Wellbeing information you choose to share. A reset may reveal information about mood or mental wellbeing. We process this special-category data only with your explicit consent. A guest gives concise session-only consent before any thought or audio is sent; account consent can be withdrawn at any time.
- Account and service data. If you register: email address, chosen name or nickname, one-way password hash, short-lived verification and recovery records, pseudonymous account identifier, consent records, approved memories and patterns, and the minimum technical data needed to operate and secure Sera.
- Text-free product events. Sera may record allow-listed technical facts such as the selected intent, coarse reflection latency, whether a reflection was confirmed, which versioned exercise was chosen, outcome category, whether a memory decision was made, weekly-review completion, Incognito use, and export or deletion success. These events use a random reset analytics key rather than an account ID and contain no thought, transcript, reflection, memory text, email, URL, referrer, IP, user agent, advertising identifier, or arbitrary property.
- Billing data. Stripe Checkout processes payment and subscription details. Real Product receives subscription status and transaction identifiers needed to grant and restore access, but does not receive your full card number.
Real Product does not sell conversations, use them for advertising, or use them to train AI models.
3. Our legal bases
- We process service and account data because it is necessary to provide Sera under our contract with you.
- We rely on your explicit consent for special-category wellbeing information (UK GDPR Article 9(2)(a)).
- We use legitimate interests for proportionate security and abuse prevention, after balancing those interests against your rights.
- We keep consent, transaction, and compliance records where needed to meet legal obligations.
4. Who processes your data
- Sera's self-hosted AI and speech systems run on Sera-controlled infrastructure hosted in the EU. With your consent, they transcribe audio, assess urgent-safety signals, reflect a thought, generate one bounded intervention and takeaway, and propose an editable causal memory. Private mode may use enabled, approved memories; Incognito reads none. Audio, transcripts, reset text, and approved memory are not sent to an external AI or speech API.
- Resend delivers account-verification and password-reset emails. It receives the destination email address, the short-lived one-time code, the message purpose, and limited delivery metadata under its data-processing terms. Sera does not send conversation or wellbeing content to Resend.
- Hosting providers store service data on EU servers.
- Stripe processes the purchase and subscription data needed for billing and entitlement management.
The AI-inference processing described above takes place on Sera's infrastructure in the EU. This statement is specific to the AI-inference path: other processors listed above may process their limited data categories outside the UK under the applicable safeguards. We do not use advertising trackers.
5. How long we keep things
Private and Incognito reset state is held only in a volatile store, expires within 24 hours, and is cleared promptly when a completed reset ends where safe. Audio is discarded immediately after transcription or failure. A thread is durable only when a signed-in user separately chooses saved-thread mode, and its raw messages are removed after 30 days or sooner on deletion. Unapproved memory and pattern candidates are not durable. Approved reset memory and causal evidence remain until you delete the item, withdraw account consent, or delete the account. Withdrawing consent stops new wellbeing processing, waits for in-flight wellbeing work to stop, and deletes the account's durable reset sessions, approved reset and derived memories, causal evidence, saved threads, derived patterns, weekly reviews, and volatile reset state. Consent audit rows and minimised safety-event metadata remain under their separate retention rules. Text-free product events and minimised safety-event metadata expire within 90 days; technical host logs rotate within 14 days. Account deletion removes live Sera service data and queues erasure for known Stripe mappings. Deleting Sera does not cancel a subscription; Stripe may retain transaction records under its own legal obligations.
Durable account collections are also bounded: Sera keeps up to 100 approved memory cards and up to 200 approved warm moments. When you save beyond either cap, the oldest item in that category is replaced first. Warm moments are a legacy account feature and are not created by the 90-second reset.
6. Your rights and controls
- Access and export a copy of your data.
- Correct, disable, or delete approved memory, its associated evidence, saved threads, and derived patterns.
- Withdraw consent at any time; Sera then stops processing new wellbeing information and deletes the reset data listed above.
- Object or restrict processing where those rights apply.
Use Settings to download a portable copy of your Sera content and consent history, withdraw consent, or delete your account. For a complete access request, or to exercise another right, email hello@seranook.com. Before disclosing or deleting data from an off-device request, we verify control through an active signed-in session or another sufficiently reliable method. An email address or account identifier by itself is not proof of ownership. If you no longer have a session, explain what you still have so we can assess whether safe identification is possible. You can complain to the UK Information Commissioner's Office at ico.org.uk.
7. Security and age limit
Data is encrypted in transit, backups are encrypted, and access is limited to authorised operational needs. No system is perfectly secure. Sera is for adults aged 18 or older and is not intended for children.
8. Changes
If we make a material change, we'll update the date above and notify you in the service before it takes effect where required.
9. Contact
Sera is operated by Real Product LLC ("Real Product", "we", "us"), which acts as the data controller for the personal data covered by this policy. Privacy questions? Email hello@seranook.com.