Privacy Policy
Last updated: 11 September 2026
Sera is designed around one short reset and a simple rule: memory of what helps, not memory of everything. A first private or Incognito reset does not require an account, email, name, card, trial, or subscription. This policy explains what Real Product LLC processes and why under UK data-protection law.
1. Your account identity
Content-free private journey counts. Focusing the private reset input or choosing voice records a declared entry using a temporary random token, without the thought, audio, transcript, IP address or account identifier in analytics. This allows bounded counts of entries, starts, completions, offers, checkouts and paid invoices. The journey is separate from wellbeing analytics. Incognito and saved-thread resets do not carry this attribution. If you switch to Incognito after a private entry, that earlier entry stays incomplete; the Incognito reset is not linked to it.
Optional visitor analytics. Only if you choose “Allow analytics”, Sera sends PostHog in the EU public page paths, explicitly selected navigation and subscription steps, a referring domain, and a small allowlist of campaign labels. A random browser identifier connects consenting visits; a random session identifier groups activity. With this permission, an anonymous private journey key can connect the visit to private entry, completion, offer, checkout and payment counts. We never send reset text, audio, transcripts, memory, email, account identifiers, full query strings, URL fragments or referring page paths to PostHog. There is no session replay or automatic capture of form contents. Incognito actions are excluded from this visitor funnel.
Independent service counts. The content-free private journey counts above, and positive invoice and revenue counts, are recorded independently of optional browser analytics and may be reported to PostHog without a browser identity. These use anonymous journey or one-way transaction keys, not raw account or payment-provider identifiers. Payment totals include renewals and invoices without an attributed private journey; they do not identify which website visitor paid. These limited counts help us operate and measure the service; wellbeing events and their categories are not exported to PostHog.
A guest reset uses a high-entropy, short-lived browser credential and the explicit processing consent given by choosing the disclosed start or record action; it does not create a durable wellbeing account or profile. If you later choose to register, no legal name is required: you may use a first name or nickname. Sera asks for an email address and password so you can sign in from another browser; the password is stored only as a one-way password hash. A short-lived one-time code confirms the email address and supports password reset.
2. What we process, and why
- Raw reset data. Audio you choose to record, its transcript or the thought you type, Sera's reflection, and the temporary generation context needed to complete the reset. Private and Incognito raw data is transient by default and is not written to the durable conversation store. Audio is discarded immediately after transcription or failure.
- Approved memory and causal evidence. Only when you choose Save or Edit and save, Sera keeps the minimised practical note, the versioned approach offered, what you chose, whether it felt lighter, and the source and approval details needed to avoid repeating an unhelpful approach. Saving a memory does not save the raw thought or thread.
- Saved threads. A signed-in user can separately opt one thread into raw retention for up to 30 days. This is distinct from memory approval and can be revoked sooner.
- Wellbeing information you choose to share. A reset may reveal information about mood or mental wellbeing. We process this special-category data only with your explicit consent. A guest gives concise session-only consent before any thought or audio is sent; account consent can be withdrawn at any time.
- Account and service data. If you register: email address, chosen name or nickname, one-way password hash, short-lived verification and recovery records, pseudonymous account identifier, consent records, approved memories and patterns, and the minimum technical data needed to operate and secure Sera.
- Text-free product events. Sera may record allow-listed technical facts such as the selected intent, coarse reflection latency, whether a reflection was confirmed, which versioned exercise was chosen, outcome category, whether a memory decision was made, weekly-review completion, Incognito use, and export or deletion success. These events use a random reset analytics key rather than an account ID and contain no thought, transcript, reflection, memory text, email, URL, referrer, IP, user agent, advertising identifier, or arbitrary property.
- Billing data. Stripe Checkout processes payment and subscription details. Real Product receives subscription status and transaction identifiers needed to grant and restore access, but does not receive your full card number.
Real Product does not sell conversations, use them for advertising, or use them to train AI models.
3. Our legal bases
- We process service and account data because it is necessary to provide Sera under our contract with you.
- We rely on your explicit consent for special-category wellbeing information (UK GDPR Article 9(2)(a)).
- Optional browser analytics and its browser storage rely on your separate consent. Limited content-free service and billing counts rely on our legitimate interests in operating and measuring Sera.
- We use legitimate interests for proportionate security and abuse prevention, after balancing those interests against your rights.
- We keep consent, transaction, and compliance records where needed to meet legal obligations.
4. Who processes your data
- Sera's self-hosted AI and speech systems run on Sera-controlled infrastructure hosted in the EU. With your consent, they transcribe audio, reflect a thought, generate one bounded intervention and takeaway, and propose an editable approved memory. Private mode may use enabled, approved memories; Incognito reads none. Audio, transcripts, reset text, and approved memory are not sent to an external AI or speech API.
- Resend delivers account-verification and password-reset emails. It receives the destination email address, the short-lived one-time code, the message purpose, and limited delivery metadata under its data-processing terms. Sera does not send conversation or wellbeing content to Resend.
- Hosting providers store service data on EU servers.
- Stripe processes the purchase and subscription data needed for billing and entitlement management.
- PostHog EU processes the optional visitor analytics and limited independent service counts described above. Browser requests necessarily expose network metadata to the recipient; we disable IP-based location enrichment and do not include IP addresses in event properties. No conversation, wellbeing or account content is sent.
The AI-inference processing described above takes place on Sera's infrastructure in the EU. This statement is specific to the AI-inference path: other processors listed above may process their limited data categories outside the UK under the applicable safeguards. We do not use advertising trackers.
5. How long we keep things
Private and Incognito reset state is held only in a volatile store, expires within 24 hours, and is cleared promptly when a completed reset ends where safe. Audio is discarded immediately after transcription or failure. A thread is durable only when a signed-in user separately chooses saved-thread mode, and its raw messages are removed after 30 days or sooner on deletion. Unapproved memory and pattern candidates are not durable. Approved reset memory and causal evidence remain until you delete the item, withdraw account consent, or delete the account. Withdrawing consent stops new wellbeing processing, waits for in-flight wellbeing work to stop, and deletes the account's durable reset sessions, approved reset and derived memories, causal evidence, saved threads, derived patterns, weekly reviews, and volatile reset state. Consent audit rows and minimised safety-event metadata remain under their separate retention rules. Text-free product events and minimised safety-event metadata expire within 90 days; technical host logs rotate within 14 days. Account deletion removes live Sera service data and queues erasure for known Stripe mappings. Deleting Sera does not cancel a subscription; manage or cancel through Stripe’s independent email login, also available on our Support page. Stripe may retain transaction records under its own legal obligations.
Durable account collections are also bounded: Sera keeps up to 100 approved memory cards and up to 200 approved warm moments. When you save beyond either cap, the oldest item in that category is replaced first. Warm moments are a legacy account feature and are not created by the current reset flow.
Your optional analytics preference and random browser identifier expire after 90 days. Analytics sessions expire after 30 minutes without a tracked action and last at most 24 hours. Turning analytics off removes these analytics identifiers from this browser and stops future browser events and new journey links; it does not undo already recorded anonymous counts.
6. Your rights and controls
- Access and export a copy of your data.
- Correct, disable, or delete approved memory, its associated evidence, saved threads, and derived patterns.
- Withdraw consent at any time; Sera then stops processing new wellbeing information and deletes the reset data listed above.
- Control optional analytics through “Analytics settings” in the page footer. You can decline or withdraw without affecting access to Sera. We also honour Do Not Track and Global Privacy Control signals.
- Object or restrict processing where those rights apply.
Use Privacy & data to download a portable copy of your Sera content and consent history, withdraw consent, or delete your account. For a complete access request, or to exercise another right, email ceo@seranook.com. Before disclosing or deleting data from an off-device request, we verify control through an active signed-in session or another sufficiently reliable method. An email address or account identifier by itself is not proof of ownership. If you no longer have a session, explain what you still have so we can assess whether safe identification is possible. You can complain to the UK Information Commissioner's Office at ico.org.uk.
7. Security and age limit
Data is encrypted in transit, backups are encrypted, and access is limited to authorised operational needs. No system is perfectly secure. Sera is for adults aged 18 or older and is not intended for children.
8. Changes
If we make a material change, we'll update the date above and notify you in the service before it takes effect where required.
9. Contact
Sera is operated by Real Product LLC ("Real Product", "we", "us"), which acts as the data controller for the personal data covered by this policy. Privacy questions? Email ceo@seranook.com.