Sereneo
  • How it works
  • Privacy
  • Questions
Contact usJoin the waitlist

Sereneo Privacy Policy

Version 1.1 — Effective Date: 19 July 2026

1. Introduction and Scope

1.1. This Privacy Policy (the “Policy”) describes how Planviah Helgesen processes personal data in connection with the Sereneo mobile application for iOS and the associated backend services (together, the “Service”). It is addressed to every natural person who creates an account for, or otherwise uses, the Service (the “user”, “you”).

1.2. Sereneo is a personal mental-wellness journaling application. It enables you to write private journal entries, to record mood check-ins, and to log stress events, and, solely where you have given a separate and explicit consent, to receive automated emotional analyses of your journal entries generated by an artificial-intelligence system. The Service is a self-reflection tool; it is not a medical device, it does not provide medical advice, and it is not a substitute for professional mental-health care.

1.3. Because the Service is designed to receive information concerning your emotional and mental state, the majority of the personal data processed through the Service constitutes data concerning health within the meaning of Article 4(15) and Article 9 of Regulation (EU) 2016/679 (the “GDPR”). This Policy has been drafted to satisfy the information duties arising under Articles 12, 13 and 14 GDPR, and, where applicable, under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (the “CCPA”).

1.4. This Policy applies to the processing of personal data carried out by the controller identified in Section 2 through the Service. It does not govern the processing of personal data carried out by third parties acting as independent controllers, including Apple Inc. where you use Sign in with Apple or the Apple App Store, and Google LLC where you use Google Sign-In. Such processing is governed exclusively by the privacy notices of those third parties.

1.5. In the event of any discrepancy between this Policy and any summary, in-app description, or marketing statement concerning the processing of personal data, this Policy prevails.

2. Controller and Contact Information

2.1. The controller within the meaning of Article 4(7) GDPR is:

Planviah Helgesen, a sole proprietorship (enkeltpersonforetak) organised under the laws of Norway, registered in the Norwegian Central Coordinating Register for Legal Entities under organisation number 935 477 549, with registered address at Kringsjåveien 19, 5162 Laksevåg, Norway (the “Controller”, “we”, “us”).

2.2. The Controller may be contacted as follows: for general inquiries, by email to help@planviah.com; for all matters concerning personal data, including the exercise of the rights described in Section 13, by email to privacy@planviah.com; or by post to the registered address stated in Section 2.1.

2.3. The Controller has not designated a data protection officer, as none of the conditions of Article 37(1) GDPR is met. All data-protection matters are handled directly by the Controller through the privacy contact address stated in Section 2.2.

2.4. The Controller is established in Norway. The GDPR applies to the processing described in this Policy by virtue of the incorporation of the GDPR into the Agreement on the European Economic Area and the Norwegian Personal Data Act of 2018 (personopplysningsloven).

3. Categories of Personal Data Processed

3.1. Account and identification data. Upon registration we process the email address you provide or, where you register through Sign in with Apple or Google Sign-In, the email address transmitted to us by the respective identity provider (including, in the case of Apple, a private relay address where you have elected to hide your email address); a display name; where you register with a password, that password in the form of a one-way cryptographic hash produced with the bcrypt algorithm (the password itself is at no point stored and cannot be reconstructed by us); where you use a third-party identity provider, the pseudonymous subject identifier assigned by that provider (we do not receive your credentials with that provider); and the verification status of your email address. You may, at your option, record additional profile details within the application, namely a gender designation and a telephone number with country code; the provision of these details is voluntary, and their absence has no effect on your use of the Service.

3.2. Journal and wellbeing data. The substance of the Service consists of data that you yourself create concerning your mental state, namely: journal entries in free text, together with an optional mood value on a scale of one to ten and optional tags; mood check-ins consisting of a value on a scale of one to ten, an optional free-text note, contextual tags and a timestamp; stress events consisting of an intensity value on a scale of one to ten, an optional free-text note, contextual tags and a timestamp; and journaling preferences, comprising reminder settings, a word-count goal, and an optional short statement of intention. All data described in this Section 3.2 is treated as data concerning health in accordance with Section 5.

3.3. AI-generated content. Where, and only where, you have enabled the artificial-intelligence processing described in Section 7, we store the automated emotional analysis derived from a journal entry. Such derived content is classified and protected as data concerning health in the same manner as the journal entry from which it derives, and is stored in encrypted form.

3.4. Consent records. We maintain an append-only record of every consent that you grant or withdraw, comprising the type of consent, the decision taken, the version of the applicable policy at the time of the decision, and a timestamp. These records constitute the Controller’s evidence of consent for the purposes of Article 7(1) GDPR. The consents currently presented in the application are: (a) the processing of health data, which is a precondition for the use of the core functions of the Service; (b) artificial-intelligence processing, which is optional and disabled by default; and (c) insight notifications, which is optional and disabled by default. The insight-notification function has not been placed into operation: no notifications of any kind are presently dispatched, and no notification-related data, such as device push tokens, is presently collected. Your election is recorded so that it can be honoured if and when the function is introduced, and this Policy will be updated before any notification function is activated.

3.5. Security and technical data. In operating the Service we process: a security audit log recording security-relevant events, including successful and failed authentication attempts, consent changes, password-reset events and account-deletion events, which log contains account identifiers and event descriptors only and at no point contains journal content, notes, or wellbeing values; server logs generated when the application communicates with our interface, containing the originating IP address and standard request metadata, from which authentication credentials are redacted and in which user content does not appear; session data in the form of refresh tokens stored exclusively as cryptographic hashes; and synchronisation metadata, comprising timestamps, record identifiers and short-lived deletion markers used to reconcile the data held on your device with the data held on our servers.

3.6. Data not collected. For the avoidance of doubt, we do not collect or process: advertising identifiers or any form of cross-application tracking data; cookies or comparable tracking technologies (the application is a native iOS application and our interface authenticates by token rather than by cookie); data from third-party analytics, advertising or social-media software development kits, none of which is embedded in the application; location data; or data from your device’s contacts, photo library, microphone or camera. No usage analytics are at present transmitted from your device. Should privacy-preserving, first-party usage analytics be introduced in the future, this Policy will be amended beforehand. We do not sell personal data, we do not disclose personal data for advertising purposes, and we do not use your content for the training of artificial-intelligence models.

3.7. All personal data processed through the Service is obtained from you directly or generated through your use of the Service, with the sole exception of the name and email address transmitted to us by Apple or Google where you elect to authenticate through those providers.

4. Purposes of Processing and Legal Bases

4.1. Provision of the account and authentication. We process account and identification data and session data in order to create and administer your account, to authenticate your access, and to maintain your session. The legal basis is Article 6(1)(b) GDPR, the processing being necessary for the performance of the contract concluded with you upon acceptance of the Sereneo Terms of Service.

4.2. Storage and synchronisation of wellbeing data. We process the journal and wellbeing data described in Section 3.2 in order to store it, to synchronise it between your device and our servers, and to display it back to you. The legal basis is your explicit consent pursuant to Article 9(2)(a) GDPR in conjunction with Article 6(1)(a) GDPR, given during onboarding. In the absence of this consent the Service will not store or synchronise wellbeing data, and the relevant interfaces of the Service refuse such processing.

4.3. Artificial-intelligence analysis. We process the text of journal entries for the purpose of generating automated emotional analyses, as described in Section 7, exclusively on the basis of a separate explicit consent pursuant to Article 9(2)(a) GDPR in conjunction with Article 6(1)(a) GDPR. This consent is disabled by default and its refusal or withdrawal has no effect on the availability of the remainder of the Service.

4.4. Transactional communications. We process your email address in order to dispatch messages that are necessary for the administration of your account, presently limited to email-address verification messages and password-reset messages. The legal basis is Article 6(1)(b) GDPR. We do not send marketing communications.

4.5. Security and abuse prevention. We process the security and technical data described in Section 3.5 for the purposes of securing the Service, detecting and preventing unauthorised access, enforcing rate limits, investigating misuse, and preserving the integrity of user data. The legal basis is Article 6(1)(f) GDPR, our legitimate interest being the protection of the Service and of the data entrusted to it. We have assessed this interest against your interests and fundamental rights and have concluded that it is not overridden by them, having regard to the facts that the processing is confined to security functions, that it involves minimal data, and that it at no point extends to the content you create.

4.6. Compliance and accountability. We process consent records and, where applicable, correspondence relating to data-subject requests in order to comply with our legal obligations under the GDPR, in particular Articles 5(2), 7(1) and 12 to 22. The legal basis is Article 6(1)(c) GDPR.

4.7. Business continuity. We process encrypted copies of the Service database for the purpose of disaster recovery, as described in Section 10.5. The legal basis is Article 6(1)(f) GDPR, our legitimate interest being the protection of your data against accidental loss or destruction.

4.8. We do not process personal data for any purpose incompatible with those stated in this Section 4. Should a new purpose arise, we will inform you in advance in accordance with Article 13(3) GDPR and, where the new purpose concerns data processed on the basis of consent, obtain a new consent.

5. Special Categories of Personal Data

5.1. The journal entries, mood check-ins, stress events, journaling preferences and AI-generated emotional analyses processed through the Service constitute data concerning health within the meaning of Article 9(1) GDPR.

5.2. We process such data exclusively on the basis of your explicit consent pursuant to Article 9(2)(a) GDPR, obtained during onboarding by means of a dedicated, granular consent dialogue that is separate from your acceptance of the Terms of Service. Consent to health-data processing is a precondition for the use of the core functions of the Service, because the Service cannot store a journal without processing its contents; consent to artificial-intelligence processing is separate, optional and disabled by default.

5.3. You may withdraw any consent at any time with effect for the future, in the manner described in Section 13.8. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Upon withdrawal of the health-data consent, the processing concerned ceases, and you may thereafter delete your account and all associated data in the manner described in Section 12.

6. Storage Location

6.1. The Service’s databases are operated on server infrastructure located in Norway. Should the hosting of the Service be migrated in the future, it will be migrated to a data centre located within the European Union or the European Economic Area.

6.2. Encrypted database backups are stored with Cloudflare, Inc. in an object-storage region located in the European Union (Eastern Europe region), subject to the safeguards described in Section 9.

7. Artificial-Intelligence Processing and Automated Decision-Making

7.1. The Service offers one artificial-intelligence function: an automated emotional analysis of individual journal entries. This Section describes that function exhaustively.

7.2. The function operates only where you have granted the specific “AI processing” consent. The consent is disabled by default, is requested separately from all other consents, and may be enabled or disabled at any time in the application’s settings; disabling it is no more onerous than enabling it.

7.3. Where the function is enabled, the text of a journal entry is decrypted transiently in the working memory of our server and transmitted over an encrypted connection to our processor OpenAI, L.L.C. (“OpenAI”) for the sole purpose of generating the emotional analysis. Only the entry text is transmitted, truncated to a maximum of eight thousand characters; your name, email address and account identifiers are not transmitted with it. The resulting analysis is returned to our server and stored in encrypted form alongside the journal entry concerned. The journal text is at no point written to logs and at no point stored in unencrypted form on our systems.

7.4. Our engagement of OpenAI is governed by a data processing agreement incorporating a zero-data-retention arrangement, under which OpenAI does not retain the transmitted text after processing and does not use it for the training or improvement of its models. The transfer of data to OpenAI in the United States is safeguarded as described in Section 9.2.

7.5. All content generated by the artificial-intelligence function is identified as such within the application.

7.6. Automated decision-making. The Service does not carry out any decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. The output of the artificial-intelligence function is reflective and informational in nature; it does not determine your access to or the terms of the Service, it is not disclosed to any third party, and it does not constitute a diagnosis, evaluation or assessment of you.

7.7. Human review. No natural person, including personnel of the Controller, reads your journal content or the output of the artificial-intelligence function in the ordinary course of operating the Service. Access to stored user content may occur only where required by law, or where strictly necessary to protect the vital interests of a natural person or to investigate serious abuse of the Service; any such access would itself be recorded in the security audit log.

8. Recipients of Personal Data

8.1. We engage a limited number of processors within the meaning of Article 28 GDPR. Each engagement is governed by a data processing agreement imposing the obligations required by Article 28(3) GDPR. The processors currently engaged are the following:

8.2. OpenAI, L.L.C., United States. Purpose: generation of the automated emotional analyses described in Section 7, exclusively where you have granted the corresponding consent. Data concerned: journal entry text, processed transiently under a zero-data-retention arrangement. Place of processing: United States.

8.3. Maileroo, with processing in Germany. Purpose: dispatch of the transactional email messages described in Section 4.4. Data concerned: your email address and the contents of the messages concerned. Place of processing: Germany.

8.4. Cloudflare, Inc., United States, with data storage in the European Union. Purpose: provision of network transport security for our interface, and storage of encrypted database backups. Data concerned: encrypted network traffic and originating IP addresses in transit; encrypted backup archives at rest. Backups are encrypted by us prior to upload with keys that are at no point disclosed to Cloudflare.

8.5. The following third parties receive personal data as independent controllers, and not as our processors, where you choose to use their services: Apple Inc., where you authenticate through Sign in with Apple and as operator of the App Store through which the application is distributed; and Google LLC, where you authenticate through Google Sign-In. The processing carried out by these parties is governed by their own privacy notices, and we exercise no control over it.

8.6. Beyond the recipients identified in this Section 8, personal data is disclosed to no one, save where disclosure is required of us by law, by enforceable order of a court or competent authority, or where disclosure is strictly necessary to establish, exercise or defend legal claims. We do not sell personal data and we do not disclose personal data for advertising or marketing purposes.

8.7. Should we engage an additional or replacement processor whose processing concerns your personal data, we will amend this Policy in advance and, where the change materially affects the processing of your health data, present the amended Policy for renewed review and consent within the application.

9. International Transfers

9.1. Personal data is stored within Norway and the European Economic Area. Transfers to countries outside the European Economic Area that have not been the subject of an adequacy decision of the European Commission occur in two cases only, each of which is described below together with the safeguards applied pursuant to Chapter V GDPR.

9.2. OpenAI (United States). Where you have enabled the artificial-intelligence function, journal entry text is transmitted to OpenAI in the United States for the duration of the analysis. This transfer is carried out on the basis of the Standard Contractual Clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR, as incorporated into our data processing agreement with OpenAI, supplemented by the zero-data-retention arrangement described in Section 7.4, under which the transmitted text is not stored in the United States following completion of the processing.

9.3. Cloudflare (United States entity; storage within the European Union). Our encrypted backups are stored in a Cloudflare storage region located in the European Union. As Cloudflare, Inc. is established in the United States, the engagement is safeguarded by the Standard Contractual Clauses incorporated into Cloudflare’s data processing addendum. As a supplementary measure, all backup archives are encrypted by us before transmission, with encryption keys that are never in Cloudflare’s possession, so that the stored material is unintelligible to Cloudflare and to any authority that might compel its disclosure.

9.4. Where a recipient holds a current certification under the EU–U.S. Data Privacy Framework, that certification constitutes an additional lawful basis for the transfer pursuant to the adequacy decision of the European Commission of 10 July 2023. You may obtain a copy of the safeguards referred to in this Section 9, or information on where they have been made available, by writing to privacy@planviah.com.

10. Security of Processing

10.1. In accordance with Article 32 GDPR, and having regard to the special category of the data processed, we apply technical and organisational measures which include those described in this Section 10.

10.2. Encryption of content at the application layer. The text of journal entries, the notes attached to mood check-ins and stress events, and AI-generated analyses are encrypted with AES-256-GCM under a data-encryption key unique to each user before being written to the database. Each user’s data-encryption key is itself encrypted (envelope encryption) under a master key that is stored separately from the database. The database at no point contains such content in intelligible form. Upon deletion of an account the user’s data-encryption key is destroyed, whereupon all content encrypted under it — including content contained in backups — is rendered permanently unintelligible (cryptographic erasure).

10.3. Limits of the encryption model. The Service is not end-to-end encrypted: our servers must be capable of processing your content in order to provide the functions of the Service, including the artificial-intelligence function where you enable it. Structured wellbeing metadata — numeric mood and stress values, tags and timestamps — is stored in structured rather than content-encrypted form in order to permit the operation of the Service, and is protected by the access controls, transport encryption and organisational measures described in this Section.

10.4. Transport security, credentials and sessions. All communication between the application and our servers is encrypted with TLS; email is dispatched over encrypted connections. Passwords are stored exclusively as bcrypt hashes. Refresh tokens are stored exclusively as cryptographic hashes, are rotated upon every use, and belong to token families that are revoked in their entirety upon detection of replay. Authentication endpoints are subject to rate limiting and progressive back-off against brute-force attack. On the device, the application’s local database is protected by iOS Data Protection (complete file protection), and the session token is held in the iOS Keychain, bound to the device and excluded from iCloud synchronisation.

10.5. Backups and operations. Database backups are encrypted before leaving our infrastructure, with the decryption key held separately from the backup storage. Security-relevant events are recorded in the audit log described in Section 3.5, which never contains content. Credentials are redacted from logs, and software dependencies are subject to routine vulnerability scanning.

10.6. Personal-data breaches. In the event of a personal-data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the Norwegian Data Protection Authority (Datatilsynet) without undue delay and, where feasible, within seventy-two hours of becoming aware of it, in accordance with Article 33 GDPR; where the breach is likely to result in a high risk, we will additionally communicate the breach to the affected users without undue delay, in accordance with Article 34 GDPR.

11. Retention of Personal Data

11.1. Account and identification data, journal and wellbeing data, AI-generated analyses, preferences and consent records are retained until the deletion of your account, which takes immediate effect in the manner described in Section 12.

11.2. Entries in the security audit log are retained for twelve months from their creation, after which they are deleted or irreversibly anonymised. Upon deletion of an account, all audit entries relating to it are immediately anonymised by severance of the account reference, so that they can no longer be attributed to any person.

11.3. Server logs, including IP addresses, are retained for thirty days.

11.4. Synchronisation deletion markers are retained for ninety days from the deletion to which they relate.

11.5. Refresh tokens are deleted upon expiry, which occurs no later than thirty days after issue, or upon sign-out, whichever is earlier. Email-verification and password-reset tokens are valid for a single use and are deleted upon use or expiry.

11.6. Backup archives are retained on a rolling basis of thirty days. Content deleted from the live database therefore ceases to exist in any backup no later than thirty days after deletion; where the deletion results from account deletion, the content contained in backups is in any event unintelligible from the moment of deletion by operation of the cryptographic erasure described in Section 10.2.

11.7. Personal data is not retained beyond the periods stated in this Section unless, and only for so long as, retention is required by a legal obligation to which the Controller is subject or is necessary for the establishment, exercise or defence of legal claims.

12. Account Deletion

12.1. You may delete your account at any time from within the application (Profile → Delete Account), without any requirement to contact us. Deletion requires re-authentication, as a safeguard against deletion by an unauthorised person.

12.2. Deletion takes immediate, permanent and irreversible effect. Upon deletion: your account record and all journal entries, mood check-ins, stress events, AI-generated analyses, preferences, consent records and session tokens are erased from the live database; your data-encryption key is destroyed, whereupon all encrypted content, wherever it exists, including within backups, is rendered permanently unintelligible; and all active sessions are terminated. There is no deactivation period and no possibility of restoration.

12.3. Following deletion, the only records retained are fully anonymised security-audit and event records that cannot be attributed to any person, and encrypted backup archives, which are unintelligible as stated in Section 12.2 and which are themselves deleted within thirty days in accordance with Section 11.6.

13. Rights of the Data Subject

13.1. You have, under Articles 15 to 21 GDPR and subject to the conditions stated therein, the rights described in this Section. All rights may be exercised free of charge by writing to privacy@planviah.com or, where an in-application control exists, by using that control. We will respond without undue delay and in any event within one month of receipt of the request, as required by Article 12(3) GDPR; where the complexity or number of requests so requires, this period may be extended by two further months, of which you would be informed within the first month. We may request information necessary to confirm your identity before acting on a request.

13.2. Right of access (Article 15). You have the right to obtain confirmation as to whether personal data concerning you is processed, access to that data, and the information enumerated in Article 15(1) GDPR, together with a copy of the data undergoing processing.

13.3. Right to rectification (Article 16). You have the right to obtain the rectification of inaccurate personal data and the completion of incomplete personal data. Account details and content you have created may be corrected directly within the application.

13.4. Right to erasure (Article 17). You have the right to obtain the erasure of personal data concerning you on the grounds stated in Article 17(1) GDPR. The most complete means of exercising this right is the account-deletion function described in Section 12; individual items of content may also be deleted within the application, whereupon they are removed from our systems subject to the synchronisation and backup periods stated in Section 11.

13.5. Right to restriction (Article 18). You have the right to obtain the restriction of processing in the circumstances stated in Article 18(1) GDPR, in which case the data concerned will, with the exception of storage, be processed only with your consent or on the other grounds stated in Article 18(2) GDPR.

13.6. Right to data portability (Article 20). You have the right to receive the personal data you have provided to us, where processed on the basis of consent or contract and by automated means, in a structured, commonly used and machine-readable format, and to transmit it to another controller. Pending the release of the in-application export function referred to in Section 13.9, this right is fulfilled on request by email.

13.7. Right to object (Article 21). You have the right to object, on grounds relating to your particular situation, to processing carried out on the basis of Article 6(1)(f) GDPR, namely the security and business-continuity processing described in Sections 4.5 and 4.7. In the event of such an objection we will cease the processing concerned unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

13.8. Right to withdraw consent (Article 7(3)). You have the right to withdraw any consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal. The consent to artificial-intelligence processing may be withdrawn directly by means of the corresponding control in the application’s settings. The consent to health-data processing may be withdrawn by writing to privacy@planviah.com or by deleting your account; because that consent is the legal basis of the Service’s core function, its withdrawal entails that the Service can no longer store or synchronise wellbeing data.

13.9. Export function. An in-application export function is planned. Until it is available, a complete copy of your data in a machine-readable format will be provided free of charge upon request to privacy@planviah.com, within the period stated in Section 13.1.

14. Right to Lodge a Complaint

14.1. Without prejudice to any other administrative or judicial remedy, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.

14.2. The supervisory authority competent for the Controller is Datatilsynet (the Norwegian Data Protection Authority), P.O. Box 458 Sentrum, 0105 Oslo, Norway, www.datatilsynet.no. We would nevertheless welcome the opportunity to address any concern before a complaint is lodged, at privacy@planviah.com.

15. Disclosures for California Residents

15.1. This Section applies to users who are residents of the State of California and supplements the remainder of this Policy. Terms used in this Section have the meanings given to them in the CCPA.

15.2. The categories of personal information collected by the Service are those described in Section 3, namely identifiers (email address, display name, provider subject identifiers), sensitive personal information (the wellbeing data described in Sections 3.2 and 3.3, which constitutes personal information concerning health, and optionally a telephone number and gender designation), and internet or network activity information limited to the security and technical data described in Section 3.5. The sources, purposes and recipients of this information are those stated in Sections 3, 4 and 8.

15.3. We do not sell personal information, we do not share personal information for cross-context behavioural advertising, and we have not done either in the preceding twelve months. We do not use or disclose sensitive personal information for any purpose other than the provision of the Service you request and the purposes permitted by section 7027(m) of the CCPA regulations. Accordingly, no opt-out right arises, and the Service does not process opt-out preference signals because there is no sale or sharing to which such signals could apply.

15.4. You have the right to know, to access, to correct, and to delete personal information, and the right not to receive discriminatory treatment for exercising any right. These rights may be exercised in the manner described in Section 13, including through an authorised agent, subject to verification of your identity and, in the case of an agent, of the agent’s authority. The retention periods applicable to each category of personal information are those stated in Section 11.

16. Children

16.1. The Service is not directed to, and may not be used by, persons under sixteen years of age. We do not knowingly collect personal data from persons under sixteen. Where we obtain knowledge that personal data of a person under sixteen has been collected, we will delete the account concerned and all associated data. Reports may be made to privacy@planviah.com.

17. Cookies and Tracking Technologies

17.1. The application is a native iOS application. It does not use cookies or comparable technologies, our interface authenticates by token rather than by cookie, and no cross-site or cross-application tracking of any kind takes place.

18. Amendments to this Policy

18.1. This Policy may be amended as the Service develops. Every version bears a version number and an effective date, and the version history is available on request.

18.2. In the case of a material amendment — in particular any amendment concerning the processing of health data, the purposes of processing, or the recipients of personal data — the application will present the amended Policy and, where the processing concerned rests on consent, will request renewed consent before the amendment applies to you. Amendments that are not material take effect upon publication at the address stated in Section 19.2.

19. Final Provisions

19.1. This Policy is issued in English. Where translations are provided in the future, the English version prevails to the extent permitted by mandatory law.

19.2. The current version of this Policy is published at https://sereneo.app/privacy and is accessible from within the application.

19.3. Questions concerning this Policy may be directed to Planviah Helgesen, Kringsjåveien 19, 5162 Laksevåg, Norway; privacy@planviah.com (privacy matters); help@planviah.com (general matters).

Sereneo Privacy Policy, Version 1.1, effective 19 July 2026.

Questions about this document? Emailprivacy@planviah.com.

See also the Terms of Service.

Sereneo

Calm progress, one day at a time.

Coming to iPhone · English and Norsk

Product

  • How it works
  • Privacy by design
  • Questions
  • Join the waitlist

Legal

  • Privacy Policy
  • Terms of Service

Contact

  • help@planviah.com
  • privacy@planviah.com

© 2026 Planviah Helgesen · Org. nr. 935 477 549

Sereneo is a self-reflection tool, not a medical device or a crisis service.