Sereneo Privacy Policy
Version 1.4 — Effective Date: 29 August 2026
1. Introduction and Scope
1.1. This Privacy Policy (the “Policy”) describes how Planviah Helgesen processes personal data in connection with the Sereneo mobile application for iOS and the associated backend services (together, the “Service”). It is addressed to every natural person who creates an account for, or otherwise uses, the Service (the “user”, “you”).
1.2. Sereneo is a personal mental-wellness journaling application. It enables you to write private journal entries, to record mood check-ins, to log stress events, to record gratitude entries, and, solely where you have given a separate and explicit consent, to receive artificial-intelligence output describing your own entries — for example an emotional analysis and short summary of a journal entry, a written summary of a completed week, month or year (a “Reflection”), and thematic summaries of what you have recorded. That processing, and its limits, are described in Section 7. The Service is a self-reflection tool; it is not a medical device, it does not provide medical advice, and it is not a substitute for professional mental-health care.
1.3. Because the Service is designed to receive information concerning your emotional and mental state, the majority of the personal data processed through the Service constitutes data concerning health within the meaning of Article 4(15) and Article 9 of Regulation (EU) 2016/679 (the “GDPR”). This Policy has been drafted to satisfy the information duties arising under Articles 12, 13 and 14 GDPR, and, where applicable, under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (the “CCPA”).
1.4. This Policy applies to the processing of personal data carried out by the controller identified in Section 2 through the Service, and to the public website at sereneo.app on which this Policy is published (Section 3.13). It does not govern the processing of personal data carried out by third parties acting as independent controllers, including Apple Inc. where you use Sign in with Apple, purchase a subscription, or obtain the application from the App Store, and Google LLC where you use Google Sign-In. Such processing is governed exclusively by the privacy notices of those third parties.
1.5. In the event of any discrepancy between this Policy and any summary, in-app description, or marketing statement concerning the processing of personal data, this Policy prevails.
2. Controller and Contact Information
2.1. The controller within the meaning of Article 4(7) GDPR is:
Planviah Helgesen, a sole proprietorship (enkeltpersonforetak) organised under the laws of Norway, registered in the Norwegian Central Coordinating Register for Legal Entities under organisation number 935 477 549, with registered address at Kringsjåveien 19, 5162 Laksevåg, Norway (the “Controller”, “we”, “us”).
2.2. The Controller may be contacted as follows: for general inquiries, by email to support@sereneo.app; for all matters concerning personal data, including the exercise of the rights described in Section 13, by email to privacy@sereneo.app; or by post to the registered address stated in Section 2.1.
2.3. The Controller has not designated a data protection officer, as none of the conditions of Article 37(1) GDPR is met. All data-protection matters are handled directly by the Controller through the privacy contact address stated in Section 2.2.
2.4. The Controller is established in Norway. The GDPR applies to the processing described in this Policy by virtue of the incorporation of the GDPR into the Agreement on the European Economic Area and the Norwegian Personal Data Act of 2018 (personopplysningsloven).
3. Categories of Personal Data Processed
3.1. Account and identification data. Upon registration we process the email address you provide or, where you register through Sign in with Apple or Google Sign-In, the email address transmitted to us by the respective identity provider (including, in the case of Apple, a private relay address where you have elected to hide your email address); a display name; where you register with a password, that password in the form of a one-way cryptographic hash (the password itself is at no point stored and cannot be reconstructed by us); where you use a third-party identity provider, the pseudonymous subject identifier assigned by that provider (we do not receive your credentials with that provider); and the verification status of your email address.
During account setup we further process your date of birth, which is used to establish that you meet the minimum age stated in Section 16 and is not used for any other purpose; the time zone your device reports, which determines where the boundaries of “your week”, “your month” and “your year” fall for the purposes of Reflections and of every daily statistic; and the language your device’s interface is set to, which determines the language of the messages we send you.
3.2. Journal and wellbeing data. The substance of the Service consists of data that you yourself create concerning your mental state, namely: journal entries in free text, together with an optional mood value on a scale of one to ten and optional tags; mood check-ins consisting of a value on a scale of one to ten, an optional free-text note, contextual tags and a timestamp; stress events consisting of an intensity value on a scale of one to ten, an optional free-text note, contextual tags and a timestamp; gratitude entries consisting of up to three short free-text answers, namely something you are grateful for, a small thing you appreciated and something you are looking forward to, together with the date to which you assign the entry; and journaling and mood preferences, comprising reminder settings, a word-count goal, mood goals, and an optional short statement of intention. All data described in this Section 3.2 is treated as data concerning health in accordance with Section 5.
3.3. AI-generated and derived content. We store the output of the processing described in Section 7: where, and only where, you have enabled artificial-intelligence processing, the analyses, summaries and thematic labels derived from your entries; and, for every user, the completed Reflection for each closed week, month and year, which contains the statistics of that period and, where you have enabled artificial-intelligence processing, the narration composed from them. Such derived content is classified and protected as data concerning health in the same manner as the entries from which it derives, and is stored in encrypted form.
3.4. Consent records. We maintain an append-only record of every consent that you grant or withdraw, comprising the type of consent, the decision taken, the version of the applicable policy at the time of the decision, and a timestamp. These records constitute the Controller’s evidence of consent for the purposes of Article 7(1) GDPR. The consents currently presented in the application are: (a) the processing of health data, which is a precondition for the use of the core functions of the Service; (b) artificial-intelligence processing, which is optional and disabled by default; and (c) insight notifications, which is optional and disabled by default. We also record which version of this Policy and of the Terms of Service you have been shown. The data processed in connection with notifications is described in Section 3.9; the insight-notification consent recorded here governs one category of notification only, and the remaining categories are governed by the settings described in that Section.
3.5. Security and technical data. In operating the Service we process: a security audit log recording security-relevant events, including successful and failed authentication attempts, consent changes, password-reset events and account-deletion events, which log contains account identifiers and event descriptors only and at no point contains journal content, notes, or wellbeing values; server logs generated when the application communicates with our interface, containing the originating IP address, the identifier of your account where the request was authenticated, and standard request metadata (the method, the route, the response status and how long it took), from which authentication credentials and any token appearing in a web address are removed and in which user content does not appear; session data in the form of credentials stored exclusively as cryptographic hashes; and synchronisation metadata, comprising timestamps, record identifiers and short-lived deletion markers used to reconcile the data held on your device with the data held on our servers.
3.6. Data not collected. For the avoidance of doubt, we do not collect or process: advertising identifiers or any form of cross-application or cross-site tracking data; cookies or comparable tracking technologies (the application is a native iOS application and our interface authenticates by token rather than by cookie); data from advertising or social-media software development kits, none of which is embedded in the application; location data; or data from your device’s contacts, photo library, microphone or camera. We do not sell personal data, we do not disclose personal data for advertising purposes, and we do not use your content for the training of artificial-intelligence models.
3.7. All personal data processed through the Service is obtained from you directly or generated through your use of the Service, with the exception of the name and email address transmitted to us by Apple or Google where you elect to authenticate through those providers, and the subscription lifecycle data transmitted to us by the processor identified in Section 8.7 where you purchase a subscription.
3.8. Product-analytics data. Where, and only where, you have agreed to it on the device concerned, we process a record of how the application is used: which screens are opened, which features are used, and events describing the completion of such actions, together with the technical context of the event (application version and build, device model, operating-system version, the language and time zone your device is set to, and its screen dimensions). No location of any kind is collected, and none is derived from your network address. Where you are signed in, these events are associated with the identifier of your account; they are therefore pseudonymous and not anonymous. No content is included in this data. The events are generated by a closed, fixed list defined in the application’s source code, which is incapable of carrying journal text, mood notes, gratitude entries or wellbeing values. The processing is carried out through the product-analytics software development kit identified in Section 8.5, which is not started at all until you have agreed to it, and which is stopped when you withdraw. Part of this data is generated by our servers rather than by the application, as described in Section 8.5a; the same agreement governs it, and where you have not agreed, our servers transmit nothing about you. The agreement is requested when the application is first opened and is decided on the device rather than in the consent records described in Section 3.4, for the reason that it concerns the device and is given before an account exists; so that it can govern what our servers transmit, your decision is reported to us and held against your account for that sole purpose. It may be given or withdrawn at any time under Privacy & Security in the application’s settings, and withdrawing is no more onerous than agreeing.
3.9. Notification data. Where you enable notifications, we process: a device push token, being an opaque identifier issued by Apple that designates the installation of the application on a particular device, together with the platform and the dates on which it was registered and last seen; your notification settings, being three independent switches governing, respectively, notifications that a Reflection is ready, reminders, and insight notifications; the reminders you create, each comprising a time of day, the days of the week on which it repeats, whether it is active, which activity it is for, and the label you give it, which label is stored in encrypted form in the manner described in Section 10.2 because it is text you have written concerning your own routine; and a record of each notification we attempt to send you, comprising its category, the outcome of the attempt and a timestamp. The record of attempts contains no content: it states that a notification of a given category was sent, or was withheld, and when. It is kept so that the limit described in the following paragraph can be demonstrated rather than merely asserted, and so that you can obtain an account of what we have sent you.
Two matters concerning notifications are properly stated here rather than in a settings screen. First, no notification we generate contains journal content, mood values, scores or any other substance of your entries; the text of such a notification is selected from a fixed list held in our source code, into which no data of yours can be inserted. Reminders you create yourself display the label you gave them, which is scheduled and shown by your own device and never leaves it as a notification. Second, we send at most two notifications of our own initiative per day, a limit enforced in our code rather than by policy; reminders that you set for yourself are not subject to that limit, as they are not notifications of our initiative.
Device push tokens are processed only from the point at which you enable notifications. Where you have never enabled them, no token exists for your account; where you sign out, the association between the token and your account is deleted.
3.10. Operational diagnostics. We process a continuous technical record of how the application performs on your device. The greater part of it is produced during ordinary, successful use rather than at the moment something goes wrong. What is collected comprises:
(a) failure reports — the call stack of the failing code, the type and message of the error, the version and build of the application, the model of the device, the version of its operating system, and the free memory and storage at the time of the failure;
(b) operational log lines written by the application about its own progress, each drawn from a fixed set of messages defined in its source code;
(c) measurements — counters and durations, such as the number of times the application has been launched, how long a synchronisation took and how long a request to our interface took to answer, each identified by a name drawn from a closed list defined in the source code; and
(d) traces — the timing of an operation together with the network requests made during it, in which every address is reduced before transmission to its general shape with each identifier removed, so that no address can indicate which of your entries was involved.
Each of the four carries an installation identifier generated for the installed copy of the application on your device.
None of this contains content of yours, and none of it is associated with your account. We do not transmit your account identifier, your name or your email address to the processor identified in Section 8.8, and we accordingly cannot connect any of this material to you; the identifier described above designates an installation and nothing further, is not an advertising identifier, and is not shared with or combined with data from any other application. Your network address is not transmitted by the application, and the processor is configured not to store the address from which the transmission is received.
Six categories of data which such tooling commonly collects are switched off in our configuration, each because it would otherwise be capable of carrying your content: a screenshot of the application at the moment of failure; a description of the interface displayed at that moment; a recording of the session; the record of what was touched or tapped, because a control in the application may be described for accessibility purposes in words you yourself wrote; the text of queries made against the application’s own store of your entries; and the names of files read on the device.
3.11. Subscription data. Where you purchase a subscription, we process: an identifier for your subscription with the processor identified in Section 8.7, which is the pseudonymous identifier of your account; the identifier of the product you hold and, where a change is pending, of the product it will become; the status of the subscription; the start and end of the current period; whether it is set to end at the close of that period; and the lifecycle events reported to us in respect of it, being purchase, renewal, cancellation, expiry, product change and billing problem. We do not receive, process or store your payment-card details, your billing address, or any other payment instrument. Payment is taken by Apple through the App Store, in Apple’s own capacity as an independent controller (Section 8.9), and neither we nor the processor identified in Section 8.7 has access to it.
We record here, because it is the reason this category is treated more carefully than a payment record ordinarily would be, that the fact that a person subscribes to Sereneo is itself an indication that they use a mental-health tool. The data set is therefore kept deliberately narrow: no attribute describing you, your entries, your wellbeing or your device is attached to your record with that processor.
3.12. Advertising measurement. We do not track you across applications or websites, and we use no advertising identifier (Section 3.6). Where we advertise the application, we receive from Apple the aggregate, privacy-preserving install reports produced by Apple’s SKAdNetwork. These reports carry no link to any account, device or person, by Apple’s design, and neither we nor Apple can attribute one to you; they tell us that an install followed a campaign, not who installed. The application’s own part in this is confined to a single number between zero and sixty-three, which it writes into your device’s operating system when the installation reaches one of five points: the first opening of the application, the creation of an account, the completion of onboarding, the beginning of a free trial, and the purchase of a subscription. That number is written to the operating system and is transmitted by us to no one; whether it is ever disclosed, to whom, and in what degree of detail is determined by Apple, which withholds it where too few installs have occurred for the result to remain aggregate. The report we eventually receive therefore indicates how far an install progressed, and not whose install it was. Because they contain no identifier, they cannot be included in an export of your data or erased on your request — there is nothing in them capable of being identified as yours. They are retained for the period stated in Section 11.13.
3.13. The website. The public website at sereneo.app is a marketing, editorial and legal-information site. It requires no account, and no account data, journal content or wellbeing data of any kind is processed by, stored on, or accessible from it. As with any web server, its hosting provider (Section 8.11) processes standard request data, including the visiting IP address, for the purposes of delivering the site and protecting it against abuse.
3.13a. Website measurement. We measure how the website is used, by two means which differ in what they require of you.
The first is a page-view count operated by our hosting provider (Section 8.11). It records the page requested, the referring page, and the country, browser and device type derived from the request. It writes nothing whatever to your device — no cookie, no other identifier, and no stored data of any kind — and it is therefore not addressed by the agreement described in the next paragraph. Its lawful basis is stated in Section 4.13.
The second is a product-analytics component operated by the processor identified in Section 8.12, and it runs only where you have agreed to it. It records which pages you open, in what order and for how long, together with the referring page and the technical context of the request; and, because it must recognise a returning visit in order to be of any use, it stores an identifier on your device, as described in Section 17.3. That identifier is generated at random, is not linked to any account, and is not combined with data from the application or from any other website. It captures no form field, and nothing you type. Where you refuse, or have not yet answered, the component is not loaded at all, and nothing is stored or transmitted.
3.13b. What the website never does. It carries no advertising, no advertising identifier, and no advertising or social-media component. It does not track you across other websites, does not build a profile of you, and nothing collected there is sold, shared for advertising, or used to train any model.
4. Purposes of Processing and Legal Bases
4.1. Provision of the account and authentication. We process account and identification data and session data in order to create and administer your account, to authenticate your access, and to maintain your session. The legal basis is Article 6(1)(b) GDPR, the processing being necessary for the performance of the contract concluded with you upon acceptance of the Sereneo Terms of Service. Your date of birth is processed on the basis of Article 6(1)(c) GDPR, in order to comply with the age condition described in Section 16.
4.2. Storage and synchronisation of wellbeing data. We process the journal and wellbeing data described in Section 3.2 in order to store it, to synchronise it between your device and our servers, and to display it back to you. The legal basis is your explicit consent pursuant to Article 9(2)(a) GDPR in conjunction with Article 6(1)(a) GDPR, given during onboarding. In the absence of this consent the Service will not store or synchronise wellbeing data, and the relevant interfaces of the Service refuse such processing.
4.3. Artificial-intelligence analysis. We process the content you write in the Service — the text of journal entries, the notes you attach to mood check-ins and stress events, and the text of gratitude entries — together with the statistics and machine-generated summaries derived from your entries, for the sole purpose described in Section 7.1, exclusively on the basis of a separate explicit consent pursuant to Article 9(2)(a) GDPR in conjunction with Article 6(1)(a) GDPR. That single consent governs all of that processing and its scope is defined in Section 7.3. It is disabled by default, and its refusal or withdrawal has no effect on the availability of the remainder of the Service: without it, a Reflection is still produced from your statistics alone, with no artificial-intelligence processing and no transmission to any processor.
4.4. Transactional communications. We process your email address in order to dispatch messages that are necessary for the administration of your account, presently limited to email-address verification messages and password-reset messages. The legal basis is Article 6(1)(b) GDPR. We do not send marketing communications.
4.5. Security and abuse prevention. We process the security and technical data described in Section 3.5 for the purposes of securing the Service, detecting and preventing unauthorised access, enforcing rate limits, investigating misuse, and preserving the integrity of user data. The legal basis is Article 6(1)(f) GDPR, our legitimate interest being the protection of the Service and of the data entrusted to it. We have assessed this interest against your interests and fundamental rights and have concluded that it is not overridden by them, having regard to the facts that the processing is confined to security functions, that it involves minimal data, and that it at no point extends to the content you create.
4.6. Compliance and accountability. We process consent records and, where applicable, correspondence relating to data-subject requests in order to comply with our legal obligations under the GDPR, in particular Articles 5(2), 7(1) and 12 to 22. The legal basis is Article 6(1)(c) GDPR.
4.7. Business continuity. We process encrypted copies of the Service database for the purpose of disaster recovery, as described in Section 10.5. The legal basis is Article 6(1)(f) GDPR, our legitimate interest being the protection of your data against accidental loss or destruction.
4.8. Product analytics. We process the data described in Section 3.8 in order to understand which parts of the Service are used, so as to decide what to improve. The legal basis is your consent pursuant to Article 6(1)(a) GDPR, given on the device concerned. The data does not include content and accordingly does not constitute data concerning health; the fact that a person uses a mental-wellness application is nonetheless sensitive in character, which is why this processing is not carried out on the basis of a legitimate interest and does not begin until you have agreed to it. Refusal or withdrawal has no effect whatever on the Service.
4.9. Notifications. We process the data described in Section 3.9 in order to deliver the notifications you have asked for. The legal basis is your consent pursuant to Article 6(1)(a) GDPR, given by the settings described in that Section, each of which is off unless you turn it on. Where a notification concerns an insight derived from your health data, the further consent identified in Section 3.4(c) is required in addition, and the corresponding processing rests on Article 9(2)(a) GDPR. A reminder you create is stored so that it is available on your other devices; the reminder itself is delivered by your device rather than by us. Withdrawing any of these settings takes effect immediately, including for a notification already scheduled but not yet sent.
4.10. Operational diagnostics. We process the data described in Section 3.10 in order to detect that the application has failed, to determine why, to correct the defect, and to establish whether the Service is performing correctly at all. The legal basis is Article 6(1)(f) GDPR, our legitimate interest being the stability, security and integrity of the Service, which is also the subject of the obligation in Article 32 GDPR. This processing is deliberately not conditioned on your agreement, and the reason is stated openly: a failure report is the only evidence that the Service failed the person using it, and were it refusable the reports would be absent precisely where the application performs worst. The continuous part of the record — the logs, measurements and traces described in Section 3.10(b) to (d), most of which are produced when nothing has gone wrong — rests on a narrower point: we cannot tell that the Service is failing a person unless we can also see what it looks like when it is not, and a measurement that only ever exists after a crash cannot establish that.
We have assessed that interest against your interests and fundamental rights and have concluded that it is not overridden by them, having regard to the following, each of which is a limitation we have imposed rather than a description of what the technology does by default: the record contains none of your content; it is not associated with your account, so that we cannot attribute a failure, a measurement or a trace to you; it contains no network address; the addresses it does contain are stripped of every identifier before they leave your device; it is processed within the European Union; and it is retained for a short period (Section 11.11). The data does not concern your health and does not constitute a special category of personal data within the meaning of Article 9 GDPR; a call stack describes our code, not your state of mind, and a duration in milliseconds describes our servers. The transfer arrangements applicable to it are described in Section 9.5, and your right to object to this processing on grounds relating to your particular situation is described in Section 13.7.
4.11. Subscriptions. We process the data described in Section 3.11 in order to establish and maintain your entitlement to the paid features of the Service, to validate purchases, and to give effect to renewals, cancellations and refunds. The legal basis is Article 6(1)(b) GDPR, the processing being necessary for the performance of the contract, and Article 6(1)(c) GDPR in respect of records we are required to keep for accounting purposes.
4.12. Advertising measurement. We process the aggregate install reports described in Section 3.12 in order to establish whether advertising we have paid for is effective. The legal basis is Article 6(1)(f) GDPR, our legitimate interest being to spend a marketing budget on the basis of evidence. The reports contain no personal data and cannot be connected to you, which is what makes this interest available without any corresponding intrusion.
4.13. The website. We process the data described in Section 3.13 in order to deliver the website and protect it against abuse. The legal basis is Article 6(1)(f) GDPR, our legitimate interest being the operation and security of our own site. The same basis covers the page-view count described in the second paragraph of Section 3.13a: it stores nothing on your device, it produces no profile, and the interference with your interests is accordingly slight, while the alternative — publishing a site with no idea whether anyone reads it — is not workable.
4.13a. Website product analytics. We process the data described in the third paragraph of Section 3.13a in order to understand which pages are useful and where readers give up. The legal basis is your consent pursuant to Article 6(1)(a) GDPR, given on the website, together with your agreement under the national law implementing Article 5(3) of Directive 2002/58/EC to the storage described in Section 17.3. It is requested before anything is stored or transmitted, it is not bundled with anything else, and refusal has no effect whatever on the website, which works identically either way. It may be withdrawn at any time by the means described in Section 17.4.
4.14. We do not process personal data for any purpose incompatible with those stated in this Section 4. Should a new purpose arise, we will inform you in advance in accordance with Article 13(3) GDPR and, where the new purpose concerns data processed on the basis of consent, obtain a new consent.
5. Special Categories of Personal Data
5.1. The journal entries, mood check-ins, stress events, gratitude entries, journaling and mood preferences, Reflections and AI-generated emotional analyses processed through the Service constitute data concerning health within the meaning of Article 9(1) GDPR.
5.2. We process such data exclusively on the basis of your explicit consent pursuant to Article 9(2)(a) GDPR, obtained during onboarding by means of a dedicated, granular consent dialogue that is separate from your acceptance of the Terms of Service. Consent to health-data processing is a precondition for the use of the core functions of the Service, because the Service cannot store a journal without processing its contents; consent to artificial-intelligence processing is separate, optional and disabled by default.
5.3. You may withdraw any consent at any time with effect for the future, in the manner described in Section 13.8. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Upon withdrawal of the health-data consent, the processing concerned ceases, and you may thereafter delete your account and all associated data in the manner described in Section 12.
6. Storage Location
6.1. The Service’s production database and application servers are operated on infrastructure located within the European Union, in Finland, provided by our hosting processor Hetzner Online GmbH (see Section 8.4). Any future migration of the hosting will be to a data centre located within the European Union or the European Economic Area.
6.2. Encrypted database backups are stored on separate storage infrastructure provided by the same processor, located within the European Union, in Germany. The backups are encrypted before they leave our infrastructure, and the storage provider does not hold the key required to read them (Section 10.5).
6.3. The remaining processors identified in Section 8 process within the European Union, with the sole exceptions stated in Section 9.
7. Artificial-Intelligence Processing and Automated Decision-Making
7.1. The purpose, which is the limit. The Service offers artificial-intelligence functions whose sole purpose is to produce output about your own entries and to return it to you within the application. Such output includes, at the date of this version, an emotional analysis and short summary of an individual journal entry; a narrated Reflection on a completed week, month or year; and thematic summaries of what you have recorded, such as the subjects that recur in your gratitude entries. Individual functions of this kind may be added, changed or withdrawn as the Service develops, and this Policy does not undertake to enumerate each of them. What does not change, and what this Section fixes, is the purpose stated in this paragraph, the categories of data that may be transmitted under Section 7.3, and the guarantee that no such processing occurs at all without the consent described in Section 7.2. Your data is not processed by these functions for any purpose other than returning output to you: it is not used to produce statistics about our users, to develop or improve any model, to make any decision about you, or to be disclosed to anyone.
7.2. Consent. Every function of the kind described in Section 7.1 operates only where you have granted the specific “AI processing” consent, and none transmits anything in its absence. The consent is disabled by default, is requested separately from all other consents, and may be enabled or disabled at any time in the application’s settings; disabling it is no more onerous than enabling it. Where it is absent, a Reflection is still generated for you, composed of your own statistics and containing no artificial-intelligence output; nothing is transmitted to any processor in order to produce it. Certain of these functions additionally require a subscription that includes them; the absence of a subscription is a product limitation and not a further processing basis.
7.3. What may be transmitted. Where the consent is granted, the data concerned is decrypted transiently in the working memory of our server and transmitted over an encrypted connection to our processor OpenAI Ireland Limited (“OpenAI”) for the sole purpose of producing the output concerned. What may be transmitted is confined to the following two categories, and to nothing else:
(a) The content you have written in the Service — the text of journal entries, the notes you attach to mood check-ins and to stress events, and the text of gratitude entries.
(b) Material derived from your entries — a structured set of statistics for the period concerned (counts, averages, days of the week, streak lengths, the labels you selected on your check-ins, and comparable derived figures), and the summaries and labels previously generated for you under this Section.
For each function only the material that function requires is transmitted, and only in bounded extracts: what leaves our infrastructure is limited both in the length of an individual item and in the total amount per request, and your archive is at no point transmitted as a whole. Your name, email address and account identifier are never transmitted, and nothing transmitted is attributed to you at the processor. The resulting output is returned to our server and stored in encrypted form. Nothing transmitted under this Section is at any point written to logs or stored in unencrypted form on our systems.
7.3a. Where you may see the current position. Because this Section describes categories rather than an enumeration of functions, the application itself states, at the point at which you grant or review the consent, which functions are in operation at that time and what each of them sends. That description is generated from the operating configuration of the Service rather than written by hand, so that it cannot fall out of step with what the Service actually does.
7.4. Our engagement of OpenAI is governed by a written data processing agreement imposing the obligations required by Article 28(3) GDPR, concluded with OpenAI Ireland Limited, the OpenAI contracting party for customers established in the European Economic Area. Under our agreements with OpenAI, it processes what we transmit solely on our documented instructions and for the sole purpose of returning the output, and does not use it to train or improve any model. Onward transfer to OpenAI entities outside the European Economic Area is addressed in Section 9.1.
7.5. All content generated by the artificial-intelligence function is identified as such within the application.
7.6. Automated decision-making. The Service does not carry out any decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. The output of the artificial-intelligence function is reflective and informational in nature; it does not determine your access to or the terms of the Service, it is not disclosed to any third party, and it does not constitute a diagnosis, evaluation or assessment of you.
7.7. Human review. No natural person, including personnel of the Controller, reads your content or the output of the artificial-intelligence functions in the ordinary course of operating the Service. Access to stored user content may occur only where required by law, or where strictly necessary to protect the vital interests of a natural person or to investigate serious abuse of the Service; any such access would itself be recorded in the security audit log.
8. Recipients of Personal Data
8.1. We engage a limited number of processors within the meaning of Article 28 GDPR. Each engagement is governed by a data processing agreement imposing the obligations required by Article 28(3) GDPR, under which the processor acts only on our documented instructions. The processors currently engaged are the following:
8.2. OpenAI Ireland Limited, Ireland, which is the OpenAI contracting party for customers established in the European Economic Area and is accordingly the processor we engage. Purpose: generation of the artificial-intelligence output described in Section 7, exclusively where you have granted the corresponding consent. Data concerned: the two categories defined in Section 7.3 — the content you have written in the Service, and material derived from your entries. Place of processing: the request is performed on OpenAI infrastructure which includes the United States, where OpenAI OpCo, LLC acts as a sub-processor to OpenAI Ireland Limited; the safeguards applying to that onward transfer are described in Section 9.1. The current list of OpenAI sub-processors is published by OpenAI and we are notified of changes to it.
8.3. Maileroo Group Pty Ltd, a company established in Australia, with processing within the European Union. Purpose: dispatch of the transactional email messages described in Section 4.4. Data concerned: your email address and the contents of the messages concerned, which are drawn from a fixed set of templates and contain none of the data described in Sections 3.2 and 3.3. Place of processing: the European Union.
8.4. Hetzner Online GmbH, Germany, with the application servers and production database located in Finland and the backup storage located in Germany. Purpose: hosting of the production infrastructure of the Service and storage of encrypted backups. Data concerned: all categories of personal data processed by the Service, including the health data described in Section 5; the content of journal entries, the notes, the Reflections and the artificial-intelligence analyses remain encrypted at rest under keys that are not disclosed to this processor, and backups are encrypted before they reach it. Place of processing: European Union.
8.5. PostHog, Inc., United States, with processing in the European Union. Purpose: the product analytics described in Section 3.8, exclusively where you have agreed to them. Data concerned: the content-free usage events described in Section 3.8, associated with your account identifier where you are signed in; and two attributes recorded against that identifier, being the tier of your subscription and whether a free trial is running. Those two attributes contain no content, no price and no payment detail; they exist so that we can establish whether a feature is used differently by subscribers and by those on the free tier. Place of processing: European Union.
8.5a. Part of the analytics described in Section 3.8 is generated by our servers rather than by the application, being events your device is not in a position to observe: that a Reflection was opened, and the subscription lifecycle as the App Store reports it to us — a trial becoming paid, a renewal, a cancellation, and the ending of a subscription. Those events carry the identifier of your account, the identifier of the product concerned and, where a subscription ends, which of three fixed reasons applies; they contain no content, no price and no payment detail. They are transmitted only where you have agreed to product analytics. Your decision is reported to us by the application and recorded against your account for that sole purpose; where no decision has been reported, or where you have refused, nothing is transmitted. Because that record is held against your account rather than against a particular device, where you use the Service on more than one device it is the most recent decision reported by any of them that governs what our servers transmit; each device continues to govern what it transmits itself.
8.6. Apple Inc., in respect of the Apple Push Notification service, by which a notification is transmitted to your device. Data concerned: the device push token identifying the installation, and the text of the notification, which is drawn from the fixed list described in Section 3.9 and contains none of your content. Place of processing: Apple’s global infrastructure, including the United States. Apple does not receive your journal entries, mood values, scores or any other substance of your data, and receives no identifier of your account. A reminder that you set for yourself is scheduled by your own device and is not transmitted to Apple at all. Where you have not enabled notifications, no data is transmitted to Apple under this paragraph. This paragraph concerns Apple in the capacity described; Apple’s separate capacities are addressed in Section 8.10.
8.7. RevenueCat, Inc., United States. Purpose: validation of subscription purchases made through the App Store and management of the resulting entitlement, as described in Section 3.11. Data concerned: the pseudonymous identifier of your account and the subscription lifecycle reported by Apple — product identifier, purchase and expiry times, trial status, store and environment. No content, no wellbeing value, no email address, no name, no date of birth and no network address is transmitted, and no attribute describing you is set on your record with this processor. Place of processing: United States. Where you never purchase a subscription, no data is transmitted to this processor.
8.8. Functional Software, Inc. (trading as Sentry), United States, with processing in the European Union. Purpose: receipt and analysis of the operational diagnostics described in Section 3.10. Data concerned: the four categories enumerated in that Section — failure reports, operational log lines, measurements and traces — together with the installation identifier described there. This processor receives no content, no account identifier, no name, no email address and no network address, and is therefore not in a position to identify you.
8.9. Raintank Inc., trading as Grafana Labs, United States, with processing in the European Union (Sweden). Purpose: receipt, storage and analysis of the operational telemetry of our production servers — the server logs described in Section 3.5, together with performance measurements and traces — so that we can see that the Service is running correctly and be alerted when it is not. Data concerned: the server logs described in Section 3.5, which include the identifier of your account on requests you made while signed in, together with performance measurements and traces. IP addresses are removed from the address-bearing fields, and credentials and tokens are removed from web addresses, before the material leaves our infrastructure. No journal content, no note, no wellbeing value and no Reflection is transmitted to this processor, and nothing you write can appear in it. Because the material carries your account identifier, it is pseudonymous rather than anonymous, and it is erased on the schedule in Section 11.3 rather than on the deletion of your account. Place of processing: European Union.
8.10. The following third parties receive personal data as independent controllers, and not as our processors, where you choose to use their services: Apple Inc., where you authenticate through Sign in with Apple, where you obtain the application from the App Store, and where you purchase a subscription (Apple, and not we, takes and holds your payment details); and Google LLC, where you authenticate through Google Sign-In. The processing carried out by these parties is governed by their own privacy notices, and we exercise no control over it.
8.11. The public website described in Section 3.13 is hosted by Vercel Inc. Data concerned: the request data of visitors to sereneo.app, including the visiting IP address; and the page-view count described in the second paragraph of Section 3.13a, which that provider operates as part of the hosting service. No account data, journal content or wellbeing data is processed by this recipient.
8.12. PostHog, Inc., United States, with processing in the European Union. Purpose: the website product analytics described in the third paragraph of Section 3.13a, exclusively where you have agreed to them. Data concerned: the page-level usage events described there, associated with the random identifier described in Section 17.3. This engagement is separate from the one described in Section 8.5 and uses a separate instance: the data of website visitors is not combined with the data of application users, and no account identifier is transmitted from the website. Place of processing: European Union. The visiting IP address is discarded on receipt and is not stored by this recipient.
8.12. We use the email service of Google Ireland Limited (Google Workspace) for the mailboxes at which we receive correspondence, including requests made under Section 13. Anything you write to us in an email is therefore processed there. Where you would prefer that a request not pass through that service, you may send it by post to the address in Section 2.1.
8.13. Beyond the recipients identified in this Section 8, personal data is disclosed to no one, save where disclosure is required of us by law, by enforceable order of a court or competent authority, or where disclosure is strictly necessary to establish, exercise or defend legal claims. We do not sell personal data and we do not disclose personal data for advertising or marketing purposes.
8.14. Should we engage an additional or replacement processor whose processing concerns your personal data, we will amend this Policy in advance and, where the change materially affects the processing of your health data, present the amended Policy for renewed review and consent within the application.
9. International Transfers
9.1. OpenAI (Irish processor; processing on infrastructure that includes the United States). Where you have enabled the artificial-intelligence functions, the data defined in Section 7.3 is transmitted for the duration of the processing concerned to OpenAI Ireland Limited, which is established in the European Economic Area, so that the transfer we ourselves make is not a transfer to a third country. The request is nonetheless performed on infrastructure that includes the United States. Under our data processing agreement, OpenAI Ireland Limited may make that onward transfer to other OpenAI entities only on the basis of agreements ensuring appropriate safeguards within the meaning of Chapter V GDPR, or of an adequacy decision of the European Commission under Article 45 GDPR. Where you have not enabled those functions, nothing is transmitted and no transfer occurs under this paragraph.
9.2. RevenueCat (United States). Where you purchase a subscription, the data enumerated in Section 8.7 is transferred to the United States. The transfer is safeguarded by the Standard Contractual Clauses incorporated into that processor’s data processing agreement. Where you never purchase a subscription, no transfer occurs under this paragraph.
9.3. Apple (United States and global infrastructure). Where you enable notifications, the device push token and the fixed notification text are transferred to Apple’s infrastructure, which includes the United States. Apple’s engagement is governed by the data protection terms of the Apple Developer Program, which incorporate the Standard Contractual Clauses.
9.4. PostHog (United States entity; processing within the European Union). Where you have agreed to product analytics, the events described in Section 3.8 — and, where you have agreed to them on the website, the events described in the third paragraph of Section 3.13a — are processed in PostHog’s European Union region. As PostHog, Inc. is established in the United States, the engagement is safeguarded by the Standard Contractual Clauses incorporated into that processor’s data processing agreement.
9.5. Sentry (United States entity; processing within the European Union). The operational diagnostics described in Section 3.10 are processed in the European Union region operated by that processor. As Functional Software, Inc. is established in the United States, the engagement is safeguarded by the Standard Contractual Clauses incorporated into that processor’s data processing addendum. As a supplementary measure, the material carries no account identifier, no content and no network address, so that what is capable of being compelled from the processor cannot be attributed to an identified user by the processor or by any authority addressing it.
9.6. Grafana Labs (United States entity; processing within the European Union). The operational telemetry described in Section 8.9 is processed in that provider’s European Union region. As Raintank Inc. is established in the United States, the engagement is safeguarded by the Standard Contractual Clauses (Module Two, controller to processor) incorporated into that provider’s data processing agreement.
9.7. Maileroo (Australian entity; processing within the European Union). The transactional email messages described in Section 4.4 are processed within the European Union. As Maileroo Group Pty Ltd is established in Australia, which is not the subject of an adequacy decision of the European Commission, the engagement is safeguarded by the Standard Contractual Clauses (Module Two, controller to processor) incorporated into that processor’s data processing addendum. The data concerned is confined to your email address and the text of the messages themselves, which is generated from a fixed set of templates and contains none of the data described in Sections 3.2 and 3.3.
9.8. Vercel (United States entity). The website described in Section 3.13 is delivered from an infrastructure that includes servers outside the European Economic Area. The engagement is safeguarded by the Standard Contractual Clauses incorporated into that provider’s data processing addendum. No account data or content is concerned.
9.9. Where a recipient holds a current certification under the EU–U.S. Data Privacy Framework, that certification constitutes an additional lawful basis for the transfer pursuant to the adequacy decision of the European Commission of 10 July 2023. You may obtain a copy of the safeguards referred to in this Section 9, or information on where they have been made available, by writing to privacy@sereneo.app.
10. Security of Processing
10.1. In accordance with Article 32 GDPR, and having regard to the special category of the data processed, we apply technical and organisational measures which include those described in this Section 10. This Section describes those measures at the level of detail appropriate to a public document; it is not a description of our security architecture.
10.2. Encryption of content at the application layer. The text of journal entries, the notes attached to mood check-ins and stress events, each of the free-text answers comprising a gratitude entry, the statement of intention recorded in your journaling preferences, the labels of the reminders you create, your Reflections and the AI-generated analyses are encrypted with strong, industry-standard authenticated encryption under a key unique to each user, before being written to the database. Each user’s key is itself held only in encrypted form, and the material required to decrypt it is kept apart from the database. The database at no point contains such content in intelligible form. Upon deletion of an account the user’s key is destroyed together with the account record, whereupon all content encrypted under it ceases to be intelligible in the live database (cryptographic erasure). Backup archives created before the deletion are addressed separately in Sections 11.7 and 12.2.
10.3. Limits of the encryption model. The Service is not end-to-end encrypted, and we state that plainly rather than leave it to be inferred: our servers must be capable of processing your content in order to provide the functions of the Service, including the artificial-intelligence function where you enable it. Structured wellbeing metadata — numeric mood and stress values, tags and timestamps — is stored in structured rather than content-encrypted form in order to permit the operation of the Service, and is protected by the access controls, transport encryption and organisational measures described in this Section.
10.4. Transport security, credentials and sessions. All communication between the application and our servers is encrypted in transit, and email is dispatched over encrypted connections. Your password is stored only as a one-way cryptographic hash and never in a form from which it could be recovered. Session credentials are stored only as cryptographic hashes, are short-lived, are replaced on use, and can be revoked; a change of password invalidates existing sessions. Authentication is protected by automated measures against guessing and abuse. On your device, the application’s local database is protected by iOS Data Protection, and session credentials are held in the iOS Keychain, bound to the device and excluded from iCloud synchronisation.
10.5. Backups and operations. Database backups are encrypted before leaving our infrastructure, and the key required to read them is not held by, or accessible to, the storage provider. Access to production systems is limited to the Controller, is individually authenticated, and the application components run with the minimum privileges they require. Security-relevant events are recorded in the audit log described in Section 3.5, which never contains content. Credentials are redacted from logs, and software dependencies are subject to routine vulnerability scanning.
10.6. Personal-data breaches. In the event of a personal-data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the Norwegian Data Protection Authority (Datatilsynet) without undue delay and, where feasible, within seventy-two hours of becoming aware of it, in accordance with Article 33 GDPR; where the breach is likely to result in a high risk, we will additionally communicate the breach to the affected users without undue delay, in accordance with Article 34 GDPR.
10.7. Reporting a vulnerability. If you believe you have found a security weakness in the Service, we would rather hear about it than not: write to security@sereneo.app. We will not pursue a good-faith reporter who acts proportionately and does not access, alter or retain another person’s data.
11. Retention of Personal Data
11.1. Account and identification data, journal and wellbeing data, Reflections, AI-generated analyses, preferences and consent records are retained until the deletion of your account, which takes immediate effect in the manner described in Section 12.
11.2. Entries in the security audit log are retained for twelve months from their creation, after which they are deleted. Upon deletion of an account, the account reference is severed from all audit entries relating to it and replaced with a random value bearing no relation to your identity, so that those entries can no longer be attributed to you, while remaining recognisable as belonging to one and the same (now deleted) account.
11.3. Server logs, including the IP addresses they contain, are retained for thirty days. They are held on our behalf by the processor identified in Section 8.9, with the IP addresses removed from the address-bearing fields before they reach it.
11.4. The originating IP address and browser or application identifier recorded against an entry in the security audit log are retained for one hundred and eighty days from the creation of that entry, after which they are erased while the remainder of the entry is retained for the period stated in Section 11.2. This period applies equally whether or not the account concerned still exists: deletion of an account does not shorten it, and does not extend it. The security audit log is kept separately from the server logs referred to in Section 11.3 because it serves a different purpose — the detection and investigation of unauthorised access, credential attacks and misuse — which is a legitimate interest of the Controller and of the users whose accounts are thereby protected, and which is also the subject of the security obligation in Article 32 GDPR. A period materially shorter than this would prevent the investigation of an intrusion that is only discovered some months after it occurs; a materially longer one would not add proportionate value. Your right to object to this processing on grounds relating to your particular situation is described in Section 13.7.
11.5. Synchronisation deletion markers are retained for ninety days from the deletion to which they relate.
11.6. Session credentials are deleted upon expiry, which occurs no later than thirty days after issue, or upon sign-out, whichever is earlier. Email-verification and password-reset links are valid for a single use and for a short period, and are deleted upon use or expiry.
11.7. Backup archives are retained on a rolling basis of thirty days. Content deleted from the live database therefore ceases to exist in any backup no later than thirty days after deletion. A backup archive created before a deletion continues, until it is itself deleted, to contain the data as it stood when the archive was made, including the encrypted content and the encrypted key which opens it. Every such archive is encrypted before it leaves our infrastructure (Section 10.5), and archives are restored only for the purpose of disaster recovery and integrity testing.
11.8. An archive prepared by the export function described in Section 13.9 is retained for seventy-two hours from the time it is prepared, after which it is deleted. While it exists it is stored in encrypted form under the same key as your journal content, so that the deletion of your account renders it unreadable at the same moment and by the same means as the content it contains (Section 12). A record that an export was requested, containing no data of yours, is retained for a further thirty days.
11.9. Product-analytics events (Section 3.8) are retained on our behalf by the processor identified in Section 8.5 for as long as your agreement to product analytics stands. Withdrawing that agreement stops all further collection immediately. Upon deletion of your account, the profile held against your account by that processor, and the events recorded under it, are deleted automatically.
11.10. A device push token is retained until you sign out on the device concerned, until you delete your account, or until Apple informs us that the installation no longer exists, whichever occurs first; in the last case the token is deleted automatically. Your notification settings and the reminders you have created are retained until the deletion of your account, in the same manner as the other preferences addressed in Section 11.1. The record of notification attempts described in Section 3.9 is retained for ninety days from the attempt, after which it is deleted; the limit it exists to demonstrate is computed from the current day only, so the remaining period serves your right of access rather than any purpose of ours.
11.11. Operational diagnostics (Section 3.10) are retained on our behalf by the processor identified in Section 8.8 for a period not exceeding ninety days from the event to which they relate, after which they are deleted. Because none of it bears any reference to your account, the deletion of your account neither shortens nor lengthens the period, and there is no record we could identify as yours in order to erase it earlier; that is a consequence of collecting the data unlinked, and we state it rather than leave the right in Section 13.4 looking wider than it is.
11.12. Subscription data (Section 3.11) is retained until the deletion of your account, upon which your record with the processor identified in Section 8.7 is deleted as well. Records required for accounting purposes are retained for the period prescribed by Norwegian bookkeeping legislation, presently five years, and are limited to what that legislation requires.
11.13. The advertising-measurement reports described in Section 3.12 are retained for one hundred and eighty days from receipt. They contain no personal data.
11.13a. The website page-view count described in the second paragraph of Section 3.13a is retained by the provider identified in Section 8.11 in aggregate form only, and contains no identifier capable of being connected to you. The website product-analytics events described in the third paragraph of Section 3.13a are retained by the processor identified in Section 8.12 for the retention period configured for that instance, presently eighty-four months. We record that figure because it is the one that presently applies and not because we consider it necessary; it is the default of the plan concerned rather than a period we have chosen, we are reducing it, and we will state the shorter period here once it is in force rather than state it in advance. Withdrawing your agreement stops all further collection immediately and removes the identifier from your device, as described in Section 17.4; because that identifier is the only connection between those events and the device that generated them, removing it leaves no means by which the earlier events could be identified as yours, and we state that plainly rather than offer an erasure we could not perform.
11.14. Personal data is not retained beyond the periods stated in this Section unless, and only for so long as, retention is required by a legal obligation to which the Controller is subject or is necessary for the establishment, exercise or defence of legal claims.
12. Account Deletion
12.1. You may delete your account at any time from within the application (Profile → Delete Account), without any requirement to contact us. Deletion requires re-authentication, as a safeguard against deletion by an unauthorised person.
12.2. Deletion takes immediate, permanent and irreversible effect in the live database. Upon deletion: your account record and all journal entries, mood check-ins, stress events, gratitude entries, Reflections, AI-generated analyses, preferences, consent records, notification settings, reminders, subscription records and session credentials are erased from the live database; your encryption key is destroyed with your account record, so that no content encrypted under it remains intelligible there; all active sessions are terminated; and the copies held by the processors identified in Sections 8.5 and 8.7 are deleted. There is no deactivation period and no possibility of restoration. Backup archives created before the deletion are not modified; they are deleted in the ordinary course within thirty days, as stated in Section 11.7, after which no copy of your data remains.
12.3. Following deletion, the only records retained are: security-audit records from which the reference to your account has been severed as described in Section 11.2; accounting records to the extent required by law (Section 11.12); and encrypted backup archives created before the deletion, which are themselves deleted within thirty days in accordance with Section 11.7. Where such an audit record still carries an originating IP address within the period stated in Section 11.4, we do not describe it as anonymous: severed from your account it can no longer be attributed to you by us, but we recognise that an address combined with a timestamp remains capable in principle of contributing to identification, and we therefore treat those records as pseudonymised and continue to protect them accordingly until the address is erased. Retaining them for that period is necessary for the security purpose described in Section 11.4, which is not set aside by the deletion of an account; the alternative — erasing the record of an attack at the request of whoever conducted it — would defeat the purpose for which the log exists.
12.4. Deleting your account does not cancel a subscription. The payment relationship is with Apple, not with us, and neither deleting your account nor deleting the application ends it. A subscription is cancelled in your Apple ID subscription settings, and the application tells you so before it deletes an account that has one.
13. Rights of the Data Subject
13.1. You have, under Articles 15 to 21 GDPR and subject to the conditions stated therein, the rights described in this Section. All rights may be exercised free of charge by writing to privacy@sereneo.app or, where an in-application control exists, by using that control. We will respond without undue delay and in any event within one month of receipt of the request, as required by Article 12(3) GDPR; where the complexity or number of requests so requires, this period may be extended by two further months, of which you would be informed within the first month. We may request information necessary to confirm your identity before acting on a request.
13.2. Right of access (Article 15). You have the right to obtain confirmation as to whether personal data concerning you is processed, access to that data, and the information enumerated in Article 15(1) GDPR, together with a copy of the data undergoing processing.
13.3. Right to rectification (Article 16). You have the right to obtain the rectification of inaccurate personal data and the completion of incomplete personal data. Account details and content you have created may be corrected directly within the application.
13.4. Right to erasure (Article 17). You have the right to obtain the erasure of personal data concerning you on the grounds stated in Article 17(1) GDPR. The most complete means of exercising this right is the account-deletion function described in Section 12; individual items of content may also be deleted within the application, whereupon they are removed from our systems subject to the synchronisation and backup periods stated in Section 11. This right is not absolute. By virtue of Article 17(3) GDPR it does not extend to the security-audit records described in Sections 11.2 and 11.4, which are retained, with the reference to your account severed, for the limited periods and for the security purpose stated there; nor to records we are required to retain in order to comply with a legal obligation, including the accounting records described in Section 11.12, or to establish, exercise or defend legal claims. Two categories are outside the right for a different reason — because they contain nothing capable of being identified as yours: the operational diagnostics described in Section 3.10 and the advertising-measurement reports described in Section 3.12.
13.5. Right to restriction (Article 18). You have the right to obtain the restriction of processing in the circumstances stated in Article 18(1) GDPR, in which case the data concerned will, with the exception of storage, be processed only with your consent or on the other grounds stated in Article 18(2) GDPR.
13.6. Right to data portability (Article 20). You have the right to receive the personal data you have provided to us, where processed on the basis of consent or contract and by automated means, in a structured, commonly used and machine-readable format, and to transmit it to another controller. This right is fulfilled by the in-application export function described in Section 13.9, and, at your election, on request by email.
13.7. Right to object (Article 21). You have the right to object, on grounds relating to your particular situation, to processing carried out on the basis of Article 6(1)(f) GDPR, namely the security processing described in Section 4.5, the business-continuity processing described in Section 4.7, the operational diagnostics described in Section 4.10, the advertising measurement described in Section 4.12, and the website processing described in Section 4.13. In the event of such an objection we will cease the processing concerned unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
13.8. Right to withdraw consent (Article 7(3)). You have the right to withdraw any consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal. The consent to artificial-intelligence processing, the agreement to product analytics, and each of the notification settings may be withdrawn directly by means of the corresponding control in the application’s settings. The consent to health-data processing may be withdrawn by writing to privacy@sereneo.app or by deleting your account; because that consent is the legal basis of the Service’s core function, its withdrawal entails that the Service can no longer store or synchronise wellbeing data.
13.9. Export function. The application provides an export function under “Privacy & Security” by which you may obtain a complete copy of your data. The export is prepared in the background and made available for download as a compressed archive containing (a) a machine-readable JSON file suitable for transmission to another controller within the meaning of Article 20(1) GDPR, (b) a human-readable document that may be read in any web browser and saved as a PDF, and (c) an explanatory note. The export is provided free of charge and is not conditional upon a paid subscription; it may be requested once in any twenty-four-hour period. The download link is valid for a limited period, and the prepared archive is deleted from our systems seventy-two hours after it is prepared. It remains available to you after you have withdrawn consent, because that is precisely when a person is most likely to need it.
13.10. Contents of the export. The export contains the personal data described in Section 3, namely your account details, your journal entries (decrypted for this purpose), your mood check-ins, stress events and gratitude entries, your Reflections, your preferences, your consent and acknowledgement history, your subscription record, your registered devices, your notification settings and reminders, and the record of the notifications we sent you. The archive itself states, in the files it contains, which categories of data are not included and why. The security-audit records described in Sections 11.2 and 11.4 are not included in the in-application export; a copy of those records relating to you may be obtained on request under Section 13.2. Authentication credentials and cryptographic key material are not included, as their disclosure would compromise the security of your account.
13.11. Alternative route. Should the export function be unavailable to you for any reason, a complete copy of your data in a machine-readable format will be provided free of charge upon request to privacy@sereneo.app, within the period stated in Section 13.1.
14. Right to Lodge a Complaint
14.1. Without prejudice to any other administrative or judicial remedy, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.
14.2. The supervisory authority competent for the Controller is Datatilsynet (the Norwegian Data Protection Authority), P.O. Box 458 Sentrum, 0105 Oslo, Norway, www.datatilsynet.no. We would nevertheless welcome the opportunity to address any concern before a complaint is lodged, at privacy@sereneo.app.
15. Disclosures for California Residents
15.1. This Section applies to users who are residents of the State of California and supplements the remainder of this Policy. Terms used in this Section have the meanings given to them in the CCPA.
15.2. The categories of personal information collected by the Service are those described in Section 3, namely identifiers (email address, display name, provider subject identifiers); sensitive personal information (the wellbeing data described in Sections 3.2 and 3.3, which constitutes personal information concerning health, and a date of birth); commercial information limited to the subscription record described in Section 3.11; internet or network activity information limited to the security and technical data described in Section 3.5 and the product-analytics data described in Section 3.8; and the operational diagnostics described in Section 3.10, which are not associated with an identified consumer or household and which we accordingly treat as deidentified within the meaning of the CCPA, without asserting that characterisation to avoid any obligation owed to you. The sources, purposes and recipients of this information are those stated in Sections 3, 4 and 8.
15.3. We do not sell personal information, we do not share personal information for cross-context behavioural advertising, and we have not done either in the preceding twelve months. We do not use or disclose sensitive personal information for any purpose other than the provision of the Service you request and the purposes permitted by section 7027(m) of the CCPA regulations. Accordingly, no opt-out right arises, and the Service does not process opt-out preference signals because there is no sale or sharing to which such signals could apply.
15.4. You have the right to know, to access, to correct, and to delete personal information, and the right not to receive discriminatory treatment for exercising any right. These rights may be exercised in the manner described in Section 13, including through an authorised agent, subject to verification of your identity and, in the case of an agent, of the agent’s authority. The retention periods applicable to each category of personal information are those stated in Section 11.
16. Children
16.1. The Service is not directed to, and may not be used by, persons under sixteen years of age. We do not knowingly collect personal data from persons under sixteen. During account setup you are asked for your date of birth; where the date given is below sixteen years of age, the account and all data associated with it are erased immediately and automatically, and the Service is not made available. Where we otherwise obtain knowledge that personal data of a person under sixteen has been collected, we will delete the account concerned and all associated data. Reports may be made to privacy@sereneo.app.
17. Cookies and Tracking Technologies
17.1. The application is a native iOS application. It sets no cookies, our interface authenticates by token rather than by cookie, and no cross-site or cross-application tracking of any kind takes place. The product analytics described in Section 3.8 measure the use of this application alone: they employ no advertising identifier, they are not combined with data from any other application or website, and they are not used for advertising or profiling. The website is addressed separately in Sections 17.3 and 17.4.
17.2. Information stored on your device. Two components store an identifier and a short queue of pending data in the application’s own storage area on your device: the product-analytics component described in Section 3.8 and the diagnostics component described in Section 3.10. Neither is readable by any other application, neither survives the deletion of the application, and neither is an advertising identifier. The advertising measurement described in Section 3.12 stores one further item in that area: the highest of the five points described there which this installation has reached, held as a single number so that a point already reported is not reported a second time and so that a later report cannot contradict an earlier one. It identifies nothing and no one, it is readable by no other application, and it does not survive the deletion of the application. Norwegian law (the Electronic Communications Act, implementing Article 5(3) of Directive 2002/58/EC) requires your agreement before information is stored on or read from your terminal equipment, save where the storage is strictly necessary to deliver a service you have requested. The analytics component is not started until you agree to it and is therefore not reached by that question at all. For the diagnostics component we rely on the exemption, on the basis that a service which cannot detect its own failures is not being delivered safely; we record here, rather than assert without qualification, that the exemption is drawn more narrowly than the legitimate interest relied on in Section 4.10, and that we keep the extent of that collection under review against it. For the number described in the preceding paragraph we record that we have not treated its storage as requiring your separate agreement, on the basis that it identifies nothing and holds no more than the fact that a measurement has already been made, and that we keep that characterisation under review.
17.3. Cookies and storage on the website. The website stores nothing on your device until you have answered the question it puts to you, save for one item which records the answer itself, so that you are not asked again on every page; that item identifies nothing and no one, and is stored whichever way you answer.
Where you agree, the component identified in Section 8.12 stores a first-party cookie and a corresponding entry in your browser’s local storage, both bearing a randomly generated identifier whose purpose is to recognise a returning visit. They are readable only by sereneo.app, are not advertising identifiers, and are not readable by, nor shared with, any other website. Norwegian law (the Electronic Communications Act, implementing Article 5(3) of Directive 2002/58/EC) requires your agreement before such information is stored on or read from your terminal equipment, and it is on that basis, together with Article 6(1)(a) GDPR, that it is stored. Where you refuse, or have not answered, the component is not loaded and neither item is created.
The page-view count described in the second paragraph of Section 3.13a stores nothing on your device and is accordingly not reached by that requirement at all.
17.4. Changing your mind on the website. Every page of the website carries a control, in its footer, which reopens the question. Withdrawing is one action, is no more onerous than agreeing was, and takes effect at once: collection stops, and the cookie and local-storage entry described in Section 17.3 are deleted from your device, returning it to the state it was in before you agreed. Refusing has no effect on your access to any part of the website.
18. Amendments to this Policy
18.1. This Policy may be amended as the Service develops. Every version bears a version number and an effective date. A summary of what changed between versions is published at the end of this Policy, and the superseded texts themselves are available on request.
18.2. In the case of a material amendment — in particular any amendment concerning the processing of health data, the purposes of processing, or the recipients of personal data — the application will present the amended Policy and, where the processing concerned rests on consent, will request renewed consent before the amendment applies to you. Amendments that are not material take effect upon publication at the address stated in Section 19.2.
19. Final Provisions
19.1. This Policy is issued in English. Where translations are provided in the future, the English version prevails to the extent permitted by mandatory law.
19.2. The current version of this Policy is published at https://sereneo.app/privacy and is accessible from within the application.
19.3. Questions concerning this Policy may be directed to Planviah Helgesen, Kringsjåveien 19, 5162 Laksevåg, Norway; privacy@sereneo.app (privacy matters); support@sereneo.app (general matters); security@sereneo.app (vulnerability reports).
Sereneo Privacy Policy, Version 1.3, effective 23 August 2026.
Version history
Version 1.4 (29 August 2026) — The website now measures how it is used, and this amendment records it. Two means are described in the new Section 3.13a. The first is a page-view count operated by the hosting provider already identified in Section 8.11; it writes nothing at all to your device and is carried out under Article 6(1)(f), as recorded in Section 4.13. The second is a product-analytics component operated by the processor newly identified in Section 8.12, which runs only where you have agreed to it on the website and which stores a random, non-advertising identifier on your device; its basis is your consent under Article 6(1)(a) together with Article 5(3) of Directive 2002/58/EC, as recorded in the new Sections 4.13a, 17.3 and 17.4. Section 3.13 previously stated that the website set no cookies and carried no analytics, tracking or advertising script of any kind, and Section 17.1 said the same; both have been conformed, and the former sentence is reproduced here so that the change is visible rather than merely superseded. Retention for the new events is stated in Section 11.13a, together with the fact that the period presently applying is the processor plan’s default rather than one we have chosen. The processor in Section 8.12 is the same undertaking as the one in Section 8.5 but a separate instance: website data is not combined with application data, and no account identifier reaches it. No new category of data concerning the application is collected, nothing about the application changes, and the consent version governing the application does not move. What the website does not do is stated in the new Section 3.13b: no advertising, no advertising identifier, no cross-site tracking, no profiling, no sale, and no use for training any model.
Version 1.3 (23 August 2026) — The Service no longer offers to record a telephone number, and no longer holds one. The sentence in Section 3.1 that described that option has been removed, and Section 15.2 has been conformed. The two fields were optional, were never used for any purpose, and the data stored in them has been deleted along with the fields themselves. This amendment narrows what is collected: no category of data is added, no purpose is broadened, and no recipient is added. The consent version does not move, and no consent is requested afresh — Article 7 concerns what you have agreed to, and nothing here asks anything further of you.
Version 1.2 (19 August 2026) — Section 8.5 was restated and Section 8.5a added. Part of the product analytics described in Section 3.8 is now generated by our servers rather than by the application: the opening of a Reflection, and the subscription lifecycle as the App Store reports it, being events a device is not in a position to observe. Two attributes were also added to the record held with that processor — the tier of the subscription and whether a trial is running. No new category of data is concerned: no content, no price and no payment detail is transmitted, and the identifier used is the one already disclosed in Section 3.8. Section 3.8 was conformed to record that the agreement, which continues to be made and withdrawn on the device, is reported to us so that it can govern what our servers transmit. The consent version does not move: the categories of data in Sections 3 and 7 are unchanged.
Version 1.1 (17 August 2026) — Section 7 was restated. Version 1.0 opened “The Service offers two artificial-intelligence functions, and this Section describes both of them exhaustively”, listed those two functions, and set out per function what each transmitted. That drafting bound the Policy to the product’s feature list: every further function of the same kind required an amendment, whether or not it processed anything new. Section 7 now fixes the purpose and the categories of data instead, and the categories are stated at their full extent — the content you write in the Service, and material derived from your entries. The extent of what may be transmitted was thereby widened: Version 1.0’s enumeration did not reach the text of gratitude entries or of notes attached to stress events, and this version does. Nothing was removed, no purpose was broadened beyond returning output to you, and Section 7.3a adds an undertaking that Version 1.0 did not contain: that the application states, at the point of consent, which functions are in operation and what each sends. Because the categories widened, the consent version moves with this Policy and the consent is requested afresh (Section 18.2). Sections 1.2, 3.3, 4.3, 7.7, 8.2 and 9.1 were conformed.
Version 1.0 (16 August 2026) — first issue under this numbering.