Privacy Policy
Last updated: 27 June 2026 · Effective: 27 June 2026
1. Who We Are
Selah is a trading name of OpenMind Limited ("we", "us", "our"), a company registered in England and Wales (Company Number: 17306059). We operate the Selah breathwork and pranayama application and website. For the purposes of UK GDPR and the Data Protection Act 2018, OpenMind Limited is the data controller for the personal data described in this policy.
Contact: hello@selahapp.co.uk
Website: selahapp.co.uk
If you have any questions, concerns, or requests regarding your personal data, please contact us at the email address above. We aim to respond to all privacy-related enquiries within 30 days.
2. The Personal Data We Collect
We collect personal data in the following categories:
2.1 Account and Identity Data
- Email address — required to create an account, used for authentication (magic link, one-time passwords) and account-related communications.
- Display name — optional, used to personalise your experience within the app and portal.
- Password — if you choose to set a password, it is hashed and salted using industry-standard cryptography (managed by Supabase Auth). We never store plaintext passwords.
- Account role and organisation membership — whether you are an individual user, organisation member, or organisation admin, and which organisation you belong to if applicable.
2.2 Payment and Billing Data
- Payment card details — We do not store your card number, expiry date, or CVV. All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We only store a Stripe Customer ID (a reference token) to link your account to your payment records.
- Billing history — Subscription status, plan type (free, trial, monthly, annual, lifetime), subscription start and end dates, and payment history are stored so we can correctly unlock app features and manage your account.
- Refund and dispute records — If you request a refund or raise a dispute, we retain records of the request and outcome for legal and accounting purposes.
2.3 App Usage and Wellness Data
- Breathing session data — Techniques practiced, session duration, timestamps, session completion status, and streak records. This data powers your progress dashboard and personal analytics.
- 30-day course progress — Which days and modules you have completed, scores, and engagement patterns.
- Wellness survey responses — If you or your organisation enables wellness check-ins (mood, stress, energy), we store your individual responses linked to your account. You can decline to answer any survey question.
- Psychology profile — Completed voluntarily during onboarding where available. This profile helps personalise technique recommendations and, where applicable, is visible to your organisation admin only with your explicit consent.
- Breathwork analytics — Aggregated metrics derived from your sessions (e.g., average session length, most-used techniques, weekly engagement). This data is never shared in identifiable form with third parties.
2.4 Guru Ji AI Conversation Data
If you use Guru Ji, our AI breathwork advisor, your conversation messages are sent to Anthropic's API for processing to generate responses. Conversation history may be stored in our database to provide continuity across sessions. Your conversations are not used to train AI models. See Section 6 for Anthropic's data handling.
2.5 Device and Technical Data
- Device information — Device type, operating system version, app version, screen resolution, and device language.
- Network information — IP address (used to detect approximate country for legal compliance purposes and to prevent abuse; not stored long-term).
- Push notification tokens — If you enable push notifications, we store a device token provided by Apple or Google to deliver notifications to your device.
- Error and crash logs — Technical error reports to help us diagnose and fix bugs. These may include device state information but are not linked to your personal identity unless you provide it in a support request.
2.6 Communications Data
- Transactional email logs — Records of emails sent to you (authentication codes, subscription confirmations, account notices). We do not store the full content of emails after delivery.
- Support correspondence — If you contact us by email, we retain the correspondence to handle your request and for a period thereafter in case of follow-up.
- Newsletter subscription — If you opt in to marketing communications, we store your email address and preference status. You may unsubscribe at any time.
2.7 Website Cookies and Analytics Data
See Section 12 (Cookies) for full details. In summary, we use essential authentication cookies and, where you consent, limited analytics cookies.
2.8 Organisation-Specific Data
If you use Selah as part of an organisation (employer, institution, or group), your organisation administrator may have configured additional data collection, including wellness surveys, department groupings, and aggregated team analytics. The organisation is a co-controller of data collected via their Selah account. You should also read your organisation's privacy notice.
3. How We Collect Your Data
3.1 Data You Provide Directly
When you register, subscribe, complete in-app surveys, set up a psychology profile, contact support, or interact with Guru Ji, you provide data directly to us.
3.2 Data We Collect Automatically
When you use the App or Website, we automatically collect device information, usage patterns, session data, and technical logs as described in Section 2.
3.3 Data from Third Parties
- Stripe — confirms whether a payment succeeded or failed and provides webhook events about subscription status.
- Apple / Google — confirms app installation and, where applicable, in-app purchase status.
4. Legal Basis for Processing (UK GDPR)
We process your personal data on the following legal bases:
| Processing Activity | Legal Basis | Details |
|---|---|---|
| Creating and managing your account | Contract | Necessary to provide the Service you signed up for. |
| Processing payments and managing subscriptions | Contract | Necessary to fulfil your subscription agreement. |
| Delivering breathwork sessions and course content | Contract | Core service delivery. |
| Sending authentication codes and account notices | Contract / Legitimate Interests | Essential for account security and service continuity. |
| Personalising your experience (Guru Ji AI, recommendations) | Legitimate Interests | Improving service quality for existing users without overriding your rights. |
| Analytics and service improvement | Legitimate Interests | Understanding how the service is used to make it better. |
| Security monitoring and fraud prevention | Legitimate Interests | Protecting users and the integrity of the platform. |
| Sending marketing newsletters | Consent | Only where you have explicitly opted in. You can withdraw consent at any time. |
| Sharing wellness data with your organisation | Consent | Only where you have explicitly consented via the app. |
| Complying with legal obligations | Legal Obligation | Tax, accounting, and regulatory requirements. |
| Responding to law enforcement requests | Legal Obligation | Where required by applicable law. |
5. How We Use Your Personal Data
- To create and manage your account and authenticate you securely.
- To deliver breathwork sessions, the 30-day course, Guru Ji AI conversations, and all other features of the Service.
- To process payments, manage subscriptions, issue receipts, and handle refund requests.
- To personalise content, technique recommendations, and AI responses based on your usage history and profile.
- To provide analytics and progress tracking visible to you on your personal dashboard.
- To enable organisation features, including aggregated team wellness reporting, employee admin access, and group code management, where applicable.
- To send you essential communications: authentication codes, subscription confirmations, renewal reminders, and account security notices.
- To send you marketing or editorial content (newsletters, app updates, new features) where you have given your consent.
- To respond to your support requests and improve our customer service.
- To detect and prevent fraud, abuse, and security threats.
- To debug technical errors and improve app performance and reliability.
- To comply with our legal and regulatory obligations under UK law.
- To enforce our Terms of Service and other agreements.
6. Data Sharing and Disclosure
We never sell your personal data to third parties. We do not share your data with advertisers or data brokers. We share data only as described below:
6.1 Service Providers (Data Processors)
We use the following trusted third-party processors who act under our instruction and are bound by data processing agreements:
Your account, session, subscription, and wellness data are stored in Supabase. Data is hosted in the EU (West EU data centre by default). Supabase processes data under a Data Processing Agreement aligned with UK GDPR.
Privacy policy →All card payments are processed by Stripe. Stripe is PCI DSS Level 1 certified. Stripe receives your name, email, and billing address to process payments. We only receive a customer reference token and subscription status from Stripe. Stripe may transfer data internationally in accordance with standard contractual clauses.
Privacy policy →Your Guru Ji conversation messages are sent to Anthropic's Claude API to generate responses. Anthropic's API data is not used for model training by default. Messages are transmitted securely. Anthropic is based in the United States; transfers are protected by standard contractual clauses.
Privacy policy →We use Resend to send authentication codes, subscription notices, and account emails. Resend receives your email address and the content of each email for delivery purposes only. Email content is not retained by Resend beyond delivery.
Privacy policy →The Selah website is hosted on Vercel's infrastructure. Vercel may process server request logs including IP addresses. Data is hosted in EU and US regions.
Privacy policy →The Selah iOS app is distributed via the Apple App Store. Apple collects certain analytics and purchase data independently under their own privacy policy. We receive confirmation of in-app purchase status from Apple.
Privacy policy →6.2 Organisation Administrators
If you access Selah through an organisation account, your organisation's designated administrator(s) may have access to:
- Your name and email address (as provided at registration).
- Your individual session activity: techniques practised and session duration.
- Aggregated wellness survey results for their team — not individual responses.
- Overall app engagement statistics in aggregated, anonymised form.
- Your psychology profile, only if you have explicitly opted to share it within the app.
Organisation administrators cannot access your individual wellness survey responses, personal app profile details (photo, age range, lifestyle tags), course progress, or any payment information. Administrators are contractually bound not to use accessible data for individual monitoring, performance reviews, or any purpose beyond team-level wellbeing improvement.
6.3 Wellness Survey Anonymity
Wellness surveys within Selah are designed to be anonymous when completed without a name. Specifically:
- If you do not provide your name in a survey response, your submission contains no personal identifier.
- Organisation administrators see only aggregated team results — never individual submissions.
- Selah does not report individual survey responses to organisation administrators.
- You may decline any survey question at any time. Participation is always voluntary.
- Survey responses are stored on your account to allow cross-device access, but are not disclosed to your organisation in individual form.
6.3 Legal Disclosure
We may disclose personal data to law enforcement agencies, regulatory bodies, courts, or other public authorities where we are legally required to do so, where we believe disclosure is necessary to protect our legal rights, or where disclosure is necessary to prevent serious harm to any person. We will notify you of any such request unless legally prohibited from doing so.
6.4 Business Transfers
If Selah undergoes a merger, acquisition, restructuring, or sale of all or substantially all of its assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Website at least 30 days before your data becomes subject to a different privacy policy, and you will have the right to delete your account.
7. International Data Transfers
Selah is a UK-based company. Some of our service providers are located outside the UK and European Economic Area (EEA), including the United States (Anthropic, Stripe, Vercel). Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (ICO).
- Adequacy decisions where the destination country has been recognised as providing adequate data protection.
- Data Processing Agreements with all processors, incorporating appropriate transfer mechanisms.
You can request a copy of the transfer mechanisms we rely on by contacting us at hello@selahapp.co.uk.
8. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law.
| Data Category | Retention Period |
|---|---|
| Account data (email, name) | Until account deletion + 30 days for permanent purge |
| Breathing session and course progress data | Until account deletion + 30 days |
| Wellness survey responses | Until account deletion + 30 days, or earlier on request |
| Payment records and invoices | 7 years (UK tax and accounting law requirement) |
| Stripe Customer ID | 7 years (accounting records) |
| Support correspondence | 3 years from last contact |
| Authentication logs (login events) | 90 days |
| Error and crash logs | 30 days |
| Marketing email opt-in records | Until opt-out + 3 years (to demonstrate consent) |
| Anonymised analytics data | Indefinitely (no personal identifiers) |
When your account is deleted, we initiate permanent deletion of all personal data within 30 days, except where retention is required by law (e.g., payment records). After this period your data is irretrievably deleted and cannot be recovered.
9. Your Rights Under UK GDPR
As a data subject under UK GDPR and the Data Protection Act 2018, you have the following rights. To exercise any right, email us at hello@selahapp.co.uk. We will respond within one month (extendable to three months for complex requests, with notice). Exercising these rights is free of charge.
Right of Access (Article 15)
You have the right to request a copy of all personal data we hold about you and information about how we process it. We will provide this in a structured, commonly used, machine-readable format.
Right to Rectification (Article 16)
You have the right to have inaccurate personal data corrected without undue delay. You can update your display name and email directly in the app. For other corrections, contact us.
Right to Erasure — "Right to be Forgotten" (Article 17)
You have the right to request deletion of your personal data where: it is no longer necessary for the purpose it was collected; you withdraw consent (where consent was the legal basis); you object and we have no overriding legitimate interests; the data was unlawfully processed; or deletion is required by law. This right does not apply where we must retain data for legal obligations (e.g., accounting records). You can initiate account deletion from within the App (Settings → Account → Delete Account) or by emailing us.
Right to Restriction of Processing (Article 18)
You have the right to request that we pause processing of your data in certain circumstances, for example while you contest the accuracy of the data or while we assess an objection.
Right to Data Portability (Article 20)
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing. For direct marketing, we will cease immediately. For other processing, we will cease unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Relating to Automated Decision-Making (Article 22)
We do not make any decisions that produce significant legal or similarly significant effects on you based solely on automated processing. Personalisation features (such as technique recommendations) involve human oversight and are not solely automated decisions.
Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. You can withdraw consent for marketing emails via the unsubscribe link in any email, or by contacting us. You can withdraw consent for psychology profile sharing within the app.
10. Security
We take the security of your personal data seriously and implement industry-standard technical and organisational measures to protect it, including:
- Encryption of data in transit using TLS 1.2 or higher.
- Encryption of data at rest using AES-256 via our database infrastructure.
- Password hashing using bcrypt with per-user salt (managed by Supabase Auth). Selah does not store plain-text passwords.
- Row-Level Security (RLS) policies enforced at the database level — users can only access their own data.
- Multi-factor authentication (TOTP) required for all administrative access to the platform.
- Least-privilege API key management — service role keys are server-side only and never exposed to client code.
- Regular security reviews of authentication flows, API routes, and access controls.
- Database and authentication infrastructure provided by Supabase (SOC 2 Type II certified).
- Hosting infrastructure provided by Vercel (SOC 2 Type II certified).
- Minimal data collection — we do not collect biometrics, location, contacts, or health sensor data.
Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot and do not guarantee absolute security.
Limitation of Liability for Security Incidents.To the fullest extent permitted by applicable law, Selah shall not be liable for any loss, damage, or harm arising from unauthorised access to, or disclosure of, personal data where such access or disclosure occurs as a result of a third-party cyberattack, security breach, or other event beyond our reasonable control, provided that Selah had implemented reasonable security measures at the time of the incident. This limitation does not apply where a breach is caused by Selah's gross negligence or wilful misconduct.
Breach Notification.In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach (Article 33, UK GDPR), and will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms (Article 34, UK GDPR). Notifications will include the nature of the breach, the categories of data involved, and the steps we have taken or propose to take.
For a plain-English explanation of our security practices and what we never do with your data, see our Privacy & Trust page.
11. Children's Privacy
The Service is not directed at or intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If you are under 13, please do not use the Service or provide any personal information.
If you are a parent or guardian and believe that your child under 13 has provided us with personal data, please contact us immediately at hello@selahapp.co.uk. We will take steps to delete that data as soon as possible.
Users between the ages of 13 and 17 may only use the Service with verifiable parental or guardian consent. Organisation administrators are responsible for ensuring age-appropriate use within their deployments.
13. Marketing Communications
We will only send you marketing emails (newsletters, product updates, offers) if you have explicitly opted in. You can unsubscribe at any time by:
- Clicking the "Unsubscribe" link at the bottom of any marketing email.
- Emailing us at hello@selahapp.co.uk with the subject "Unsubscribe".
We will never share your email address with third parties for marketing purposes. Withdrawing consent for marketing does not affect your account or access to the Service.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other factors. When we make significant changes, we will:
- Update the "Last updated" date at the top of this page.
- Send you an email notification at least 14 days before the changes take effect, where the changes materially affect how we process your data.
- Display a notice in the App.
Your continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes. If you do not agree to the updated policy, you should stop using the Service and delete your account.
15. Contact Us
For all privacy-related enquiries, requests, or complaints:
Email: hello@selahapp.co.uk
Subject line: Privacy Request — [Your Name]
Response time: We aim to respond to all privacy requests within 30 days. Complex requests may take up to 3 months, in which case we will acknowledge receipt and explain the delay.
If you are unsatisfied with our response, you may escalate to the UK Information Commissioner's Office (ICO): ico.org.uk/concerns
