Selah

Privacy is not an afterthought.

Selah is a wellness tool. The data you share with us is some of the most personal data there is — your breath, your mental state, your daily practice. We treat it accordingly.

Our ethos

Breathwork and meditation are deeply personal practices. People use Selah during moments of anxiety, grief, stress, and healing. That context shapes everything about how we build.

We are a privacy-first company. That means we collect the minimum data needed to deliver the service, we do not sell or rent your data to anyone, we do not use your wellness data to profile or target you commercially, and we do not share your individual data with your employer — under any circumstances.

Privacy is a design principle at Selah, not a compliance checkbox.

For individuals

When you use the Selah app, we store your practice data — sessions completed, streaks, course progress, preferences — so it is available across your devices and does not disappear if you reinstall the app. This data is tied to your account and is never shared with third parties for commercial purposes.

What is stored on your account

  • Session history (technique, duration — no audio or biometric data)
  • Practice streak and milestones
  • Profile preferences (name, photo, experience level, goals)
  • Course and programme progress
  • Wellness survey responses (if you complete one)
  • Your audio or voice during sessions
  • Location data
  • Contacts or calendar
  • Health app data (Heart Rate, HealthKit etc.)

Your profile photo is stored in our secure cloud storage (Supabase Storage) and is only accessible via a private URL tied to your account.

For organisations

When Selah is deployed in a workplace or institutional setting, there is a clear and enforced data wall between what your organisation administrator can see and what is private to you as an individual.

What your organisation administrator CAN see:

  • Your display name and email address (as provided at registration)
  • Your individual session activity: techniques used and session duration
  • How many members have joined the organisation
  • Overall usage statistics (total sessions, active users)
  • Aggregated wellness survey results for the team as a whole
  • Whether you have completed a psychology profile, only if you opted to share it

What your organisation administrator CANNOT see:

  • Your individual wellness survey responses (see Anonymous Surveys below)
  • Your personal app profile: photo, age range, or lifestyle tags
  • Your psychology profile contents, unless you explicitly shared it
  • Your course progress or personal milestones
  • Your subscription tier or payment information
  • Any breath hold times, article reading history, or personal preferences

Our commitment to organisation members

Selah is a personal wellbeing tool. We will never allow an organisation to use our platform as a surveillance or monitoring tool. Organisation administrators agree, as a condition of using Selah, that they will not use any accessible data for performance reviews, disciplinary proceedings, or individual employee monitoring. Breach of this condition terminates their access immediately.

For organisation decision-makers

If you are evaluating Selah for your organisation, here is what you need to know about how we handle your data and how liability is allocated:

Your organisation's data is encrypted and access-controlled

All data is encrypted in transit (TLS) and at rest (AES-256). Row-Level Security at the database level means data belonging to your organisation cannot be accessed by other organisations, and employee data cannot be accessed by administrators beyond what is explicitly permitted.

We use MFA and least-privilege access internally

Administrative access to the Selah platform requires multi-factor authentication (TOTP). No Selah engineer can query your organisation's data without authenticated, audited access. Service credentials follow least-privilege principles and are never exposed client-side.

Your data is not used for anything other than delivering the service

We do not sell, rent, or share your organisation's data. We do not use it to train AI models. We do not use it for advertising or third-party analytics.

Infrastructure is SOC 2 Type II certified

Our database (Supabase) and hosting (Vercel) providers are independently SOC 2 Type II certified, meaning their security controls are regularly audited by independent third parties.

Liability is clearly defined in our Terms

Organisation contracts are B2B agreements. Selah's total liability to your organisation is capped at fees paid in the preceding 12 months. Indirect losses — including regulatory fines, business disruption, and reputational damage — are excluded. Full detail is in Section 15 of our Terms of Service.

Anonymous wellness surveys

The Selah wellness survey is designed to give organisations a picture of team wellbeing — without compromising individual privacy.

How anonymity works

  • If you do not include your name, your response contains no personal identifier. Your organisation administrator sees only your answers — not who gave them.
  • Organisation admins never see individual responses— the admin dashboard shows aggregated team results only. No admin can drill into a single person's submission.
  • Selah does not report individual responses to organisations. We have no commercial incentive to do so, and our systems are built to prevent it.
  • You can decline any question at any time. Participation is always voluntary.

We strongly encourage employees to complete surveys anonymously. The value to your organisation comes from the aggregate picture, not from identifying individuals.

How we protect your data

We implement layered technical and organisational security controls. Below is an honest account of what we do — without overstating our credentials.

Encryption in transit — TLS 1.2+

All data between your device and our servers is encrypted using Transport Layer Security. No data is ever transmitted in plain text.

Encryption at rest — AES-256

All database data is encrypted at rest by Supabase, our database provider. This applies to your profile, progress data, and all stored content.

Row-Level Security (RLS)

Our database enforces RLS policies at the infrastructure level — your data can only be read or written by requests authenticated as you. Not even a Selah engineer can query your data without authentication.

No passwords stored by Selah

Selah does not store passwords. Authentication uses magic links (one-time codes) via Supabase Auth. When passwords are set, they are hashed using bcrypt with per-user salt — we never hold the plain-text password.

Multi-factor authentication for admin access

Administrative access to the Selah platform requires authenticator-app based two-factor authentication (TOTP). There is no admin backdoor accessible with a password alone.

Least-privilege access controls

API keys and service credentials follow least-privilege principles. No client-facing code ever holds privileged database credentials. Service-role keys are server-side only.

SOC 2 Type II certified infrastructure

Our database and authentication infrastructure is provided by Supabase, which holds SOC 2 Type II certification. Our hosting infrastructure is provided by Vercel, which also holds SOC 2 Type II certification.

HTTPS-only

The Selah website and all API endpoints are served exclusively over HTTPS. HTTP requests are automatically redirected.

Minimal data collection

We apply data minimisation principles — we collect only the data needed for the service to function. We do not collect biometrics, location, contacts, or health sensor data.

Honest about what we are not (yet)

We do not currently hold ISO 27001 or Cyber Essentials certification. We are a growing company and we intend to pursue formal security certification as we scale. The absence of a certificate does not reflect the seriousness with which we treat security — it reflects the early stage of our company. If your organisation requires a specific certification before deployment, please contact us to discuss.

What we never do

  • Sell or rent your personal data to any third party
  • Share individual user data with employers or organisation administrators
  • Use your wellness or health data for commercial profiling or ad targeting
  • Train AI models on your personal session data or journal entries
  • Access your device microphone, camera, contacts, or location
  • Request access to your full photo library (we use Apple's system photo picker)
  • Send your data to countries without adequate data protection safeguards, without GDPR-compliant safeguards in place
  • Retain your data after you delete your account (beyond our 30-day grace period)

Data breach commitment

Despite our best efforts, no online system can guarantee absolute security. If a data breach occurs that is likely to result in risk to your rights and freedoms, we commit to:

Notify you promptly

We will notify affected users as quickly as is reasonably practicable, and in any event within the timeframes required by UK GDPR.

Report to the ICO

We will report to the Information Commissioner's Office within 72 hours of becoming aware of a qualifying breach, as required by UK GDPR Article 33.

Transparent communication

We will tell you clearly what data was involved, what we have done to contain the breach, and what steps you can take to protect yourself.

No cover-ups

We will not attempt to conceal or minimise a breach. Transparency is a core value.

Limitation of liability

Selah implements reasonable and industry-standard security measures. However, to the fullest extent permitted by applicable law, Selah shall not be liable for any unauthorised access to, disclosure of, or loss of data arising from a third-party cyberattack, security breach, or other event beyond our reasonable control, provided that such an event occurred despite our implementation of reasonable security measures. Our full liability position is set out in our Terms of Service.

Questions about privacy or security?

We are happy to answer questions from individuals or organisations about our data practices, security controls, or compliance posture.

Contact us

Or email: hello@selahapp.co.uk