SELF Privacy Policy
Last Updated: August 14, 2026
Version: 9.8.0
Our Privacy Promise: We Cannot Read What You Encrypt
SELF uses zero-knowledge encryption for specific protected content. Your device encrypts this content with keys we never receive:
- AI conversations and Memory Bank entries
- Messenger content and attachments
- Vault file contents, file metadata and folder names
- Calendar event content
- Mail sent between SELF accounts
- Chain validator private keys
Your browser derives encryption keys from your 12-word recovery phrase using BIP39. Those keys are never transmitted to SELF. We store ciphertext for the protected content named above and cannot decrypt it.
What We Can See
Clear boundaries are part of our privacy promise. SELF can access limited information needed to run the service:
- Account email address - Encrypted at rest with a server-held key so SELF can use it for contact and account recovery
- External mail - Standard internet mail arriving from or leaving for another provider is readable while crossing the service boundary
- Message routing data - Sender and room identifiers and timing needed for delivery
- Calendar reminder data - Reminder times and event types held separately from encrypted event content
- Mail envelope data - Timestamp, size and folder
- Wallet addresses - Public by the nature of the blockchain
- Live AI prompts - Processed on SELF-controlled EU GPU infrastructure to generate responses
- Account operations - Username, account identifiers, subscription status, usage volumes, security data and billing records needed to provide and protect the service
Our Six Privacy Commitments
SELF is built on six fundamental commitments to privacy and data sovereignty:
- Human rights alignment - We make decisions that are in accordance with human rights
- Harm prevention - We do not cause or enable harm whilst upholding those rights
- Data ownership - We enable people to have control and ownership of their own data, and decide how it is used
- Transparency - We are fully transparent in our practices so that people understand how we operate
- Regulatory responsibility - We work to meet the privacy and data-protection requirements that apply to our operations
- No commercial compromise - We do not sacrifice any of our responsibilities in pursuing commercial gain
Data Minimization
We design our collection practices around data minimization and limit personal data to what we reasonably need for the purposes described in this policy. We review those practices as the service and applicable requirements develop.
The SELF Difference
SELF gives people direct control over their protected content through client-side encryption and user-held keys:
- Zero-knowledge encryption = Server cannot decrypt the protected content named above
- Your recovery phrase = Derives encryption keys via BIP39 on your device
- Your protected content = Your property, secured with client-side encryption
What We Collect
Account Information
- Username - Your chosen unique identifier (required for account creation)
- Account UUID - Technical identifier for your account
- Account creation date - For account management
- Usage volumes - Stored temporarily for display purposes only, not permanently retained
Legal Basis: We rely on contract performance where applicable to provide account access and communications. For these purposes, we store a lookup-only HMAC of your normalized email and an encrypted copy for communications.
Note: Stripe may collect email addresses independently during payment processing. SELF never returns plaintext email via APIs; we store a lookup-only hash of your email for sign-in and an encrypted copy for operational email (AES-256-GCM). Admin tools display masked email only.
Authentication, Encryption and Recovery Information
- Primary authentication - SELF uses WebAuthn passkeys for secure account access, with device support such as Face ID, Touch ID, or fingerprint recognition
- Secondary authentication - Email and a single-use OTP provide a fallback sign-in path when a passkey is unavailable
- Email privacy - We store a lookup-only hash of your normalized email and an AES-256-GCM encrypted copy that SELF can decrypt for operational communications. Plaintext email is not returned by APIs, and admin tools show a masked address.
- Encryption key derivation - Your browser derives encryption keys from your 12-word recovery phrase using BIP39. Passkeys and OTPs authenticate account access and do not derive encryption keys.
- Recovery phrase privacy - Your plaintext recovery phrase and encryption keys are never transmitted to SELF
- Optional recovery password - You may choose to store a server copy of your recovery phrase wrapped client-side with a password-derived key using 600,000 PBKDF2 iterations. SELF receives the wrapped blob and does not receive your password.
- Recovery limits - A passkey or email OTP may restore account access without restoring encrypted content. Without the recovery phrase or the optional recovery-password path, encrypted content cannot be recovered by you or SELF.
Legal Basis: Contract performance (necessary for secure account access and data encryption)
Payment Information (Paid Tiers Only)
- Billing information - Processed by Stripe, our secure payment provider
- Subscription status - Active, cancelled, expired
- Transaction records - For billing support and compliance
- Fraud prevention - Stripe Radar analyzes transaction patterns for security
Important: We never store credit card details on our servers. Payment card data is handled entirely by Stripe. We may use IP addresses briefly for security (for example OTP and login rate limiting) but not for advertising or long-term profiling.
Legal Basis: Contract performance (billing and subscription management)
Technical Coordination Data
- Node connection status - To ensure your services are running
- Basic performance metrics - Anonymous server health data only
- Security-related IP use - IP addresses may be used briefly for login rate limiting and abuse prevention (not retained for profiling)
- Error logs - Anonymous debugging information (no personal content)
Legal Basis: Legitimate interests (service optimization and security)
Content We Cannot Read
Your Protected Content
- Vault files, metadata and folder names - Encrypted client-side so the server cannot decrypt them
- AI conversation history, Memory Bank entries, calendar event content, SELF-to-SELF mail, and messenger content and attachments - Protected with client-side encryption using keys derived from your recovery phrase
- Encryption keys - Derived from your recovery phrase using BIP39. The server never receives the keys or plaintext phrase.
- Browsing history - Never sent to us
- Location data - We don't track where you are
- Device information - Beyond basic compatibility checks
AI Model Processing
- Model outputs at rest - Stored in your Memory Bank as client-side encrypted blobs
- Live AI processing - Prompts are processed on our dedicated EU GPU infrastructure to generate responses; we do not use your conversations to train models or share them with third-party model providers
- Dedicated infrastructure - AI inference runs on dedicated (non-shared) GPU hardware in the EU, separate from multi-tenant cloud compute
- No data sharing with model providers - Your conversations and AI interactions are not used to train third-party models. Model providers do not receive your data for training purposes.
- No model training - We do not use your conversations to train models. Your AI usage is private to you.
- Memory Bank storage - AI conversation history is stored as client-side encrypted blobs; the server cannot decrypt your content
- EU data residency - AI processing and encrypted storage use EU-based infrastructure
Behavioral Analytics
We do not use advertising analytics, cross-site tracking, or behavioral profiling:
- No ad profiles - We don't build profiles for advertisers or data brokers
- No cross-site tracking - We don't follow you across other websites or apps
- No click tracking - No behavioral analytics for marketing purposes
Advertising Data
- Profile building - We don't create user profiles for advertisers
- Interest tracking - We don't categorize your interests for advertisers
- Third-party data - We don't buy or sell data about you or with anyone
Your Rights and Controls
Access and Control
- View your data - See exactly what account information we have
- Correct errors - Update your username or billing details
- Export data - Download your account information
- Delete account - Request removal of your account and associated data under our retention rules
Data Portability
- Account export - Download your account data in standard formats
- Service migration - Move to other providers if desired
- No lock-in - Export your data and leave anytime
Data Breach Response
If a data breach creates a risk to your privacy, we will assess it promptly and notify affected people and relevant authorities within the timeframes required by applicable law.
Privacy Contact
For data protection inquiries, use Settings → Contact Us in the SELF App, choose an appropriate purpose, and describe your request.
Automated Decision-Making
We do not use automated decision-making or profiling that would significantly affect you. Any automated processes (such as fraud detection by Stripe Radar) are limited to payment and subscription integrity and do not grant access to your zero-knowledge encrypted content. You retain full control over your account and data.
Contact Us About Privacy
The SELF team will never DM you or reply to DMs. For privacy questions, data access requests, or any other inquiry, create a free account at self.app and use Settings → Contact Us. When the team respond, it will appear in your in-app Alerts.
Mail: SELF Technology Pty Ltd, 194 Varsity Parade, Varsity Lakes, Queensland 4227, Australia
Third-Party Data Processing
SELF uses several third-party services for infrastructure and payments. Here's how your data is processed:
Memory Bank Definition
Your Memory Bank uses client-side end-to-end encryption on both tiers. AI conversations and Memory Bank entries are stored as ciphertext in PostgreSQL on single-tenant bare metal servers in the EU:
- Both Tiers - Your browser encrypts Memory Bank content using the WebCrypto API (AES-256-GCM) with keys derived from your recovery phrase before transmission. The server cannot decrypt that content.
- Data Export - Both tiers can export supported decrypted content through Settings. Decryption happens in your browser.
- Recovery Options - Keep your recovery phrase secure. You may also enable the optional recovery-password feature, which stores a client-side wrapped phrase copy as described above. SELF cannot recover encrypted content without one of those paths.
Data Processing Summary
- Frontend CDN - Delivers our static frontend application (public JS/CSS/HTML only; no user ciphertext)
- EU backend (bare metal) - API, database, encrypted Memory Bank, messaging, mail, and signaling on single-tenant bare metal in the EU
- EU object storage - Client-side encrypted Vault files, messenger attachments and SELF-to-SELF mail blobs use dedicated EU object storage (S3-compatible)
- Dedicated GPU infrastructure (EU) - AI text and image processing on dedicated (non-shared) GPU hardware in EU data centers
- Stripe - Processes subscription and card payments securely (PCI compliant, no card data stored by us)
- External transactional email delivery - Processes account email addresses to deliver OTPs and account and service messages
- Search services (Connect tier) - Search text and URL retrieval requests are sent to a third-party provider without your SELF account ID, username, or email. Providers may change and this policy will be updated accordingly.
SELF App Validator Infrastructure
SELF App uses browser-based validators with backend chain coordination:
- Browser-based validators - Browser validators participate in validation and consensus
- Backend coordination - Orchestrator and coordinator services support rounds, chain state, availability, validator participation records, and prize draw coordination
- Validator keys - Validator private keys are derived from your recovery phrase, remain encrypted on your device, and are not provided to coordination services
- Service availability - Validator and prize draw participation may be temporarily unavailable if backend coordination services are interrupted
EU Infrastructure
Production services that handle user data run on single-tenant bare metal and dedicated EU-based infrastructure:
- Single-tenant bare metal - Backend API, database, messaging, mail, and signaling on dedicated physical servers in the EU (not shared multi-tenant cloud compute)
- Dedicated GPU hardware - AI text and image inference on dedicated (non-shared) GPU servers in EU data centers
- Encrypted object storage - Client-side encrypted Vault files and attachments use dedicated EU object storage. Mail blobs are stored in EU object storage, with the encryption boundary depending on whether mail stays within SELF or crosses to an external provider.
- Infrastructure provider role - Infrastructure providers host and operate systems. They do not receive the keys for client-side encrypted protected content.
- Account deactivation - When your account is deactivated, associated storage is permanently deleted per our retention policy
Legal Basis: Contract performance (necessary to provide SELF services with EU-based infrastructure)
Account & Payment Data
- Account data - Username, subscription status, and usage metrics on EU single-tenant bare metal PostgreSQL. Email stored encrypted (AES-256-GCM).
- Payment data - Stripe handles payment processing; we don't store card information
Data Export and Recovery
- Both Tiers - You can export supported decrypted content through Settings. Conversations and Memory Bank entries are decrypted in your browser and available for download in JSON format.
- Data Recovery - Your recovery phrase derives the keys used to decrypt protected content. If you enable the optional recovery-password feature, a phrase copy is wrapped client-side using a password-derived key with 600,000 PBKDF2 iterations and the wrapped blob is stored on the server. SELF does not receive the password. Without the phrase or that optional recovery path, SELF cannot recover the encrypted content.
Service Metadata
- Memory Bank identifiers - Technical identifiers for your isolated Memory Bank
- Session metadata - Account and session identifiers and usage patterns needed for service operation and security
- Performance metrics - Response times and system health (no personal content)
- Error logs - Anonymous debugging information for service improvement
Search Services
Web Search Integration (Connect Tier)
Web search is available on the Connect tier only, including during the 3-day free trial. When you enable search in chat, your search text is sent to a third-party provider without your SELF account ID, username, or email.
- Availability - Connect tier only; not available on Zero
- Search requests - The provider receives the search text needed to return results
- Account identifiers - SELF does not include your SELF account ID, username, or email in the provider request
- URL retrieval - Requested URLs are sent to the provider when you use URL content retrieval
- Result accuracy - Search results are provided "as-is" from third-party sources; we do not verify or guarantee their accuracy
Search Service Disclaimers
- Third-party content - All search results come from external sources beyond our control
- No endorsement - SELF does not endorse or verify the accuracy of search results
- User responsibility - You are responsible for evaluating the credibility and accuracy of information from search services
- Service availability - Search services depend on third-party availability and may be temporarily unavailable
- No liability - We are not liable for decisions made based on search results
International Data Transfers
- Primary location - Australia (SELF Technology Pty Ltd)
- AI processing - Dedicated GPU infrastructure in EU data centers
- Backend API hosting and encrypted Memory Bank storage - Single-tenant bare metal servers in the EU (PostgreSQL; encrypted blobs only)
- Frontend delivery - Static frontend assets delivered via a third-party CDN
- Payment processing - Stripe (US-based payment processor)
- Legal framework - Australian privacy law applies to SELF Technology Pty Ltd, with additional privacy requirements applying where relevant to users in other regions
- Transfer mechanisms - We use appropriate transfer mechanisms and safeguards with service providers where applicable. Encrypted Memory Bank storage uses EU-based single-tenant bare metal infrastructure.
- AI data residency - AI processing uses dedicated EU-based GPU infrastructure
Changes to This Policy
Notification Process
- 30 days advance notice for any material changes
- In-app notification to all active users
- Clear explanation of what's changing and why
Our Commitments
We will never change this policy to:
- Start collecting data we previously didn't collect
- Share data in ways we previously didn't
- Reduce your privacy protections
- Introduce tracking or advertising
Data Retention Periods
We retain different types of data for specific periods based on legal requirements and service needs:
- Account information - Retained while your account is active and for 30 days after deletion
- Payment data - Retained by Stripe for 7 years (legal requirement for financial records)
- Secure vault/AI data - Trial users: automatically deleted 24 hours after trial cancellation with advance in-app notice. Paid users: automatically deleted when subscription is deactivated
- Usage logs - Retained for 30 days for debugging and service optimization
- Support communications - Retained for 2 years for service improvement and legal compliance
- Transactional email only - We send account, billing, and trial-related emails only; we do not send marketing newsletters
Trial Data Deletion Process
For trial users who don't convert to paid subscriptions, we follow a clear deletion process to maintain storage efficiency while protecting your privacy:
- Trial warning - In-app alert during last 24 hours of trial with upgrade and cancellation options
- Cancellation notice - In-app notification when trial is cancelled with 24-hour deletion schedule
- Grace period - 24 hours to export your conversations and memories via Settings
- Automatic deletion - Memory Bank data permanently deleted 24 hours after trial cancellation
- Deletion confirmation - In-app confirmation when deletion is complete
- Audit trail - Deletion events logged for compliance and transparency
Legal Basis: Legitimate interests (cost management and storage efficiency) balanced with user rights (advance notice and data export opportunities)
SELF App Prize Draw Program
SELF App operates a Category 4 promotional game under Queensland's Charitable and Non-Profit Gaming Act 1999, where users earn prize draw entries through validator participation:
- Prize draw entries - We collect validator participation data to calculate prize draw entries (1 vote = 1 entry)
- Winner records - Winner information (user ID, prize amount, draw date) is retained for 5 years (Queensland regulatory requirement)
- Privacy protection - Winners may request anonymity; winner names published only with permission
- Legal basis - Contract performance (providing the SELF App prize draw program)
Age Requirements and Children's Privacy
SELF is intended for users 18 years or older. We do not knowingly collect personal data from users under 18.
If we discover we have collected information from a user under 18, we will delete it immediately and, where possible, notify their parent or guardian.
If you are a parent or guardian and believe someone under 18 has provided us with personal information, please use Settings → Contact Us in the SELF App (or create an account at self.app first).
Regulatory Information
Australian Privacy Principles
This policy is intended to support SELF Technology Pty Ltd's obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.
European Data Protection
For users in the EU, we apply GDPR requirements where they are applicable to our processing.
Data Protection Rights
Depending on the law that applies to you, your rights may include the right to:
- Be informed about data processing
- Access your personal data
- Rectify inaccurate data
- Erase your data
- Restrict processing
- Data portability
- Object to processing
Exercising Your Rights with Third-Party Data
For data processed by our infrastructure providers, Stripe, and AI services:
- Access requests - Use Settings → Contact Us to access your data
- Deletion requests - Your Memory Bank data is automatically deleted when your subscription is deactivated
- Portability - We can export your account data, but AI conversations remain in your Memory Bank
- Restriction - You can stop using SELF services to restrict further processing
- Objection - Use Settings → Contact Us if you object to how your data is processed by third parties
- Payment data - For Stripe-related data requests, we can facilitate contact with Stripe support

