TR EN ES

Privacy Policy

What we collect, what we don't, and what leaves your device

Effective date: 29 July 2026
Applies to: Selfinity for Android and iOS, version 5.2.0 and later, and the website getselfinity.com. For older Android versions, see section 14.1.

1. Introduction

Selfinity ("Selfinity", "the app", "we", "us") is a personal wellbeing and self-development app developed and operated by Mindoria Studio, based in Türkiye.

This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and what rights and choices you have. It is written to be read, not to be survived — where something is unusual or important, we say so plainly rather than burying it.

Data controller: Mindoria Studio, Türkiye. Contact: hello@getselfinity.com

If you do not agree with this policy, please do not use Selfinity.

2. At a glance

  • We do not show advertisements and we do not collect advertising identifiers.
  • We use no analytics, attribution or crash-reporting SDK. There is no Google Analytics, no Firebase, no social-network SDK, no third-party tracker inside the app.
  • We do not sell your personal data and we do not share it for advertising. Not now, not previously, not planned.
  • We do not track you across other companies' apps or websites, which is why the app never asks for App Tracking Transparency permission on iOS.
  • A meaningful part of what you record never leaves your device at all — the full list is in section 7.
  • You can delete your account, and the data on our servers with it, from inside the app — see section 9.
  • Some optional features send content to Google's Gemini AI only when you choose to use them. Section 5 lists exactly what, feature by feature.

3. The data we collect

3.1 Account information

3.2 Wellbeing content you create

Selfinity is a wellbeing app, so most of what it holds is content you deliberately enter. Under the GDPR a large part of this is special category data concerning health; under Turkish KVKK it is özel nitelikli kişisel veri. We process it only on the basis of your explicit consent, which you give by choosing to use the relevant feature.

Some of the above never leaves your device — section 7 says which.

3.3 Device permissions and sensors

Every permission below is optional. The app runs without it; only the related feature stops working. You can revoke any of them at any time in your operating system settings.

Permission Why the app asks Does anything leave the device?
Camera Scanning a food barcode; photographing a meal for AI analysis Barcode: no — decoding happens on the device. Meal photo: yes, it is sent to Google Gemini for analysis (section 5).
Microphone and speech recognition Speaking to the Komorebi assistant instead of typing Usually yes. Your speech is transcribed by your operating system's own speech recognition — Google on Android, Apple on iOS — which may process the audio on their servers. Selfinity never stores your audio and never sends it to our own servers.
Physical activity / motion Counting your daily steps from the device's step sensor The resulting daily step count is stored and synced. Raw sensor readings are not.
Notifications The reminders you set yourself No. Every reminder is scheduled and fired on your device. We do not use push notifications and we hold no push token for you.
Exact alarm (Android) Ringing precisely at the end of a Pomodoro session No.

3.4 Technical data collected automatically

We keep this deliberately minimal:

What we explicitly do not collect: no analytics or behavioural events, no usage-tracking SDK, no crash-reporting SDK, no advertising identifier (Android Advertising ID or Apple IDFA), no device fingerprinting, no cross-app or cross-site tracking, and no tracking cookies inside the app.

3.5 Subscription and purchase data

Premium subscriptions are sold through Apple's App Store and Google Play, and managed through RevenueCat.

3.6 Social features

If you use the friends features:

4. Why we use your data, and on what legal basis

Purpose Data used Legal basis (GDPR)
Running the app: storing your entries, syncing across your devices, showing your history and statistics 3.1, 3.2 Performance of a contract, Art. 6(1)(b); for health-related content, your explicit consent, Art. 9(2)(a)
The AI features you actively trigger see section 5 Explicit consent, Art. 6(1)(a) and Art. 9(2)(a), given each time you use the feature
Reminders and notifications you configure your reminder settings Contract, Art. 6(1)(b)
Selling and managing Premium subscriptions 3.5 Contract, Art. 6(1)(b)
Keeping the service secure; preventing fraud, abuse and manipulation of the in-app reward economy 3.4 and progress data Legitimate interests, Art. 6(1)(f)
Detecting text that suggests a risk of self-harm and surfacing support resources (section 5.1) free text you write Vital interests, Art. 6(1)(d), together with your explicit consent, Art. 9(2)(a)
Answering your support requests your email address and what you tell us Contract and legitimate interests
Meeting legal obligations as required Legal obligation, Art. 6(1)(c)

Under Turkish KVKK the corresponding grounds are Art. 5/2-c (necessary for performance of a contract) and Art. 5/2-f (legitimate interests), and — for special-category health data — your explicit consent under Art. 6.

You can withdraw consent at any time by stopping use of the relevant feature, deleting the relevant entries, or deleting your account. Withdrawal does not affect processing that has already taken place.

5. AI features: exactly what is sent, and to whom

Selfinity has four optional AI features. Each of them runs through our own server, which calls Google's Gemini API as a processor on our behalf. If you never use these features, nothing described in this section ever happens.

A correction to earlier versions of this policy. Previous versions of this page, and of our Terms of Use, stated that raw journal or thought text is never sent to Google. That was not accurate for every feature. The table below is the accurate description, and we have corrected the wording everywhere it appeared.

Feature What is sent to Google Gemini Kept on our servers?
Meal photo scan The photo of your meal (downscaled to at most 1024 pixels), your app language, and — if you correct the result — the correction you type No. We keep only a counter of how many scans you have used that day. The photo itself is not stored on our servers.
Komorebi assistant Your conversation with the assistant (up to the last 12 messages), the names of your own personal-care tasks and routines so it can match what you describe, and your device's local time No. The conversation stays on your device. Only a usage counter is kept.
Thought analysis (CBT) The automatic thought you wrote (up to 2,000 characters) and the cognitive distortions you selected No. Only a usage counter.
Weekly AI report Not your raw text. Our server reads your own week's data and turns it into factual summaries (for example "mood logged on 5 of 7 days, average sleep 6 h 20") plus recurring theme keywords. Only that derived summary is sent to the model. Yes — the generated report is saved to your account so you can read it again later.

5.1 Automated safety screening

To reduce the risk of harm, our server automatically checks free text you write — journal entries, quick thoughts, thought records, mood notes, Life Log notes and assistant messages — for patterns that suggest self-harm or a mental-health crisis. When a pattern matches, the app changes what it shows you, for example offering support resources instead of a generated response.

Selfinity is not an emergency service and cannot get help to you. If you are in danger or in crisis, contact your local emergency number or a crisis helpline immediately.

6. Who we share your data with

We do not sell your personal data, and we do not share it for cross-context behavioural advertising. Under the CCPA and CPRA, we have not sold or shared personal information in the preceding twelve months. We use only the processors below.

Recipient Purpose What they receive
Supabase (infrastructure hosted on Amazon Web Services) Hosting, database, authentication, file storage, our server-side functions Your account and all synced content — sections 3.1 and 3.2
Google (Gemini API) The AI features in section 5 Only what section 5 lists, and only when you use those features
RevenueCat Subscription management Your random user identifier and your store subscription status
Apple and Google Play App distribution, payment and billing The purchase and billing data they collect directly from you
Open Food Facts (non-profit food database, France) Looking up nutrition information The barcode number you scan or the food term you search. No account identifier and no personal data are attached.
Apple / Google speech recognition Converting your dictation into text The audio you dictate, handled by your device's operating system rather than by us

Beyond these, we may disclose data where we are legally required to — for example a valid court order or a binding legal obligation — or where it is necessary to establish, exercise or defend legal claims.

7. What stays only on your device

The following is stored in the app's local database and is never uploaded to our servers:

Because this data exists only on your device, uninstalling the app deletes it permanently and we cannot restore it.

8. Photos and files you upload

Two features upload images to our storage: Vision Board and Life Log.

These storage areas are private. An image you upload can only be reached through your own signed-in account: to display it, the app generates a short-lived signed link that stops working once it expires. Your images do not sit at any address that can be opened without signing in, and we never list, index, publish or share them.

Deleting the item inside the app deletes the underlying file.

Correction to earlier versions: before 29 July 2026 these two areas were public, and anyone who knew an image's exact URL could open it without logging in. That access was fully closed on 29 July 2026; every image — including older uploads — is now served only through the signed links described above. Older app versions (5.1.x) cannot generate signed links and may fail to display these images; updating to the latest version resolves this.

Meal-scan photos work differently: they are sent to Google for analysis and are not placed in our storage at all. A copy may remain in the app's own cache on your device until you clear it.

9. How long we keep data, and how to delete it

10. Your rights

Wherever you live, you can exercise the rights below by emailing hello@getselfinity.com. We respond within 30 days, we do not charge for it, and we will never treat you differently for exercising a right.

10.1 If you are in the EEA or the United Kingdom (GDPR / UK GDPR)

We do not make decisions producing legal or similarly significant effects about you by solely automated means.

10.2 If you are in Türkiye (KVKK Art. 11)

Applications under Art. 13 of the KVKK are answered within 30 days, and you may lodge a complaint with the Turkish Personal Data Protection Board (KVKK Kurulu).

10.3 If you are in California (CCPA / CPRA)

10.4 Everywhere else

As a matter of policy we apply the same rights globally, whether or not local law requires them.

11. International data transfers

We are based in Türkiye and our providers operate in the European Union and the United States. When your data crosses a border we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), on the EU–US Data Privacy Framework where a provider is certified under it, and — for transfers out of Türkiye — on your explicit consent under Art. 9 of the KVKK where no adequacy decision or written undertaking applies.

12. Children's privacy

Selfinity is not directed at children under 13, and we do not knowingly collect personal data from them. Our Terms of Use require you to be at least 13 years old, and if you are under 18 you need permission from a parent or guardian.

We comply with the United States Children's Online Privacy Protection Act (COPPA). In countries where the age of digital consent is higher than 13 — up to 16 in parts of the European Union — you need parental authorisation below that age.

If you believe a child has provided us with personal data, contact hello@getselfinity.com and we will delete it promptly.

13. Security

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your password and your device safe. If we become aware of a breach affecting your personal data, we will notify you and the competent supervisory authority as required by law.

14. Changes to this policy

We update this page when the app changes, and we change the effective date at the top. For significant changes we will notify you in the app or by email before they take effect. Continuing to use Selfinity after a change means you accept the updated policy.

14.1 Versions 5.1.x and earlier (Android only)

Older Android versions of Selfinity behaved differently. This section is kept for people who have not yet updated:

From version 5.2.0 onwards, all advertising, all analytics SDKs and all push messaging have been removed from the app, and step counting uses the device's own sensor instead of Health Connect. If you are still on an older version, updating the app moves you to the practices described in this policy.

15. Contact us

Developer and data controller: Mindoria Studio
Country: Türkiye
App: Selfinity — Mind & Development
Email: hello@getselfinity.com
Website: getselfinity.com

We answer privacy and data-rights requests within 30 days, and general questions usually within 48 hours.