Privacy Policy
Last updated 12 September 2026
Serai has no accounts. You do not give us a name, an email address or a phone number to use the app. Almost everything you do in Serai stays on your iPhone. This page describes the exceptions precisely, because one of them is an AI coach and you deserve to know exactly what it sends and where.
The controller is Ahmet Eren, an individual developer in Türkiye, trading as Serai. Contact: ahmetrnn03@gmail.com.
1. What stays on your device
| Data | Where it lives | Does it leave the device? |
|---|---|---|
| Onboarding answers, goals, movement level, safety flags | A protected file on your iPhone | Only inside coach context, and only if you allow that |
| Daily check-ins (energy, moods, body, pain flag, need) and inner-weather labels | Your iPhone | Only today's check-in and the last seven labels, inside coach context, if you allow it |
| Completed pairs, rhythm, milestones, weekly recaps | Your iPhone | Never |
| Journal entries and reflections | Your iPhone | Never, unless you tap "Reflect with Coach" on one specific entry |
| Coach conversations | Your iPhone, kept 30 days, then deleted automatically | Each message is sent when you send it — see section 3 |
| Installation identifier | Your iPhone's Keychain | Yes, to our server, so that quotas and subscriptions work without an account |
| Subscription receipt (Apple signed transaction) | Apple | Yes, to our server, to verify that Serai Plus is active |
2. The coach is off until you turn it on
The coach does nothing until you open it and read the consent screen. That screen names the provider, lists exactly what will be sent, and gives you two switches: "Include today's check-in and profile" (on by default) and "Include my name" (off by default). You can use Serai for as long as you like without ever enabling it, and you can turn it back off at any time in Settings.
If we ever change the provider or the retention terms, the consent screen is shown again before your next message.
3. Exactly what the coach sends, and what it never sends
Sent with every coach message: the text of your message and the last ten turns of the current conversation.
Sent as well, only while the context switch is on: today's check-in (energy, moods, body, whether you marked pain, what you need), today's inner-weather label and mode, the words of your last seven labels, your profile basics (goals, bad-day patterns, movement level, safety flags as yes/no, your default time budget), the titles and ids of today's pair, and the app's language. Your first name is sent only if you turn on the second switch.
Never sent: journal text (unless you tap "Reflect with Coach" on one specific entry, which asks you again for that entry), your full history, completion history, device identifiers beyond the installation identifier described above, advertising identifiers, contacts, photos, health-app data, precise location, or your purchase details.
If you report a reply, that reply, your reason and your note are sent to us and kept for 90 days so we can review it. Nothing else from the conversation goes with it — not your own message, not the turn before it, not your check-in. Reporting is the only thing that makes us keep a coach reply; the report screen says so before you send it.
4. Who processes it
Your message and its context go first to our own server, a Cloudflare Worker running at serai-api.ahmetrnn03.workers.dev, which assembles the request and forwards it to MiniMax, the AI provider that generates the reply. MiniMax acts as a processor for this purpose. Cloudflare hosts our server and this website and acts as a processor for that.
Our server does not store your messages or the replies, with one exception you choose: a reply you report (section 3). Otherwise it holds the request in memory long enough to stream the answer back to your phone, and then it is gone. What it does keep is a hashed installation identifier, a daily message count, and error logs that contain no message text.
MiniMax processes the request on its own infrastructure. The API is operated by Nanonoble Pte. Ltd., 152 Beach Road, #14-02 Gateway East, Singapore, and its API privacy policy took effect on 30 March 2026. Read it at the source. The parts that bear on you: your input and the generated output are processed as part of providing the service; personal data described by that policy is stored in a data centre in the United States; MiniMax states that it does not use input personal data to infer characteristics about an individual, nor personal data for training to profile or target consumers; and it reserves the right, on a legitimate-interests basis, to de-identify or anonymise data and to analyse and commercially use the resulting database. Questions to them go to api@minimax.io. What we do is narrower: we send the minimum listed in section 3, we do not attach your name unless you asked us to, and we keep nothing except a reply you ask us to look at.
Coach messages leave Türkiye and the EEA when they are forwarded to MiniMax, and are stored in the United States. Where a transfer requires a safeguard, we rely on your explicit consent, given on the coach consent screen for that specific purpose.
5. How long things are kept
- Our server: no conversations, ever, except a reply you report, which is kept for 90 days and then deleted automatically. Quota counters and the hashed installation identifier are kept while the installation is active and deleted when you delete your coach data.
- Your iPhone: coach conversations are kept for 30 days and then removed automatically. Everything else stays until you delete it or remove the app.
- MiniMax: no fixed period. Their policy keeps data for as long as it is necessary for the purpose it was collected for or permitted by law, and then deletes or anonymises it. We cannot shorten that for you, and we cannot delete data held on their systems on your behalf.
- This website: waitlist entries until you ask us to remove them; anonymous page events for 24 months.
6. Training
We do not train any model on your messages, and we do not build profiles from them. MiniMax's API privacy policy says it does not use input personal data to infer characteristics about an individual, nor personal data for training to profile or target consumers. That is narrower than a blanket promise never to use API data for model improvement: the same policy allows de-identified and anonymised data to be analysed and used commercially. We cannot give you a guarantee on their behalf. If you would rather nothing left your phone at all, leave the coach switched off — the check-in, the pairs, the player and the journal all work without it.
7. What the coach can get wrong, and what it does with a serious conversation
Coach replies are generated by a language model. They can be wrong, out of date, or badly judged, and they are not medical, psychological, legal or financial advice. The coach is instructed never to diagnose, never to name a condition, never to recommend medication or a diet, and never to discourage you from seeing a professional. It can only suggest exercises that already exist in Serai's reviewed catalog; it cannot invent a movement.
Serai runs crisis detection on your message twice: a keyword check on your iPhone before anything is sent, and a second keyword check on our server. If either one matches, no request is sent to MiniMax at all. Instead the app shows a fixed, non-generated message and a card of support resources, and stays there until you dismiss it. Those resources are never behind the paywall and never behind the consent screen. Serai is not a crisis service.
8. Analytics, and this website
In the app: we use TelemetryDeck for anonymous product analytics — which screens are opened, whether a pair was completed, whether a paywall was shown. Signals are sent with a hashed identifier that cannot be traced back to you, and they never contain free text, journal content, coach messages or check-in detail. TelemetryDeck's privacy information is at telemetrydeck.com.
Crashes: when the app crashes, freezes or starts slowly, iOS itself hands us a report through MetricKit — the same mechanism Apple uses, with no third-party crash SDK. We rebuild that report field by field before it leaves your phone, keeping only the app version, the iOS version, the device model and the anonymised stack of code addresses, and dropping everything else Apple includes. It carries no identifier, so we cannot tell whose phone crashed, and no content from a check-in, journal or coach conversation. Reports go to our own server and are deleted after 90 days. You can switch this off in Settings.
On this website: no cookies, no advertising identifiers, no third-party scripts. We record which page a button was clicked on, the language, the campaign parameters in the link you followed, the referring domain, and the approximate country Cloudflare reports. We do not store your IP address in that table. If you join the waitlist, we store the email address you typed, your consent timestamp and the same campaign fields, and we use it for exactly one message.
9. Apple's privacy label
Our App Store answers match this page: Identifiers — the installation identifier (App Functionality) and the hashed device identifier TelemetryDeck generates for a signal (Analytics); Other User Content (coach messages, App Functionality); Health & Fitness (check-in energy and mood, only as coach context, App Functionality); Purchases (App Functionality); Product Interaction (Analytics); and Diagnostics — the MetricKit crash, hang and launch reports described in section 8 (App Functionality). Every one of them is declared as not linked to you, because there is no account, name or contact detail to link them to. Nothing is used for tracking.
10. Your rights
Under the GDPR and the UK GDPR you can ask for access, correction, erasure, restriction, portability, and you can object to processing. Because there is no account, the fastest route for most of these is inside the app: Settings → Data holds "Export my data", "Delete coach data" and "Reset everything".
Legal bases. The coach relies on your explicit consent under Article 6(1)(a) and, because check-in context can reveal information about your mental wellbeing, Article 9(2)(a) GDPR. Analytics and the operation of the app rely on our legitimate interest in a working, secure product (Article 6(1)(f)); the waitlist relies on your consent. You can withdraw consent at any time, and withdrawing it does not affect what happened before.
KVKK (Türkiye). Under Law No. 6698, check-in and coach content that relates to your mental wellbeing is special-category personal data. We process it only with your explicit consent (açık rıza), given on the coach consent screen for that specific purpose, and we transfer it abroad — to MiniMax, for the sole purpose of generating your reply — on the basis of that same explicit consent, as permitted under Article 9. You have the rights listed in Article 11, including the right to learn whether your data is processed, to request its deletion and to object to results produced by automated analysis. You may also complain to the Kişisel Verileri Koruma Kurumu.
11. Children
Serai is designed for adults. It is not directed at children under 13 and we do not knowingly collect anything from them. The App Store rating is 13+ because of the free-form AI chat; our Terms ask you to be 16 or older.
12. Contact
Write to ahmetrnn03@gmail.com for anything on this page, including a request to delete data. We answer within 30 days, usually much sooner. For everything else, ahmetrnn03@gmail.com. See also Delete my data.