Selora Health LLC ("Selora", "we", "us"), a California limited liability company at 6280 W Las Positas Blvd, Ste B #1010, Pleasanton, CA 94588, USA, operates the Selora app and service. This policy explains what we collect, why, how we use and share it, how long we keep it, and your choices. Selora is a US-based consumer wellness and self-tracking app. It is not a HIPAA-covered entity and this is not a HIPAA notice, but we handle sensitive health-related data and treat it with heightened care. Selora does not provide medical advice, diagnosis, or treatment.
1. Data we collect
Selora is offline-first: most data is created and usable locally on your device. Data listed as synced below is transmitted to our server to provide cross-device persistence, real history-derived stats, and the AI features described in section 4. Local-only settings never leave your device.
- Account — email address, hashed password, session tokens. (synced — authentication)
- Training — workouts, sets/reps/weights, cardio and activity bouts, plans, custom exercises, strength baselines. (synced)
- Protocol / therapies — the compounds, supplements, and hormone/peptide/metabolic therapies you choose to log, and your dose logs. You have chosen or been prescribed these elsewhere; Selora does not prescribe. (synced — sensitive)
- Labs — lab-report files (images/PDFs) you upload, and the marker values, units, and reference ranges extracted from them. The most sensitive category (see section 4). (synced; files stored server-side; sent to our AI subprocessor for extraction)
- Body & check-ins — bodyweight, body composition, habits, and daily check-ins (mood, energy, sleep, stress, focus, libido, symptoms, and any notes you add). (synced — sensitive)
- Fuel — hydration and food/macro logs. If you log a meal by photo or typed description, that photo or text is sent to our AI subprocessor to suggest the items and macros for you to confirm (section 4). (synced)
- Demographics — your biological sex and birth date, used to select the correct age- and sex-specific lab reference ranges and stats. (synced, if you enter them)
- Connected health platforms (optional) — if you connect Apple Health or Health Connect, we read the metrics you authorize (activity, workouts, heart rate, HRV, sleep, body composition, and vitals) to show them alongside your logged data, and we write your Selora workouts, weight, water, and meals back to your health platform. Write-back sends data out to your platform at your request; it is not additional collection by us. You control exactly what is shared and can change it anytime in your phone's health settings. (read-in data is synced; off until you connect)
- Purchases — subscription/entitlement status via the app stores and RevenueCat. No card or payment-instrument data touches Selora; the app stores process payment. (synced when you subscribe)
- Diagnostics & analytics — crash reports (Sentry) are collected automatically in release builds and are stripped of health data before anything leaves your device, under our default-deny allowlist. Pseudonymous product-analytics events (PostHog) are opt-in and off by default, stripped the same way. No workout, dose, lab, or other health value is ever included in either. (analytics off until you turn it on)
- Server access logs — standard request logs (IP address, app version, platform/OS, timestamps) for security and reliability. (server-side)
What stays local (not collected): theme, unit toggle, alert/haptic/sound preferences, rest-timer, feature-flag overrides, the in-app network meter, and local notification schedules never leave your device. In-app "Report a problem" sends a diagnostics email, free of health data, only when you choose to send it.
2. How we use it
To provide the Service: store, sync, and display your data and compute your real stats; authenticate you; power the AI features you choose to use (section 4); send reminders you set; manage your subscription; fix crashes (crash reports never include your health data); and, only if you opt in, understand product usage in aggregate.
We do not sell your personal data. We do not share it for advertising. We do not use your content to train AI models. No advertising SDKs, no data brokers, no cross-app tracking.
3. Legal bases & consent
- Consent is opt-in, not opt-out. We ask for your explicit consent before we store/sync your health data, before we send a lab file to our AI subprocessor (section 4), before we enable analytics, before we connect a health platform, and before we send marketing email. Nothing is pre-checked; declining any one of these does not break the app (Selora works offline).
- Sensitive consumer-health data (labs, therapies, symptoms, libido, sex) is processed only with your explicit opt-in consent, which you can withdraw at any time (section 9).
- Providing the Service you request is the basis for the core processing needed to run your account (authentication, sync, subscription).
- Launch posture is US-first. The EU/EEA is not a launch market. If we open an EU market we will add an explicit GDPR Article 9 consent flow and appoint an EU representative before doing so.
- You can withdraw any consent at any time (section 9); withdrawal stops future processing but does not undo processing already performed.
4. Third-party AI processing
Selora's AI features are powered by our AI subprocessor, Anthropic. Each flow below is gated behind an explicit consent notice shown before your first use, sends no account identifier, and none of it is used to train AI models.
Lab documents. When you upload a lab report, the file you upload is transmitted to Anthropic solely to extract the results and the reference ranges printed on your report. Only the file is sent — not your name, email, or account identifier. The extracted values are then saved to your account. Automated reading can make mistakes, so you should check every extracted value against your original report before relying on it. Selora shows the values and the ranges printed on your report; it does not interpret them or tell you whether a result is normal. A persistent reminder sits on the upload screen.
Meal photos and descriptions. When you log a meal by photo or typed description, that photo or text is sent to Anthropic solely to suggest the food items and macros, which you review and confirm before they are logged. Only the photo or text is sent — no name, email, or account identifier.
Training plans and the AI coach. When you use AI plan drafting or the AI training coach, Selora sends your request and, for the coach, your current training plan (the exercises, sets, and target reps in it), a short summary of your recent training (which lifts you have been doing, your weekly sets per exercise, and whether each has been progressing or has stalled), and the messages you type in the chat. Your actual weights, your lab results, and anything you log in Protocol (medications, supplements, and doses) are not sent — they are excluded before anything leaves your device. Because your typed messages are sent, please keep personal health details out of the chat. The coach drafts training plans only; it is not medical advice and never suggests medications, supplements, or doses, and you review and edit every change before it is applied. Selora does not store the coach conversation.
5. Who we share data with (subprocessors)
We share data only with service providers who process it on our behalf under contractual data-protection terms. Transfer to a service provider acting on our instructions is processing, not a sale or ad-share.
| Subprocessor | Purpose | Data it receives | Region |
|---|---|---|---|
| Anthropic, PBC | (1) Automated extraction of lab-result values and reference ranges from lab reports you upload. (2) Suggesting food items and macros from meal photos or descriptions you log. (3) Drafting and revising your training plans in the AI coach. | (1) The lab-report file (image/PDF) you upload — file only, no account id or email. (2) The meal photo or typed description — content only, no account id or email. (3) Your current training-plan structure (exercises, sets, target reps), a summary of your recent training (weekly set counts and progression flags), and the messages you type to the coach — not your weights, lab results, or the medications/supplements/doses you log, and no account id or email. None of it is used to train AI models. | United States |
| RevenueCat | Subscription / entitlement management | Purchase and entitlement state plus a pseudonymous app-user id. No health data. | United States |
| PostHog (EU Cloud) | Product analytics (only if you opt in) | Pseudonymous events, stripped of health data under our allowlist | European Union |
| Sentry | Crash / error diagnostics (automatic in release builds) | Error metadata, stripped of health data under our allowlist | United States |
| Resend | Transactional and (opt-in) lifecycle email | Your email address and non-health message content | United States |
| Expo | Delivery of the push notifications you enable | An opaque device push token and platform; fixed notification text, no health data | United States |
| Fly.io (+ Tigris for backups) | Server and database hosting; stores your synced data and uploaded files at rest, with continuous encrypted backup | All synced user data at rest | United States |
| Cloudflare | Website hosting and delivery (selorahealth.ai) | Standard web-request data for site visitors (section 12) | Global (platform) |
| Plausible | Website visit analytics — cookieless, no advertising trackers | Aggregate, anonymized site-visit counts; no account or health data | European Union |
| Apple / Google | App distribution and in-app-purchase payment processing | Purchase/account data (store-processed) | Global (platform) |
Anthropic, in full: Anthropic receives only the content each AI flow needs — the lab-report file, the meal photo or description, or the coach's training context and chat messages; no Selora account identifier, email, or contact data is ever sent, and none of it is used to train AI models. Anthropic retains API inputs only as long as needed to provide the service and meet its legal and safety obligations, under its data-processing terms. Selora stores your lab files, meal photos, and extracted values in your account until you delete them or close your account; Selora does not retain the coach conversation.
We may also disclose data if required by law or to protect rights and safety. If we ever add or change a subprocessor, we update this list and, for a material change, notify you (section 11).
6. International transfers
For users outside the US, your data is processed in the United States (hosting on Fly.io, US region). The one exception is product analytics, which stays in the EU (PostHog EU Cloud). Where required, transfers rely on Standard Contractual Clauses.
7. Data retention
- While your account is active, we retain your synced data so it is available across your devices.
- Account deletion cascades a true erasure of all of your data: every account-scoped record, uploaded lab and meal files, extracted values, sessions, and your password hash are deleted server-side. Residual copies in our encrypted backups are purged automatically within 30 days.
- Per-item deletion: you can delete an individual lab report or logged meal, which removes its extracted values and any stored file from your account.
- Data export is available so you can take your data with you (section 9).
- Session tokens expire after 90 days; each login mints a fresh token.
- Server access logs (including IP) are retained for up to 30 days and then deleted.
- Anthropic retains API inputs only transiently to provide the service and meet legal and safety obligations, under its data-processing terms (section 5).
8. Security
Passwords are scrypt-hashed; sessions are opaque bearer tokens with expiry, rotation, and a logout-all control; all data is per-user scoped and transmitted over TLS/HTTPS. Signup abuse controls (rate limits, an optional invite code, and a daily signup ceiling) protect the service. Access to production data is restricted. Data at rest is encrypted: the database and uploaded lab files sit on an encrypted volume, and continuous backups are server-side encrypted. No method of transmission or storage is 100% secure, but we work to protect your data.
9. Your rights & choices
- Access / export — download a complete copy of your data any time in Settings → Your data → Export my data in the app (one JSON file, delivered to your device's share sheet). No longer have the app? Email support@selorahealth.ai and we'll send you a copy.
- Delete — delete your account and all associated data in Settings → Delete account in the app, or via our web deletion page at selorahealth.ai/delete-account. Deletion is a true server-side erasure (section 7).
- Withdraw consent / control processing:
- Share anonymous usage analytics — a toggle in Settings, off by default; turn it off to stop all product analytics.
- Disconnect Apple Health / Health Connect — in Settings; stops our reads and writes. You can also revoke per-type access in your phone's health settings.
- AI features (lab uploads, meal photos, the coach) are each consent-gated before first use. To withdraw a consent you've given, email privacy@selorahealth.ai and we will block future use until you consent again.
- Selora works fully offline. To stop and erase all server processing of your data, delete your account (above); for anything else, email privacy@selorahealth.ai.
- Marketing email — every marketing email includes an unsubscribe link (transactional email continues).
- Regional rights — depending on where you live you may have rights under GDPR/UK GDPR, CCPA/CPRA (California), and the Washington My Health My Data Act (and CT/NV analogues): to access, correct, delete, port, and, where applicable, restrict or object to processing, plus the right not to be discriminated against for exercising them. We do not sell or "share" personal data as those laws define it. To exercise a right, contact us (section 13).
10. Minimum age
You must be at least 16 years old to create an account or use the Service; if you are under the age of majority where you live, you may use it only with a parent or guardian's permission. The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn we have, we will delete it.
11. Changes
We'll post changes here with a new "Last updated" date. For material changes we'll notify you in-app or by email and, where required, re-request your consent.
12. Our website and the waitlist
This policy also covers selorahealth.ai. If you join the waitlist, we collect your email address (and, optionally, what you're most interested in) and use it only to tell you when Selora Health launches — no spam, no selling, and every email includes an unsubscribe link. Waitlist email is sent via Resend (section 5). The site uses Plausible, a cookieless visit-analytics service hosted in the EU, to count visits in aggregate; we run no advertising trackers on the site. The site is hosted on Cloudflare, and standard server logs apply (section 1).
13. Contact
Privacy contact: privacy@selorahealth.ai ·
Support: support@selorahealth.ai ·
Legal notices: legal@selorahealth.ai
Entity: Selora Health LLC, 6280 W Las Positas Blvd, Ste B #1010,
Pleasanton, CA 94588, USA (California limited liability company).
EU/UK representative and DPO: not applicable at US launch (EU market
not opened); we will appoint one before opening an EU market.