Legal
Privacy Policy
Last updated: August 9, 2026
This policy explains what Selis collects, why, and what it does not do with your data. If a sentence here doesn't match what the app actually does, tell us — that's a bug in the policy, not a license to read it loosely.
The short version
- Using Selis without sync: nothing leaves your device. There's no account, no server contact, no analytics tied to your notes.
- Turning on sync: your notes are encrypted on your device before upload. Our server stores ciphertext it cannot decrypt — we don't have your key.
- We don't sell data, run ads, or share your notes with anyone. There's nothing to sell — we can't read them either.
What we collect, by feature
Using Selis without sync (free tier)
Notes, settings, and everything else are stored only in a local database on your device. Nothing is transmitted anywhere. No account is created or required.
Signing in and syncing (paid tier)
Signing in uses Google or Apple's own sign-in — we receive your email address and a stable account identifier from them, used only to identify your Selis account. We never see your Google or Apple password.
Once signed in, you set a master password. It never leaves your device — Selis uses it to derive an encryption key locally, and that key encrypts your notes before they're sent to our server. The server stores encrypted data (ciphertext) and cannot decrypt it: we don't hold your master password or the key derived from it. If you forget your master password, your encrypted data cannot be recovered by us either — there's no back door, including for us.
Push notifications
To tell your other signed-in devices that something changed (so they sync promptly instead of polling), we use Firebase Cloud Messaging (Google) on mobile and a direct connection on desktop. This only carries a "something changed, go sync" signal — never note content.
Crash reports and error logs
If the app crashes or hits an error, diagnostic information (what failed, a stack trace, device/OS info) is sent to our own self-hosted error-tracking instance — not a third-party analytics company. This can include which screen you were on, but not your note content.
In-app purchases
Selis Pro (monthly or annual) is billed entirely by Apple's or Google's own payment systems, always in your local currency. We receive confirmation that a purchase was made and which plan, not your payment details — we never see your card number.
What we don't do
- We don't sell or rent your data to anyone.
- We don't run advertising or ad-tracking of any kind.
- We don't read your notes — with sync on, we structurally can't; the server only ever sees encrypted bytes.
- We don't share data with third parties beyond the specific, named purposes above (sign-in identity verification, push delivery, payment processing).
Your data, your control
You can delete your account and its server-side data at any time from within the app ("Start fresh" in Sync settings), which removes your encrypted notes and account record from our server. Uninstalling the app removes everything stored locally.
Changes to this policy
If this policy changes in a way that affects what we collect, we'll update the date above and, for material changes, note it in the app.
Contact
Questions about this policy: support@selis.day