Privacy

Privacy and your data

This page explains what happens to your data in Selera, from signing in and uploading a document to AI explanations and deletion.

Updated 10 October 2026

Who to contact

Selera was created by Yaroslav Tykhonchuk. For questions about personal data, access or deletion, write to hello@selera.health.

The data we process

  • Account: your email address, language, sign-in data and consent record. When you sign in with Google, we also receive the profile information Google provides for authentication, including your name and photo.
  • Records: names and information you add about people, including dates of birth and family relationships.
  • Health history: uploaded files, notes, extracted values, diagnoses from documents, prescriptions, plans and doctor summaries.
  • AI explanations: your questions and the answers in your conversation.
  • Technical data: IP address, browser information, request times, identifiers, statuses and error codes needed to operate and protect the service.

Documents may contain names and other personal information. Signing in with only an email address does not make uploaded documents anonymous.

Why we use the data

To let you sign in, store your history, read documents and notes, show changes in values, prepare summaries and explanations, provide the access you choose and keep the service running.

Before using a record, you give separate consent to the processing of health data. We do not sell your data or use it for advertising targeting.

Only add information about other people when you have the right to do so, including their consent or lawful authority to act on their behalf.

Who has access

Only you can see your own “Me” record. You can invite people to relatives’ records: they receive access only to selected records and can add and correct data. The record owner controls access.

An AI conversation is private to the person asking questions. Other users of that record cannot see it.

A doctor summary opens without registration. Anyone with its active link can see it. You choose its expiry and can revoke it. Revoking a link does not delete a PDF or screenshot someone has already saved.

Administrative access to storage is needed for support, handling your requests and manually deleting accounts. Private records do not mean that the service operator is technically unable to access them.

Storage and providers

Cloudflare. Hosts the site and app, database, files, sign-in emails and PDF generation. The main database and file storage are configured for EU storage. Request processing and other infrastructure operations may take place outside the EU.

Anthropic. Reads documents and notes and creates explanations and short summaries. For extraction, we send the file or note contents. For an explanation, we send your question, conversation history and record text: values, units, reference ranges, diagnoses and prescriptions. A relative’s record may also include its name and age.

This processing may take place outside the EU, including in the US. Under the standard Anthropic API policy, inputs and outputs are deleted within 30 days, with exceptions including safety and legal requirements. Under its commercial API terms, use for model training requires a separate opt-in.

Google. If you choose Google sign-in, Google processes authentication under its own policies. The public website also loads Google Fonts: that request gives Google connection information, including your IP address.

EU storage of the main record does not mean its contents are never sent outside the EU.

Retention and deletion

We keep record data while you use the service and have not deleted it. Deleting a document removes its file and associated record data. Deleting a relative’s record removes its documents, notes and saved summaries.

A saved summary is a separate snapshot. Deleting its source document does not automatically remove facts from an already saved summary: delete that summary separately.

“Start over” deletes your AI conversation. Deleting a record also deletes its associated conversations.

In the current beta, we manually delete your own record and account on request to hello@selera.health. Write from the email address you use to sign in so we can verify the request.

The database’s recovery history covers up to 30 days, so deleted records may remain in that backup history during this period. Deletion in Selera does not erase copies others have already saved or change the AI provider’s request retention periods.

Cookies and technical logs

Cookies support sign-in and remembering your language. The language cookie lasts up to a year and is shared by the site and app. The current version has no advertising trackers.

Application logs do not record document contents, notes, lab values, AI questions or answers. Technical logs contain request information, identifiers, statuses and errors. Request logging and caching in AI Gateway are disabled.

Your requests and changes

To request a copy of your data, correction, deletion, an end to processing or withdrawal of consent, write to hello@selera.health. We may ask for additional verification of your right to the data. Withdrawal stops future processing and does not undo processing that has already taken place.

If you believe processing infringes your rights, you can contact the competent data protection authority in your country.

We update this page when data uses or providers change. Where new consent is required, we ask for it in the app.