Your data is yours

Privacy Policy

Direct Intent Ltd · ICO registration ZC148712

Version 1.1 · September 2026

This policy covers data processed within the Seloa app only: your profile, matches, messages, Signals posts, and everything else that happens once you have an account. If you have not yet joined the beta and are only visiting this website, see the Site tab.

1. Who we are

Seloa is operated by Direct Intent Ltd, a company incorporated in England and Wales (company number 17192725) (“we”, “us”, “Seloa”).

We are registered with the ICO under reference ZC148712.

Seloa is a queer-first community and dating application. We take our responsibilities to our users seriously, including users who may not be publicly out regarding their sexual orientation or gender identity, or who may be in unsafe personal situations.

2. The data we collect and why

Seloa collects the minimum data needed to operate a safe, consent-driven queer community and dating app.

Data categoryWhat we collectWhy / legal basis
Account identityEmail address, username, date of birthContract (account creation); legal obligation (age verification)
Legal nameYour real name, collected at signup, encrypted at rest. Never shown to other users.Legal obligation and safety
Identity data (special category, Art. 9 UK GDPR)Gender identities, pronouns, sexual orientation, matching preferencesExplicit consent. Never shared with third parties for advertising.
Profile contentBio, ideal first date, top artists, interests, prompt answers, communication styleContract
PhotosUp to 5 photos. One real photo required at signup. Photo moderation checks run via Sightengine.Contract
Queer flag accentAn optional flag identity accent, stored encrypted at rest. Visibility toggled by you.Explicit consent. Special category data under Art. 9 UK GDPR.
Location (Dating mode)No precise location stored. Coarse location (city/area) used only for profile discovery.Contract; legitimate interest
Location (Signals)No GPS stored. You choose a coarse area label when composing a Signal post.Contract; consent at post composition
Behavioural dataSwipe actions, match interactions, message timestamps, image permission requests, ghost detection eventsContract; legitimate interest (behaviour scoring)
Signals postsPost body, content warning (if added), intent category, expiry, coarse location, reactions receivedContract. Posts expire by default.
Signal thread messagesPrivate messages between a post author and a responding userContract. Visible only to the two participants.
Reports and moderationReport content, immutable snapshots at time of report, moderation decisionsLegal obligation; legitimate interest
Device and usage dataPush notification tokens, app version, session dataLegitimate interest
Age verificationA government ID photo and a selfie/liveness check, captured at signup and processed by Didit, our identity verification partner (see Third-party processors below). Didit returns only a pass/fail result to us; we do not receive or store the document image or biometric data ourselves — only the verification status and a timestamp.Legal obligation (age verification)
Supporter statusWhether you hold a paid supporter membership, and when it started/expires. No payment card details are stored by us.Contract
AI opener usageHow many AI-generated conversation openers you've used that day, so we can apply a fair daily limit.Legitimate interest (abuse prevention)
Invite relationshipsIf you invited someone (or were invited) to the beta, we keep a record of that relationship.Legitimate interest (invite administration)
Consent recordsTimestamps of acceptance for Terms, Privacy Policy, and special category consent. Version numbers recorded for re-consent tracking.Legal obligation (UK GDPR Art. 7; Art. 9)
Invite emailEmail address collected when we send you an invitation to join the app beta. Stored in our invite system only. Not linked to your account after signup is complete.Legitimate interest (invite administration)

3. Your legal name: a plain statement

  • We collect your real name at signup for safety and legal compliance only.
  • It is encrypted at rest using Supabase Vault and cannot be read without the decryption key.
  • It is never shown to other users: not on your profile, not in messages, not in notifications, not anywhere in the app.
  • Your username is your only public identity on Seloa.
  • It will only be disclosed to law enforcement in response to a valid UK court order or production order. We do not voluntarily disclose it.
  • We will notify you of any such request where the law permits us to do so.
  • It is deleted when you delete your account.
  • Business/venue staff accounts go through a separate, equivalent encrypted-name process when they join a business account — the same protections apply.

4. Your queer flag accent

You may optionally set a queer flag accent on your profile. This is special category data under UK GDPR Article 9, processed on the basis of your explicit consent. It is stored encrypted at rest. You control whether it is visible to other users via a toggle in your profile settings. It is never shared with third parties.

5. The behaviour scoring system

Seloa operates a behaviour scoring system to protect users from poor conduct. In-app interactions are used to derive a score band (green, amber, or red) that is visible to you in Settings. Your band affects your visibility and access to certain features. A recovery window allows your score to improve through positive engagement over time.

The legal basis is legitimate interest. The system protects the safety of all users.

6. Signals (Community mode)

  • Posts are short-lived by default. You set an expiry of 12, 24, 72, or 168 hours when composing.
  • Posts include a coarse location label (city or area). No GPS coordinates are stored at any point.
  • Reaction counts on your posts are visible in your activity view. Reactor identity is never disclosed to you or to other users.
  • Signal threads are private conversations between you and one other user only. They are not visible to anyone else.
  • Your Signals standing is derived from your behaviour score band. It is visible to you but not to other users.
  • You can pause composing and replies at any time in Community Settings.

7. Image permission system

Images in chat are transmitted only after a recipient explicitly grants permission to a sender's request. Permission requests and outcomes are recorded as part of the behaviour system. A 24-hour cooldown applies after a declined request in any given conversation. The legal basis is contract and legitimate interest.

8. Legal bases for processing

  • Contract: to provide the service you signed up for.
  • Explicit consent: for special category data under Article 9 UK GDPR.
  • Legal obligation: age verification, Online Safety Act 2023 compliance, law enforcement disclosure under valid legal order.
  • Legitimate interest: fraud prevention, safety, behaviour scoring, service improvement.

9. Third-party processors

These companies act under our instructions and are not permitted to use your data for their own purposes. We do not sell your data. We do not share your data with advertisers.

ProcessorPurposeLocation
SupabaseDatabase, authentication, file storage, edge functions, real-time messagingUSA (SCCs in place)
SightenginePhoto moderation: detecting AI-generated or stock images at signupEU
DiditAge/identity verification at signup: captures a government ID photo and a selfie/liveness check on their own platform, then returns a pass/fail result to us. We never receive or store the document or biometric data itself.EU (GDPR-compliant)
ResendTransactional email (verification, notifications)USA (SCCs in place)
ExpoPush notification deliveryUSA (SCCs in place)
Anthropic (Claude Haiku)AI-generated conversation opener on first message in Dating mode only. Anthropic receives limited profile context (your bio, ideal first date, top artists, interests, and prompt answer) to generate the opener. No message content is retained by Anthropic beyond the immediate API call.USA (SCCs in place)
MapboxConverts a business/venue's own address into map coordinates for event listings. Business address data only — not your personal data.USA (SCCs in place)
Companies HouseUK government business registry lookup, used to verify a business account's registration details. Business data only — not your personal data.UK

Ko-fi and Tally are external platforms you may navigate to from within the app: Ko-fi for voluntary donations and Tally for optional feedback. When you use these services you leave the Seloa platform and their own privacy policies apply. Direct Intent Ltd does not receive personal data from these interactions and neither platform is a data processor acting on our behalf.

10. International transfers

Where data is transferred outside the UK, we rely on UK-approved Standard Contractual Clauses (SCCs) or equivalent adequacy mechanisms. Contact privacy@seloa.app for details.

11. Retention

Our aim is to keep data only for as long as it's needed, and no longer than the periods below — we're in the process of building the automated deletion tooling to enforce these consistently, so treat these as targets we're actively working towards rather than a guarantee that's already fully automated end to end.

  • Account data is retained until you delete your account.
  • Your legal name is deleted on account deletion.
  • Special category identity data (gender identities, pronouns, sexual orientation) is deleted on account deletion.
  • We aim to retain moderation records for no more than 12 months after the relevant event, for safety and accountability purposes.
  • Behaviour events are used on a rolling 30-day basis for score calculation; older events are not used in scoring.
  • We aim to retain match records (including expired and unmatched matches), and message thread content within those matches, for no more than 12 months.
  • Consent records are retained for the account lifetime and for 6 years after deletion as evidence of lawful processing.

12. Your rights

Contact privacy@seloa.app to exercise any of the following rights.

  • Right of access: a copy of the personal data we hold about you.
  • Right to rectification: correction of inaccurate data.
  • Right to erasure: deletion of your data, subject to legal retention obligations.
  • Right to restriction: pausing processing in certain circumstances.
  • Right to data portability: your data in a machine-readable format.
  • Right to object: to processing based on legitimate interest.
  • Right to withdraw consent: you can withdraw at any time. Withdrawal does not affect the lawfulness of prior processing.

You also have the right to lodge a complaint with the ICO at ico.org.uk/make-a-complaint or 0303 123 1113.

13. Special category data

Your gender identities, pronouns, sexual orientation, and queer flag accent are special category data under UK GDPR Article 9. We process this data only with your explicit consent, given at signup. You can withdraw consent at any time by deleting your account. We do not use this data for advertising, profiling for third parties, or any purpose beyond operating the matching and community features of Seloa.

14. Safety guidance for vulnerable users

Seloa serves users who may not be publicly out, or who may be in unsafe personal situations. Our architecture is designed to minimise identity exposure by default:

  • Your legal name is never shown to other users.
  • Your username is the only identity displayed anywhere on the platform.
  • You control what information appears on your profile.
  • Profile, chat, and Signal thread screens are shielded from screenshots: a full OS-level block on Android. Apple doesn't allow apps to block the screenshot itself, so on iOS we detect when one is taken instead.
  • You can delete your account at any time from the Settings screen.

If you are concerned about your safety or privacy while using Seloa, contact us at hello@seloa.app.

15. Online Safety Act 2023

Seloa is a user-to-user service subject to the Online Safety Act 2023. We take our obligations under this Act seriously, including duties to prevent illegal content and specific duties relating to cyberflashing and content harmful to children. Our image permission system, behaviour scoring, report system, and moderation architecture are all designed in part to fulfil these obligations.

16. Security

We take reasonable technical and organisational measures to protect your data, including encryption of sensitive fields at rest (Supabase Vault) and Row Level Security on our database. Our most sensitive tables are locked down entirely, with access only through audited server-side functions; everything else uses row-level policies that scope each person to their own data, so no one can read another user's data directly.

No system is completely secure. If you become aware of a security issue, contact us immediately at security@seloa.app.

17. Children

Seloa is strictly for users aged 18 and over. We verify this at signup with a government ID and selfie/liveness check via Didit (see Third-party processors above), not just a self-reported date of birth. If we discover, including through a report from another user, that an account belongs to someone under 18, that account is suspended pending review and any relevant data reported to the appropriate authority where legally required.

18. Changes to this policy

We will notify you of material changes via the app and by email. We record consent version numbers in your account. Where a material change requires fresh consent under UK GDPR, we will ask you to review and re-accept before you can continue using the app.

19. Contact

Direct Intent Ltd, 66 Paul Street, London, England, EC2A 4NA. Company number: 17192725. ICO registration: ZC148712.