Your data is yours
Privacy Policy
Direct Intent Ltd · ICO registration ZC148712
Version 1.1 · September 2026
This policy covers data processed within the Seloa app only: your profile, matches, messages, Signals posts, and everything else that happens once you have an account. If you have not yet joined the beta and are only visiting this website, see the Site tab.
1. Who we are
Seloa is operated by Direct Intent Ltd, a company incorporated in England and Wales (company number 17192725) (“we”, “us”, “Seloa”).
- Registered office: 66 Paul Street, London, England, EC2A 4NA
- General contact: hello@seloa.app
- Privacy contact: privacy@seloa.app
- Security contact: security@seloa.app
We are registered with the ICO under reference ZC148712.
Seloa is a queer-first community and dating application. We take our responsibilities to our users seriously, including users who may not be publicly out regarding their sexual orientation or gender identity, or who may be in unsafe personal situations.
2. The data we collect and why
Seloa collects the minimum data needed to operate a safe, consent-driven queer community and dating app.
| Data category | What we collect | Why / legal basis |
|---|---|---|
| Account identity | Email address, username, date of birth | Contract (account creation); legal obligation (age verification) |
| Legal name | Your real name, collected at signup, encrypted at rest. Never shown to other users. | Legal obligation and safety |
| Identity data (special category, Art. 9 UK GDPR) | Gender identities, pronouns, sexual orientation, matching preferences | Explicit consent. Never shared with third parties for advertising. |
| Profile content | Bio, ideal first date, top artists, interests, prompt answers, communication style | Contract |
| Photos | Up to 5 photos. One real photo required at signup. Photo moderation checks run via Sightengine. | Contract |
| Queer flag accent | An optional flag identity accent, stored encrypted at rest. Visibility toggled by you. | Explicit consent. Special category data under Art. 9 UK GDPR. |
| Location (Dating mode) | No precise location stored. Coarse location (city/area) used only for profile discovery. | Contract; legitimate interest |
| Location (Signals) | No GPS stored. You choose a coarse area label when composing a Signal post. | Contract; consent at post composition |
| Behavioural data | Swipe actions, match interactions, message timestamps, image permission requests, ghost detection events | Contract; legitimate interest (behaviour scoring) |
| Signals posts | Post body, content warning (if added), intent category, expiry, coarse location, reactions received | Contract. Posts expire by default. |
| Signal thread messages | Private messages between a post author and a responding user | Contract. Visible only to the two participants. |
| Reports and moderation | Report content, immutable snapshots at time of report, moderation decisions | Legal obligation; legitimate interest |
| Device and usage data | Push notification tokens, app version, session data | Legitimate interest |
| Age verification | A government ID photo and a selfie/liveness check, captured at signup and processed by Didit, our identity verification partner (see Third-party processors below). Didit returns only a pass/fail result to us; we do not receive or store the document image or biometric data ourselves — only the verification status and a timestamp. | Legal obligation (age verification) |
| Supporter status | Whether you hold a paid supporter membership, and when it started/expires. No payment card details are stored by us. | Contract |
| AI opener usage | How many AI-generated conversation openers you've used that day, so we can apply a fair daily limit. | Legitimate interest (abuse prevention) |
| Invite relationships | If you invited someone (or were invited) to the beta, we keep a record of that relationship. | Legitimate interest (invite administration) |
| Consent records | Timestamps of acceptance for Terms, Privacy Policy, and special category consent. Version numbers recorded for re-consent tracking. | Legal obligation (UK GDPR Art. 7; Art. 9) |
| Invite email | Email address collected when we send you an invitation to join the app beta. Stored in our invite system only. Not linked to your account after signup is complete. | Legitimate interest (invite administration) |
3. Your legal name: a plain statement
- We collect your real name at signup for safety and legal compliance only.
- It is encrypted at rest using Supabase Vault and cannot be read without the decryption key.
- It is never shown to other users: not on your profile, not in messages, not in notifications, not anywhere in the app.
- Your username is your only public identity on Seloa.
- It will only be disclosed to law enforcement in response to a valid UK court order or production order. We do not voluntarily disclose it.
- We will notify you of any such request where the law permits us to do so.
- It is deleted when you delete your account.
- Business/venue staff accounts go through a separate, equivalent encrypted-name process when they join a business account — the same protections apply.
4. Your queer flag accent
You may optionally set a queer flag accent on your profile. This is special category data under UK GDPR Article 9, processed on the basis of your explicit consent. It is stored encrypted at rest. You control whether it is visible to other users via a toggle in your profile settings. It is never shared with third parties.
5. The behaviour scoring system
Seloa operates a behaviour scoring system to protect users from poor conduct. In-app interactions are used to derive a score band (green, amber, or red) that is visible to you in Settings. Your band affects your visibility and access to certain features. A recovery window allows your score to improve through positive engagement over time.
The legal basis is legitimate interest. The system protects the safety of all users.
6. Signals (Community mode)
- Posts are short-lived by default. You set an expiry of 12, 24, 72, or 168 hours when composing.
- Posts include a coarse location label (city or area). No GPS coordinates are stored at any point.
- Reaction counts on your posts are visible in your activity view. Reactor identity is never disclosed to you or to other users.
- Signal threads are private conversations between you and one other user only. They are not visible to anyone else.
- Your Signals standing is derived from your behaviour score band. It is visible to you but not to other users.
- You can pause composing and replies at any time in Community Settings.
7. Image permission system
Images in chat are transmitted only after a recipient explicitly grants permission to a sender's request. Permission requests and outcomes are recorded as part of the behaviour system. A 24-hour cooldown applies after a declined request in any given conversation. The legal basis is contract and legitimate interest.
8. Legal bases for processing
- Contract: to provide the service you signed up for.
- Explicit consent: for special category data under Article 9 UK GDPR.
- Legal obligation: age verification, Online Safety Act 2023 compliance, law enforcement disclosure under valid legal order.
- Legitimate interest: fraud prevention, safety, behaviour scoring, service improvement.
9. Third-party processors
These companies act under our instructions and are not permitted to use your data for their own purposes. We do not sell your data. We do not share your data with advertisers.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, edge functions, real-time messaging | USA (SCCs in place) |
| Sightengine | Photo moderation: detecting AI-generated or stock images at signup | EU |
| Didit | Age/identity verification at signup: captures a government ID photo and a selfie/liveness check on their own platform, then returns a pass/fail result to us. We never receive or store the document or biometric data itself. | EU (GDPR-compliant) |
| Resend | Transactional email (verification, notifications) | USA (SCCs in place) |
| Expo | Push notification delivery | USA (SCCs in place) |
| Anthropic (Claude Haiku) | AI-generated conversation opener on first message in Dating mode only. Anthropic receives limited profile context (your bio, ideal first date, top artists, interests, and prompt answer) to generate the opener. No message content is retained by Anthropic beyond the immediate API call. | USA (SCCs in place) |
| Mapbox | Converts a business/venue's own address into map coordinates for event listings. Business address data only — not your personal data. | USA (SCCs in place) |
| Companies House | UK government business registry lookup, used to verify a business account's registration details. Business data only — not your personal data. | UK |
Ko-fi and Tally are external platforms you may navigate to from within the app: Ko-fi for voluntary donations and Tally for optional feedback. When you use these services you leave the Seloa platform and their own privacy policies apply. Direct Intent Ltd does not receive personal data from these interactions and neither platform is a data processor acting on our behalf.
10. International transfers
Where data is transferred outside the UK, we rely on UK-approved Standard Contractual Clauses (SCCs) or equivalent adequacy mechanisms. Contact privacy@seloa.app for details.
11. Retention
Our aim is to keep data only for as long as it's needed, and no longer than the periods below — we're in the process of building the automated deletion tooling to enforce these consistently, so treat these as targets we're actively working towards rather than a guarantee that's already fully automated end to end.
- Account data is retained until you delete your account.
- Your legal name is deleted on account deletion.
- Special category identity data (gender identities, pronouns, sexual orientation) is deleted on account deletion.
- We aim to retain moderation records for no more than 12 months after the relevant event, for safety and accountability purposes.
- Behaviour events are used on a rolling 30-day basis for score calculation; older events are not used in scoring.
- We aim to retain match records (including expired and unmatched matches), and message thread content within those matches, for no more than 12 months.
- Consent records are retained for the account lifetime and for 6 years after deletion as evidence of lawful processing.
12. Your rights
Contact privacy@seloa.app to exercise any of the following rights.
- Right of access: a copy of the personal data we hold about you.
- Right to rectification: correction of inaccurate data.
- Right to erasure: deletion of your data, subject to legal retention obligations.
- Right to restriction: pausing processing in certain circumstances.
- Right to data portability: your data in a machine-readable format.
- Right to object: to processing based on legitimate interest.
- Right to withdraw consent: you can withdraw at any time. Withdrawal does not affect the lawfulness of prior processing.
You also have the right to lodge a complaint with the ICO at ico.org.uk/make-a-complaint or 0303 123 1113.
13. Special category data
Your gender identities, pronouns, sexual orientation, and queer flag accent are special category data under UK GDPR Article 9. We process this data only with your explicit consent, given at signup. You can withdraw consent at any time by deleting your account. We do not use this data for advertising, profiling for third parties, or any purpose beyond operating the matching and community features of Seloa.
14. Safety guidance for vulnerable users
Seloa serves users who may not be publicly out, or who may be in unsafe personal situations. Our architecture is designed to minimise identity exposure by default:
- Your legal name is never shown to other users.
- Your username is the only identity displayed anywhere on the platform.
- You control what information appears on your profile.
- Profile, chat, and Signal thread screens are shielded from screenshots: a full OS-level block on Android. Apple doesn't allow apps to block the screenshot itself, so on iOS we detect when one is taken instead.
- You can delete your account at any time from the Settings screen.
If you are concerned about your safety or privacy while using Seloa, contact us at hello@seloa.app.
15. Online Safety Act 2023
Seloa is a user-to-user service subject to the Online Safety Act 2023. We take our obligations under this Act seriously, including duties to prevent illegal content and specific duties relating to cyberflashing and content harmful to children. Our image permission system, behaviour scoring, report system, and moderation architecture are all designed in part to fulfil these obligations.
16. Security
We take reasonable technical and organisational measures to protect your data, including encryption of sensitive fields at rest (Supabase Vault) and Row Level Security on our database. Our most sensitive tables are locked down entirely, with access only through audited server-side functions; everything else uses row-level policies that scope each person to their own data, so no one can read another user's data directly.
No system is completely secure. If you become aware of a security issue, contact us immediately at security@seloa.app.
17. Children
Seloa is strictly for users aged 18 and over. We verify this at signup with a government ID and selfie/liveness check via Didit (see Third-party processors above), not just a self-reported date of birth. If we discover, including through a report from another user, that an account belongs to someone under 18, that account is suspended pending review and any relevant data reported to the appropriate authority where legally required.
18. Changes to this policy
We will notify you of material changes via the app and by email. We record consent version numbers in your account. Where a material change requires fresh consent under UK GDPR, we will ask you to review and re-accept before you can continue using the app.
19. Contact
- Privacy: privacy@seloa.app
- General: hello@seloa.app
- Security: security@seloa.app
Direct Intent Ltd, 66 Paul Street, London, England, EC2A 4NA. Company number: 17192725. ICO registration: ZC148712.