Legal document

Serena AI Companion Privacy Policy

Updated on Aug 31, 2026 v 2026.08.31

In short

  • Serena is local-first; persistent conversations, memories, tasks, reminders, preferences, and the optional name stay on the device by default.
  • A technical Firebase guest session protects consent, the lifetime 10-response balance, and purchase access; Google or Apple linking is optional except for secure backup and cross-device recovery.
  • Serena requests separate permission for message and context processing by Google Cloud Gemini and voice-note transcription by Cloudflare; Iugu processes eligible Brazilian Pix payments.

Plain-Language Summary

This summary explains, in simple language, what this Privacy Policy covers. It is not a substitute for the full Privacy Policy below.

Serena AI Companion is a wellness-focused AI companion app. Serena uses a local-first design: your persistent conversation history, memories, tasks, reminders, and preferences are stored locally on your device by default. Serena does not sell your personal data and does not show ads.

Some data must still be processed outside your device. After you accept the required Terms, Privacy Policy, and age confirmation, Firebase Authentication creates a technical guest identifier so Serena can protect consent, the lifetime balance of 10 complimentary responses, and purchase access without requiring a name, email address, Google, or Apple account. Google and Apple login are optional for store and Pix purchases. After a Pix payment is confirmed, you may optionally link the same guest session to Google or Apple to recover paid access after reinstalling Serena or changing devices; a linked account is required only for encrypted backup and cross-device recovery. RevenueCat, Apple App Store, and Google Play handle store purchase metadata; Serena’s backend combines valid store access with local Pix grants; and Iugu processes Pix invoices. Before the first AI message request, Serena separately asks permission to send the message and necessary context to Google Cloud Gemini. Before the first voice transcription, Serena separately asks permission to send the voice-note audio to Cloudflare. Security tools such as Firebase App Check help protect the App from abuse.

Serena also offers an optional secure backup feature after you choose to link Google or Apple. If you turn it on, Serena creates an encrypted backup package on your device and uploads only encrypted backup data and technical metadata to Firebase/Google Cloud infrastructure. We do not receive the plaintext contents of your conversations, memories, tasks, transcripts, or preferences as part of secure backup.

You can delete your account and erase local data in the App. Depending on where you live, you may also have privacy rights such as access, deletion, correction, portability, objection, restriction, or opt-out rights.

1. Scope of This Policy

This Privacy Policy explains how SERENA TECNOLOGIA E BEM ESTAR LTDA. (“Company”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects information when you use Serena AI Companion (“Serena”, the “App”, or the “Service”).

This Policy applies to the Serena mobile app and related support, account, subscription, AI, transcription, and security services.

This Policy should be read together with our Terms of Use.

2. Wellness App Notice

Serena is a wellness-focused AI companion. It is not a regulated professional advice service, licensed provider, emergency response service, or safety-critical service. You should not use Serena as a substitute for qualified human judgment in regulated, high-risk, urgent, or safety-critical situations.

If you are in immediate danger or need urgent help, contact local emergency services or an appropriate trusted resource.

3. Information We Process

We process only the information needed to operate, secure, improve, and support Serena.

After you accept the required Terms, Privacy Policy, and age confirmation, Serena creates a Firebase guest session with a technical Firebase user ID. This lets the App protect your consent and subscription state without requiring a name, email address, Google, or Apple account. The guest identifier is not presented as a social profile, does not by itself enable remote backup, and is not used for advertising. AI-message processing and voice transcription are not required to create this session, view local data, manage settings, or access purchase and restoration options.

You may voluntarily link Google Sign-In or Sign in with Apple to the same Firebase user ID. That link enables optional secure backup and access on another device. Depending on the provider and your settings, we may receive or process:

  1. Firebase user ID, whether guest or linked.
  2. Provider identifier when you choose to link Google or Apple.
  3. Email address or Apple private relay email only when provided by a linked provider.
  4. Display name or profile metadata only when provided by a linked provider.
  5. Login timestamps and authentication metadata.
  6. Security and fraud-prevention signals processed by Firebase.

We do not operate a Serena password system and do not store your Google or Apple password.

3.2 Subscription and Purchase Information

Serena determines premium access by aggregating valid store entitlement information with any active Pix grant recorded by Serena’s backend. RevenueCat projects Apple App Store and Google Play receipt status, paywall offerings, and store restoration, and may receive a promotional projection of a Pix grant. That promotional record is not an independent payment source, and a RevenueCat outage does not invalidate an otherwise valid local Pix grant. Apple App Store and Google Play process store purchases, billing, renewals, cancellations, refunds, and store account management. Iugu processes Pix invoices, payment confirmation, and Pix refunds.

Subscription-related information may include:

  1. Serena App User ID based on your guest or linked Firebase user ID.
  2. RevenueCat customer and subscription identifiers associated with that Firebase user ID.
  3. Subscription or grant status, renewal status, cancellation or refund status, and access expiration.
  4. Product identifiers, such as Serena Unlimited annual subscription.
  5. Store, platform, region, and app version information needed for subscription management and support.
  6. For Pix, the internal attempt/order/grant identifiers, invoice identifier, amount, currency, status, timestamps, idempotency references, sanitized provider status, and the payer name you provide.
  7. Apple or Google external-purchase tokens and disclosure results, stored in restricted server-only records and reported with transaction, refund, correction, or no-purchase status as the platform requires. These tokens are never returned by read endpoints or used as document identifiers.
  8. Immutable financial-ledger and reporting records needed for reconciliation, tax, accounting, fraud prevention, disputes, refunds, and platform commissions.

For Iugu invoice creation, Serena sends the payer name you provide and the fixed operational email serena@serenaapp.com. It does not send your linked Google/Apple email, CPF/CNPJ, phone, address, full card number, bank-account credentials, or Pix banking credentials in the approved invoice request. Iugu and participating financial institutions may separately process data required to complete the Pix payment. Serena does not receive your full payment card number from Apple, Google, or Iugu.

3.2A Lifetime Complimentary Message Balance

Serena uses a server-only operational ledger to enforce 10 complimentary completed AI message responses once per account. Active annual access bypasses consumption while it remains valid. The request sends the technical Firebase user ID through authentication, a random logical request identifier, and a strict text-or-voice channel value. Serena reserves one response before processing, commits it only after a completed response is delivered, and releases or expires the reservation after an error or attempt without a completed response.

The ledger stores only the contract version, limit, used-response count, random pending and committed request identifiers with operational timestamps, and initialization/update timestamps. It does not contain message text, audio, transcripts, prompts, AI responses, names, email addresses, or local conversation history. Because the balance is lifetime rather than daily, the current ledger is retained with the account to prevent repeated grants and is deleted or de-identified through the applicable account-deletion process, subject to security and legal requirements. We use it only to enforce the lifetime balance, preserve idempotency, prevent abuse, troubleshoot access state, and distinguish complimentary from active annual access.

3.3 Local App Data

The following persistent data is stored locally on your device by default:

  1. Conversation history.
  2. Memories generated or saved in the App.
  3. Tasks, reminders, and gentle follow-ups.
  4. Preferences and settings.
  5. Voice-note transcripts saved as conversation text.
  6. Optional name or nickname and other local profile details used inside the App.

Your name or nickname is optional. It is not required to use chat, receive the 10 complimentary responses, buy or restore a store subscription, or manage settings. If you provide one, Serena stores it in your local profile and may include it in the encrypted backup if you enable that feature. When you authorize AI-message processing and send a message, the name or nickname may be included in the necessary context sent to Google Cloud Gemini so Serena can address you naturally. A payer name is required separately only when you deliberately choose Pix; Serena sends that payer name to Iugu as described above.

This local data is not stored in a Serena cloud account by default. It may be deleted if you erase local data, uninstall the App, reset the device, lose the device, or delete local app storage.

If you enable local app lock, Serena uses your device’s own local authentication, such as Face ID, Touch ID, fingerprint, PIN, pattern, or device passcode, to help protect access to local app data. Serena does not receive, store, collect, or send your biometric data, device PIN, pattern, passcode, or hashes of those credentials. Local authentication is processed by the operating system on your device.

3.3A Optional Secure Backup

If you choose to enable secure backup, Serena may process:

  1. An encrypted backup package stored in Cloud Storage.
  2. Backup metadata stored in Firestore, such as backup ID, object path, size, checksums, creation time, app version, platform, and backup status.
  3. Encrypted key envelopes needed for recovery. These envelopes are designed so we do not receive the Account Backup Key, data encryption key, recovery code, or plaintext backup contents.
  4. App Check and Firebase Authentication tokens used to authorize backup, restore, and delete operations.

Secure backup is optional and available only after you voluntarily link Google or Apple. It is not the default storage location for your persistent app data. If you do not enable it, or remain in a guest session, your persistent conversation history, memories, tasks, reminders, and preferences remain local by default.

Secure backup is end-to-end encrypted by the App before upload. The encrypted package may leave your device, but the backup service is not designed to read its plaintext contents. You are responsible for keeping your recovery code and account access safe. If you lose the code and no longer have an already-enabled trusted device, we may not be able to help you decrypt a backup.

3.4 AI and Transcription Request Data

Serena requests separate, purpose-specific permission at the point of use. Before your first AI message request, the App asks permission to send your message and the necessary conversation context to Google Cloud Gemini. Before your first voice transcription, the App asks permission to send the voice-note audio to Cloudflare. The resulting transcript stays in the composer and is sent with necessary context to Gemini only if you separately authorize AI-message processing and choose to send it.

You can withdraw either permission independently in Settings. Refusing or withdrawing one permission disables only the corresponding external processing on that device: it does not erase existing local data and does not prevent access to purchases, restoration, settings, or other local features. A request already in progress may finish, and withdrawal does not by itself delete data previously processed by a provider. If you later try to use the affected feature, Serena asks for permission again before sending new data.

When you send a message or audio note, Serena may process the content needed for that request through Google Cloud Gemini for AI responses or Cloudflare for transcription infrastructure. This may include:

  1. The message you typed.
  2. The audio file or audio segment you asked to transcribe.
  3. Necessary context for the requested AI response.
  4. Language and technical request metadata.

We use this processing to generate replies, transcripts, and related App functionality. Provider processing is governed by our configurations, provider terms, and applicable law. We do not sell this content or use it for ads.

Audio notes used for chat transcription are treated as transient processing data. Serena does not store the audio file as chat history; after transcription, the transcript may remain in your local conversation history as text.

To improve contextual recall, Serena may select messages from your local history and send their text to Google Cloud to generate semantic query or document embeddings. The resulting vectors and search index are stored only in the App’s encrypted local database. Serena’s embedding backend relays the request and does not persist the message text or returned vectors. Google may still process and retain request data under our configurations, provider terms, and applicable law; we do not promise that provider retention is zero. When you clear chat history, delete a message, or erase the corresponding local data, Serena also deletes the derived local vectors. Secure backup may include messages, but it does not transport derived embeddings or the search index; those are regenerated after restore.

3.5 Security, App Check, Diagnostics, and Logs

Serena may process security and diagnostic data to protect the Service and maintain stability, including:

  1. Firebase App Check tokens and attestation signals.
  2. Device and app integrity signals.
  3. IP address and network metadata processed by service providers for security.
  4. App version, operating system, device model, and error information.
  5. Logs needed to investigate abuse, crashes, or technical issues.

If enabled, Firebase Crashlytics may process crash logs, device and operating system information, app version and build number, stack traces, and limited technical context such as locale, theme mode, authentication state, subscription state, startup phase, feature area, and build channel. We configure Serena’s app-controlled crash reporting fields to avoid sending conversation text, audio, transcripts, memories, tasks, prompts, AI responses, tokens, email addresses, local file paths, precise location, phone numbers, or full external-provider payloads. Crash diagnostics are used for app stability and security, not for advertising.

3.6 Support Communications

If you contact support, we may process:

  1. Your email address.
  2. Support message content.
  3. Support ID or Firebase user ID.
  4. Subscription status needed to resolve the request.
  5. Technical information you choose to provide.

Messages sent to support@serenaapp.com are handled manually as support communications and are not automatically ingested into the billing ledger. The fixed address serena@serenaapp.com used in Iugu invoice creation is an operational billing address and is not your support email or linked-account email.

4. How We Use Information

We use information to:

  1. Provide and operate Serena.
  2. Authenticate your account.
  3. Manage annual store subscriptions, Pix grants, and aggregated access.
  4. Restore purchases.
  5. Generate AI replies and transcribe audio.
  6. Store and display local app data on your device.
  7. Protect the App from abuse, fraud, and unauthorized access.
  8. Provide customer support.
  9. Debug, maintain, and improve the App.
  10. Comply with legal obligations and app store requirements.
  11. Enforce our Terms of Use and safety rules.
  12. Provide optional encrypted backup, restore, and backup deletion when you enable secure backup.

We do not sell personal data. We do not show ads in Serena. We do not share personal data for cross-context behavioral advertising.

Depending on your location, our legal bases for processing may include:

  1. Performance of a contract, such as providing the App, subscriptions, login, AI replies, transcription, and support.
  2. Legitimate interests, such as preventing abuse, securing the App, debugging, improving reliability, and understanding subscription status.
  3. Consent, where required by law, such as for certain permissions or optional processing.
  4. Compliance with legal obligations, such as tax, accounting, consumer protection, fraud prevention, or app store requirements.

6. How We Share Information

We share information only as needed to operate, secure, and support Serena.

6.1 Service Providers

We may share or make information available to:

  1. Firebase and Google services for authentication, App Check, infrastructure, and security.
  2. RevenueCat, Serena’s backend, Apple App Store, and Google Play for store purchase status, paywalls, aggregated access, restoration, promotional Pix projection, reporting, and support flows.
  3. Iugu for Pix invoice creation, payment confirmation, refund confirmation, reconciliation, and transaction support using the limited fields described above.
  4. Apple and Google for external-purchase token and transaction reporting required for alternative-payment compliance, including tokens that did not result in a purchase.
  5. Google Cloud Gemini for AI response generation.
  6. Cloudflare for transcription infrastructure and speech-to-text processing.
  7. Diagnostic and crash reporting providers, if enabled.
  8. Customer support tools, if used.
  9. Firebase and Google Cloud services for optional encrypted backup storage, metadata, App Check verification, and backup operations.

These providers process information according to their contracts, policies, and applicable legal obligations.

We may disclose information if we believe it is reasonably necessary to:

  1. Comply with law, regulation, legal process, or government request.
  2. Enforce our Terms.
  3. Detect, prevent, or address fraud, abuse, security issues, or technical issues.
  4. Protect the rights, safety, and property of users, the Company, or others.

6.3 Business Transfers

If we are involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to applicable law.

7. Local Data Controls

Because Serena stores persistent app data locally by default, many privacy controls are available directly on your device.

You may be able to:

  1. Clear chat history.
  2. Erase all local data.
  3. Delete tasks, reminders, and memories.
  4. Delete the App from your device.

Erasing local data deletes data on that device. It does not automatically refund purchases, end active annual access, or delete account, store, Pix, financial-ledger, or reporting metadata held by Firebase, RevenueCat, Serena’s backend, Iugu, Apple, Google, or participating financial institutions.

If secure backup is enabled, erasing local data on one device does not automatically delete the encrypted remote backup unless you also use the backup deletion control or account deletion flow that requests remote backup deletion.

8. Account Deletion

You can delete a guest session or linked account from within the App. Deleting a guest session removes its Firebase technical identifier and its Serena remote operational footprint, subject to legally required retention. Deleting a linked account removes or initiates deletion of the Firebase Authentication account and associated account metadata, subject to provider retention, security, backup, fraud-prevention, and legal requirements.

Where available, account deletion or the secure backup settings screen also lets you request deletion of the remote encrypted backup. Deleting the remote backup removes backup metadata and starts deletion of the encrypted storage object. Temporary infrastructure replicas or logs may persist for a limited period according to provider operations, but without the required keys the encrypted package is not designed to be readable by us.

When you delete a guest session or linked account, you may also choose or be prompted to erase local device data. Deletion does not automatically refund purchases or end active access. Serena deletes direct account links from operational billing state and may pseudonymize retained financial/reporting records, but it cannot erase records that must remain for legal, tax, accounting, platform-reporting, support, fraud-prevention, refund, or dispute obligations. Cancel a store subscription through Apple App Store or Google Play; contact support@serenaapp.com for Pix support or refund requests.

9. Retention

We retain information only for as long as needed for the purposes described in this Policy, unless a longer retention period is required or permitted by law.

Retention depends on the type of data:

  1. Local app data remains on your device until you delete it, erase local data, uninstall the App, reset the device, or the data is otherwise removed by device or operating system behavior.
  2. Firebase guest or linked-account metadata is retained while the session or account is active and then deleted or de-identified according to Firebase processes, legal requirements, and security needs.
  3. RevenueCat/store metadata and Serena’s Pix attempts, orders, grants, immutable ledger, reporting events/outboxes, Iugu references, and platform-token records may be retained as needed for access, reconciliation, accounting, fraud prevention, tax, platform reporting, legal compliance, refunds, dispute resolution, and customer support. Direct account links are removed or pseudonymized where the account-deletion process requires it, without corrupting mandatory financial evidence.
  4. AI and transcription request data is processed as needed to provide the requested response or transcript and then handled according to provider terms, our configurations, and applicable law.
  5. Manually handled support records may be retained as needed to resolve requests and maintain business records; they are separate from the automated billing ledger.
  6. Security logs may be retained for abuse prevention, debugging, and compliance.
  7. Optional secure backup remains until you replace it, delete it, delete your account where backup deletion is available, or the feature otherwise removes it according to the backup retention rules. Superseded or deleted backup objects may remain temporarily as encrypted operational residue until cleanup completes.
  8. Legal consent records are kept while a guest session or linked account is active to show the Terms of Use, Privacy Policy, document hashes, locale, app version, build number, platform, consent screen version, and timestamps accepted by the relevant Firebase technical identifier. When a guest session or linked account is deleted, Serena may move a minimal consent archive to a backend-only compliance area for up to 5 years from deletion or the latest consent event, solely to prove consent, comply with legal or regulatory obligations, and establish, exercise, or defend rights. The archive does not include your conversations, audio, memories, tasks, name, email, advertising ID, device fingerprint, or AI provider payloads, and it is not used for product features, analytics, marketing, personalization, profiling, or AI training. After the retention period, the archive is deleted or irreversibly anonymized.

10. International Transfers

Serena is a global app. Your information may be processed in countries other than where you live, including the United States and other locations where our service providers operate.

Where required, we use appropriate safeguards for international transfers, such as contractual protections, standard contractual clauses, adequacy decisions, data protection frameworks, or other lawful transfer mechanisms.

11. Security

We use technical and organizational measures designed to protect information. These may include encryption in transit, local encrypted storage where applicable, Firebase App Check, secure authentication providers, access controls, and security monitoring.

For optional secure backup, Serena encrypts the backup package on your device before upload and stores only encrypted backup data plus technical metadata remotely. Recovery codes, Account Backup Keys, data encryption keys, and plaintext backup contents are not intended to be sent to our backup backend.

No system is completely secure. You are responsible for keeping your device, operating system account, App Store or Google Play account, and any Google or Apple login you choose to link secure.

12. Children’s Privacy

Serena is intended only for adults aged 18 or older and is not directed to children or minors. You must be at least 18 years old to create an account, start a subscription, access the App, or use the Service. Parent or guardian consent does not authorize use by anyone under 18.

We do not knowingly collect personal data from anyone under 18. If we learn that a person under 18 has used Serena, we will take appropriate steps to close the account and delete associated personal data, subject to applicable legal, security, fraud-prevention, dispute, and retention obligations.

Parents or guardians may contact us at privacy@serenaapp.com if they believe a child or minor has used Serena.

13. Your Privacy Rights

Depending on your location, you may have rights regarding your personal data, including:

  1. Access.
  2. Correction.
  3. Deletion.
  4. Portability.
  5. Restriction of processing.
  6. Objection to processing.
  7. Withdrawal of consent.
  8. Appeal of certain privacy decisions.
  9. Opt-out of sale, sharing, or targeted advertising where applicable.

We do not sell personal data or share it for cross-context behavioral advertising. If this changes, we will update this Policy and provide required choices.

To exercise privacy rights, contact us at privacy@serenaapp.com. We may need to verify your request. Some rights may be limited by local law, security requirements, local-first architecture, or data we do not control because it is held by Apple, Google, or another provider.

For store subscriptions, billing, and refunds, you may also need to use Apple App Store or Google Play account tools. For Pix, contact support@serenaapp.com; Iugu or a participating financial institution may need to handle data or rights that Serena does not control.

14. Permissions

Serena may request device permissions, such as microphone access for voice transcription, notifications for reminders, and local authentication for device-level protection.

You can manage permissions in your device settings. Some features may not work if permissions are disabled.

15. AI Content Reporting

The App includes or will include in-app mechanisms that allow users to report or flag AI-generated content that they believe is offensive, unsafe, inaccurate, or otherwise problematic.

If you submit a report, we may process the report content, relevant technical metadata, and the content you choose to include so we can investigate, improve safety, address abuse, and comply with app store policies.

Do not use content reporting for emergencies. If you are in immediate danger or need urgent help, contact local emergency services or an appropriate trusted resource.

16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by applicable law. The “Last updated” date shows when this Policy was last revised.

17. Contact

For privacy questions or requests, contact us at: