Legal document

Serena AI Companion Privacy Policy

Updated on Jul 19, 2026 v 2026.07.19

In short

  • Serena is a wellness-focused, local-first mobile app; persistent conversations, memories, tasks, reminders, and preferences stay on the device by default.
  • Login, subscriptions, security, AI replies, voice transcription, legal records, reports, and optional encrypted backup require limited external processing.
  • Serena is intended only for adults aged 18 or older and does not sell personal data or use conversation content for advertising or AI model training.

Plain-Language Summary

This summary explains, in simple language, what this Privacy Policy covers. It is not a substitute for the full Privacy Policy below.

Serena AI Companion is a wellness-focused AI companion app. Serena uses a local-first design: your persistent conversation history, memories, tasks, reminders, and preferences are stored locally on your device by default. Serena does not sell your personal data and does not show ads.

Some data must still be processed outside your device. Firebase Auth handles Google and Apple social login. RevenueCat, Apple App Store, and Google Play handle subscription and purchase metadata. Serena’s backend may handle limited non-authoritative subscription support, legal, consent, and account-deletion records. To generate AI replies or transcribe voice notes, the message or audio needed for that request may be processed by AI or transcription providers. Security tools such as Firebase App Check help protect the App from abuse.

Serena also offers an optional secure backup feature. If you turn it on, Serena creates an encrypted backup package on your device and uploads only encrypted backup data and technical metadata to Firebase/Google Cloud infrastructure. We do not receive the plaintext contents of your conversations, memories, tasks, transcripts, or preferences as part of secure backup.

You can delete your account and erase local data in the App. Depending on where you live, you may also have privacy rights such as access, deletion, correction, portability, objection, restriction, or opt-out rights.

1. Scope of This Policy

This Privacy Policy explains how SERENA TECNOLOGIA E BEM ESTAR LTDA. (“Company”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects information when you use Serena AI Companion (“Serena”, the “App”, or the “Service”).

This Policy applies to the Serena mobile app and related support, account, subscription, AI, transcription, and security services.

This Policy should be read together with our Terms of Use.

2. Wellness App Notice

Serena is a wellness-focused AI companion. It is not a regulated professional advice service, licensed provider, emergency response service, or safety-critical service. You should not use Serena as a substitute for qualified human judgment in regulated, high-risk, urgent, or safety-critical situations.

If you are in immediate danger or need urgent help, contact local emergency services or an appropriate trusted resource.

3. Information We Process

We process only the information needed to operate, secure, improve, and support Serena.

3.1 Account and Login Information

Serena uses Firebase Authentication for social login with Google Sign-In and Sign in with Apple. Depending on the provider and your settings, we may receive or process:

  1. Firebase user ID.
  2. Provider identifier.
  3. Email address or Apple private relay email.
  4. Display name or profile metadata provided by the provider.
  5. Login timestamps and authentication metadata.
  6. Security and fraud-prevention signals processed by Firebase.

We do not operate a Serena password system and do not store your Google or Apple password.

3.2 Subscription and Purchase Information

Serena uses RevenueCat as the source of truth for subscription entitlement status, paywall offerings, purchase restoration, and entitlement checks. Apple App Store and Google Play process purchases, billing, renewals, cancellations, refunds, and store account management. Serena’s backend may process limited non-authoritative subscription support, legal, consent, and account-deletion records, but it does not decide premium access when RevenueCat entitlement status differs.

Subscription-related information may include:

  1. Serena App User ID based on your Firebase user ID.
  2. RevenueCat customer and subscription identifiers associated with your Firebase user ID.
  3. Subscription status, renewal status, trial status, cancellation status, and entitlement status.
  4. Product identifiers, such as Serena Unlimited annual subscription.
  5. Store, platform, region, and app version information needed for subscription management and support.

We do not receive your full payment card number from Apple or Google.

3.3 Local App Data

The following persistent data is stored locally on your device by default:

  1. Conversation history.
  2. Memories generated or saved in the App.
  3. Tasks, reminders, and gentle follow-ups.
  4. Preferences and settings.
  5. Voice-note transcripts saved as conversation text.
  6. Local user profile details used inside the App.

This local data is not stored in a Serena cloud account by default. It may be deleted if you erase local data, uninstall the App, reset the device, lose the device, or delete local app storage.

If you enable local app lock, Serena uses your device’s own local authentication, such as Face ID, Touch ID, fingerprint, PIN, pattern, or device passcode, to help protect access to local app data. Serena does not receive, store, collect, or send your biometric data, device PIN, pattern, passcode, or hashes of those credentials. Local authentication is processed by the operating system on your device.

3.3A Optional Secure Backup

If you choose to enable secure backup, Serena may process:

  1. An encrypted backup package stored in Cloud Storage.
  2. Backup metadata stored in Firestore, such as backup ID, object path, size, checksums, creation time, app version, platform, and backup status.
  3. Encrypted key envelopes needed for recovery. These envelopes are designed so we do not receive the Account Backup Key, data encryption key, recovery code, or plaintext backup contents.
  4. App Check and Firebase Authentication tokens used to authorize backup, restore, and delete operations.

Secure backup is optional. It is not the default storage location for your persistent app data. If you do not enable it, your persistent conversation history, memories, tasks, reminders, and preferences remain local by default.

Secure backup is end-to-end encrypted by the App before upload. The encrypted package may leave your device, but the backup service is not designed to read its plaintext contents. You are responsible for keeping your recovery code and account access safe. If you lose the code and no longer have an already-enabled trusted device, we may not be able to help you decrypt a backup.

3.4 AI and Transcription Request Data

When you send a message or audio note, Serena may process the content needed for that request through Google Cloud Gemini for AI responses or Cloudflare for transcription infrastructure. This may include:

  1. The message you typed.
  2. The audio file or audio segment you asked to transcribe.
  3. Necessary context for the requested AI response.
  4. Language and technical request metadata.

We use this processing to generate replies, transcripts, and related App functionality. Provider processing is governed by our configurations, provider terms, and applicable law. We do not sell this content or use it for ads.

Audio notes used for chat transcription are treated as transient processing data. Serena does not store the audio file as chat history; after transcription, the transcript may remain in your local conversation history as text.

To improve contextual recall, Serena may select messages from your local history and send their text to Google Cloud to generate semantic query or document embeddings. The resulting vectors and search index are stored only in the App’s encrypted local database. Serena’s embedding backend relays the request and does not persist the message text or returned vectors. Google may still process and retain request data under our configurations, provider terms, and applicable law; we do not promise that provider retention is zero. When you clear chat history, delete a message, or erase the corresponding local data, Serena also deletes the derived local vectors. Secure backup may include messages, but it does not transport derived embeddings or the search index; those are regenerated after restore.

3.5 Security, App Check, Diagnostics, and Logs

Serena may process security and diagnostic data to protect the Service and maintain stability, including:

  1. Firebase App Check tokens and attestation signals.
  2. Device and app integrity signals.
  3. IP address and network metadata processed by service providers for security.
  4. App version, operating system, device model, and error information.
  5. Logs needed to investigate abuse, crashes, or technical issues.

If enabled, Firebase Crashlytics may process crash logs, device and operating system information, app version and build number, stack traces, and limited technical context such as locale, theme mode, authentication state, subscription state, startup phase, feature area, and build channel. We configure Serena’s app-controlled crash reporting fields to avoid sending conversation text, audio, transcripts, memories, tasks, prompts, AI responses, tokens, email addresses, local file paths, precise location, phone numbers, or full external-provider payloads. Crash diagnostics are used for app stability and security, not for advertising.

3.6 Support Communications

If you contact support, we may process:

  1. Your email address.
  2. Support message content.
  3. Support ID or Firebase user ID.
  4. Subscription status needed to resolve the request.
  5. Technical information you choose to provide.

4. How We Use Information

We use information to:

  1. Provide and operate Serena.
  2. Authenticate your account.
  3. Manage Serena Unlimited subscriptions and entitlements.
  4. Restore purchases.
  5. Generate AI replies and transcribe audio.
  6. Store and display local app data on your device.
  7. Protect the App from abuse, fraud, and unauthorized access.
  8. Provide customer support.
  9. Debug, maintain, and improve the App.
  10. Comply with legal obligations and app store requirements.
  11. Enforce our Terms of Use and safety rules.
  12. Provide optional encrypted backup, restore, and backup deletion when you enable secure backup.

We do not sell personal data. We do not show ads in Serena. We do not share personal data for cross-context behavioral advertising.

Depending on your location, our legal bases for processing may include:

  1. Performance of a contract, such as providing the App, subscriptions, login, AI replies, transcription, and support.
  2. Legitimate interests, such as preventing abuse, securing the App, debugging, improving reliability, and understanding subscription status.
  3. Consent, where required by law, such as for certain permissions or optional processing.
  4. Compliance with legal obligations, such as tax, accounting, consumer protection, fraud prevention, or app store requirements.

6. How We Share Information

We share information only as needed to operate, secure, and support Serena.

6.1 Service Providers

We may share or make information available to:

  1. Firebase and Google services for authentication, App Check, infrastructure, and security.
  2. Serena’s backend, Apple App Store, and Google Play for subscription management, paywalls, entitlements, purchase restoration, and customer support flows.
  3. Apple App Store and Google Play for billing, purchases, subscriptions, refunds, and store account management.
  4. Google Cloud Gemini for AI response generation.
  5. Cloudflare for transcription infrastructure and speech-to-text processing.
  6. Diagnostic and crash reporting providers, if enabled.
  7. Customer support tools, if used.
  8. Firebase and Google Cloud services for optional encrypted backup storage, metadata, App Check verification, and backup operations.

These providers process information according to their contracts, policies, and applicable legal obligations.

We may disclose information if we believe it is reasonably necessary to:

  1. Comply with law, regulation, legal process, or government request.
  2. Enforce our Terms.
  3. Detect, prevent, or address fraud, abuse, security issues, or technical issues.
  4. Protect the rights, safety, and property of users, the Company, or others.

6.3 Business Transfers

If we are involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to applicable law.

7. Local Data Controls

Because Serena stores persistent app data locally by default, many privacy controls are available directly on your device.

You may be able to:

  1. Clear chat history.
  2. Erase all local data.
  3. Delete tasks, reminders, and memories.
  4. Delete the App from your device.

Erasing local data deletes data on that device. It does not automatically refund purchases, end active annual access, or delete account or subscription metadata held by Firebase, RevenueCat, Serena’s backend, Apple, or Google.

If secure backup is enabled, erasing local data on one device does not automatically delete the encrypted remote backup unless you also use the backup deletion control or account deletion flow that requests remote backup deletion.

8. Account Deletion

You can request account deletion from within the App. Account deletion removes or initiates deletion of your Firebase Authentication account and associated account metadata, subject to provider retention, security, backup, fraud-prevention, and legal requirements.

Where available, account deletion or the secure backup settings screen also lets you request deletion of the remote encrypted backup. Deleting the remote backup removes backup metadata and starts deletion of the encrypted storage object. Temporary infrastructure replicas or logs may persist for a limited period according to provider operations, but without the required keys the encrypted package is not designed to be readable by us.

When you delete your account, you may also choose or be prompted to erase local device data. Account deletion does not automatically refund purchases, end active annual access, or remove purchase records that Serena must retain for legal, accounting, support, fraud-prevention, restore, or dispute purposes.

9. Retention

We retain information only for as long as needed for the purposes described in this Policy, unless a longer retention period is required or permitted by law.

Retention depends on the type of data:

  1. Local app data remains on your device until you delete it, erase local data, uninstall the App, reset the device, or the data is otherwise removed by device or operating system behavior.
  2. Firebase account metadata is retained while your account is active and then deleted or de-identified according to Firebase processes, legal requirements, and security needs.
  3. RevenueCat, store, and limited Serena backend subscription support metadata may be retained as needed for subscription management, accounting, fraud prevention, tax, legal compliance, dispute resolution, and customer support.
  4. AI and transcription request data is processed as needed to provide the requested response or transcript and then handled according to provider terms, our configurations, and applicable law.
  5. Support records may be retained as needed to resolve support issues and maintain business records.
  6. Security logs may be retained for abuse prevention, debugging, and compliance.
  7. Optional secure backup remains until you replace it, delete it, delete your account where backup deletion is available, or the feature otherwise removes it according to the backup retention rules. Superseded or deleted backup objects may remain temporarily as encrypted operational residue until cleanup completes.
  8. Legal consent records are kept while your account is active to show the Terms of Use, Privacy Policy, document hashes, locale, app version, build number, platform, consent screen version, and timestamps accepted by your authenticated account. When your account is deleted, Serena may move a minimal consent archive to a backend-only compliance area for up to 5 years from account deletion or the latest consent event, solely to prove consent, comply with legal or regulatory obligations, and establish, exercise, or defend rights. The archive does not include your conversations, audio, memories, tasks, name, email, advertising ID, device fingerprint, or AI provider payloads, and it is not used for product features, analytics, marketing, personalization, profiling, or AI training. After the retention period, the archive is deleted or irreversibly anonymized.

10. International Transfers

Serena is a global app. Your information may be processed in countries other than where you live, including the United States and other locations where our service providers operate.

Where required, we use appropriate safeguards for international transfers, such as contractual protections, standard contractual clauses, adequacy decisions, data protection frameworks, or other lawful transfer mechanisms.

11. Security

We use technical and organizational measures designed to protect information. These may include encryption in transit, local encrypted storage where applicable, Firebase App Check, secure authentication providers, access controls, and security monitoring.

For optional secure backup, Serena encrypts the backup package on your device before upload and stores only encrypted backup data plus technical metadata remotely. Recovery codes, Account Backup Keys, data encryption keys, and plaintext backup contents are not intended to be sent to our backup backend.

No system is completely secure. You are responsible for keeping your device, operating system account, App Store or Google Play account, and Google or Apple login secure.

12. Children’s Privacy

Serena is intended only for adults aged 18 or older and is not directed to children or minors. You must be at least 18 years old to create an account, start a subscription, access the App, or use the Service. Parent or guardian consent does not authorize use by anyone under 18.

We do not knowingly collect personal data from anyone under 18. If we learn that a person under 18 has used Serena, we will take appropriate steps to close the account and delete associated personal data, subject to applicable legal, security, fraud-prevention, dispute, and retention obligations.

Parents or guardians may contact us at privacy@serenaapp.com if they believe a child or minor has used Serena.

13. Your Privacy Rights

Depending on your location, you may have rights regarding your personal data, including:

  1. Access.
  2. Correction.
  3. Deletion.
  4. Portability.
  5. Restriction of processing.
  6. Objection to processing.
  7. Withdrawal of consent.
  8. Appeal of certain privacy decisions.
  9. Opt-out of sale, sharing, or targeted advertising where applicable.

We do not sell personal data or share it for cross-context behavioral advertising. If this changes, we will update this Policy and provide required choices.

To exercise privacy rights, contact us at privacy@serenaapp.com. We may need to verify your request. Some rights may be limited by local law, security requirements, local-first architecture, or data we do not control because it is held by Apple, Google, or another provider.

For subscriptions, billing, and refunds, you may also need to use Apple App Store or Google Play account tools.

14. Permissions

Serena may request device permissions, such as microphone access for voice transcription, notifications for reminders, and local authentication for device-level protection.

You can manage permissions in your device settings. Some features may not work if permissions are disabled.

15. AI Content Reporting

The App includes or will include in-app mechanisms that allow users to report or flag AI-generated content that they believe is offensive, unsafe, inaccurate, or otherwise problematic.

If you submit a report, we may process the report content, relevant technical metadata, and the content you choose to include so we can investigate, improve safety, address abuse, and comply with app store policies.

Do not use content reporting for emergencies. If you are in immediate danger or need urgent help, contact local emergency services or an appropriate trusted resource.

16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by applicable law. The “Last updated” date shows when this Policy was last revised.

17. Contact

For privacy questions or requests, contact us at: