Privacy Policy

Please read our privacy policy carefully to understand how we collect, use, and protect your personal information.

Selpflow - Privacy Policy

Effective date: 2025-09-08

Selpflow ("we", "us", "our") respects your privacy. This notice explains what we collect, why we collect it, how long we keep it, who we share it with, and the rights you have under the EU/EEA GDPR.
Contact for privacy matters: info@selp.life (We currently operate under individual activity; no separate company name or postal address is published.)

1) What data we collect and why

We only collect the minimum necessary to generate and deliver your program.

A. Data you give us at checkout / delivery

* Email (so we can deliver your program and send you the download link)
* Program ID (to let you re-access your purchase)
Purpose / legal basis: contract performance (GDPR Art. 6(1)(b)).
Retention: kept indefinitely so you can re-download your program later (until you ask us to delete).

B. Data you enter in the program wizard ("jobs")

During program generation, you may provide fitness-related inputs such as:
* Goals & preferences (e.g., primary/secondary goals, training frequency, workout duration, location/equipment, diet preferences and "other" notes)
* Profile inputs (gender, age range, height, weight, fitness level, meals per day)
* Health-related info (optional): injuries or medical conditions affecting training
Important: we do not permanently store your answers. They live in a temporary "job" record used to generate your program and are deleted after 7 days (audit/debug).
For any
health-related information (e.g., injuries), we rely on your explicit consent (GDPR Art. 9(2)(a)). This field is optional.
Purpose / legal basis:
Generate a tailored program = contract performance (Art. 6(1)(b))
Optional health data (injuries) =
consent (Art. 6(1)(a) + Art. 9(2)(a))
Audit/debug until deletion = legitimate interests (Art. 6(1)(f))

C. Generated content we keep

* Program content and PDF (do not include your personal answers)
We keep them so you can access and download again later.
Purpose / legal basis: contract performance (Art. 6(1)(b)).
Retention: indefinitely (until you ask us to delete).

D. Application logs

Technical logs (errors, performance, security events). We do
not use these to profile you.
Purpose / legal basis: security and service integrity (legitimate interests, Art. 6(1)(f)).
Retention: 7 days, then deleted.

E. Newsletter database (separate)

If you subscribe, we store your
email in a separate newsletter list. You can unsubscribe anytime.
Purpose / legal basis: consent (Art. 6(1)(a)) or permissible direct marketing rules where applicable.
Retention: until you unsubscribe or we delete the list.

2) Cookies, analytics, and marketing technologies

We use essential cookies (e.g., for Stripe embedded elements and basic session needs) and, with your consent, we use analytics/marketing cookies and pixels.
* Analytics: Google Analytics
* Session replay/UX: Microsoft Clarity
* Marketing / ads: Meta Pixel (Facebook/Instagram), TikTok Pixel, Google Ads
Legal basis:
Essential cookies = legitimate interests (Art. 6(1)(f))
Analytics/marketing =
consent (Art. 6(1)(a)) via our cookie banner/manager
Your choice: You can accept/decline non-essential cookies in the banner, and change your selection anytime. You can also set your browser to block cookies.

3) Payments

We use Stripe (embedded elements) to process one-time payments. Stripe acts as an independent controller for certain payment data.
See Stripe Privacy Center for details.
Legal basis: contract performance (Art. 6(1)(b)); fraud prevention = legitimate interests (Art. 6(1)(f)).

4) Where we process data and whom we share it with (processors)

We use reputable providers to host and operate Selpflow. We only share what's necessary.
* Amazon Web Services (AWS) (hosting, S3 storage, Amazon SES email) - EEA and (where applicable) other regions
* MongoDB (database) - region as configured (we aim for EEA where possible)
* OpenAI (program generation AI) - data may be transferred to the United States
* Stripe (payments)
We have data processing terms in place and, where required, EU Standard Contractual Clauses (SCCs) or equivalent safeguards for international transfers (GDPR Arts. 44–49).
International transfers:
* OpenAI (US): We send your job inputs to generate your plan. These "jobs" are deleted from our database after 7 days; your generated program/PDF stored by us does not include your personal answers. Transfers rely on SCCs and appropriate safeguards.

5) Children

Selpflow is not intended for persons under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided data, email info@selp.life and we will delete it.

6) Your rights under GDPR

You can email info@selp.life to exercise your rights. We will verify your identity and respond without undue delay.
* Access - get a copy of your personal data and information about processing
* Rectification - correct incomplete or inaccurate data
* Erasure - request deletion (e.g., email/programId; we will also remove your generated files)
* Restriction - ask us to pause certain processing
* Objection - object to processing based on legitimate interests (e.g., analytics/marketing)
* Portability - receive your data in a machine-readable format (where legally applicable)
* Withdraw consent - for anything we process based on your consent (e.g., injuries field; cookies/analytics; newsletter)
Supervisory authority: You may lodge a complaint with State Data Protection Inspectorate (VDAI), Lithuania.

7) Security

We use appropriate technical and organizational measures (encryption in transit, access controls, least-privilege roles, logging, backups) to protect your data against unauthorized access, loss, or misuse.

8) How long we keep your data (summary)

Data categoryPurposeLegal basisRetention
Email + Program IDDeliver & let you re-access your programArt. 6(1)(b)Indefinitely (until you ask us to delete)
Program content & PDF (no personal answers)Re-download & accessArt. 6(1)(b)Indefinitely (until deletion request)
"Jobs" (your answers incl. optional injuries)Generate your program; audit/debugContract (Art. 6(1)(b)), Legitimate interests (Art. 6(1)(f)); injuries: consent (Art. 6(1)(a) + 9(2)(a))7 days, then deleted
Application logsSecurity, stabilityArt. 6(1)(f)7 days
Newsletter email listComms/marketingArt. 6(1)(a)Until you unsubscribe

9) Legal bases (quick map)

* Contract performance (Art. 6(1)(b)): generating the program, delivering links/PDFs, letting you re-access
* Legitimate interests (Art. 6(1)(f)): security logs, service reliability, essential cookies, limited fraud prevention
* Consent (Art. 6(1)(a)): analytics/marketing cookies, newsletter, optional injuries/medical details (also Art. 9(2)(a) for special-category data)
* Legal obligations (Art. 6(1)(c)): if we must retain certain records under applicable laws

10) Sharing and disclosures

We do not sell your personal data. We share data with our processors listed above and may disclose data if required by law or to defend legal claims. If our service is reorganized, merged, or sold, your data may transfer to the new operator under the same protections.

11) Changes to this notice

We may update this Privacy Policy from time to time. We'll post the new version here and update the effective date. Material changes will be highlighted where reasonable.

12) Contact

Questions or rights requests: info@selp.life

Cookies Overview (Summary, EN)

* Essential cookies (e.g., Stripe elements, basic session functions) - legitimate interest
* Analytics / marketing (Google Analytics, Microsoft Clarity, Meta Pixel, TikTok Pixel, Google Ads) - only with your consent
You can change your consent at any time through our cookie manager or browser settings.
For questions or support, please contact: info@selp.life
Privacy Policy | Selpflow