Serendipity (“Seren,” “we,” “us”) believes privacy isn’t a limitation on romance — it’s part of it. This page explains, plainly, what that means in practice: what we collect, what we deliberately never ask for, and what happens to it when you delete your account.
This policy covers the Seren mobile app and this website. It applies wherever Seren is used, with specific notes for the Philippines (Republic Act 10173, the Data Privacy Act) and Vietnam (Decree 13/2023 on personal data protection) called out below.
The short version
- No email, no phone number, no real name. Signing up for the app needs none of them. We know you by your face and a screen name you choose.
- Your exact location is never shown to anyone, including matches. It’s used server-side to tell you “someone’s nearby” — never a distance, a direction, or a map.
- We don’t sell your data, and we never will. Nothing here monetizes your loneliness or your attention.
- Deleting your account is permanent and immediate — your profile, photos, matches, and messages are erased, not deactivated.
1. Information we collect
1.1 What signing up requires
Creating an account does not collect an email address, a phone number, or your legal name. Instead:
- A screen name you choose — never your real name.
- Face photos, with a liveness checkat signup. This is your identity anchor on Seren — it’s what stands in for the email/phone verification most apps use, and it’s how we catch impersonation and fake profiles. Your liveness selfie is matched only against your own uploaded photos, never against any outside database or any other user’s face.
- Date of birth— collected only to confirm you’re 18 or older. It is never shown on your profile or to anyone else; other users see only your computed age.
- Educational attainment(e.g. “BS Biology,” “high school graduate”) — the program or level only, never the name of the school.
- Hobbies and interests you choose to add.
- Authentication:Seren uses passkeys (via Supabase Auth), stored on your device and synced by iCloud Keychain or Google Password Manager. There’s no password for us to store or for anyone to steal. You may optionally add a recovery email purely so you can get back into your account if you lose your device and its passkey sync — it’s never required, and it’s never used to identify you to other users.
1.2 Location
Location is the one sensitive input serendipity actually needs, so we’ve kept it as narrow as we could make it work:
- Your location is only captured while the app is open in the foreground — never in the background, and Seren never requests “Always” location permission.
- Matching and proximity are resolved on our servers. Your device never receives another user’s coordinates, and no other user ever receives yours — only a “you’re nearby” signal once you’ve matched and both of you are within the unlock radius you each set (100–500 meters).
- A location fix that’s gone stale (you haven’t had the app open recently) can never be used to unlock a chat — this is enforced on the server, not just in the app.
- Sending your location in chat is different, and it’s opt-in. Once a chat is active, you can choose to send your literal current coordinates as a message — this is the one place in Seren where an exact location is shared, and only because you explicitly chose to send it, only to the one match in that conversation. The coordinates become unreadable after one hour; the message stays in the conversation history, but the location itself doesn’t.
1.3 Photos and media you send in chat
Beyond your profile photos, an active chat lets you send a live selfie (“this is me right now”) to the person you’re talking to. It’s stored separately from your profile photos and is only ever readable by the two people in that specific conversation — not by anyone browsing profiles.
1.4 Safety data: reports and blocks
If you report or block someone, we record who, when, and — for reports — the reason you selected (for example, harassment or a fake profile) and any note you add. You can see your own reports and blocks; nobody, including the person reported or blocked, can see who reported or blocked them. Writing a report or block only happens through a server-side function that checks it’s really you, so a report can’t be forged client-side.
1.5 Device and security signals
To keep banned users from simply reinstalling and coming back, and because a device’s hardware address isn’t something apps can read on modern iOS or Android, we use:
- iOS DeviceCheck and Android Play Integrity — per-device signals from Apple and Google, purpose-built for exactly this, that persist across a reinstall or factory reset.
- A push notification token (via Expo), tied to your device, used only to deliver notifications — never to track your location or behavior.
We also compare a new signup’s liveness selfie against faces associated with banned accounts — new hardware doesn’t get around a ban if the face is the same.
1.6 If you join the beta waitlist on this website
Before the app is available, joining the waitlist on this website collects only an email address, which button you used, and the page that referred you (when your browser sends one). This list is deliberately kept apart from the app: it has no link, no shared ID, and no way to connect an email address to any in-app account — even after you sign up for Seren with the same address. It exists for exactly two things: telling you when we launch, and — if you opt into the beta — sending you the TestFlight or Play Store invite. If you’d rather not be on it, every email includes an unsubscribe link.
A copy of the waitlist may also be mirrored to a private Google Sheet we use operationally; this is optional and best-effort, and a signup is recorded regardless of whether the mirror succeeds.
1.7 Website analytics
This marketing website uses Google Analytics 4 to understand how many visitors reach the waitlist form or a store link — nothing about the app itself is measured this way, and analytics never has access to your account, your matches, or anything you do inside Seren. Google Analytics sets a first-party cookie in your browser. We don’t run a consent banner today; if that changes as we better understand our audience, this page will say so.
2. How we use your information
- Operating matching and discovery — resolved server-side only.
- Confirming and unlocking proximity-gated chat, and enforcing its rules (like the reciprocation window).
- Trust and safety — reviewing reports, enforcing blocks and bans.
- Sending the marketing and beta emails you signed up for, and delivering push notifications you’ve enabled.
- Understanding, in aggregate, how this website performs.
We do not use your data to sell you attention. Per our product constitution, we never build features that monetize rejection, insecurity, or compulsive use — and that commitment extends to how we treat your data, not just the features we ship.
3. Who we share information with
We don’t sell your personal information, to anyone, ever. Seren runs on a small set of infrastructure and service providers, each with access limited to what their job requires:
- Supabase — our database, authentication, file storage, and real-time messaging, protected with row-level security so, for example, a user can only ever read their own reports.
- Vercel — hosts this website.
- Apple (DeviceCheck) and Google (Play Integrity) — the anti-ban-evasion device signals described above.
- Expo — delivers push notifications to your device.
- Google— Analytics for this website, and Gmail’s sending infrastructure for waitlist and beta emails.
We may also disclose information if required by law, or to protect the safety of our users or the public.
4. How long we keep it
- Your profile, photos, matches, and messages persist for as long as your account exists.
- A location you send in chat stops being readable after one hour, even though the message stays in your conversation history.
- Deleting your account (Settings → Delete Account, in-app) is immediate and permanent: it removes your profile, photos, prompts, likes and passes, reports and blocks, push token, and every match and its messages. We don’t keep a hidden copy, and there’s no “reactivate” afterward.
- A waitlist signup on this website is kept until you unsubscribe or until it’s no longer needed for launch communications.
5. Your rights
You can access, correct, or delete most of your profile information directly in the app. Deleting your account is the complete, permanent way to exercise your right to erasure — described above.
If you’re in the Philippines, the Data Privacy Act of 2012 (RA 10173) gives you the right to be informed, to access and correct your data, to object to processing, to erasure or blocking, to data portability, and to file a complaint with the National Privacy Commission.
If you’re in Vietnam, Decree 13/2023 on personal data protection gives you similar rights, including to know what’s collected, to access, correct, and withdraw consent, and to have your data deleted.
Wherever you are, you can reach us at gawa.developers@gmail.com with any privacy question or request.
6. Children’s privacy
Seren is for adults only. We require a date of birth confirming you’re 18 or older at signup, and “underage” is one of the reasons a profile can be reported. We don’t knowingly collect information from anyone under 18; if we learn we have, we’ll delete the account.
7. International data transfers
Because Seren runs on cloud infrastructure (Supabase, Vercel, and the providers listed in Section 3), your data may be processed on servers outside the Philippines or Vietnam. Wherever it’s processed, it’s protected under this policy.
8. Security
Passkey authentication means there’s no password to be phished or leaked. Access to your data is enforced at the database layer (row-level security), not just in app code, and sensitive server-side actions — like deleting an account or filing a report — run through functions that re-check it’s really you before doing anything. Photos and chat media are stored in private buckets, never publicly reachable by guessing a URL.
No system is perfectly secure, and we can’t guarantee absolute security — but the app is built, by default, to know as little about you as it can while still working.
9. Cookies on this website
This website sets a cookie to remember a language you’ve explicitly chosen, and — when analytics is enabled — a first-party Google Analytics cookie. Neither is used to identify you personally or to track you across other websites.
10. Changes to this policy
If we materially change how we handle your data, we’ll update this page and change the “last updated” date above. For anything that affects data you’ve already given us, we’ll make a reasonable effort to let existing users know in-app.
11. Contact us
Questions, requests, or concerns about this policy or your data: gawa.developers@gmail.com.