Privacy Policy
Last updated: June 2026
Overview
We take the protection of your personal data seriously. This policy explains what data Sellah processes, why, on what legal basis, and the rights you have. Sellah is a Christian prayer app for iOS and Android; this policy covers both the app and the website at sellah.ai.
Controller
The controller responsible for data processing is:
Melo Designer GmbH
Zum Wallgraben 50b, 49696 Molbergen, Germany
info@melodesigner.de
+49 4475 9296 293
Hosting
Our application and database are hosted on servers operated by Hetzner Online GmbH within Germany (EU). A data processing agreement (Art. 28 GDPR) is in place.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in secure, reliable hosting).
What data we process
- Account data: your name, email address, and, where you provide them, gender and date of birth.
- Sign-in identifiers: when you use Sign in with Apple or Google, the identifier and email they return.
- Prayer inputs: the mood, topics, and tradition you choose, and the prayers composed for you (which you can edit, save, or delete).
- Usage data: prayer times you set, streak and journey counts, and feature usage needed to provide the service.
- Device tokens: a push token if you enable reminders.
- Technical data: IP address, device type, and request logs, processed transiently to deliver and secure the service.
Data revealing religious beliefs (special categories)
Your chosen tradition (Catholic, Evangelical, or Scripture-only), the prayers you receive, and your mood check-ins reveal your religious beliefs and are special categories of personal data under Art. 9 GDPR. We process them only to provide the prayer experience you ask for, and only with your explicit consent, which you give in the app and can withdraw at any time.
Legal basis: Art. 9 (2)(a) GDPR (explicit consent).
How your prayers are created
Each prayer is composed by an AI model from the mood, topics, and tradition you select. The text is generated in seconds, is always editable by you word by word, and is never a binding or automated decision producing legal effects (Art. 22 GDPR does not apply). For voice playback, the prayer text is converted to speech by our text-to-speech provider. We do not use your prayers to train third-party AI models.
Processors and third-party services
We use the following processors and service providers, each under a data processing agreement or equivalent safeguards. Only the data needed for each purpose is shared.
Hetzner Online GmbH, Germany (EU)
Hosting and object storage for the application, database, and media backups.
Google (Gemini API), Google Ireland Ltd. / Google LLC
AI generation of prayer text. Receives the mood, topics, and tradition you select to compose the prayer; not your name or contact details.
ElevenLabs, Inc., United States
Text-to-speech: converts prayer text into the lifelike voices. Receives the prayer text to synthesize audio.
Cloudflare, Inc., EU edge
Content delivery and (for the website) the country signal used to show local pricing. Processes IP transiently; raw IPs are not stored by us.
Apple Inc.
App Store billing, Sign in with Apple, and Apple Push Notification service for reminders.
Google LLC (Google Play, Firebase)
Google Play billing, Google sign-in, and Firebase Cloud Messaging for Android reminders.
Email delivery
Transactional email (e.g. account and receipt messages) is sent via our email provider within the EU.
Stripe (web checkout, when enabled)
If you subscribe on the website, payment is processed by Stripe. We do not store your card details.
Google Analytics & Meta Pixel (website only)
Used only after you accept the relevant cookie categories. See "Analytics & marketing" below.
International data transfers
Some processors (e.g. ElevenLabs and Meta) are located in or transfer data to the United States. Such transfers are safeguarded by the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You may request a copy of the safeguards from us.
Sign-in
You can create an account with your email or via Sign in with Apple or Google. These providers confirm your identity and return an identifier and email; we do not receive your password.
Legal basis: Art. 6 (1)(b) GDPR (performance of a contract).
Push notifications
If you enable reminders, we store a device push token and send gentle invitations at the times you choose, via Apple (APNs) and Google (FCM). You can turn reminders off at any time in the app or your device settings.
Legal basis: Art. 6 (1)(a) GDPR (consent).
Server logs
Our servers automatically record technical information for each request:
- IP address
- Date and time
- Requested resource
- HTTP status
- Referrer
- User agent
Legal basis: Art. 6 (1)(f) GDPR (security and operation).
Retention: server logs are deleted after 14 days unless needed to investigate a security incident.
Media backups
Share videos and image sets you create may be backed up to encrypted object storage at Hetzner (EU) so they survive a device change. Backups are automatically deleted after 14 days.
Encryption
All traffic between your device and our servers is encrypted via TLS/SSL. We self-host our fonts, so no font request leaves to a third party.
Analytics and marketing
On the website, with your consent, we use Google Analytics to understand how the site is used, and the Meta Pixel to measure the effectiveness of campaigns. Both load only after you accept the relevant category in the cookie banner, and Google Analytics runs with IP anonymization and Consent Mode. You can change or withdraw your choice at any time via "Cookie Settings" in the footer.
Legal basis: Art. 6 (1)(a) GDPR and § 25 (1) TDDDG (consent).
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectify inaccurate data (Art. 16).
- Erase your data (Art. 17).
- Restrict processing (Art. 18).
- Data portability (Art. 20).
- Object to processing (Art. 21).
- Withdraw consent at any time, without affecting prior processing (Art. 7 (3)).
Right to complain
You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the State Commissioner for Data Protection of Lower Saxony (Landesbeauftragte für den Datenschutz Niedersachsen).
Deleting your account
You can delete your account and associated data at any time from the app under Settings → Account. Deletion removes your account data, saved prayers, and journey from our systems, subject to any retention required by law.
Changes to this policy
We may update this policy as the service evolves or the law changes. The current version is always available here, with the date of the last update shown above.