Privacy Policy — Selida
Effective date: 7 August 2026
This policy explains what personal data Selida ("Selida", "the service", "we") collects, why, and what rights you have. We've tried to write it plainly rather than in scary boilerplate.
Selida is a service for churches and worship teams to manage songs, a calendar of services and rehearsals, setlists, repertoires, team assignments, and notes. It is operated by Danyil Selivanov, a solo operator based in Poland (EU). Because we are established in the EU and serve EU users, the GDPR applies.
Questions or requests: privacy@selida.app · https://app.selida.app
1. Who is responsible for your data (controller vs. processor)
There are two different roles, and it matters which one applies:
- Account data — we are the controller. For the data needed to give you an account and log you in (your email, display name, password, language preference, and which organizations you belong to), Selida decides how and why it is processed. We are the data controller for that.
- Data a church puts into the app — the church is the controller, we are the processor. When a church or worship team uses Selida to organize its own life — member assignments, calendars, setlists, notes about who plays what — the church is the data controller of that content. Selida only stores and processes it on the church's behalf and under its instructions, so for that data we are a data processor. If you want that content changed or removed, the organization that owns it is your first point of contact; we will support them.
If your church needs a formal Data Processing Agreement (DPA), contact us at privacy@selida.app.
2. What we collect and why
We only collect what the service needs. We do not run advertising, third-party analytics, or tracking.
| Data | Why we have it |
|---|---|
| Email address | To create your account, log you in, send account and (once enabled) transactional email such as invitations or password resets. |
| Display name | So your teammates can recognize you in the app. |
| Password | To authenticate you. It is hashed with Argon2 and never stored or readable in plaintext — not even by us. |
| UI language preference | To show the app in your chosen language across your devices. |
| Organization membership & role | To connect you to your church/team and control what you can do (e.g. member vs. owner). |
| Content you create | Songs (chords + lyrics), events, setlists, repertoires, team assignments, and notes. Some notes are private to you; others are shared with your organization — the app shows you which. |
| Basic technical logs | Standard server logs (e.g. IP address, timestamps, error traces) kept briefly for security, debugging, and keeping the service running. |
We do not sell your data, and we do not use it to build advertising or marketing profiles.
3. Legal bases for processing (GDPR Art. 6)
- Performance of a contract — creating and running your account, storing your content, and providing the features you signed up for.
- Legitimate interests — keeping the service secure, preventing abuse, fixing bugs, and maintaining reliable backups. We balance these against your rights and keep them minimal.
- Consent — where a feature is genuinely optional (for example, if we later add optional communications), we ask first, and you can withdraw consent at any time.
- Legal obligation — where we must retain or disclose data to comply with the law.
For content that a church enters about its members, the church is responsible for having a valid legal basis; we process it on their instructions.
4. Cookies and local storage
We use only strictly-necessary storage to keep you logged in. Specifically, after you sign in we store a session token (a JWT) in your browser's localStorage. This is required for the app to function and is removed when you log out.
We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Because we only use strictly-necessary storage, we don't show a cookie-consent banner for tracking — there's nothing to consent to.
5. How long we keep data (retention)
- While your account is active, we keep your account data and content so the service works.
- When you delete your account (see below), we delete your account data and your private content. Content you shared into an organization may remain with that organization if it still needs it (the church is the controller of that content).
- Backups are kept for a limited rolling window and then overwritten; deleted data disappears from backups within that cycle rather than instantly.
- Server logs are kept only for a short period for security and debugging.
We'll set concrete retention periods (e.g. backup window in days) here before launch: [RETENTION PERIODS — TO CONFIRM].
6. Your rights
Under the GDPR you have the right to:
- Access — get a copy of your personal data.
- Rectification — correct data that is wrong or incomplete.
- Erasure — have your data deleted ("right to be forgotten").
- Portability — receive your data in a structured, machine-readable format.
- Object / restrict — object to, or ask us to restrict, processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, at any time.
- Complain to a supervisory authority — in Poland this is the UODO (Urząd Ochrony Danych Osobowych / President of the Personal Data Protection Office), https://uodo.gov.pl. If you're in another EU country, you may contact your local authority.
How to exercise them
- Delete your account and export your data directly in the app — both are self-serve in your account settings.
- For anything else, email privacy@selida.app. We'll respond within the timeframe the GDPR requires (normally one month).
For content owned by your organization (church), please also contact that organization, since they are its controller.
7. International data transfers
By default, your data stays in the EU. The service is hosted on Hetzner Cloud data centres in Germany and Finland. We do not transfer personal data outside the EU/EEA in normal operation. If that ever changes, we will update this policy and put an appropriate transfer mechanism (e.g. Standard Contractual Clauses) in place first.
8. How we protect your data
- Passwords hashed with Argon2 — a strong, modern password-hashing algorithm; we never store plaintext passwords.
- Encryption in transit — all traffic is served over TLS (HTTPS).
- EU hosting — infrastructure in EU data centres (Hetzner, Germany/Finland).
- Access minimization — only the operator has administrative access, used only to run and support the service.
No system is perfectly secure, but we take reasonable, up-to-date measures appropriate to a service of this size.
9. Sub-processors
We use a small number of trusted providers to run the service. They process data only as needed to provide their part of it:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting and storage | Germany / Finland (EU) |
| Email provider (e.g. Resend) | Transactional email (invitations, password resets) — once enabled | [TO CONFIRM — verify EU/GDPR terms] |
We'll keep this list current. If we add or change a sub-processor, we'll update this page.
10. Children's data
Selida is intended for church and worship-team administration by adults, and is not directed at children. We do not knowingly collect personal data directly from children. If a church chooses to record information about minors (for example, a young musician on a team), the church is the controller of that data and is responsible for having the appropriate consent and legal basis. If you believe a child has created an account directly with us without appropriate consent, contact privacy@selida.app and we will address it.
11. Changes to this policy
As the service grows we may update this policy. If we make a material change, we'll update the effective date above and, where appropriate, notify you in the app or by email. Continuing to use the service after a change means the updated policy applies to you.
12. Contact
- Operator: Danyil Selivanov, Poland (EU)
- Email: privacy@selida.app
- Website: https://app.selida.app
- Polish supervisory authority (UODO): https://uodo.gov.pl