Legal
Last updated: July 15, 2026
Seren ("we", "us") provides an AI workspace at seren.im and through the Seren browser extension. This policy explains what we collect, why, and the controls you have. The short version: we collect what the product needs to work, we do not sell your data, and we do not run advertising or third-party trackers.
When you send a message, the content needed to generate a response (your message, relevant conversation history, attached documents and, if enabled, memory and search results) is sent to the AI provider behind the model you selected, such as OpenAI, Anthropic, Google, xAI or DeepSeek. The same applies to the extension's Email Reply feature: the email text needed to draft or learn your style is sent to an AI provider for that one request and is not kept by Seren. Providers process this data under their own terms to generate the response. We choose API access precisely because provider API terms treat business data more strictly than consumer chat apps do.
Web search runs through our own self-hosted search proxy. To gather results, your query text is forwarded from our servers to public search engines, without your IP address, account identity or cookies; we hold no search API relationship that ties queries to you.
We use a small set of processors: the AI model providers you choose to use, Stripe for payments, and an email delivery service for transactional messages such as password resets and receipts. Each receives only what its job requires.
Seren runs on servers we operate in Canada. The database, the search proxy behind web answers, and the storage that holds your images all run on infrastructure we control; they are not multi-tenant clouds shared with other apps. The only outside services in the loop are:
That is the whole list. We do not use advertising cookies, analytics beacons or cross-site trackers.
Seren runs on infrastructure we operate. Data is encrypted in transit (TLS); provider keys and other secrets are encrypted at rest; access to your rows is enforced by database-level policies; and two-factor authentication is available on every account. Content is retained while your account exists. Deleting a conversation, image, memory or your entire account removes it from the live system; routine database backups age out on a seven-day rotation.
We handle personal information in accordance with Canadian privacy law, including PIPEDA. If you believe we have not met these obligations you may also contact the Office of the Privacy Commissioner of Canada.
In a team workspace, your organization's administrator manages seats and billing and can see membership and usage totals. Individual conversations remain private to each member; administrators cannot read them.
Seren is not directed to children under 13, and we do not knowingly collect their information.
If this policy changes materially we will update the date above and note the change on this page. Questions are always welcome through the contact form.