Privacy Policy
Last updated: 22 May 2026
This policy explains what personal information Selah collects, why we collect it, how we use it, and the rights you have over it. It is written to comply with the South African Protection of Personal Information Act (POPIA, Act 4 of 2013).
1. Who we are
Selah is operated by Selah (operated by Pirow Engelbrecht), the responsible party for your personal information under POPIA. You can reach us at support@selah.quest.
Our registered business address is: [TODO_LEGAL: Physical business address — required by POPIA s.18 and ECT s.43]
Registration: [TODO_LEGAL: Company registration number, or 'Sole proprietor — N/A']
VAT: [TODO_LEGAL: VAT number if registered, otherwise leave blank]
2. Our Information Officer
In line with POPIA s.55, our Information Officer is responsible for ensuring this policy is followed. You can contact them at support@selah.quest for any privacy-related question, complaint, or data subject request.
3. What we collect and why
Account information
- Email address, display name, profile picture — to create and identify your account. Provided by you or by Google when you sign in with Google.
- Authentication tokens — stored by our auth provider (Supabase) so you stay signed in.
Reading and study activity
- Verses read, chapters completed, streaks, XP, game results — to power your reading progress, streaks, levels, and the journeys you join.
- Journal entries, prayer notes, reflections — stored only for you. We do not display them to anyone else without your explicit action (e.g. sharing in a fellowship).
- Fellowships and friends you join — to provide the social features you opted into.
Payment information
- We do not store your card details. Payment is processed by PayFast (Pty) Ltd, a registered South African payment service provider that holds PCI DSS Level 1 certification.
- We retain the transaction reference, amount, currency, status, and PayFast token so that we can manage your subscription, issue refunds, and meet our tax obligations.
Device and usage information
- IP address, browser type, device type, timestamps — for security, fraud prevention, and to diagnose problems.
- Time zone — to draw the day boundary for streaks in your local time.
Email lifecycle
- We send transactional emails (welcome, trial reminders, cancellation confirmations, security alerts). These are essential to the service.
- Any non-essential marketing email is opt-in only and you can unsubscribe at any time.
4. Lawful basis for processing
POPIA s.11 lets us process your information when one of these applies:
- Contract — we process your account, subscription, and payment data to provide the Selah service you signed up for.
- Consent — for non-essential things like marketing emails or social features. You can withdraw consent at any time.
- Legitimate interest — for security, fraud prevention, and improving the product. Always balanced against your rights.
- Legal obligation — to meet our tax, accounting, and other South African legal duties.
5. Who else sees your data (operators)
We share personal information only with operators who help us run the service. Each operator is bound by an agreement to use your data only for the purposes we direct.
| Operator | What they do | Where the data lives |
|---|---|---|
| Supabase | Database + authentication | European Union |
| PayFast (Pty) Ltd | Payment processing | South Africa |
| Google (OAuth) | Sign-in with Google | United States / global |
| Anthropic | AI-generated study content | United States |
| Google AI (Gemini) | Journey cover-art generation | United States |
| Cloudflare R2 (when enabled) | Image and asset storage | Global edge network |
We never sell your personal information, and we do not share it with advertisers.
6. Cross-border transfers
Some of our operators are outside South Africa, as listed above. POPIA s.72 lets us transfer your information across borders when the receiving country has substantially similar data protection laws, when you consent, or when the transfer is necessary to perform our contract with you. All operators we use meet at least one of these conditions.
7. How long we keep your information
- Account data — for as long as your account is active, plus 30 days after deletion (a grace window in case you change your mind).
- Payment and tax records — at least 5 years after the transaction, as required by the South African Revenue Service.
- Audit logs — at least 12 months, for security and dispute resolution.
- Backups — automatically expire on a rolling 30-day cycle.
8. Your rights under POPIA
You have the right to:
- Access — request a copy of the personal information we hold about you. Use Profile → Privacy → Export my data, or email us.
- Correction — fix anything that is inaccurate or out of date. Most of this you can do yourself in Profile.
- Deletion — ask us to delete your account and your personal information. Use Profile → Privacy → Delete my account, or email us. Some records (e.g. tax invoices) must be retained by law.
- Object to processing that relies on consent or legitimate interest.
- Withdraw consent at any time for anything we asked your permission for.
- Lodge a complaint with the Information Regulator if you believe we have mishandled your information: inforegulator.org.za
9. Security
We use industry-standard measures to protect your information: HTTPS in transit, encryption at rest in our database, scoped database access policies, hashed and salted credentials, and regular dependency updates. No system is perfectly secure. If a data breach occurs that materially affects you, we will notify you and the Information Regulator within a reasonable time, as required by POPIA s.22.
10. Children
Selah is intended for users aged 18 and over. If you are between 13 and 17, you may only use Selah with the consent of a parent or guardian, who agrees to these terms on your behalf. We do not knowingly collect personal information from children under 13. If you believe a child has registered an account, please contact us and we will delete the account promptly.
11. Changes to this policy
We will post any material changes to this page and update the “last updated” date. For significant changes we will also notify you by email.
12. Contact us
Privacy and data questions: support@selah.quest
General support: support@selah.quest
