Sepamo Privacy Policy

Effective date: 13 September 2026

Sepamo is a personal planning app for Android made by Eetu Halonen (“we”, “us”), an individual developer based in Finland and the data controller for the processing described here under the EU General Data Protection Regulation (GDPR). This policy explains what data Sepamo reads, what stays on your device, what is stored in your account, what is sent to third parties and why, and what control and rights you have. It applies to the Sepamo Android app distributed on Google Play.

Sepamo has no analytics, no ads, and no tracking. Using Sepamo requires an account — an email address and password, or your Google account — and a backend that we operate — the open-source Supabase server software, which we self-host on a virtual server we rent from UpCloud in the European Union (Finland). That backend signs you in, routes Sepamo’s AI, map, weather, and place requests to their providers (so third-party API keys are never shipped in the app), and backs up and synchronises your plans across your devices.

The short version

Data Sepamo reads, and where it goes

Data that never leaves your device

Data Why Sepamo reads it Where it lives
Health Connect data (steps, calories, distance, exercise, sleep, heart rate) To show health cards and trigger plan steps you set up (e.g. “remind me if I’m under 8 000 steps by evening”) Read on demand, processed on-device only. Never sent off your device.
Notifications (notification access) To trigger plan steps on notifications you choose On-device only
App usage for triggers To trigger steps like “after 1 h of Instagram” Evaluated on-device
Precise location for place triggers To fire “when I arrive home”-style steps, including in the background if you grant it Evaluated on-device
Physical activity (still, walking, running, cycling, driving, in transit) To trigger steps like “when I stop driving”, and to remember where the car was parked Evaluated on-device; the parked-car location is kept on the device only
Call state (whether a call is in progress — never who you are talking to) To trigger “while I’m on a call” / “right after a call” steps Evaluated on-device
Connected Bluetooth devices and Wi-Fi network name To trigger “when my headphones connect” / “when I’m on home Wi-Fi” steps Evaluated on-device
Contact birthdays and anniversaries To show cards for the days around them Read on-device only

Data stored in your Sepamo account (our backend)

To sign you in, back up your work, and keep it in sync across your devices, the following is stored on our backend — the self-hosted Supabase software running on our UpCloud server in the EU (Finland) — over encrypted connections (HTTPS):

This data stays in your account until you delete it or delete your account (see below). It is not sold, not used for advertising, and not shared except with the processors named below when a feature you use requires it.

Signing in with Google

Signing in with Google is optional — the email-and-password route needs no Google account at all. If you do choose it, your device asks Google (Google Ireland Limited for users in the EEA, Google LLC elsewhere) to confirm who you are, so Google learns that you signed in to Sepamo and when. Google hands us a signed token containing the details listed above, which we exchange for a Sepamo session; we never see your Google password, and we ask Google for nothing beyond your basic profile. Google’s own handling of that sign-in is covered by the Google Privacy Policy. If you would rather Google not know you use Sepamo, sign up with an email address and password instead.

Subscriptions and Google Play

Paid plans are sold through Google Play (Google Ireland Limited for users in the EEA, Google LLC elsewhere). Google is the seller of record and an independent controller for the purchase: it collects your payment, issues the receipt, applies its refund policy, and handles the purchase data under the Google Privacy Policy. What Google shares with us is limited to the purchase token and the state of the subscription (active, cancelled, expired, in grace period, and its expiry date), which our backend fetches from Google’s Play Developer API to confirm a purchase and to re-check it when the app opens. We use it for nothing else. The Free plan involves no purchase and sends nothing to Google beyond what the Play Store itself does to distribute the app.

Data sent to our AI providers when you use AI features

Sepamo’s AI features are handled by two processors, each over encrypted connections (HTTPS/WSS) and only when you use the feature:

The following is sent, to the provider noted, so each feature can work:

See OpenAI’s privacy policy and Mistral AI’s privacy policy for their handling. We do not send health data, passwords, phone numbers, email addresses, or files from your device.

Place search additionally sends the place text you asked about (and, for nearby search, your coordinates) to Stadia Maps to look up locations, and map tiles are loaded from Stadia Maps when you view a map. See Stadia Maps’ privacy policy. Weather lookups send approximate coordinates to Open-Meteo. Nearby-place lookups (a plan step “near a café”) and the train/boat detection behind the activity condition are answered by our own backend from a copy of the open Overture Maps dataset that we host ourselves; those coordinates never leave our infrastructure.

We process your data on the following legal bases:

Your rights (EU GDPR)

You have the right to:

To exercise any of these rights, email help@sepamo.com; we will respond within one month. You also have the right to lodge a complaint with a data protection supervisory authority — in Finland, the Data Protection Ombudsman (tietosuoja.fi) — or with the authority of your own EU/EEA country.

Where your data is processed (international transfers)

Your account and synced data live on our backend, which we self-host on an UpCloud virtual server in Finland (European Union). UpCloud Ltd (Helsinki, Finland) operates that infrastructure as our hosting provider; the Supabase software running on it is operated by us, not by Supabase, Inc., which receives none of your data. Mistral AI SAS is established in France. Your account data, backups, and Mistral AI’s processing therefore stay within the EU/EEA.

Two providers involve transfers outside the EU/EEA: OpenAI, L.L.C. (the AI planner, suggestions, and background checks) and Stadia Maps, Inc. (place search and map tiles) are United States companies, and limited data may be processed in the United States when you use those features. These transfers are safeguarded by the European Commission’s Standard Contractual Clauses incorporated into each provider’s data-processing terms. Weather (Open-Meteo) lookups receive only approximate coordinates, with no account identifier attached. Nearby-place and transport-context lookups are served from map data we host on UpCloud in Finland and reach no third party.

If you sign in with Google, that sign-in is handled by Google Ireland Limited (Dublin, Ireland) for users in the EEA, under the same Standard Contractual Clauses where Google moves data to the United States. Choosing the email-and-password route avoids that transfer entirely.

Storage, retention, and deletion

Your Sepamo data lives in two places: on your device, and in your account on our backend (for the categories listed above). Both are retained until you delete them:

Data sent to OpenAI, Mistral AI, Stadia Maps, or Open-Meteo is retained by those providers under their own policies; deleting your Sepamo account does not delete data already processed by them.

Your controls

Children

Sepamo is for people aged 16 and over. Creating an account requires confirming that you are at least 16, and we do not knowingly collect data from anyone younger.

Why 16 and not 13: Sepamo relies on your consent to send device data to the AI planner, and under Article 8 GDPR a child’s consent to an online service is only valid from the age of digital consent, which each EU country sets somewhere between 13 and 16. Rather than apply a different rule in each country, Sepamo uses the highest of them everywhere.

If you believe a child under 16 has created an account, email help@sepamo.com and we will delete it.

Changes

If this policy changes, the updated version will be posted at this address and the effective date updated. Material changes will be highlighted in the app.

Automated processing and AI

Sepamo uses an AI model to write plans, flashcard decks you ask for, to word its occasional suggestions, and to run background checks. Two things follow that you should know:

The suggestions feature looks for patterns in how you use your phone in order to offer a plan. That is profiling in the GDPR’s sense, so it is optional: turn Suggestions off in Settings and nothing derived from your usage is computed or sent. You may also object to it, or to any processing we base on legitimate interests, by emailing us.

Terms

Your use of Sepamo is also governed by our Terms of Service, which cover what Sepamo is, what you may not use it for, how to report AI-generated content, and your rights as a consumer.

Contact

Questions or requests about your data, including account deletion: help@sepamo.com

That address is also our point of contact under Articles 11 and 12 of the EU Digital Services Act. Our full trader details, including postal address, are in the imprint.