Sepamo Privacy Policy
Effective date: 13 September 2026
Sepamo is a personal planning app for Android made by Eetu Halonen
(“we”, “us”), an individual developer based in Finland and the data
controller for the processing described here under the EU General Data
Protection Regulation (GDPR). This policy explains what data Sepamo
reads, what stays on your device, what is stored in your account, what
is sent to third parties and why, and what control and rights you have.
It applies to the Sepamo Android app distributed on Google Play.
Sepamo has no analytics, no ads, and no tracking.
Using Sepamo requires an account — an email address and password, or
your Google account — and a backend that we operate — the open-source Supabase server software, which we
self-host on a virtual server we rent from UpCloud in
the European Union (Finland). That backend signs you in, routes Sepamo’s
AI, map, weather, and place requests to their providers (so third-party
API keys are never shipped in the app), and backs up and
synchronises your plans across your devices.
The short version
- You sign in with an email address and password, or
with your Google account if you prefer.
- Your plans, plan history, and planner conversations
are stored on your device and backed up to your Sepamo
account on our backend, so they sync across the devices where
you sign in.
- When you use the AI planner, the text of your
conversation — and any device data you have allowed the planner to read
(calendar events, screen-time statistics, contact names, the list of
apps and home-screen widgets you have installed, the names of your
paired Bluetooth devices, approximate location for place search,
clipboard text if you switch that on, attached photos) — is sent through
our backend to OpenAI, which runs the planner. Voice
you dictate is transcribed by Mistral AI.
- Health data is never sent anywhere. Health Connect
data is read and used entirely on your device.
- You can delete your account and all its data at any
time (see Storage, retention, and deletion), and revoke any
permission whenever you like.
Data Sepamo reads, and
where it goes
Data that never leaves your
device
| Health Connect data (steps, calories, distance, exercise, sleep,
heart rate) |
To show health cards and trigger plan steps you set up (e.g. “remind
me if I’m under 8 000 steps by evening”) |
Read on demand, processed on-device only. Never sent off
your device. |
| Notifications (notification access) |
To trigger plan steps on notifications you choose |
On-device only |
| App usage for triggers |
To trigger steps like “after 1 h of Instagram” |
Evaluated on-device |
| Precise location for place triggers |
To fire “when I arrive home”-style steps, including in the
background if you grant it |
Evaluated on-device |
| Physical activity (still, walking, running, cycling, driving, in
transit) |
To trigger steps like “when I stop driving”, and to remember where
the car was parked |
Evaluated on-device; the parked-car location is kept on the device
only |
| Call state (whether a call is in progress — never who you are
talking to) |
To trigger “while I’m on a call” / “right after a call” steps |
Evaluated on-device |
| Connected Bluetooth devices and Wi-Fi network name |
To trigger “when my headphones connect” / “when I’m on home Wi-Fi”
steps |
Evaluated on-device |
| Contact birthdays and anniversaries |
To show cards for the days around them |
Read on-device only |
Data stored in
your Sepamo account (our backend)
To sign you in, back up your work, and keep it in sync across your
devices, the following is stored on our backend — the self-hosted
Supabase software running on our UpCloud server in the EU (Finland) —
over encrypted connections (HTTPS):
- Your email address, and — if you sign in with a
password — a salted hash of that password (we never store the password
itself). Used to authenticate you.
- If you sign in with Google, the details your Google
account releases to us when you do: your email address, your name, a
link to your profile picture, and the identifier Google uses for you.
Used to recognise you on each sign-in.
- Your account identifier (a random ID), used as the
key for your data and for rate-limiting.
- Your plans and plan history — the plans you create,
edit, and archive.
- Your planner conversations — your saved chats with
the AI planner.
- A little app state — for example which cards you
have minimised on your home screen, so your devices agree on how the app
looks.
- Usage metadata — a per-request record of
which backend service was called (AI, maps, weather) and when,
and for AI calls which model answered, how many tokens it used, what
that cost, how long it took and whether it succeeded. Used only to
enforce fair-use rate limits and the AI cost budget and to keep the
service healthy. No content is stored in this log, and it is tied to
your account for three days only (see Retention).
- Reports you file — if you use the Report
action on an AI response, the text you reported and any note you wrote
are stored so we can look at them.
- Feedback you send — if you use Send
feedback in Settings, your message, the reply address you gave, and
your app version and device model are stored so we can reproduce what
you described. Feedback is also emailed to us so we act on it.
- Your subscription record — if you subscribe to
Basic or Pro through Google Play, we store which plan you are on, the
Play product name, when it expires or renews, whether it auto-renews,
and the opaque purchase token Google issues for the purchase.
The token is what lets us ask Google whether the purchase is still
valid; it contains no payment details. We never see your payment method,
card number, billing address, or invoice — Google holds those as the
seller (see Subscriptions and Google Play below).
This data stays in your account until you delete it or delete your
account (see below). It is not sold, not used for advertising, and not
shared except with the processors named below when a feature you use
requires it.
Signing in with Google
Signing in with Google is optional — the email-and-password route
needs no Google account at all. If you do choose it, your device asks
Google (Google Ireland Limited for users in the EEA,
Google LLC elsewhere) to confirm who you are, so Google learns that you
signed in to Sepamo and when. Google hands us a signed token containing
the details listed above, which we exchange for a Sepamo session; we
never see your Google password, and we ask Google for nothing beyond
your basic profile. Google’s own handling of that sign-in is covered by
the Google Privacy
Policy. If you would rather Google not know you use Sepamo, sign up
with an email address and password instead.
Subscriptions and Google
Play
Paid plans are sold through Google Play (Google
Ireland Limited for users in the EEA, Google LLC elsewhere). Google is
the seller of record and an independent controller for
the purchase: it collects your payment, issues the receipt, applies its
refund policy, and handles the purchase data under the Google Privacy Policy.
What Google shares with us is limited to the purchase token and the
state of the subscription (active, cancelled, expired, in grace period,
and its expiry date), which our backend fetches from Google’s Play
Developer API to confirm a purchase and to re-check it when the app
opens. We use it for nothing else. The Free plan involves no purchase
and sends nothing to Google beyond what the Play Store itself does to
distribute the app.
Data
sent to our AI providers when you use AI features
Sepamo’s AI features are handled by two processors, each over
encrypted connections (HTTPS/WSS) and only when you use the feature:
- OpenAI (OpenAI, L.L.C., United States) runs every
text-generating AI feature: the AI planner — the model
that reads your request and writes your plan, including any web searches
the planner makes — the app’s occasional suggestions,
and the background checks a plan can wait on (“tell me
when X happens”). This content is sent with OpenAI’s no-retention flag
set, so it is not stored by OpenAI and is not used to train its
models.
- Mistral AI (Mistral AI SAS, France) transcribes
your voice dictation and extracts text from
photos you attach (OCR).
The following is sent, to the provider noted, so each feature can
work:
- Your planner conversations — the messages you type
or dictate, and attached photos — go to OpenAI to
generate your plan. Attached photos are also sent to Mistral
AI to extract their text (OCR).
- Voice audio — while you dictate, audio is streamed
to Mistral AI for transcription; the resulting text
goes to the planner.
- Calendar events (titles, times, locations) — to
OpenAI, only when the planner needs your schedule for a
request and you have granted calendar access.
- Screen-time statistics (top apps and duration) — to
OpenAI, only for screen-time related requests, with
app-usage access granted.
- Contact names — to OpenAI, when
you ask for a plan involving a person. Phone numbers and email addresses
are replaced with anonymous tokens and are not
sent.
- Approximate location — to OpenAI,
when the planner searches for places near you.
- The list of apps you have installed (label, package
name, category) — to OpenAI, so a plan can reference an
app that is really on your phone rather than one the model guessed
at.
- The names of your home-screen widgets and of your paired
Bluetooth devices — to OpenAI, only when a
plan needs to embed a widget or react to a device connecting, so it uses
a name that really exists rather than a guess.
- Clipboard text — to OpenAI, only
when you refer to something you copied, and only if you have
turned clipboard access on. This is off by
default; the switch is in Settings under Planner
behaviour. With it off, Sepamo never reads your clipboard.
- Web search queries derived from your request — run
by OpenAI’s web search when the planner searches the
web.
- The topic of a flashcard deck you ask the planner
to make (“I want to learn X”) — to OpenAI, which writes
the deck, grounded with a web search.
- A short description of a pattern the app noticed
(for example a plan name you keep following through on) — to
OpenAI, used to word the occasional suggestion, and
only while suggestions are switched on.
- The question a waiting step is watching for (the
text you wrote, for example “when the tickets go on sale”) — to
OpenAI, which re-checks it with a web search on a
schedule until it comes true, and only while such a step is active.
See OpenAI’s
privacy policy and Mistral AI’s privacy
policy for their handling. We do not send health data, passwords,
phone numbers, email addresses, or files from your device.
Place search additionally sends the place text you asked about (and,
for nearby search, your coordinates) to Stadia Maps to
look up locations, and map tiles are loaded from Stadia Maps when you
view a map. See Stadia Maps’
privacy policy. Weather lookups send approximate coordinates to
Open-Meteo. Nearby-place lookups (a plan step “near a café”) and the
train/boat detection behind the activity condition are answered by our
own backend from a copy of the open Overture Maps dataset that we host
ourselves; those coordinates never leave our infrastructure.
Legal bases (EU GDPR)
We process your data on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): creating
and authenticating your account; backing up and syncing your plans, plan
history, and planner conversations; fulfilling the AI, map, weather, and
place requests you make in the app; and recording and verifying your
subscription so the plan you paid for is the plan you get.
- Consent (Art. 6(1)(a)): sending device data
(calendar events, screen-time statistics, contact names, installed apps
and widgets, paired Bluetooth device names, location, clipboard text,
voice audio) to the AI planner. Consent is asked in the app, via a
disclosure shown before your first use of the AI planner — nothing in
these categories is transmitted before you accept it — and most
categories additionally sit behind an Android permission you grant and
can revoke at any time. Clipboard access has no Android permission of
its own, so it has its own switch in Settings and is off until
you turn it on. You can withdraw consent at any time by turning
suggestions or clipboard access off in Sepamo’s settings, or by revoking
the relevant permission; withdrawal does not affect processing that
already took place.
- Legitimate interests (Art. 6(1)(f)): the
usage-metadata log described above, kept solely to enforce fair-use rate
limits and the AI cost budget, prevent abuse of our backend, and notice
when the service is unhealthy. No content is stored in it.
Your rights (EU GDPR)
You have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data (delete individual items in the
app, or delete your account and everything in it);
- Receive a copy of the data you have provided in a
machine-readable format (data portability) — you can do this yourself at
any time, without asking us, from Settings → Export my
data;
- Restrict or object to processing based on
legitimate interests;
- Withdraw consent at any time (see Legal
bases above).
To exercise any of these rights, email
help@sepamo.com; we will respond within one month. You
also have the right to lodge a complaint with a data protection
supervisory authority — in Finland, the Data Protection Ombudsman (tietosuoja.fi) — or with the
authority of your own EU/EEA country.
Where your
data is processed (international transfers)
Your account and synced data live on our backend, which we self-host
on an UpCloud virtual server in Finland
(European Union). UpCloud Ltd (Helsinki, Finland) operates that
infrastructure as our hosting provider; the Supabase software running on
it is operated by us, not by Supabase, Inc., which receives none of your
data. Mistral AI SAS is established in France. Your
account data, backups, and Mistral AI’s processing therefore stay within
the EU/EEA.
Two providers involve transfers outside the EU/EEA: OpenAI,
L.L.C. (the AI planner, suggestions, and background checks) and
Stadia Maps, Inc. (place search and map tiles) are
United States companies, and limited data may be processed in the United
States when you use those features. These transfers are safeguarded by
the European Commission’s Standard Contractual Clauses incorporated into
each provider’s data-processing terms. Weather (Open-Meteo) lookups
receive only approximate coordinates, with no account identifier
attached. Nearby-place and transport-context lookups are served from map
data we host on UpCloud in Finland and reach no third party.
If you sign in with Google, that sign-in is handled by Google
Ireland Limited (Dublin, Ireland) for users in the EEA, under
the same Standard Contractual Clauses where Google moves data to the
United States. Choosing the email-and-password route avoids that
transfer entirely.
Storage, retention, and
deletion
Your Sepamo data lives in two places: on your
device, and in your account on our backend
(for the categories listed above). Both are retained until you delete
them:
- Deleting a plan or conversation in the app removes it from your
device and marks it deleted in your account, so the deletion propagates
to your other devices.
- Deleting your account removes your account and
all data associated with it from our backend (your
sign-in details, plans, plan history, conversations, app state, any
reports or feedback you sent, and usage metadata). Deletion is immediate
and permanent. You can delete your account in any of three ways:
- In the app: open Settings → Delete
account.
- On the web: sign in at sepamo.com/delete-account —
no need to have the app installed.
- By email: write to help@sepamo.com
from the address you registered with, and we will delete it within one
month (usually much sooner).
- Uninstalling Sepamo removes all data stored locally on that device,
but does not by itself delete your account; use one of the deletion
options above to remove the backend copy.
- Usage metadata is the one category with its own
clock: it is tied to your account for three days, after which the
account identifier is removed from it; the anonymised per-call records
(model, tokens, cost, latency, outcome) are kept for thirty days and
then deleted.
Data sent to OpenAI, Mistral AI, Stadia Maps, or Open-Meteo is
retained by those providers under their own policies; deleting your
Sepamo account does not delete data already processed by them.
Your controls
- Every device permission (calendar, location, contacts, microphone,
health, app usage, notifications, physical activity, phone state, nearby
devices, Do Not Disturb access, display over other apps, exact alarms)
is optional and requested only when a feature needs it. Denying a
permission disables only that feature.
- Health Connect access can be reviewed and revoked in Health Connect
settings at any time.
- Suggestions can be disabled in Sepamo’s settings;
with them off, nothing derived from your app usage is sent
anywhere.
- You can delete your account and all its data at any time — in the
app (Settings → Delete account), on the web, or by email (see
Storage, retention, and deletion above) — and exercise any of
the rights listed under Your rights by email.
Children
Sepamo is for people aged 16 and over. Creating an
account requires confirming that you are at least 16, and we do not
knowingly collect data from anyone younger.
Why 16 and not 13: Sepamo relies on your consent to send device data
to the AI planner, and under Article 8 GDPR a child’s consent to an
online service is only valid from the age of digital consent, which each
EU country sets somewhere between 13 and 16. Rather than apply a
different rule in each country, Sepamo uses the highest of them
everywhere.
If you believe a child under 16 has created an account, email
help@sepamo.com and we will delete it.
Changes
If this policy changes, the updated version will be posted at this
address and the effective date updated. Material changes will be
highlighted in the app.
Automated processing and AI
Sepamo uses an AI model to write plans, flashcard decks you ask for,
to word its occasional suggestions, and to run background checks. Two
things follow that you should know:
- We make no automated decisions with legal or similarly
significant effects about you (Art. 22 GDPR). Nothing Sepamo
generates is applied without you choosing to accept it.
- AI-written text is marked as such — visibly,
wherever it is not obvious from the context that a model wrote it, and
as a machine-readable marker in the data you export. This is our
transparency obligation under Article 50 of the EU AI Act.
The suggestions feature looks for patterns in how you use your phone
in order to offer a plan. That is profiling in the GDPR’s sense, so it
is optional: turn Suggestions off in Settings and
nothing derived from your usage is computed or sent. You may also object
to it, or to any processing we base on legitimate interests, by emailing
us.
Terms
Your use of Sepamo is also governed by our Terms of Service, which cover what
Sepamo is, what you may not use it for, how to report AI-generated
content, and your rights as a consumer.
Questions or requests about your data, including account deletion:
help@sepamo.com
That address is also our point of contact under Articles 11 and 12 of
the EU Digital Services Act. Our full trader details, including postal
address, are in the imprint.