1. Who We Are
Seraa is an AI-powered women's wellness platform operated in Pakistan. This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with applicable Pakistani laws including PECA 2016.
2. Information We Collect
2.1 Information You Provide Voluntarily
- Nickname / Name: Any name you choose (can be fake โ we encourage anonymity)
- Age Range: General age bracket (e.g., 25-30) โ not exact date of birth
- City: Optional โ only if you choose to provide it
- Phone or Email: Only if you choose to register โ stored encrypted
- Chat Messages: Your conversations with Seraa's AI
2.2 Information Collected Automatically
- Anonymous Session ID: A randomly generated ID to maintain your session
- Language Preference: English or Roman Urdu
- Topic Selection: The wellness topic you selected
- Usage Data: Message count, session duration (no browsing history)
2.3 Information We Do NOT Collect
- โ Real name (unless you choose to share it)
- โ CNIC or government ID
- โ Precise location or GPS data
- โ Device identifiers or advertising IDs
- โ Financial information
- โ Social media profiles or contacts
3. How We Use Your Information
We use collected information solely for the following purposes:
- To provide and improve the AI wellness service
- To maintain your conversation history across sessions (if registered)
- To send OTP verification codes (if you choose to register)
- To analyze anonymized, aggregated trends for platform improvement
- To ensure platform safety and prevent misuse
We never use your data for advertising targeting, profiling, or selling to third parties.
4. How We Protect Your Data
We take data security seriously. Your data is protected through:
- AES-256 Encryption: All chat messages are encrypted before storing in our database
- Encrypted Transmission: All data is transmitted over HTTPS/TLS
- Encrypted at Rest: Database is encrypted at the infrastructure level
- No Plain-text Storage: Phone numbers and emails are hashed and encrypted
- Access Controls: Only authorized personnel can access admin systems
- No Third-party Data Sharing: We do not share raw user data with any third party
5. Data Retention
- Guest sessions: Retained for 90 days, then automatically deleted
- Registered accounts: Retained until you delete your account
- Deleted chats: Immediately hidden from your view; permanently deleted from servers within 30 days
- OTP codes: Deleted immediately after use or expiry (10 minutes)
- Aggregated analytics: Retained indefinitely in anonymized form only
6. Your Rights
You have the following rights regarding your personal data:
- Right to Anonymity: Use the platform without providing real personal information
- Right to Delete: Delete your chat history at any time with one click
- Right to Access: Request a copy of your stored data by contacting us
- Right to Erasure: Request complete deletion of your account and all associated data
- Right to Correction: Update your profile information at any time
To exercise any of these rights, email us at: privacy@seraa.pk
7. AI & Third-Party Services
Seraa uses third-party AI services to generate responses. Your messages are sent to these services to generate AI replies:
- AI Provider: Messages are processed by our AI provider's servers to generate responses
- We do not share your name, phone, email or any identifying information with AI providers
- Messages sent to AI are subject to the AI provider's own data processing policies
- We recommend not sharing highly sensitive personal identifiers (CNIC, exact address) in chat
Our database is hosted on Neon (PostgreSQL cloud) with encryption at rest. Server infrastructure complies with industry-standard security practices.
8. Cookies & Local Storage
Seraa uses browser local storage (not tracking cookies) to:
- Remember your language preference
- Maintain your anonymous session between visits
- Store your nickname and topic preference locally on your device
We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
9. Children's Privacy
Seraa is intended for users aged 18 and above. We do not knowingly collect personal information from individuals under 18. If you believe a minor has used our Platform, please contact us immediately at privacy@seraa.pk and we will delete the associated data.
10. Compliance with Pakistani Law
This Privacy Policy is designed to comply with:
- Prevention of Electronic Crimes Act (PECA) 2016 โ Section 16 (unauthorized access), Section 18 (data protection)
- Pakistan Telecommunication (Re-organization) Act 1996
- PTA Guidelines on digital content and user data
We cooperate with lawful requests from Pakistani authorities in accordance with applicable law. We will notify users of any such requests to the extent legally permissible.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of significant changes via their registered contact. Continued use of the Platform after changes constitutes acceptance of the revised policy.
12. Contact Us
For any privacy-related questions, data requests, or concerns:
๐ง Email: privacy@seraa.pk
๐ง Support: support@seraa.pk
We aim to respond to all privacy requests within 7 business days.