What Sebairo collects
“We collect data to improve your experience” tells you nothing, so here is the actual list. Sebairo holds what it needs to run the things you asked it to run, and each item below exists because a feature you use would not work without it.
- Your account
- The email address or phone number you sign in with, your display name, a photo if you add one, and your chosen language. Sign in by phone and we hold the number; sign in by email and we hold the address. Passwords are stored only as an irreversible digital fingerprint.
- What you create
- Posts, comments, messages, live streams and their replays, Marketplace listings, job posts and applications, notes, memories, workspace projects and tasks, and business pages. This is your content: Sebairo stores it so it can show it back to you and to the people you sent it to, and to nobody else.
- Money records
- Your SBX Wallet balance, top-ups, purchases, withdrawals and a reference for each one. Card numbers are never part of this — the card step happens on Stripe's own page, never on Sebairo.
- Technical data needed to reach your device
- A push token so a notification reaches your phone and not someone else's, and the ordinary server records any hosted service keeps in order to stay up, fix faults and catch abuse.
What Sebairo does not collect or keep
Some of these are decisions we had to build for deliberately. They are the ones worth checking us on.
- Your address book is never uploaded
- Finding which of your contacts already use Sebairo works the way it does in WhatsApp: your phone sends the numbers, the server matches them in memory and answers, and nothing from your address book is written down. No copy of your contacts exists on our side.
- Your card number
- Sebairo has no field for it — the card step happens on Stripe's own checkout page. If a page claiming to be Sebairo asks you to type a card number, it is not Sebairo.
- Your location, unless you switch it on
- The Memories map can show where you are to your contacts or to everyone — and it starts switched off. Off is not “we hide the pin”: until you change the setting, your location is not released to anyone but you.
sell your personal data, or hand it to anyone for advertising targeting.
Who can see what
Most apps decide this in the screen: the server sends everything and the app hides the parts you should not see. In Sebairo, permissions are enforced by Sebairo's servers, not by the screen. When you are not allowed to see something, you do not receive it and then have it hidden; you never receive it.
- Posts carry an audience
- Every post is public, followers, contacts or private, and the rule is enforced where it cannot be bypassed — on the server and in the ranked feed alike. Change a post's audience and the reach changes with it immediately.
- Messages reach participants
- A conversation is readable by the people in it. Direct chats, groups, business inboxes and client portals are separate surfaces on purpose, so a customer thread never lands beside your personal chats.
- Blocking works in both directions
- Blocking someone is not a filter on your screen — it is enforced by Sebairo's servers in both directions: a blocked pair cannot post into an existing direct thread, blocked authors drop out of your feed, and a blocked person's map pin disappears entirely.
- Private links stay private
- Group, chat and contract links never render as a public web page. Share one and the recipient opens it inside the app, where membership is checked — a search engine cannot index it and a stranger with the URL sees nothing.
- Business pages are public by design
- A business page, a Marketplace listing and a job post exist to be found. Everything you put on one is public — that is the point of it — so keep personal details out of a shop front.
Encryption, stated plainly
Everything between your phone and Sebairo travels over TLS, and the database and file storage are encrypted at rest by the hosting platform. That is the ordinary, expected standard and Sebairo meets it.
Sebairo is not end-to-end encrypted, and we are not going to imply otherwise. Messages are stored in a form the service can read. In practice that means moderation can act on something you report, and that a lawful order could compel disclosure. If you need end-to-end encryption for a particular conversation, use a tool built for that and do not assume Sebairo is one.
Nobody at Sebairo reads private conversations as a matter of routine. Access happens when a report needs reviewing, when a fault needs fixing at your request, or when the law requires it — and staff actions are recorded.
The controls you actually have
- Choose an audience per post
- Public, followers, contacts or private — set before you post and changeable afterwards.
- Block, and see who you blocked
- The blocked list is a real screen in Settings, not a one-way action you can never review.
- Report anything, from where you see it
- Posts, messages, listings, streams and profiles all carry a report action. Your report is not shown to the person you reported.
- Delete the account, for real
- Settings has a danger zone that asks you to type the word DELETE. Confirm it and the account is removed at the authentication layer, which cascades your profile and everything attached to your profile with it.
One known gap, stated rather than buried: files already published to the public parts of the app are not purged in the same instant as the account — the delete-account page states this in full.
The companies involved in running Sebairo
Sebairo is one app, but it does not pretend to run on air. These are the services your data touches, and what each one is for.
- Supabase
- A subprocessor Sebairo uses to run the service.
- Stripe
- Payments — the card step happens on Stripe's PCI-certified checkout, not on Sebairo.
- LiveKit
- Carries the audio and video of calls and live streams while they are happening.
- Firebase Cloud Messaging
- Delivers push notifications to your device. It gets a token and a notification, not your content library.
This page is not the policy
What you have just read is an explanation. The Privacy Policy is the binding document — it is where the legal basis, retention and your statutory rights are set out, and it governs if the two ever disagree. If you find a place where this page claims more than the system does, tell us and we will correct this page the same day.
Questions people actually ask
Short answers. If yours is not here, the Help Centre answers in more depth.
Is Sebairo end-to-end encrypted?
No — and we say so plainly rather than let you assume otherwise. The encryption section above explains what that means in practice.
Do you sell my data?
No. Sebairo earns from subscriptions, from SBX top-up packs, and from advertisers who buy reach — not from selling personal data to anyone.
Does Sebairo upload my contacts?
No. Numbers are matched in memory to tell you who is already here, and nothing from your address book is stored on our side.
What happens when I delete my account?
The account is deleted at the authentication layer and your profile and profile-scoped data go with it — already-published public files are the one exception, removed separately.
Where are my card details?
With Stripe, never with Sebairo — we hold only the outcome of a payment and a reference for it.