SELF Terms of Service
Last Updated: August 9, 2026
Version: 9.5.0
What SELF Is
SELF is your private and productive set of digital tools. Protected content is encrypted client-side before it reaches our servers. You hold the keys.
Progressive Web App (PWA)
SELF is available as a Progressive Web App. This means:
- Installable - You can install SELF on your device like a native app
- Offline capabilities - SELF can work offline for basic functions (planned feature)
- Service workers - Live background processes for caching and notifications
- Cross-platform - Works on desktop, mobile, and tablet devices
- Browser install - You can install from your browser without app store restrictions
We Cannot Read What You Encrypt
SELF uses zero-knowledge encryption for specific protected content. Your device encrypts this content with keys we never receive:
- AI conversation history and Memory Bank entries
- Messenger content and attachments
- Vault file contents, file metadata and folder names
- Calendar event content
- Mail sent between SELF accounts
- Chain validator private keys
The server stores ciphertext for this protected content and does not hold the keys needed to decrypt it.
Information Needed to Run SELF
SELF can access limited service information, including your account email address, message routing identifiers and timing, calendar reminder times and event types, mail envelope data such as timestamp, size and folder, public wallet addresses, and billing or subscription status. Standard internet mail exchanged with external providers is readable while crossing the service boundary. Live AI prompts are processed on SELF-controlled EU GPU infrastructure to generate responses.
Your Data Stays Yours
- We don't sell or mine your data - No advertisers, advertising profiles, or cross-site tracking
- Client-side encryption - Named protected content is encrypted in your browser using the WebCrypto API (AES-256-GCM)
- Recovery phrase-based encryption - Encryption keys are derived from your 12-word recovery phrase using BIP39
- You can leave anytime - Export available data or delete your account anytime
You Can Always
- Access your data - Export and decrypt supported protected content with your recovery phrase
- Delete your account - Request deletion of your account and associated data under our retention rules
- Export your data - Download supported account and protected content before leaving
- Update information - Update your username or payment details anytime
We Can't And Won't
- Try and access your messages or files
- Track your browsing for advertising, or build cross-site profiles from your activity
- Add SELF account identifiers to search requests - When you enable Connect-tier web search, search text is sent to a third-party provider without your SELF account ID, username, or email
- Lock you into our service
What You Can't Do
To keep SELF safe for everyone, please don't:
- Share illegal content or use SELF for anything unlawful
- Try to hack or interfere with our service or other users
- Spam or harass other users through messaging features
- Resell access to your SELF account
Your Content
The protected content named above is encrypted with keys only you hold:
- You own everything you create, upload, or store in SELF
- You're responsible for ensuring you have rights to any content you add
- Protected content stays private - the encrypted content named above remains unreadable to SELF
- Keep it legal - don't store anything that violates laws
Intellectual Property
- SELF software - We own the SELF application, interface, and core technology
- Your content - You retain full ownership of everything you create using SELF
- AI outputs - You own the results generated by customized SELF AI models within your Memory Bank
- Open source - SELF uses open-source components under their respective licenses
- No claims - We make no claims to your intellectual property or creative works
Security & Encryption
How We Protect Your Data
- Client-side end-to-end encryption - Named protected content is encrypted in your browser using the WebCrypto API (AES-256-GCM) before transmission
- Zero-knowledge architecture - The server stores encrypted blobs and cannot decrypt the protected content named above
- Recovery phrase-based encryption keys - Encryption keys derived from your 12-word recovery phrase using BIP39 (mnemonic to seed)
- TLS encryption in transit - Service traffic, including encrypted blobs, is protected by HTTPS during transmission
- Stripe payment security - All payment processing uses Stripe's PCI-compliant encryption and security protocols
- Both tiers - Zero and Connect tiers use identical client-side E2E encryption for maximum privacy
- No server access to protected content - Server cannot read your AI conversation history, Memory Bank entries, messenger content, Vault content, calendar event content, SELF-to-SELF mail, or validator private keys
App Permissions
SELF requests only the permissions necessary for core functionality:
- File system access - To save and sync your documents and data locally
- Network access - To connect to your Memory Bank and sync data
- Notification permissions - To alert you about important updates or security issues
- Optional: Camera/microphone - Only when you choose to upload media or use voice features
- Core functionality works - SELF operates fully even if you deny optional permissions
Authentication, Encryption and Recovery
Authentication and encryption use separate mechanisms. WebAuthn passkeys authenticate you to your SELF account. Your 12-word BIP39 recovery phrase derives your encryption keys on your device.
- Primary authentication - WebAuthn passkeys provide secure, passwordless account access, with device support such as Face ID, Touch ID, or fingerprint recognition
- Secondary authentication - Email and a single-use OTP provide a fallback sign-in path when a passkey is unavailable
- Email privacy - We store a lookup-only email hash and a server-decryptable encrypted copy of your email for account access and operational communications. Plaintext email is not returned by APIs, and admin tools show a masked address.
- Encryption key derivation - Your browser derives encryption keys from your recovery phrase using BIP39. Passkeys and OTPs do not derive those keys.
- Optional recovery password - You may choose to store a server copy of your recovery phrase wrapped client-side with a password-derived key using 600,000 PBKDF2 iterations. SELF receives the wrapped blob and does not receive your password.
- Multi-device access - The same recovery phrase derives the same encryption keys on each device
- Recovery limits - A passkey or email OTP may restore account access without restoring access to encrypted content. Without the recovery phrase or the optional recovery-password path, encrypted content cannot be recovered by you or SELF.
Vulnerability Reporting
Found a security issue? We want to hear from you:
- Security vulnerabilities - Report code and security issues to security@self.app (see Bug Bounty program). For all other inquiries use Settings → Contact Us
- Responsible disclosure - We'll acknowledge reports within 48 hours and work with you on fixes
- Security updates - Critical security patches are released immediately and pushed to all users
- No penalties - Good faith security research is welcomed and protected
Third-Party Services
Memory Bank Definition
Your Memory Bank uses client-side end-to-end encryption on both tiers, with encrypted blobs stored in PostgreSQL on single-tenant bare metal infrastructure in the EU:
- Both Tiers - AI conversations and Memory Bank entries are encrypted in your browser using the WebCrypto API (AES-256-GCM) before transmission. The server stores ciphertext and cannot decrypt it.
- Data Export - Both tiers can export supported decrypted content through Settings. Decryption happens in your browser.
- Recovery Options - Keep your recovery phrase secure. You may also enable the optional recovery-password feature, which stores a client-side wrapped phrase copy as described above. SELF cannot recover encrypted content without one of those paths.
Service Dependencies
- Service availability depends on frontend CDN delivery, EU-based infrastructure providers, and Stripe billing
- Performance may vary based on CDN delivery, single-tenant bare metal backend infrastructure, and dedicated EU GPU hardware conditions
- Data sovereignty is maintained through zero-knowledge encryption, Memory Bank isolation, and EU-based single-tenant bare metal infrastructure
- Payment security - Payments use Stripe's certified infrastructure
- Frontend reliability depends on third-party CDN hosting of static assets (JS, CSS, HTML)
- Backend reliability depends on EU-based single-tenant bare metal infrastructure
- AI processing reliability depends on dedicated GPU infrastructure in EU data centers
Frontend Delivery (CDN)
- SELF uses a third-party CDN for frontend hosting and global delivery of static assets (JS, CSS, HTML)
- The CDN delivers public application files only. It does not receive your encrypted user content.
- We are not responsible for CDN service interruptions or changes
- CDN providers may change over time; these terms will be updated accordingly
EU Infrastructure
- SELF backend API, database, encrypted Memory Bank, messaging, mail, and signaling run on single-tenant bare metal servers in the EU
- Client-side encrypted Vault files, messenger attachments and SELF-to-SELF mail blobs use dedicated EU object storage (S3-compatible)
- AI text and image processing uses dedicated (non-shared) GPU hardware in EU data centers
- Infrastructure providers operate systems and do not receive the keys for client-side encrypted protected content
- Providers may change over time; these terms will be updated accordingly
- When your account is deactivated, associated storage is permanently deleted per our retention policy
Memory Bank Lifecycle
Your Memory Bank follows this lifecycle:
- Creation - Storage is created when you first use SELF (available for both Zero and Connect tiers)
- Isolation - Your storage is completely isolated from other users' data
- Runtime - Storage holds your conversations and AI processes them securely
- Encryption - Memory Bank conversations and entries are stored as client-side encrypted blobs on single-tenant bare metal infrastructure in the EU
- Automatic deletion - Associated Memory Bank storage and content are permanently deleted when you deactivate your account
- No recovery - Once deleted, storage data cannot be recovered
SELF App Validator Infrastructure
- SELF App uses browser-based validators with backend chain coordination.
- Browser validators participate in validation and consensus while backend orchestrator and coordinator services support rounds, chain state, availability, and prize draw coordination.
- Validator private keys are derived from your recovery phrase, remain encrypted on your device, and are not provided to the coordination services.
- Validator and prize draw participation may be temporarily unavailable if backend coordination services are interrupted.
AI Model Processing
- SELF uses SELF AI models on dedicated GPU infrastructure in EU data centers
- Live prompts are processed to generate responses; stored conversation history remains client-side encrypted in your Memory Bank
- Memory Bank conversation history is stored as client-side encrypted blobs; the server cannot decrypt your content
- No data sharing with model providers - Your conversations and AI interactions are not used to train third-party models
- No model training - We do not use your conversations to train models
- Model performance and availability depend on dedicated EU GPU infrastructure
Web Search Services (Connect Tier)
- Availability - Connect tier only (including the 3-day free trial); not available on Zero
- Search requests - Search text and URL retrieval requests are sent to a third-party provider without your SELF account ID, username, or email
- Search results are provided "as-is" and we do not guarantee their accuracy or completeness.
- We are not responsible for the content or accuracy of search results from third-party sources.
- Service availability depends on third-party infrastructure and may be temporarily unavailable.
Search Service Limitations
- Third-party dependency - Search services depend on external providers
- No guarantees - We do not guarantee the accuracy, completeness, or reliability of search results
- User responsibility - You are responsible for evaluating and verifying information from search services
- Service interruptions - Search services may be unavailable due to third-party issues
- No liability - We are not liable for decisions made based on search results
- Content changes - Search provider behavior may change without notice
Stripe Payment Processing
- SELF uses Stripe for secure payment processing and subscription management
- During signup, we use Stripe's fraud detection (Stripe Radar) to verify payment methods
- Stripe may analyze transaction patterns and geographic data for fraud prevention
- We do not store IP addresses or payment details on our servers; IPs may be used briefly for login security
- Your use of payment services is subject to Stripe's Terms of Service
- For more information about Stripe's security practices, visit docs.stripe.com/security
- For detailed information about Stripe's privacy practices, visit stripe.com/privacy-center
SELF App Prize Draw Program
SELF App operates a Category 4 promotional game under Queensland's Charitable and Non-Profit Gaming Act 1999, where users earn prize draw entries through validator participation.
Program Duration and Token Allocation
- Program duration - The prize draw and referral rewards program runs for 48 months (4 years) from launch
- Token allocation - User Adoption pool: 125,000,000 SELF (125M SELF), covering prize draws and early adopter rewards over the User Adoption unlock schedule
Prize Draw Overview
- No purchase necessary - Free Zero tier users are eligible to participate
- Entry mechanism - 1 entry per vote (typically about 1 per minute while your node is active). When your node is active, you're casting votes in the blockchain. Each vote earns you 1 prize draw entry.
- Vote rounds - Votes happen once per round (~60s). If you're reconnecting you may miss a round and won't earn an entry for it.
- Prize tiers - Daily (5,000 SELF), Weekly (50,000 SELF), Monthly (200,000 SELF)
- Cryptographically verifiable randomness - Winners selected via cryptographically verifiable randomness (verifiable on-chain)
- Age requirement - Must be 18 years or older to participate
Prize Draw Terms Summary
- Entries - Earned automatically through validator votes (1 entry per vote, typically about 1 per minute while your node is active). Votes happen once per round (~60s). If you're reconnecting you may miss a round and won't earn an entry for it.
- Eligibility - Open to all SELF users 18+ where permitted by law
- Winner notification - Winners notified via in-app alert within 24 hours
- KYC verification required - Winners must complete KYC (Know Your Customer) verification before prizes can be claimed. We will send instructions when sending you an in-app alert if you win.
- Prize delivery - Prizes credited within 7 days of successful KYC verification; pre-TGE prizes claimable after Token Generation Event and KYC verification
- Unclaimed prizes - Winners have 3 months to claim; unclaimed tokens are burned
- Record keeping - Draw records are retained for 5 years to support applicable record-keeping obligations
- Full terms - Complete Prize Draw Official Rules available in-app (SELF Wallet > Prize Draw)
Early Adopter Program (First 100,000 Users Only)
- Subscriber bonus - First 100,000 users receive 100 SELF/month (Connect tier only) as lifetime benefit
- Referral bonus - First 100,000 users receive 100 SELF/month per verified referral as lifetime benefit
- Program end - After user #100,000, subscriber and referral bonuses are no longer available
- Prize draws continue - All users (including those joining after 100k) remain eligible for prize draws
Billing and Payments
Subscription Plans
- SELF Zero (Free) - Memory Bank with client-side E2E encryption. 5 messages/day and seamless cross-device sync via recovery phrase (same phrase = same keys on all devices).
- SELF Connect (USD $20/month via Stripe, 3-day free trial) - Memory Bank with client-side E2E encryption (same zero-knowledge security as Zero tier). Enhanced features include 100 messages/day, anonymous live web search, voice input, and AI personality customization.
Data Export and Recovery
- Both Tiers - You can export supported decrypted content through Settings. Conversations and Memory Bank entries are decrypted in your browser and available for download in JSON format.
- Data Recovery - Your recovery phrase derives the keys used to decrypt protected content. If you enable the optional recovery-password feature, a phrase copy is wrapped client-side using a password-derived key with 600,000 PBKDF2 iterations and the wrapped blob is stored on the server. SELF does not receive the password. Without the phrase or that optional recovery path, SELF cannot recover the encrypted content.
Payment Terms
- Billing cycle - Monthly subscriptions renew automatically
- Payment due - Charged immediately upon signup and each renewal
- Failed payments - Service suspended after 7 days, cancelled after 30 days
- Price changes - 30 days notice for existing subscribers
Refunds and Cancellation
- Cancel anytime - No long-term contracts or cancellation fees
- Immediate access - Use your paid features until the end of your billing period
- No partial refunds - Subscriptions are billed monthly in advance
- Refund exceptions - Technical issues preventing service use (use Settings → Contact Us)
Data Retention After Cancellation
- Data export - Before deleting your account, you can download your conversations and memories anytime via Privacy. When your account is deleted, the data no longer exists.
Service Limitations
What We Can't Promise
- 100% uptime - Services may be unavailable due to maintenance or technical issues
- Perfect performance - Speed and responsiveness depend on many factors beyond our control
- Bug-free experience - We fix issues quickly but can't guarantee zero bugs
- Third-party reliability - Infrastructure providers and Stripe issues may affect your experience
When Things Go Wrong
- Planned maintenance - We'll give advance notice when possible
- Unexpected outages - We'll work to restore service as quickly as possible
- Data loss prevention - Service data is backed up, and you should also keep your own exports and recovery phrase secure
- Security incidents - We'll assess incidents promptly and provide notices where applicable law requires them
Force Majeure
We are not liable for service interruptions caused by events beyond our reasonable control, including:
- Natural disasters - Earthquakes, floods, fires, or other natural events
- Infrastructure failures - Major outages by CDN providers, EU infrastructure providers, or Stripe
- Government actions - Regulatory changes, sanctions, or internet restrictions
- Cyber attacks - Large-scale attacks on internet infrastructure
- Pandemics - Public health emergencies affecting global infrastructure
During force majeure events, we will work to restore service as soon as reasonably possible and keep you informed of our progress.
Security Updates & Maintenance
- Security patches - We provide prompt updates to fix any security vulnerabilities
- Third-party updates - We monitor and update dependencies when security fixes are available
- Automatic notifications - Critical security updates are pushed to users via our in-app notification system
- Supply chain monitoring - We continuously monitor our infrastructure providers and Stripe for security updates
Removing SELF
Since SELF is a Progressive Web App (PWA), you can remove it anytime:
- From your device - Remove the PWA from your device's app list or home screen
- Browser data - Clear your browser's local storage and cache for SELF
- Account closure - Use the Settings > Legal page in the app to request account closure and data deletion
- Data export - Export your data before removing via Settings > Legal page
Important Disclaimers
Use SELF At Your Own Risk
While we work hard to make SELF reliable and secure:
- SELF is provided "as is" - We can't guarantee it will meet all your specific needs
- Your business decisions - Any choices you make based on SELF outputs are entirely your responsibility
- Third-party issues - We're not responsible for problems caused by infrastructure providers or Stripe
- Data safety - While we protect your data, you should maintain your own backups
Limitation of Liability
To the maximum extent permitted by law:
- No liability for indirect damages - We're not responsible for lost profits, data, or business opportunities
- Maximum liability - Our total liability is limited to the amount you paid us in the past 12 months
- Legal protection - This protects both you and us from unreasonable legal costs
- Your local laws - Some jurisdictions don't allow these limitations, so they may not apply to you
Account Termination
When We May Terminate Your Account
We may suspend or terminate your account if you:
- Violate these terms - Breach any of our terms of service
- Illegal activity - Use SELF for unlawful purposes
- Security threats - Attempt to hack or compromise our systems
- Payment issues - Repeated failed payments or fraudulent activity
- Abuse - Harassment or harmful behavior toward other users
Termination Process
- Notice - We'll give you reasonable notice before termination (except for serious violations)
- Data export - You can export your data before termination
- Appeal process - Use Settings → Contact Us to dispute termination decisions
- Account data deletion - Your account data will be deleted within 30 days of account termination (separate from trial cancellation policies above)
We May Update These Terms
- To clarify existing policies
- Comply with legal requirements
- But we will never change these terms to reduce your privacy, sell your data, or add tracking without your consent
Legal Stuff (The Necessary Parts)
General
- These terms are governed by Australian law, where SELF Technology Pty Ltd is incorporated
- We prefer to resolve issues directly with you, and if needed, disputes will be handled through binding arbitration
- If any part of these terms is found invalid, the rest remains in effect
- SELF is intended for users 18 years or older. We do not knowingly collect data from users under 18
- By using SELF, you agree to these terms. If you don't agree, please don't use our service
- The SELF Token is offered via SELF Technology Limited, Intershore Chambers, Road Town, Tortola, British Virgin Islands, VG1110, (BVI IBC Number 2169550)
International Data Transfers
- Primary location - Australia (SELF Technology Pty Ltd)
- AI processing - Dedicated GPU infrastructure in EU data centers
- Backend API hosting - Single-tenant bare metal servers in the EU
- Frontend delivery - Static frontend assets delivered via a third-party CDN
- Payment processing - Stripe (US-based payment processor)
- Legal framework - Australian privacy law applies to SELF Technology Pty Ltd, with additional privacy requirements applying where relevant to users in other regions
- Transfer safeguards - We use appropriate transfer mechanisms with service providers where applicable. Encrypted Memory Bank storage uses EU-based single-tenant bare metal infrastructure.
- Protected content - Memory Bank conversations and entries remain encrypted on single-tenant bare metal infrastructure in the EU
- AI data residency - AI processing uses dedicated EU-based GPU infrastructure
Legal Basis for Processing (EU Users)
- Contract performance - Processing necessary to provide SELF services
- Legitimate interests - Service optimization and security
- Consent - For optional features and communications
Data Retention
- Account data - Retained while your account is active
- Memory Bank data - Automatically deleted when your subscription is deactivated
- Payment data - Retained by Stripe as required by law
- Error logs - Retained for 30 days for debugging purposes
Contact Us
The SELF team will never DM you or reply to DMs. To contact us, create a free account at self.app, then open Settings → Contact Us to submit partnership proposals, job inquiries, support requests, or anything else. When the team respond, it will appear in your in-app Alerts.
For app bugs use Settings → Bugs. For feature ideas use Settings → Ideas. To report security vulnerabilities email security@self.app (Bug Bounty program).
Mail: SELF Technology Pty Ltd, 194 Varsity Parade, Varsity Lakes, Queensland 4227, Australia

