Last updated · 9 June 2026

Privacy Policy

This policy explains what information Seelo collects, how we use it, who we share it with, and the rights you have. We've tried to keep it plain — if anything is unclear, get in touch.

1. General

Seelo is operated by Tunemind, Ltd. ("Tunemind", "Seelo", "we", "us", or "our"), a company registered in the Commercial Register at the Bulgarian Registry Agency with UIC 207152429, having its registered seat at Bul. Vitosha No. 1, fl. 3, Sofia 1000, Bulgaria.

This Privacy Policy applies to our mobile applications, our website at seelo.app, and related services (together, the "Services"). It is provided in accordance with Regulation (EU) 2016/679 (the "GDPR") and the Bulgarian Personal Data Protection Act.

By using the Services, you acknowledge this Privacy Policy, which should be read together with our Terms of Use and EULA. If you do not agree with it, please stop using the Services.

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and make reasonable efforts to notify you through the Services.

2. Data controller

Tunemind, Ltd. is the controller of the personal data processed through the Services.

Tunemind, Ltd. UIC 207152429 Bul. Vitosha No. 1, fl. 3, Sofia 1000, Bulgaria Email: hello@seelo.app

Given the nature and scale of our processing, we are not required to appoint a Data Protection Officer. You can reach us about any privacy matter at the address above.

3. Definitions

  • "Personal data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on personal data, such as collection, storage, use, disclosure, or erasure.
  • "Controller" means the party that determines the purposes and means of processing — here, Tunemind, Ltd.
  • "Processor" means a party that processes personal data on the controller's behalf.
  • "Special categories" means data revealing racial or ethnic origin, political opinions, religious beliefs, health, biometric or genetic data, or data about sex life or sexual orientation.

4. What we collect

Information you provide:

  • Account information — your email address, a password (stored only in hashed form by our authentication provider), and an optional display name and profile picture. We do not offer social or third-party login, so we do not receive data from external identity providers.
  • Asset and Job content — the properties ("Assets") you create, including addresses and location details you enter, and the Jobs, notes, and details you record about them.
  • Photos — images you upload. Photos are re-encoded on upload and their embedded metadata, including any GPS location, is removed before the image is stored.
  • Financial records — budgets, expenses, ledger entries, and payment records you create. These are records you keep for your own convenience. Seelo does not process payments and never collects or stores card or bank-account numbers.
  • Messages — communications you send to other Users within the Services.
  • Invitation details — when you invite a Co-owner or Contractor, the email address or contact detail you provide for them.
  • Communications with us — the content of any message you send us for support or other enquiries.

Information we collect automatically:

  • Device and log data — device model, operating system, app version, language and time-zone, IP address, and similar technical information.
  • Push token — if you enable notifications, a Firebase Cloud Messaging token used to deliver them to your device.
  • Diagnostics — crash reports and error traces (via Firebase Crashlytics) that help us find and fix problems.
  • Usage analytics — aggregate, event-level usage data (via Firebase Analytics) that helps us understand how the Services are used and improve them.

We do not intentionally collect any special categories of personal data. Please do not upload Content (for example, photos) that reveals such data unless you are comfortable doing so; you are responsible for the Content you choose to upload.

5. How we use your data and legal bases

PurposeLegal basis (GDPR Art. 6)
Create and operate your Account and provide the ServicesPerformance of a contract (Art. 6(1)(b))
Enable collaboration — sharing Assets, Jobs, and messages with people you invitePerformance of a contract (Art. 6(1)(b))
Send push notifications you have enabledConsent (Art. 6(1)(a))
Diagnose crashes, secure the Services, and prevent fraud or abuseLegitimate interests (Art. 6(1)(f))
Understand usage and improve the ServicesLegitimate interests (Art. 6(1)(f))
Respond to your support requestsPerformance of a contract / legitimate interests
Keep records and meet tax, accounting, and other legal obligationsLegal obligation (Art. 6(1)(c))
Establish, exercise, or defend legal claimsLegitimate interests (Art. 6(1)(f))

Where we rely on consent, you may withdraw it at any time (for example, by turning off notifications in your device settings); this does not affect processing carried out before withdrawal.

6. Sharing with other Users

Seelo is a collaboration tool, so some sharing is initiated by you and is central to how it works.

When you invite a Co-owner or Contractor to an Asset or Job, or share a Quote request via a link or QR code, you disclose the relevant Content and personal data to those people. Co-owners can see the Asset content you share with them; Contractors can see only the Jobs to which they are invited; and a shared link may be opened by anyone who has it.

You control who you invite and what you share. Once information has been shared with another User, they may retain it, and we are not responsible for how they use it.

7. Sub-processors and other recipients

We rely on a small number of service providers ("sub-processors") who process personal data on our behalf under contracts that require appropriate safeguards:

  • Google Firebase / Google Cloud — authentication, database (Cloud Firestore), file storage, server functions (hosted in the EU, europe-west1), crash diagnostics (Crashlytics), analytics (Firebase Analytics), and push notifications (Firebase Cloud Messaging). Provided by Google Cloud EMEA Limited (Ireland), with Google LLC (United States) as a sub-processor.
  • Resend — delivery of transactional emails (such as invitations and notifications), provided by Resend, Inc. (United States).

We may also disclose personal data: to professional advisers (such as lawyers and accountants) under confidentiality; to public authorities where required by law or legal process; to protect our rights, Users, or the public, or to prevent fraud; and to a successor entity in connection with a merger, acquisition, or sale of assets, in which case we will make reasonable efforts to notify you. We may share aggregated or anonymised data that does not identify you.

We do not sell your personal data.

8. International transfers

We are based in Bulgaria, and our core data is hosted in the European Union. Some of our sub-processors process data in the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, together with encryption in transit and at rest.

9. Cookies and similar technologies

Our website uses only essential cookies and similar technologies — for example, to keep your session secure and remember your preferences. We do not use advertising or cross-site tracking cookies. The mobile app does not use cookies; it stores limited data on your device (such as your session and a local cache) to function. You can manage cookies through your browser settings.

10. How long we keep your data

We keep personal data only for as long as necessary for the purposes described in this policy or as required by law:

  • Account data — for as long as your Account is active. After you delete your Account, we delete or anonymise your personal data within 30 days, except where we must retain it.
  • Asset and Job records — by design, Jobs are never deleted; they move into terminal states and are retained as part of the record of an Asset. Content you have shared with other Users may be retained by them.
  • Diagnostic and log data — typically up to 90 days, unless needed longer to investigate an issue.
  • Accounting and tax records — for the period required by Bulgarian law (generally up to 10 years).

11. Security

We use appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, Firebase App Check, server-side access rules that scope each User's access, and the removal of photo metadata (including GPS) on upload. No system can be completely secure, so we encourage you to use a strong, unique password and to keep your credentials confidential. If you suspect unauthorised access to your Account, contact us at hello@seelo.app.

12. Your rights

Subject to applicable law, you have the right to: access your personal data; have inaccurate data corrected; have your data erased; restrict or object to certain processing; receive your data in a portable format; and withdraw consent where processing is based on it. You also have the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at hello@seelo.app. We will respond within one month, which we may extend by a further two months for complex requests, in which case we will let you know. Exercising these rights is free, unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting on a request.

13. Automated decision-making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.

14. Children

The Services are intended for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us at hello@seelo.app and we will take steps to remove it.

15. Supervisory authority

If you are in the European Union, you may lodge a complaint with your local data protection authority. In Bulgaria, this is:

Commission for Personal Data Protection (CPDP) 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria Tel: +359 2 91 53 518 Email: kzld@cpdp.bg Web: www.cpdp.bg

We would appreciate the chance to address your concerns first, so please consider contacting us before lodging a complaint.

16. Third-party links

The Services may link to third-party websites or services that we do not control. This Privacy Policy does not apply to them, and we are not responsible for their content or privacy practices. Please review their policies before providing them with personal data.

17. Governing law

This Privacy Policy is governed by the laws of the Republic of Bulgaria and the applicable laws of the European Union. Any dispute relating to it is subject to the exclusive jurisdiction of the competent courts in Sofia, Bulgaria, without prejudice to any mandatory rights you have as a consumer.

18. Contact

For any questions about this Privacy Policy or your personal data:

Tunemind, Ltd. Bul. Vitosha No. 1, fl. 3 Sofia 1000, Bulgaria Email: hello@seelo.app