Legal

Privacy Policy

Last updated: June 3, 2026

Our Commitment

Seshy is built on a privacy-first architecture. Your client CRM data — names, phone numbers, session notes, and history — is stored exclusively on your device. It never leaves your phone. We cannot access it, we cannot read it, and we cannot sell it. This is by design, not by policy.

Section 1

Introduction

This Privacy Policy ("Policy") describes how Novus Broker Technology, Inc. ("Seshy," "we," "us," or "our") collects, uses, and protects information in connection with the Seshy mobile application and web platform at seshy.pro (collectively, the "Service"). This Policy applies to all users of the Service, including providers and clients who book sessions through the platform.

By using the Service, you agree to the collection and use of information in accordance with this Policy. This Policy should be read in conjunction with our Terms of Service.

Section 2

Our Privacy Architecture

Seshy uses a split-architecture model designed to minimize the data we hold. Understanding where your data lives is central to this Policy:

On Your Device (Local Only)

  • Client records (names, contact info)
  • Session history and notes
  • Calendar data
  • Revenue statistics
  • Personal CRM settings and preferences

This data is stored in the app's local database on your phone. It is never transmitted to our servers. We have zero access to it.

In the Cloud (Our Servers)

  • Your phone number (for authentication)
  • Your display name and profile bio (if set)
  • Your booking page configuration (Pro only)
  • Booking records (date, time, session type, client name)
  • Stripe Connect account identifiers
  • Booking and review data

This data is necessary to operate the booking system and your public profile. It is stored securely in our cloud infrastructure.

Section 3

Information We Collect

Account Information. When you create an account, we collect your phone number for authentication via SMS verification. We may also collect a display name and profile photo if you choose to provide them.

Booking Data.When a client books a session through your booking page, we collect the booking details (date, time, session type, duration, price) and the client's name and contact information as provided during booking. This data is necessary to facilitate the booking and payment process.

Payment Information. Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other sensitive financial information on our servers. We retain only Stripe account identifiers and transaction references necessary to manage your subscription and facilitate payouts.

Usage Data. We may collect basic usage analytics such as app version, device type, and general usage patterns. This data is anonymized and used solely to improve the Service. We do not use third-party analytics SDKs that track individual user behavior.

Review Data. Reviews are anonymous and contain no client-identifying information. Only clients who completed a verified booking can submit a review.

Section 4

How We Use Your Information

We use the limited information we collect to:

  • Authenticate your account and verify your identity
  • Operate and maintain the booking system
  • Display your public booking page and provider profile
  • Process subscription payments and facilitate provider payouts via Stripe
  • Operate the booking and review system
  • Provide customer support
  • Improve and maintain the Service
  • Comply with legal obligations

We do not sell, rent, or trade your personal information to third parties. We do not use your data for advertising purposes. We do not build behavioral profiles of our users.

Section 5

Third-Party Service Providers

We work with a limited number of trusted third-party providers to operate the Service. Each has been selected for their security practices and commitment to data protection:

SupabaseCloud database and authentication

Hosts our backend infrastructure including user accounts and booking data. Data is encrypted at rest and in transit. Supabase is SOC 2 Type II compliant.

StripePayment processing

Handles all payment processing for subscriptions and booking payments via Stripe Connect. Stripe is PCI DSS Level 1 certified. We do not store card data.

VercelWeb hosting

Hosts the seshy.pro website and booking pages. Vercel processes standard HTTP request data (IP addresses, user agents) as necessary to serve web pages.

AppleApp distribution and push notifications

The Seshy app is distributed through the Apple App Store. Push notification tokens are used solely to deliver booking notifications.

We do not share your data with any other third parties except as required by law (see Section 9).

Section 6

Data Retention

Cloud Data.We retain your account and booking data for as long as your account is active. If you delete your account, we will delete your personal data from our servers within 30 days, except where retention is required by law or necessary to resolve disputes. Anonymized, aggregated data that cannot be used to identify you may be retained indefinitely.

Local Data.Data stored on your device (client records, session notes) is under your sole control. We cannot access or delete it. If you uninstall the app, locally stored data may be deleted by your device's operating system.

Payment Records.Transaction records may be retained for up to 7 years as required by tax and financial regulations.

Section 7

Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Request that we correct inaccurate personal data.
  • Deletion. Request that we delete your personal data. You can delete your account by contacting us at hi@seshy.pro.
  • Portability. Request a machine-readable copy of your data.
  • Objection. Object to certain processing of your data.

To exercise any of these rights, contact us at hi@seshy.pro. We will respond to all legitimate requests within 30 days. Note that local CRM data on your device is already fully under your control — you can export or delete it at any time through the app.

Section 8

Cookies and Tracking

The seshy.pro website uses only essential cookies necessary for the operation of the Service (e.g., authentication session tokens). We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

The Seshy mobile app does not use cookies. It does not contain any third-party advertising or analytics SDKs that track user behavior across apps or websites.

Section 9

Legal Disclosure

We may disclose your personal information if required to do so by law, or in the good-faith belief that such action is necessary to: (a) comply with a legal obligation, court order, or subpoena; (b) protect and defend the rights or property of Novus Broker Technology, Inc.; (c) prevent or investigate possible wrongdoing in connection with the Service; or (d) protect the personal safety of users of the Service or the public.

Because your CRM data is stored locally on your device and not on our servers, we are unable to produce client records, session notes, or other local data in response to any legal request. We literally do not have it.

Section 10

Data Security

We implement industry-standard security measures to protect the data we do hold. This includes:

  • Encryption of data in transit (TLS 1.2+) and at rest
  • Row-level security policies on all database tables
  • Regular security audits of our infrastructure
  • Minimal data collection philosophy — we don't store what we don't need

However, no method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee its absolute security. If you become aware of any security breach, please contact us immediately at hi@seshy.pro.

Section 11

Children’s Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and you believe your child has provided us with personal information, please contact us at hi@seshy.pro, and we will take steps to delete such information promptly.

Section 12

International Data Transfers

Our servers and third-party service providers are located in the United States. If you access the Service from outside the United States, your data may be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction. By using the Service, you consent to such transfers.

Section 13

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date at the top of this page and, where appropriate, notify you via the app or email. Your continued use of the Service after any changes constitutes your acceptance of the updated Policy.

We encourage you to review this Policy periodically to stay informed about how we protect your information.

Section 14

Contact Information

If you have questions about this Privacy Policy or our data practices, please contact us:

Novus Broker Technology, Inc.hi@seshy.proseshy.pro