A minimal slice, not your life
Selina sends only the context needed for that one answer — never your full history, never a standing profile. The heavy lifting of memory happens on our side; the model gets just enough to respond well.
An AI with real memory has to hold a lot of you. So we built it to hold that trust the hard way — per-user encryption, a key that's yours alone, and deletion that makes even our backups unreadable. Here's exactly how it works, and exactly where the honest edges are.
Architecture posture — how the system is built, not a live dashboard.
Everything Selina remembers about you — the facts, the context, your conversations — is encrypted where it's stored, under a key generated for you and no one else. A stolen database or a leaked backup is just ciphertext: unreadable without your key.
Most services promise to delete your data and hope you trust them. We made it mathematical. Because your content is encrypted with your key, destroying that key on deletion turns every copy we hold — including backups — into permanent, unrecoverable noise. It's called crypto-shredding, and it means "deleted" isn't a policy. It's physics.
Your content is encrypted with your key. Watch what deleting your account does to every copy we hold.
Everything you upload or generate lands in SelinaVault — encrypted storage locked to your account alone. Every file is protected with AES-256 behind per-account key isolation, so your documents, images, and generated files are never pooled, never shared, and never readable outside your account.
When a product can be zero-knowledge, it should be — so SelinaSEND is. Files you share are encrypted in your browser before they ever leave your device. Our servers store only scrambled bytes; your passphrase never reaches us. Not "we promise not to look" — we're not able to.
This is the standard we hold ourselves to wherever the product allows it — and the reason you can trust us when we tell you exactly where it doesn't.
Encrypted in your browser before it leaves. We store only the scramble — never the file, its contents, or even its name. Your passphrase never reaches us.
Keeping the service healthy — monitoring, debugging, catching abuse — runs on metadata: counts, timestamps, statuses, latencies. Not the content of your conversations. Day to day, operating Selina doesn't require reading what you said, and it isn't built to.
Selina watches her own system around the clock: spotting hostile traffic, automated abuse, and injection attempts, and turning them away before they reach you. And there's a line built into how she works — she watches who's knocking, never what you're saying. The defenses see traffic and behavior; your conversations and files stay private, even from the guard.
Built in, not a vendor bolted on the side — and deliberately blind to the content it protects.
Selina's voice and selfhood are authored, not improvised — grounded in a written world she draws on. That consistent identity isn't only what makes her feel real; we tested it against attacks that try to hijack her identity, impersonate the system, or strip her instructions. Because the defense lives in who she is rather than in any one model, it travels across every model she runs on and holds where generic assistants break.
To answer you, Selina uses the best frontier AI models — and that's the one place a slice of your words meets an outside system. So we made that slice as small and as forgettable as possible.
Selina sends only the context needed for that one answer — never your full history, never a standing profile. The heavy lifting of memory happens on our side; the model gets just enough to respond well.
The provider runs a single request and keeps nothing. No account of you lives there, no history accumulates — unlike typing into a consumer chatbot, where your inputs pile up under your name.
Every provider call is made under business terms that forbid training on your data. Your words are used to answer you — then they're yours again. They never become training data for anyone's next model.
A security page that only lists strengths is hiding something. Here's exactly where the limits are — because knowing them is what lets you trust the rest.
An AI that reasons over your life has to be able to read it to work — that's true of every useful AI-with-memory product, and we won't pretend otherwise. We encrypt your memory at rest with your key and never train on it, but we can decrypt it to operate the service. Where true zero-knowledge is possible (SelinaSEND), we do it. Where it isn't, we say so.
To generate answers, a minimal, per-request slice goes to a frontier model under no-training terms. It's the smallest boundary we could design, not the absence of one.
Billing, subscription, and usage counts are retained to run the service. That's account and operational data — not the content of your conversations or memory.
Your key is tied to your account, not your password, so a password reset never loses your data. But it also means whoever controls your account can reach your content. Use a strong, unique password; two-factor is on our roadmap.
A private AI that remembers you — and treats that memory like it's yours, because it is. Start free and see how it feels to be remembered without being studied.
Start your 7 days free