Last updated: July 2026
Serendip was built around one rule from the start: no accounts, no passwords, and no personal information required to use it. This page explains exactly what that means in practice — what's stored, what's not, and who else touches your data.
When you post, you can optionally type in an email address to have your private link sent to you. That address is sent once to our email-delivery provider (Resend — see below), used only to deliver that one message, and is never written to our database or logged anywhere. If you don't use this feature, no email is ever collected.
Posts and their responses are automatically and permanently deleted 14 days after posting. There's no way to extend this — if the moment's gone, it's gone, by design.
Every post and response is automatically screened for prohibited content before it's saved (see the Terms of Use for details). Anyone can also flag a post as inappropriate; after a small number of reports, a post is automatically hidden from public view pending review. Reports themselves aren't tied to any identifying information about who submitted them.
Serendip is built on a small number of third-party infrastructure providers, who process data on our behalf:
| Provider | What they handle |
|---|---|
| Supabase | Hosts the database where post and response text is stored |
| Resend | Delivers the optional one-time recovery email, if you choose to use that feature |
We don't sell or share data with anyone beyond what's needed to run the app, and we don't use tracking or advertising services.
The private link you're given after posting is the only way to view responses to your post — there's no account or login tied to it. Anyone who has that link can access it, so keep it somewhere safe. If you lose it and didn't use the email-recovery option, there's currently no way to recover access.
This policy may be updated as the app changes. Meaningful changes will be reflected here with an updated date.
Questions about this policy can be sent to info@serendip.cloud.