Privacy Policy

Last updated: 19 June 2026  ·  Effective: 25 May 2026

Important: Sivolo is an analytical tool designed to help you recognise patterns in your own communications. It is not a crisis service, not a replacement for professional legal or psychological advice, and not connected to emergency services. If you are in immediate danger, contact your local emergency services. For domestic abuse support, please contact a helpline in your country:

1. Who we are

Sivolo is operated by Sivolo Limited, a company incorporated in England and Wales (Company Number 17240351), with its registered office at 51 St Marys Road, Tonbridge, TN9 2LE.

Sivolo Limited is the data controller for the personal data described in this policy. We are registered with the UK Information Commissioner's Office (ICO) as a data controller.

You can contact us about data protection matters at: privacy@sivolo.app

2. What data we collect and why

2.1 Data you provide to run an analysis

To analyse a message log, you paste or upload the text of a conversation. This content typically includes:

When you run an analysis it is processed by our secure backend, with content sent from your device over an encrypted HTTPS connection and forwarded to the Anthropic API where the analysis is performed. For shorter analyses this is a single request; for longer logs it runs as a background job so you can close the app. In both cases your message content is held in server memory only for the time it takes to perform the analysis — never written to disk, never logged, never stored in any database — and is discarded as soon as the analysis completes.

The analysis Anthropic returns is then refined by Sivolo’s own deterministic processing — additional logic that filters, organises and calibrates the results. For background analyses this refinement runs on our backend as part of the job; for shorter analyses it may run within the app on your device. It involves no further transmission of your data to additional third parties.

Your message history is stored on your device only, encrypted using AES-256-GCM; we have no access to it. When an analysis runs in the background, the finished result is stored on our servers only briefly — encrypted with a key that only you hold (kept on your device, and, if you choose to set a collection passphrase, re-creatable by you alone on your other devices), so we cannot read it. It is deleted as soon as your device confirms it has collected it, and in any case within 7 days if you do not collect it.

2.2 Account and entitlement data (paid tier)

If you create an account or make a purchase, we process:

2.3 Technical data

Our backend logs standard server request metadata (IP address, timestamp, HTTP status code, response time) for security monitoring and reliability. These logs are retained for 7 days and are not linked to your identity or to the content of your analyses.

We do not use advertising trackers, analytics SDKs, or behavioural tracking of any kind.

Crash reports are opt-in only. If you enable crash reporting, reports are scrubbed of all message content and personally identifiable information before transmission.

2.4 Launch-interest list

If you choose to register your interest on our website, we collect only your email address and the fact and time you gave consent. We use a double opt-in process — you confirm your address by clicking a link we email you — and we use the address for one purpose only: to let you know when Sivolo becomes available. We do not use it for any other marketing, profiling, or analytics, and we do not share or sell it.

The legal basis is your consent (Article 6(1)(a) UK GDPR), which you can withdraw at any time via the unsubscribe link in any email we send — doing so deletes your address from the list. We store the list in Cloudflare D1 (Western Europe region) and send confirmation and launch emails through Resend, both acting as our data processors. We keep an address only until you unsubscribe or until we have completed the launch announcement, after which the list is deleted.

2.5 Background analysis

Some analyses run as a background job on our secure backend rather than entirely within the app. We do this for reliability: a longer analysis can then survive a lost signal or you closing the app, and you can collect the finished result whenever it suits you. During the job your message content is processed in memory only and never retained (see Section 2.1). The finished result is encrypted with a key that only you hold before it is stored, so it exists on our servers only as ciphertext we cannot read. It is deleted as soon as it is delivered to your device, or automatically purged within 7 days if you do not collect it. This processing of special-category data is covered by our Data Protection Impact Assessment (DPIA).

3. Special category data

Message logs you submit for analysis may contain sensitive personal information relating to domestic abuse, coercive control, sexual conduct, health, or other special category data as defined by UK GDPR Article 9. We process this data solely for the purpose of providing the analysis you have requested, on the basis of your explicit consent (Article 9(2)(a) UK GDPR).

You give this consent by actively choosing to submit a message log for analysis. You can withdraw your consent at any time by deleting your data from the app. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

We handle this data with particular care. Message content is never stored on our servers, never used to train machine learning models, and never shared with third parties except as described in Section 5.

4. Legal bases for processing

Processing activityLegal basis
Analysing message content you submitPerformance of contract (Article 6(1)(b)); explicit consent for special category data (Article 9(2)(a))
Managing your account and entitlementsPerformance of contract (Article 6(1)(b))
Server security logs (IP, timestamps)Legitimate interests — maintaining the security and reliability of our service (Article 6(1)(f))
Responding to your support enquiriesLegitimate interests (Article 6(1)(f))
Complying with legal obligationsLegal obligation (Article 6(1)(c))

5. Who we share data with

5.1 Anthropic

Message content is transmitted to Anthropic, PBC (a US company) via their API in order to perform the analysis. Anthropic processes this data as a data processor acting on our instructions. Anthropic does not use data submitted through the API to train its models. International transfers to the US are made under appropriate safeguards (Anthropic's standard contractual clauses and Data Processing Agreement).

Anthropic's privacy policy: anthropic.com/privacy

5.2 Railway

Our backend server is hosted by Railway in the EU West (Amsterdam, Netherlands) region. Railway processes request metadata as a data processor. Message content is processed on our backend (hosted by Railway) in memory only and is not persisted there. Encrypted background-analysis results are stored transiently (see Section 6) and are unreadable to us or to Railway.

5.3 Apple / Google

In-app purchases and Sign in with Apple / Sign in with Google are handled by Apple Inc. and Google LLC under their own privacy policies. From these sign-in services we receive an account identifier; we also receive your email address unless you use Apple’s Hide My Email, which gives us only a private relay address. For purchases, Apple does not share your contact details with us, while Google may provide limited information such as your email address and country where it acts as the seller of record.

5.4 No sale of data

We do not sell, rent, or share your personal data with any third party for marketing or advertising purposes.

6. How long we keep your data

Data typeRetention period
Message content submitted for analysisNot retained — processed in memory (synchronously or as a background job) and never persisted
Your analysis historyOn your device only — until you delete it or uninstall the app
Background analysis result (in transit to you)Stored only as ciphertext we cannot read; deleted on delivery to your device, or after 7 days, whichever is sooner
Account and entitlement recordsDuration of your account, plus 3 years after account closure (for financial record-keeping)
Server security logs7 days, then automatically deleted
Support correspondence3 years from last contact

7. Your rights

Under UK GDPR you have the following rights in relation to your personal data:

To exercise any of these rights, contact us at privacy@sivolo.app. We will respond within one calendar month. We will not charge a fee except in cases of manifestly unfounded or excessive requests.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

8. Security

We take appropriate technical and organisational measures to protect your data, including:

No method of transmission or storage is 100% secure. If you believe your data has been compromised, please contact us immediately at privacy@sivolo.app.

9. Children

Sivolo is not directed at or intended for use by children under the age of 17. We do not knowingly collect personal data from anyone under 17. If you believe a child under 17 has provided us with personal data, please contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the app. Continued use of Sivolo after changes are posted constitutes acceptance of the updated policy.

11. Contact

Sivolo Limited
51 St Marys Road, Tonbridge, TN9 2LE
England
Email: privacy@sivolo.app