Sipru

Privacy notice

Last updated: 9 September 2026

Sipru is in private beta. This notice describes what the app actually does today, not what it is planned to do.

1. Who we are

Sipru is operated by Stepan Zarichnyi, a sole trader based in the United Kingdom. Contact: [email protected].

2. Two different roles

Sipru holds two kinds of personal data, and the law treats them differently.

Role Whose data Examples
We are the controller Yours, as the person using Sipru Your email address, display name, workspace settings, accessibility preferences
We are the processor Your clients' and enquirers' Names, emails, phone numbers, notes and enquiries you enter about them

When you record a client, you decide why that data is held and you are the controller of it. We process it only to give you the features of the app. You are responsible for having a lawful basis for holding your clients' data and for telling them about it.

3. What we collect

Your account

Your workspace and team

What you record about other people

Clients and additional contacts (name, email, phone, type, tags), your private notes, and enquiries with their stage, budget, event date and next action. These are free-text fields and may contain whatever you put in them, so treat them the way you would treat a notebook about your customers.

Sipru does not read your device's address book, and there is no import from it.

On your device

4. What we do not collect

The app contains no analytics, advertising, attribution, crash-reporting or tracking software — no Firebase Analytics, Sentry, Segment, Mixpanel, Amplitude, AppsFlyer or ad network — and no advertising identifier is read.

There is no access to contacts, calendar, precise location, camera, microphone recording, health data or your photo library. Release builds for Android explicitly block storage and microphone permissions.

We do not sell personal data, and we do not share it for advertising.

5. Where it is stored, and who else touches it

Sipru runs on Supabase — authentication, database, file storage and server functions — in its London region. Supabase is the only processor that receives your data in the current beta.

Supabase Inc. is incorporated in the United States, so some operational metadata may be handled outside the United Kingdom under its own terms. Sign in with Apple and Google sign-in exist in the code but are switched off in the beta; no data reaches them. Confirmation and password-reset email is sent through Supabase's built-in provider, which in the beta only delivers to addresses on the project's own team.

6. Why we are allowed to hold it

Data Lawful basis (UK GDPR)
Account, workspace and CRM content Performance of a contract — you asked us to run the app for you
Security and audit records Legitimate interests — keeping accounts safe and changes accountable
Marketing, if it is ever introduced Consent, which you would give and could withdraw

7. How long it is kept

Your data is kept while your account exists. When you delete your account:

Invitations that were accepted or revoked stay in the record as history rather than disappearing; pending ones expire after seven days. No fixed retention period has been set for audit history yet, and this notice will say so plainly until one is.

8. Your rights

Under the UK GDPR and the Data Protection Act 2018 you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to how we use it, or ask for it in a portable form.

Two of those are buttons rather than requests: More → Account → Export my data gives you a JSON file of everything your account can reach, through a private link that expires after one hour; More → Account → Delete account does what section 7 describes.

For anything else, write to [email protected]. If you are not satisfied with the answer, you can complain to the Information Commissioner's Office at ico.org.uk.

9. How it is protected

Every workspace is separated in the database itself, by row-level security rather than by application code alone, so one workspace cannot read another's records even if the app is wrong. The app ships only a public key; the key that can bypass those rules never leaves the server. Passwords are hashed by Supabase Auth and are not visible to us.

No system is perfect, and Sipru is a beta. If you find something that looks wrong, please tell us at [email protected].

10. Children

Sipru is a tool for running a business and is not intended for anyone under 16.

11. Changes

If this notice changes in a way that matters, the date at the top changes with it and significant changes will be told to you in the app.