Privacy Policy

Last updated: 14 August 2026  ·  Effective: 25 May 2026

Important: Sivolo is a private tool for keeping a record and recognising patterns in your own communications. It is not a crisis service, not a replacement for professional legal or psychological advice, and not connected to emergency services. Nothing you record in Sivolo — including a Crisis Capture — is seen by us or sent to anyone unless you choose to share it. If you are in immediate danger, contact your local emergency services. For domestic abuse support, please contact a helpline in your country:

1. Who we are

Sivolo is operated by Sivolo Limited, a company incorporated in England and Wales (Company Number 17240351), with its registered office at 51 St Marys Road, Tonbridge, TN9 2LE.

Sivolo Limited is the data controller for the personal data described in this policy. We are registered with the UK Information Commissioner's Office (ICO) as a data controller.

You can contact us about data protection matters at: [email protected]

2. What data we collect and why

2.1 Data you provide to run an analysis

To analyse a message log, you paste or upload the text of a conversation. This content typically includes:

When you run an analysis it is processed by our secure backend, with content sent from your device over an encrypted HTTPS connection and forwarded to the Anthropic API where the analysis is performed. For shorter analyses this is a single request and your content is held in server memory only. Longer logs run as a background job so you can close the app; because that work has to survive a restart or a lost connection, your content is encrypted with a key held by our server and written to our job queue — and, if the job is scheduled or waiting its turn, to our database. It is deleted the moment the job completes. If a job fails outright it is kept, still encrypted, for up to 7 days so that the failure can be diagnosed and your analysis returned to you, and is then deleted automatically. Message content is never written to our logs.

We want to be plain about one thing. This is the only part of Sivolo that is not encrypted so that only you can read it — and it cannot be, because an analysis can only be performed on readable text. Your Journal, your recordings, your photographs, your location trails and your Cloud Backup are all sealed on your device with a key we never receive (Section 2.9). A message log submitted for analysis is different: for the duration of that job it is readable by our backend, and by Anthropic, in order to produce your report. If that trade is not one you want to make, everything else in Sivolo still works without it.

The analysis Anthropic returns is then refined by Sivolo’s own deterministic processing — additional logic that filters, organises and calibrates the results. For background analyses this refinement runs on our backend as part of the job; for shorter analyses it may run within the app on your device. It involves no further transmission of your data to additional third parties.

Your message history is stored on your device only, encrypted using AES-256-GCM; we have no access to it. When an analysis runs in the background, the finished result is stored on our servers only briefly — encrypted with a key that only you hold (kept on your device, and, if you choose to set a collection passphrase, re-creatable by you alone on your other devices), so we cannot read it. It is deleted as soon as your device confirms it has collected it, and in any case within 7 days if you do not collect it.

2.2 Account and entitlement data

If you create an account or make a purchase, we process:

Your email address is the only thing we require. Your name, phone number, postal address and organisation are optional, are asked for only so that they can appear in the header of a PDF you export, and can be left blank.

2.3 Technical data

We record a small number of reliability events — for example that a submission failed, or that an analysis job ended in an error — together with the HTTP status, the app version, the platform, and the country the request came from. These records carry no account identifier, so they cannot be traced back to you, and they contain no message content. They are kept for 90 days and then deleted.

Your IP address is used in the moment — to apply rate limits and to block repeated failed sign-in attempts — and is not written to any database. Our hosting and network providers keep their own short-lived operational logs, as any hosting provider does.

We do not use advertising trackers, analytics SDKs, behavioural tracking, or crash-reporting services of any kind. There is no advertising identifier in Sivolo on either platform, and no third-party SDK collects anything about you.

2.4 Launch-interest list

If you choose to register your interest on our website, we collect only your email address and the fact and time you gave consent. We use a double opt-in process — you confirm your address by clicking a link we email you — and we use the address for one purpose only: to let you know when Sivolo becomes available. We do not use it for any other marketing, profiling, or analytics, and we do not share or sell it.

The legal basis is your consent (Article 6(1)(a) UK GDPR), which you can withdraw at any time via the unsubscribe link in any email we send — doing so deletes your address from the list. We store the list in Cloudflare D1 (Western Europe region) and send confirmation and launch emails through Resend, both acting as our data processors. We keep an address only until you unsubscribe or until we have completed the launch announcement, after which the list is deleted.

2.5 Background analysis

Some analyses run as a background job on our secure backend rather than entirely within the app. We do this for reliability: a longer analysis can then survive a lost signal or you closing the app, and you can collect the finished result whenever it suits you. During the job your message content is processed in memory only and never retained (see Section 2.1). The finished result is encrypted with a key that only you hold before it is stored, so it exists on our servers only as ciphertext we cannot read. It is deleted as soon as it is delivered to your device, or automatically purged within 7 days if you do not collect it. This processing of special-category data is covered by our Data Protection Impact Assessment (DPIA).

2.6 Your Journal

The Journal is where you keep a contemporaneous record of what has happened. An entry can contain the text you write, photographs and video you attach or take with the camera, voice notes, the date and time something occurred, and — if you choose — the location (Section 2.8) and the weather at that place and time.

Voice notes are transcribed on your own device. The audio is not sent to us or to any transcription service to produce the text. If your device cannot transcribe on its own, Sivolo keeps the recording and tells you the transcript is unavailable, rather than sending the audio away to get one.

Everything in the Journal is encrypted on your device as it is saved, using AES-256-GCM. If you use Secure Cloud Backup (Section 2.9) it is encrypted a second time, with a key derived from your passphrase, before any of it leaves your device — so what reaches us is ciphertext we cannot open.

You can attach a trusted timestamp to an entry. This proves the entry existed at a given moment and has not been altered since. To do it, your device calculates a one-way fingerprint (a SHA-256 hash) of the entry and we pass only that fingerprint to an independent timestamping authority, which signs it. Neither we nor the authority sees any of the entry's content — a fingerprint cannot be turned back into what it was made from.

2.7 Crisis Capture

Crisis Capture is a feature you start deliberately, when something is happening that you want recorded. While it is running, and only while it is running, Sivolo records ambient audio through the microphone and a trail of your location.

Both continue while the screen is locked and while the app is in the background. That is the point of the feature: incidents do not wait for you to be holding your phone, and a recording that stops when the screen goes dark would lose exactly the part that mattered. Your device will show its own indicator — a coloured status bar, dot or icon — for as long as recording is in progress. Recording stops when you end the capture, and neither the microphone nor background location is used at any other time.

The audio is broken into short segments and each segment is encrypted on your device the moment it is written. If you have Secure Cloud Backup switched on, segments are sealed again with your key and uploaded as they are made, so that evidence survives the phone being taken, broken or thrown. We hold that upload as ciphertext and cannot listen to it. Nothing is transmitted to anyone else, and no capture is shared with anybody unless you afterwards choose to share it through Trusted Circle.

2.8 Location — and who sees it

Sivolo uses your location in two places: attached to a Journal entry, so your record shows where something happened, and as the trail recorded during a Crisis Capture. Journal entries capture location automatically by default; you can turn that off in the Journal settings, and you can revoke the permission entirely in your device settings at any time. Crisis Capture asks separately for permission to continue in the background.

Your location is stored inside the entry, and is therefore encrypted on your device with everything else. But producing the map, the place name and the weather that make a location useful requires asking somebody who has that data, and we think you should know exactly who is asked and what they receive:

Who is askedWhat they receiveWhy
what3wordsThe coordinatesTo convert them into a three-word address you can read out to an emergency operator
Google (Maps)The coordinates, or the shape of a location trailTo draw the map picture on your entry and inside an exported PDF (Android and web)
Apple (Maps)The coordinates, or the shape of a location trailThe same, on iPhone and iPad
OpenStreetMapWhich map squares to send, which indicates the areaTo draw the interactive map you can pan and zoom
Open-MeteoThe coordinates and the dateTo look up the weather at that place and time

These requests go directly from your device to the service concerned, over an encrypted connection. They do not pass through our servers, and no name, email address or account identifier is sent with them — the request carries the coordinates and nothing that identifies you to us or to them. Each of those companies handles the request under its own privacy policy.

Please read this next part carefully, because it is a safety matter and not only a privacy one. A recorded location can be a refuge address, a friend's house, a workplace, or a route you take regularly. If any of that would be dangerous in the wrong hands, turn automatic location off in the Journal settings, or decline the location permission altogether. Sivolo works without it.

2.9 Secure Cloud Backup

Secure Cloud Backup keeps a copy of your Journal, your media, your recordings and your reports off your device, so that losing the phone does not mean losing the record. It is on by default once you have an account, because in this context losing the evidence is the more likely harm — but you can turn it off at any time, and you can delete everything we hold from within the app.

It is end-to-end encrypted. Keys are derived on your device from your passphrase — and, if you set one, your recovery phrase — using Argon2id, and only sealed data is uploaded. Your passphrase and your recovery phrase are never sent to us in any form. What we store is ciphertext together with a copy of the key that has itself been locked with a secret we do not hold. We cannot read your backup, and we cannot recover it for you if you lose both your passphrase and your recovery phrase. That is the cost of the guarantee, and we would rather state it than soften it.

Backups are stored in Cloudflare R2 in the United Kingdom. Free accounts have an allowance of 2 GB and Sivolo Plus 50 GB. If a file is too large to be backed up, Sivolo tells you plainly that it stayed on your device — we never let you believe something is safe when it is not.

2.10 Trusted Circle

Trusted Circle lets you give a named person — a solicitor, an IDVA, a support worker, a friend — access to particular reports or Journal entries you choose, through a link they open in a browser.

To do that we process, for each person you nominate, the details you enter: their name, email address, and optionally a phone number, address, organisation and role. That is personal data about someone else, and you should only enter it for people who would expect you to. It is stored on our servers so that we can send them the invitation and manage their access. You can revoke any person's access at any time, which invalidates their link.

The content they see is decrypted in their browser, not on our servers. The key that unlocks it travels in the part of the web link that browsers never transmit to a web server. One honest qualification: in order to compose and send that invitation email, the key passes through our systems and through our email provider at the moment the invitation is created. We do not store it. But it does exist, briefly, in our email — which means that anyone with access to the recipient's mailbox could open the share. Treat an invitation link as you would a key to a filing cabinet: send it to the right person, and revoke it if it goes astray.

If you grant emergency access to a contact, that is an escalation you set up in advance and can withdraw at any time; nothing is released to them automatically without the conditions you set.

2.11 Notifications

If you allow notifications, we store a push token issued by Apple or Google for that installation, linked to your account, so that we can tell you when a background analysis has finished. Notifications are deliberately content-free — they never contain any part of your report, your Journal or your messages, because a notification appears on a locked screen that somebody else may be looking at. You can turn notifications off in your device settings, and the token is removed when you sign out.

3. Special category data

Almost everything Sivolo holds is capable of being special category data as defined by UK GDPR Article 9. Message logs you submit for analysis may contain sensitive personal information relating to domestic abuse, coercive control, sexual conduct, health, religious or philosophical belief, or racial or ethnic origin. So may your Journal entries, your voice notes and Crisis Capture recordings, your photographs and video, and your location trails. The fact of using Sivolo at all is itself sensitive. We do not pretend otherwise, and we have built the product on that assumption.

We process this data solely for the purpose of providing the service you have asked for, on the basis of your explicit consent (Article 9(2)(a) UK GDPR). You give that consent by actively choosing to submit a log for analysis, to write an entry, to start a capture, or to turn on a feature. You can withdraw your consent at any time by deleting the data from the app, by turning the feature off, or by closing your account. Withdrawal does not affect the lawfulness of processing carried out before it.

We handle this data with particular care. None of it is ever used to train machine learning models, by us or by anyone we work with, and none of it is shared with third parties except as described in Section 5. With the single exception of a message log during the analysis that you asked for (Section 2.1), everything you record is encrypted before it reaches us and is unreadable to us while we hold it.

4. Legal bases for processing

Processing activityLegal basis
Analysing message content you submitPerformance of contract (Article 6(1)(b)); explicit consent for special category data (Article 9(2)(a))
Storing your Journal, media, recordings and location in encrypted backupPerformance of contract (Article 6(1)(b)); explicit consent for special category data (Article 9(2)(a))
Recording ambient audio and a location trail during a Crisis CaptureExplicit consent, given by starting the capture (Articles 6(1)(a) and 9(2)(a)); your vital interests may also apply (Article 9(2)(c))
Sharing selected records with a person you nominate to your Trusted CircleExplicit consent (Articles 6(1)(a) and 9(2)(a)); legitimate interests in respect of that person's own contact details (Article 6(1)(f))
Managing your account and entitlementsPerformance of contract (Article 6(1)(b))
Reliability records, rate limiting and abuse preventionLegitimate interests — maintaining the security and reliability of our service (Article 6(1)(f))
Responding to your support enquiriesLegitimate interests (Article 6(1)(f))
Complying with legal obligationsLegal obligation (Article 6(1)(c))

5. Who we share data with

5.1 Anthropic

Message content is transmitted to Anthropic, PBC (a US company) via their API in order to perform the analysis. Anthropic processes this data as a data processor acting on our instructions. Anthropic does not use data submitted through the API to train its models. International transfers to the US are made under appropriate safeguards (Anthropic's standard contractual clauses and Data Processing Agreement).

Anthropic's privacy policy: anthropic.com/privacy

5.2 Railway

Our backend server is hosted by Railway in the EU West (Amsterdam, Netherlands) region. Railway processes request metadata as a data processor. Message content is processed on our backend (hosted by Railway) in memory only and is not persisted there. Encrypted background-analysis results are stored transiently (see Section 6) and are unreadable to us or to Railway.

5.3 Apple / Google

In-app purchases and Sign in with Apple / Sign in with Google are handled by Apple Inc. and Google LLC under their own privacy policies. From these sign-in services we receive an account identifier; we also receive your email address unless you use Apple’s Hide My Email, which gives us only a private relay address. For purchases, Apple does not share your contact details with us, while Google may provide limited information such as your email address and country where it acts as the seller of record.

5.4 Cloudflare

Encrypted backups are stored in Cloudflare R2 in the United Kingdom, and Cloudflare also sits in front of our websites and API as a content delivery and security layer. Cloudflare acts as a data processor. What it stores for us is ciphertext it cannot read.

5.5 Location, mapping and weather services

what3words, Google, Apple, OpenStreetMap and Open-Meteo receive location coordinates in order to produce place names, maps and weather. These requests are made directly from your device, do not pass through our servers, and carry no information identifying you. Section 2.8 sets out exactly what each one receives and why.

5.6 Timestamping authority

When you attach a trusted timestamp to a Journal entry, a one-way fingerprint of that entry — and nothing else — is sent to an independent RFC-3161 timestamping authority to be signed. No content is transmitted, and the fingerprint cannot be reversed.

5.7 Resend

Resend delivers our email: address verification, password reset, notifications you have asked for, and Trusted Circle invitations. It processes the recipient's email address and the contents of that email as a data processor. As noted in Section 2.10, a Trusted Circle invitation contains the link that grants access to what you shared.

5.8 Expo

Expo provides the app's update service and relays push notifications. It receives the technical details of the update check and the push token, never the content of a notification beyond the short, deliberately content-free text you see.

5.9 RevenueCat

When in-app purchases are enabled, RevenueCat manages subscription and purchase state on our behalf. It receives an account identifier and the purchase information supplied by Apple or Google. It receives none of your content.

5.10 No sale of data

We do not sell, rent, or share your personal data with any third party for marketing or advertising purposes.

6. How long we keep your data

Data typeRetention period
Message content submitted for analysisHeld in memory for a direct analysis. For a background job, encrypted and held in the job queue only until the job finishes — or, if the job fails outright, for up to 7 days, then deleted automatically
Your analysis historyOn your device, and in your encrypted backup if you use it — until you delete it
Background analysis result (in transit to you)Stored only as ciphertext we cannot read; deleted on delivery to your device, or after 7 days, whichever is sooner (you can extend this to 30 days)
Journal entries, media, voice notes and Crisis Capture recordingsOn your device until you delete them. In Secure Cloud Backup, held as ciphertext for as long as you keep backup switched on — we do not expire it, because it is your evidence. You can delete all of it from within the app at any time
Record of an analysis job (that it ran, its size, its outcome — never its content)180 days
Trusted Circle contacts and share recordsUntil you revoke the share or delete the contact
Account and entitlement recordsDuration of your account, plus 3 years after account closure (for financial record-keeping)
Reliability records (no account identifier, country-level only)90 days, then automatically deleted
Push notification tokenUntil you sign out or turn notifications off
Support correspondence3 years from last contact

7. Your rights

Under UK GDPR you have the following rights in relation to your personal data:

To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month. We will not charge a fee except in cases of manifestly unfounded or excessive requests.

To close your account and have everything we hold deleted, use sivolo.app/delete-account. That page explains exactly what is deleted, what is kept and why, and how long it takes.

Much of what Sivolo holds you can delete yourself, immediately and without asking us: individual Journal entries, captures and reports from within the app, and everything in Secure Cloud Backup from the backup screen. Because your backup is encrypted with a key we do not have, deleting it is the only way that data can be removed — we could not read it in order to edit it even if you asked us to.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

8. Security

We take appropriate technical and organisational measures to protect your data, including:

No method of transmission or storage is 100% secure. If you believe your data has been compromised, please contact us immediately at [email protected].

9. Children

Sivolo is not directed at or intended for use by children under the age of 17. We do not knowingly collect personal data from anyone under 17. If you believe a child under 17 has provided us with personal data, please contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the app. Continued use of Sivolo after changes are posted constitutes acceptance of the updated policy.

11. Contact

Sivolo Limited
51 St Marys Road, Tonbridge, TN9 2LE
England
Email: [email protected]