Privacy Policy
Last updated 30 September 2026
Who this covers
This policy covers the Sinilumi website (sinilumi.com, sinilumi.ee) and every Sinilumi app you sign in to with Google (“the apps”). “We” means Sinilumi. Some apps have features that others don’t; where a point below applies only to some apps, it says so.
Visiting the website
- No cookies, no tracking. The public pages set no cookies, run no analytics, embed no third-party scripts and load their fonts from our own server. There is no tracking pixel and no advertising network.
- Server logs. Our host records standard request logs — IP address, time, requested address, browser — to run and secure the service. They are not used to build a profile of you.
Signing in with Google
- What we receive. Your email address and whether Google has verified it; in some apps also your name and your Google account ID. We ask Google for nothing else — no contacts, calendar, mail, files or other account data.
- How we keep it. Your email address is stored only as a one-way SHA-256 hash, never as the address itself. Where an app uses your name and Google account ID, it keeps them to recognise you and to show your name back to you.
- Invitations. Some apps are open to any Google account; others check your address against a list of invited users and let only them in.
- Google’s rules. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. It is used only to sign you in and run the app you signed in to — never for advertising, and it is never sold.
What the apps keep
- Your settings and choices — the things you set up in an app, such as what you follow, which groups you see, what you hide, your time zone and country — stored under your account so the app can show you your own view.
- Sign-in records (some apps): when you signed in and last visited, and the IP address a sign-in came from, to keep accounts secure.
- Messages and requests you send us through an app, such as feedback or a request to add something, and our replies. They are read and handled by a person; no AI service is used.
- Email you send to info@sinilumi.com, so we can reply.
Cookies
Each app sets one sign-in cookie once you sign in. It is signed so it cannot be forged and holds only what the app needs to recognise you (for example the hash of your email address). There are no advertising or tracking cookies.
Service providers
- Fly.io hosts the website and the apps and stores their data, in its EU regions (Stockholm and Frankfurt).
- Google provides the sign-in.
- Resend (some apps): delivers email that an app sends, such as a digest.
We do not sell personal data or pass it on for marketing.
Keeping and deleting data
Server logs are kept for a limited period. Your settings and your account in an app are kept until you remove them or ask us to; several apps let you reset your settings yourself. Signing out removes the sign-in cookie. To have everything about you removed from every app, write to info@sinilumi.com.
Legal basis
Sign-in and the data an app keeps for you are processed to provide the service you asked for. Server logs and sign-in records are processed on the basis of legitimate interest: running the service and keeping it secure.
Your rights
Under the GDPR you may ask for access to, correction of, or deletion of personal data we hold about you, and you may object to processing or ask for it to be restricted. Write to info@sinilumi.com. You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
Changes
If this policy changes materially, the date at the top changes with it.