The short version: We collect the minimum data needed to run Sivarr. We never sell your data. You can delete your account and all associated data at any time.
We collect only what we need to provide you with a working, personalised Sivarr experience:
The data we collect is used for the following purposes:
We do not use your personal data to train third-party AI models, and we do not sell or share it with advertisers.
Your data is stored in a PostgreSQL database hosted on Railway, with servers in the EU and US. Railway's infrastructure is SOC 2 compliant.
All data is transmitted over HTTPS (TLS 1.2+). Passwords are hashed using bcrypt before storage. We never store plaintext passwords or payment card numbers.
Payments are processed by Paystack and Flutterwave. We receive only a transaction reference and subscription status — not your card details.
Sivarr uses the following third-party services. Each has its own privacy policy:
| Service | Purpose | Privacy policy |
|---|---|---|
| Google Gemini AI | Powers Sivarr AI responses and writing tools | policies.google.com/privacy |
| Google OAuth | Optional sign-in with Google (see section 5) | policies.google.com/privacy |
| Paystack | Payment processing (Nigeria) | paystack.com/privacy-policy |
| Flutterwave | Alternative payment processing | flutterwave.com/privacy-policy |
| Railway | Cloud hosting and database infrastructure | railway.app/legal/privacy |
| Resend / Gmail SMTP | Sending transactional emails (verification, notifications) | resend.com/privacy |
If you choose to sign in with Google, we request the following scopes only:
These sign-in scopes do not store any Google OAuth tokens beyond your current session.
Sivarr does not access your Google Calendar unless you explicitly connect it from the Calendar page. If you connect it, we request a single scope:
How we use this data. Calendar event data retrieved through this scope is used solely to show your schedule to you within the Sivarr app and to create events you explicitly create. We do not sell it, use it for advertising, or share it with third parties, and no humans read it except where required for security or to comply with the law.
What we store. To keep the connection active, we securely store a Google Calendar OAuth refresh/access token associated with your account. We do not copy your calendar contents into our database. You can disconnect at any time, which discards the stored token.
We do not request access to Google Drive, Gmail, Contacts, or any other Google service.
You can revoke Sivarr's access to your Google account at any time at myaccount.google.com/permissions.
Sivarr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We keep your data for as long as your account is active. If you delete your account:
You can export your data at any time before deleting your account by going to Settings → Data export.
You have the following rights over your data:
To exercise any of these rights, email privacy@sivarr.com. We'll respond within 30 days. You can also delete your account directly from Settings at any time without contacting us.
Sivarr uses session tokens stored in your browser's local storage (not cookies) to keep you signed in. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
The only data stored in your browser is your session token (a random string used to authenticate your requests) and your UI preferences (like selected theme or sidebar state).
We do not use Google Analytics, Facebook Pixel, or any advertising network tracking on the platform.
Sivarr is not intended for children under 13 years old. We do not knowingly collect personal data from anyone under 13.
If you're a parent or guardian and believe your child has created an account, please email privacy@sivarr.com and we will delete the account promptly.
We may update this Privacy Policy from time to time to reflect changes in the platform or applicable law. When we make material changes, we'll:
Continued use of Sivarr after the effective date of a change means you accept the updated policy. If you don't agree, you can delete your account before the change takes effect.
For any privacy-related questions, requests, or concerns:
We aim to respond to all privacy requests within 30 days.