Privacy Policy
Effective
This policy explains what personal data Sylog handles while it is in early access, why, who receives it, where it is processed, how long it is kept and the rights you have.
1. Who is responsible
Sylog is operated by Maksim Mikhnev, an individual, who is responsible for the personal data described here ("Sylog", "we", "us"). Write to contact@sylog.app with any question or request about your data, with "Privacy request" in the subject. We have not appointed a representative in the European Union or the United Kingdom.
2. Early access
Sylog is in early access and does not admit the public yet: only the operator's own test accounts, which he uses to build and test Sylog, can sign in. Sign-up is closed to everyone, so no one else can open an account; the operator adds his test accounts himself. Payments are not open, and no one can buy a plan.
This policy therefore covers what happens today: your visits to this website (section 3), the sign-in service (section 5) and messages you send us, including requests for early access (section 6). Sylog's product -- the agent, project computers, chats, files and billing -- will have its own, complete privacy policy. It will be published on this page and take effect before public sign-up opens, and no one outside the test accounts will be admitted before then.
3. Visiting this website
This website runs on Google Cloud Run, in Google Cloud's us-central1 region in the United States. When your browser loads a page, Google Cloud records the request in our logs: the address of the page, the time, your IP address, your browser's user agent, the page that linked to it and how the server answered. When a page fails, the site's server also logs the error with the address of the page. Google keeps these logs in its Cloud Logging service, in a global location rather than a region we have chosen.
We use these logs to run the website, find and fix faults, and protect it against attacks. They are kept for 30 days and then deleted. When we investigate a fault or an attack, we may copy an excerpt of them, which can include an IP address, into our engineering records, which we keep in a private repository at GitHub, and into the working sessions of the AI coding tools named in section 8. Such a copy has no fixed end date: it stays as long as those records do, unless you ask us to remove it (section 11).
The website loads no analytics, advertising or tracking scripts, and no fonts, scripts or images from other websites.
4. Cookies and similar technologies
The pages of this website set no cookies. If you choose a light, dark or system theme with the theme button, your browser keeps that choice in its local storage under the name sylog-theme until you clear the site's data; it is never sent to us. Nothing else is stored on your device, so we do not ask for cookie consent. If that ever changes, this section and a consent choice change first. The sign-in service sets its own cookies, which section 5 describes.
This website does not track you across other websites, and no third party collects information about your activity across websites through it. It therefore does not respond differently to a Do Not Track signal, and a Global Privacy Control signal has nothing to opt you out of: we do not sell or share personal data.
5. The sign-in service
The address /sign-in on this website leads to our sign-in service, which runs on Google Cloud Run in us-central1 and uses Google Identity Platform for accounts and passwords. To tell people from bots, its pages use Google reCAPTCHA Enterprise, which analyses signals from your device and your interaction with the page and sets a cookie named _GRECAPTCHA, whose lifetime Google sets and does not publish. We treat it as strictly necessary to protect sign-in, so we do not ask for consent to it; the pages of this website do not load it. Google does this as our service provider.
Test accounts. When a test account signs in, Sylog sets the cookies strictly necessary to keep it signed in. They last 14 days at most, and the session they carry ends sooner if the account goes unused for 7 days. To protect the account, Sylog records the sign-in with a one-way fingerprint computed from the IP address and the browser it came from and a label such as "Chrome on Windows", never the address itself, and records security events such as a changed password. Session records are kept for 180 days after the session ends, and security events for 180 days. When a test account chooses a new password, the service checks it against Have I Been Pwned's list of passwords exposed in data breaches by sending only the first five characters of a one-way hash of it, never the password or the email address.
Everyone else. Sign-up is closed to everyone: the sign-in service opens no account for anyone, and the operator adds his test accounts himself. For any other email address it stores no account and sends no email. If you type an address into its pages, it keeps only counters that limit repeated attempts, keyed by a one-way hash of your IP address and that address and deleted when the service next counts an attempt after they are a day old, and its logs record the requests as section 3 describes, with a one-way hash of the address in place of the address itself.
6. Messages to us
If you write to contact@sylog.app or support@sylog.app -- for example to ask for early access -- we receive your email address, your name if you give it, and what you write. Both addresses deliver to our mailbox at Zoho Mail, which keeps it in Zoho's United States data centre.
We use your message only to answer it and to deal with what you ask, including keeping a request for early access on our waiting list and deciding on it. We do not add you to a mailing list and do not send marketing email. We keep a message while we need it to answer you and for any follow-up, and we delete it when you ask, unless the law requires us to keep it.
7. Why we use your data
- Running and protecting the website, and keeping its logs: our legitimate interest in a working and secure website.
- Protecting sign-in, including the counters that limit repeated attempts: our legitimate interest in keeping accounts and Sylog secure.
- Answering messages: our legitimate interest in answering people who write to us, or, for a request for early access, steps you ask us to take before a possible contract.
- Responding to lawful requests and defending legal claims: a legal obligation, or our legitimate interest in establishing and defending legal claims.
These are the legal bases of the EU and UK GDPR; the same purposes rely on the equivalent bases of other laws. Where we rely on legitimate interests, we have weighed them against your rights, and you can object (section 11). We do not use your data for advertising and do not build profiles about you.
You do not have to give us any personal data. Your browser has to send its IP address to load a page, so without it you cannot visit the website; without an email address we cannot answer you or consider a request for early access.
8. Who receives your data
- Our service providers, each only to provide its service to us: Google (hosting, logs, our database, sign-in and reCAPTCHA); Zoho (our mailbox, and ZeptoMail for the sign-in service's emails); GitHub (the private repository that holds our engineering records); and Cloudflare, which registers our domains and runs their DNS and, when you arrive through one of our other domains such as sylog.org, receives that request, your IP address included, and redirects it to this website.
- The AI coding tools the operator uses to run and repair Sylog -- Anthropic's Claude Code and, where it is used, OpenAI's Codex. While doing that work they can read the website's logs, IP addresses included, the sign-in service's records and our database, and the messages in our mailbox.
- Authorities, where the law requires it.
- A company the operator moves Sylog into, or a successor to the business, which stays bound by this policy; we say so here before it happens.
We do not sell personal data, and we do not share it for advertising.
9. Where your data is processed
The data in this policy is processed in the United States, where the servers are. The website, the sign-in service and our database run in Google Cloud's us-central1 region; Google Identity Platform and Cloud Logging are global services, so Google may keep accounts and logs in other countries where it operates. Our mailbox is in Zoho's United States data centre, which Zoho's support staff may access from other countries. GitHub, Anthropic and OpenAI are based in the United States. If you visit or write to us from outside the United States, your data goes to the United States, whose data protection law may protect you less than your own.
Google and Cloudflare process it under the data processing terms that form part of their terms for business customers. We have not yet entered into a data processing agreement with Zoho, GitHub, Anthropic or OpenAI; until we do, they handle it under their own standard terms. You can ask us at contact@sylog.app which safeguards apply to your data.
10. How long we keep it
- The website's request and error logs: 30 days. An excerpt copied into our engineering records: as section 3 describes.
- A test account's session records: 180 days after the session ends; its security events: 180 days.
- The counters that limit repeated sign-in attempts: a day, then deleted when the service next counts an attempt.
- Messages to us: as section 6 describes, and deleted on your request unless the law requires us to keep them.
- Your theme choice: in your browser, until you clear the site's data.
- Data the law requires us to keep, such as data under a preservation request: as long as that law requires.
11. Your rights
Your right to object. You can object at any time to our use of your data based on legitimate interests, on grounds relating to your situation, by writing to contact@sylog.app. We then stop, unless we have compelling legitimate grounds that override your interests or need the data to establish, exercise or defend legal claims.
Wherever you live, you can also ask us to:
- tell you whether we hold your data and give you a copy;
- correct inaccurate data;
- delete your data, subject to the records the law requires us to keep;
- give you the data you provided in a common machine-readable format;
- restrict our use of your data while a dispute about it is open;
- withdraw any consent you gave, without affecting earlier use.
Write to contact@sylog.app with "Privacy request" in the subject. We may ask for information to confirm it is you, and we confirm a request made by an authorised agent with you. We answer within one month, or sooner where your law requires; for a complex request we may extend this by up to two further months and tell you why. We do not charge, unless a request is manifestly unfounded or excessive, and we do not treat you differently for using your rights. If we say no, we explain why, and you can ask us to reconsider.
Complaints. You can complain to the data protection authority of the place where you live, work or believe your rights were infringed: for example, in the EU or EEA, your national supervisory authority; in the United Kingdom, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner; in Brazil, the Autoridade Nacional de Protecao de Dados; in Canada, the Office of the Privacy Commissioner of Canada (and in Quebec, the Commission d'acces a l'information); in Australia, the Office of the Australian Information Commissioner; in California, the California Privacy Protection Agency.
12. Security
Connections to the website and the sign-in service are encrypted, and Google Cloud encrypts our logs and our database at rest. No system is perfectly secure. If a breach affects your personal data, we notify you and the authorities as the law of the place where you live requires.
13. Children
Early access is for people aged 18 and over, and this website is not directed to children. If we learn that a request for early access comes from someone under 18, we decline it and delete the message, unless the law requires us to keep it. If we learn that we hold any other personal data of a child under 13, we delete it. If you believe a child has written to us, tell us at contact@sylog.app.
14. Changes and contact
We change this policy when what we do changes, and the date at the top shows when this version took effect. A change that lets us use data in a new way applies only to data collected after it, or with your consent where the law requires it. We keep every version and send an earlier one on request. Privacy questions and requests: contact@sylog.app, with "Privacy request" in the subject. Help with Sylog: support@sylog.app.