Privacy Policy

Silma · Last updated: July 25, 2026

Silma ("we", "us", "our") is operated by Joonas Soininen, based in the United States. This policy describes how we collect, use, and protect your personal data when you use silma.app and related services. It applies to all users regardless of location. We are committed to complying with applicable privacy laws including the EU General Data Protection Regulation (GDPR) for users in the EU/EEA.

1. Information we collect

Account information: Email address, name, and profile image when you sign up via Google OAuth or email/password.

Content you submit: Instagram Reel and TikTok URLs you submit, video frames extracted from videos you upload for Pre-Check analysis, AI-generated analysis results, and content suggestions.

Brand profile: Niche, target audience, content pillars, tone, differentiator, and any brand document (PDF or text) you upload voluntarily.

Chat messages: Conversations with our AI assistant (Chroma) are stored to provide context across sessions.

Watchlist data: Competitor account handles you add to your watchlist and the associated content analysis results.

Content history: Ideas you save, mark as posted, and outcome ratings you log.

Payment information: Processed securely by Stripe. We never store your card details.

Device identifier: A non-persistent device identifier generated in your browser to prevent multi-account abuse on the free tier. This identifier is not shared with third parties.

Usage data: Feature usage counts, submission timestamps, and error logs for service reliability.

2. Legal basis for processing (GDPR)

We process your personal data under the following legal bases:

Where we rely on legitimate interest, you have the right to object. See Section 7 for how to exercise your rights.

3. How we use your information

We do not use your data to train AI models. Your content is sent to our AI provider solely to generate results for you.

4. Third-party service providers

We share data with the following categories of service providers only as necessary to operate the Service. All providers are contractually required to protect your data and process it only for the purposes we specify.

We do not sell your data to third parties.

5. International data transfers

We are based in the United States. If you are located in the EU/EEA or another jurisdiction with data transfer restrictions, your personal data will be transferred to and processed in the United States and potentially other countries. For EU/EEA users, we rely on appropriate transfer mechanisms such as the European Commission's Standard Contractual Clauses (SCCs) where required. By using the Service you acknowledge that your data may be processed in countries outside your own.

6. Data retention

7. Your rights (GDPR)

If you are in the EU/EEA, you have the following rights. Contact us at support@silma.app. We will respond within 30 days.

You also have the right to lodge a complaint with the data protection authority in your country of residence. EU/EEA residents can find their national authority at edpb.europa.eu.

8. Data security

We use industry-standard security measures including encrypted connections (HTTPS/TLS), hashed API keys, signed access tokens, and encrypted session management. Stored data is encrypted at rest by our infrastructure providers.

9. Data breaches

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33, and notify affected users without undue delay where required by Article 34.

10. Cookies

In the Service itself we use essential cookies only, specifically an httpOnly session cookie for authentication.

On our public website we additionally use analytics cookies, set by Google Analytics (named _ga and _ga_<id>) and by our product analytics provider, to measure visits and distinguish returning visitors.

No cookie is set until you accept. On your first visit we ask. If you decline, or simply never answer, no analytics cookie is written and no session recording happens. Your choice is remembered in your browser, and you can change it at any time by clearing site data for silma.app, which brings the banner back.

The two providers behave differently before you answer, and we would rather spell that out than round it off:

These are analytics cookies, not advertising cookies: we do not run advertising cookies, we do not use Google Analytics for ad personalization or remarketing, and we do not sell this data.

11. Children

The Service is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email. Continued use of the Service after changes constitutes acceptance.

13. Contact

For privacy-related inquiries or to exercise your rights: support@silma.app