Privacy Policy
Silo — app.silo.day Last updated: 23 July 2026
1. Who we are
Silo is operated by Colson Studio Ltd, a company incorporated in England and Wales (company number 16538540), registered office at C/O Goodier Smith & Watts, Devonshire House, Borehamwood, Hertfordshire, England, WD6 1QQ ("Colson Studio," "we," "us").
For any privacy question, request, or complaint: [email protected]
We are the data controller for the account and billing information you give us directly. For job data you create in Silo — client names, call-sheet contents, schedules, day rates — you are the data controller, and Colson Studio acts as your data processor. See our Data Processing Agreement for the detail of that relationship.
2. What we collect
Account data: name, email, password hash, billing details (handled by our payment provider — we do not store card numbers).
Job data you create or import:
- Booking details, kit checklists, expense entries
- Call-sheet content ingested via your personal inbound email address, including client names, locations, contact numbers, and schedules
- Calendar data read (never written) from any Google, Outlook, or Apple/webcal calendar you connect
- Day rates and other figures used for invoice and overtime calculation
Connection data: OAuth tokens for any third-party account you connect (Google, Microsoft, Dropbox, Xero), stored encrypted at rest. We never see or store your passwords for these services.
Technical data: IP address, browser/device information, and error logs, collected automatically for security and to keep the service running.
3. How we use it, and why we're allowed to
| Purpose | Lawful basis |
|---|---|
| Providing the core service (bookings, kit lists, rate calculation) | Contract |
| Extracting data from call sheets you forward, via AI | Contract |
| Pushing invoices to your connected Xero account | Contract |
| Security, fraud prevention, keeping the service running | Legitimate interests |
| Responding to support requests | Contract / legitimate interests |
| Sending you service updates (not marketing) | Contract |
We do not use your job data to train any AI model, ours or anyone else's.
4. Who we share it with
We keep this list short by design, because most of the third parties in Silo's workflow are your own accounts, not ours:
- Google Drive, Microsoft OneDrive, Dropbox — when you connect one of these, call sheets are stored in your own account under it, not on our servers. We never gain broader access than the specific files Silo itself creates there (
drive.file/Files.ReadWriteapp-file scopes only — we cannot see the rest of your drive). - Xero — invoices are generated and pushed into your own connected Xero organisation. We do not retain a copy as our system of record; Xero is.
- Google Calendar, Outlook, Apple/webcal — read-only. We never write, edit, or delete anything in your calendar.
The following are our sub-processors — companies we contract with directly, who may process data on our behalf:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting and database | Germany (Nuremberg) |
| Google (Gemini API) | AI extraction of call-sheet text | United States / EU, per Google's processing terms |
| Resend | Transactional and inbound email delivery | United States |
| Sentry | Error monitoring | United States |
| Stripe | Subscription billing and payment processing | United States / EU, per Stripe's processing terms |
Where a sub-processor is located outside the UK, we rely on the appropriate transfer safeguard (Google's, Resend's, Sentry's, and Stripe's standard contractual terms, as updated to reflect the UK's current international transfer framework). We'll update this table if that list changes, and you can ask us for the current version at any time.
We never sell your data, and we don't share it for advertising purposes.
5. AI features
Call-sheet text you forward to your inbound email address is sent to Google's Gemini API for extraction into structured job data. The in-app assistant is powered by the same underlying model. Two things worth knowing:
- No AI credentials ever reach your browser — the AI runs entirely on our servers.
- The assistant's tools execute against your own logged-in session. It cannot see or act on data that you, the logged-in user, couldn't already see or act on yourself.
6. How long we keep it
Silo is a working tool, not your system of financial record. Once an invoice is raised, your own connected Xero organisation holds the authoritative copy — Silo doesn't need to, and doesn't, retain it as a record of account.
When you delete a job, expense, or your whole account, that data is marked for deletion and held for a short recovery window of 30 days purely to protect against accidental taps — during that window it isn't visible to you and isn't used for anything, it's just recoverable if you contact [email protected] quickly. After the window closes, it is permanently and irreversibly deleted, including from our backups within 30 days as the backup cycle rolls over.
This means: no indefinite retention, no "soft delete" as a permanent state, and no copy kept by us once both the recovery window and backup cycle have passed.
7. Security
- Every database query is automatically scoped to your account by construction — requesting another user's data returns a not-found response, not an access-denied one, so no information about other accounts' existence leaks.
- Third-party tokens (Google, Microsoft, Dropbox, Xero) are encrypted at rest. A stolen database backup does not yield usable credentials.
- Day-rate and invoicing figures are protected using standard server-side security, not end-to-end encryption — this is a deliberate trade-off, since Xero sync and overtime/invoice calculations require the application to read these values.
- Your inbound call-sheet email address uses a random token unconnected to your identity, and can be regenerated at any time if you believe it's been exposed. Inbound webhooks are cryptographically signature-verified.
8. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure (see Section 6 — for your own account, this is instant and self-serve)
- Object to or restrict certain processing
- Data portability
- Complain
To exercise any of these, email [email protected]. We'll respond within one month.
9. How to complain
If you're unhappy with how we've handled your data, you can complain to us directly — see our Complaints Procedure for how that works. You can also complain to the UK Information Commissioner's Office (ico.org.uk) at any time; you don't need to complain to us first.
10. Cookies
See our Cookie Notice.
11. Changes to this policy
We'll post updates here and, for material changes, notify you by email.