The English version of this document is the legally binding one. Translations are provided for your convenience only - if there is any conflict, the English text controls.
Privacy Policy
At a glance
- Who we are. SYLAR is a software platform that lets small service businesses (salons, barbershops, tattoo studios, and similar) run their booking, CRM, payments, and discovery from a single mobile app.
- What we collect. Your account data, the content you create inside SYLAR (services, bookings, reviews, chat messages, photos), your approximate location when you turn on the discovery map, and technical data needed to keep the service running.
- Why. To operate the service, process payments, prevent abuse, and comply with the law.
- Who sees it. Only the people you would expect: the business you booked with sees your booking; you see your own data; we use a small set of named infrastructure providers (listed in §7) to host and deliver the service.
- What we don't do. We don't sell your data. We don't share it with advertisers. We don't train AI models on your content. We don't use third-party analytics (Google Analytics, Mixpanel, or similar).
- Your control. Export your data or delete your account in-app at any time. Deletion takes effect within 30 days and is final.
- Two roles we play. For your own account, we are the data controller. For records a business creates about its own clients inside SYLAR, the business is the controller and we act as a processor on its behalf - explained in §3.
- How to reach us. privacy@sylar.app
1. Who we are
The service known as SYLAR is operated by Sylar Moser, sole proprietor (the "operator", "we", "us"). The operator can be reached at:
In this Policy, "the Service" means the SYLAR mobile applications for iOS and Android, the SYLAR website at sylar.app, and the backend infrastructure that powers them.
2. Scope
This Policy applies to:
- People who create a SYLAR account, whether as a business owner, a business administrator, a staff member, or a client.
- Visitors to
sylar.app.
It does not apply to:
- Third-party services we integrate with (Apple App Store, Google Play, Paddle, YooKassa, etc.) - those services have their own privacy policies, and your relationship with them is governed by those policies.
- Any business profile inside SYLAR - when a business uses SYLAR to run its own operations, it is responsible for its own use of client data, with us acting as a processor (see §3).
3. The two roles we play
SYLAR is a B2B-leaning platform: most data flows through it because a business is using it to manage its own work. That creates two distinct roles under European data-protection law (GDPR), Russian law (152-ФЗ), and similar regimes elsewhere.
3.1 We are the controller of your account data
For data that belongs to you personally - your email, password, name, avatar, the businesses you operate, the bookings you make, your device tokens, your account preferences - we determine why and how that data is processed. We are the controller. This Policy describes that processing.
3.2 We act as a processor for clients-of-business data
When a business uses SYLAR to keep records about its own clients - contact details, visit history, free-form notes such as colour formulas or allergies, custom fields, tags, mass notifications - that data belongs to the business and is processed under the business's instructions. The business is the controller; we are the processor.
If you are a client whose information was added by a business inside SYLAR (for example, the salon you visit keeps a CRM record on you), your primary point of contact for any data-protection request is that business. We will support the business in honouring your request, but we cannot release, modify, or delete client records on behalf of the business without its instruction.
A short Data Processing Addendum, available on the website, governs the processor relationship and is incorporated by reference into the SYLAR Terms of Service that every business owner accepts when creating an account.
4. Information we collect
4.1 Account and profile information
When you create a SYLAR account, we collect:
- Email address, hashed password, display name, optional avatar image, optional phone number, preferred language and time zone.
- For business accounts: business name, business type ("vertical"), legal location (country / city), services offered, staff members, schedule, pricing, payment receipts, gallery and logo images.
- For staff invited by a business: name, email, optional avatar, permissions assigned by the business owner, individual schedule.
If you sign in with Google or Apple, we receive the identifiers and profile fields those providers send us (email, name, optional avatar). We never receive your Google or Apple password.
4.2 Content you create inside the Service
- Bookings: appointment details, service selected, staff selected, date and time, optional notes, and intake-form responses.
- Reviews: rating, optional written review, optional photo, optional voice recording (up to 30 seconds), optional video recording (up to 15 seconds round preview).
- Chat messages: the content of messages exchanged between a business and a client inside the Service.
- Portfolio media: images you upload to your business gallery, including before/after pairs.
- CRM data (business owners only): notes about your clients, custom fields, tags, mass-notification campaigns. Some fields - for example colour formulas and allergies for hair salons - may reveal limited categories of sensitive information about a third party (your client). You alone are responsible for collecting that data lawfully and for the consent of the person it describes.
4.3 Booking and payment data
- For subscriptions: a transaction receipt from Apple, Google, Paddle, or YooKassa. We do not receive or store your card details. We receive a subscription identifier, a product identifier, the renewal date, and the renewal status.
- For self-employed payouts (Russian market only - see §4.8).
4.4 Communications you send to us
- Support messages.
- Reports and complaints about other users or content.
- Email correspondence at any of our
@sylar.app addresses.
4.5 Device and technical information
- Device model, operating system version, app version, language, and a randomly generated device identifier used for push notification routing.
- IP address (for the request - we do not build long-term IP profiles beyond what is required for security and rate limiting; see §13).
- A short-lived session token, a long-lived refresh token (rotated on every refresh, hashed at rest), and a per-device push notification token issued by Apple, Google, or Expo.
- Pino structured server logs covering request metadata, with passwords, one-time codes, JWTs, and other secrets actively redacted before write.
4.6 Approximate location
- Your mobile device's coarse location, only while the in-app discovery map is in use, to find businesses within roughly 50 km of you. We do not collect background location, and we do not retain precise coordinates beyond the immediate request.
- The business's location is shared by the business itself when it sets its address - that location is public on the discovery map by design.
- Your approximate country, derived from your IP at billing time via a Geo-IP lookup (see §7), to display local pricing.
4.7 In-app moderation signals
Every image you upload to a public surface (gallery, portfolio, review attachment) is automatically scanned by a content-classifier running inside our infrastructure to detect obviously unsafe content (nudity, weapons, hate symbols). The classifier produces a numerical score that determines whether the upload is accepted, queued for human review, or rejected. We retain the scores and the resulting moderation decision.
4.8 Self-employed payout data (Russian market only)
If you opt in to receive referral payouts as a Russian self-employed person ("самозанятый") under regime 422-ФЗ (НПД), we additionally collect:
- Your individual taxpayer number ("ИНН"), validated server-side.
- A bank-card token issued by YooKassa, plus the last four digits of the card for display purposes. The full card number never reaches our servers.
- KYC (know-your-customer) status set by our review team after we verify the data you submit.
- A history of your payout requests, payments received, and year-to-date amount earned (used to enforce the 2.4 million ruble annual cap of regime 422-ФЗ).
Submitting this data also requires that you have enabled two-factor authentication on your account. We rely on legal obligation (tax compliance) and contractual necessity (paying you what you have earned) as the legal basis for this processing.
We retain self-employed payout records for four years after your last transaction, as required by Article 23 of the Russian Tax Code.
5. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. SYLAR is a B2B platform; if you are a business that takes appointments for minors (for example, a kids' haircut), the minor's parent or guardian must consent to your collection of any data, and you remain the controller of that data. If you believe we have inadvertently collected personal information from someone under 16, contact privacy@sylar.app and we will delete it.
6. Legal bases for processing (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar law, we rely on the following bases under Article 6 GDPR:
- Performance of a contract - to operate the Service you signed up for: authenticating you, storing your bookings and content, delivering messages and notifications, billing you for any paid plan, paying you for any referral payouts.
- Legitimate interests - to keep the Service secure (rate limiting, brute-force detection, audit logging), prevent fraud and abuse, moderate publicly visible content, debug errors, and improve the Service. You can object to processing based on legitimate interests at any time.
- Consent - for optional features that require it: location permission, push notifications, and any future marketing communication. You can withdraw consent in-app or by writing to us.
- Legal obligation - to comply with tax, accounting, anti-money laundering, and lawful requests from public authorities.
7. Subprocessors and recipients
We use the following named third parties to deliver the Service. The list below is current as of the "Last updated" date at the top of this Policy; we will update this Policy when we change subprocessors.
| Recipient | Purpose | Region |
| Supabase Inc. | Primary database, authentication store, file storage for avatars and media | Singapore (APAC) |
| Cloudflare Inc. | Object storage (R2) for large media, CDN, DDoS protection, DNS | Global edge |
| Railway Corp. | Backend application hosting and Redis (cache, queues, rate-limit store, OTP store) | US / EU |
| Apple Inc. | App Store distribution, in-app purchases, Sign in with Apple, push notifications (APNs) | Global |
| Google LLC | Google Play distribution, in-app billing, Google Sign-In, push notifications (FCM) | Global |
| Paddle.com Market Limited | Subscription billing for users outside Russia (web checkout, fallback) | UK / EU |
| NBCO YuMoney LLC ("YooKassa") | Subscription billing and self-employed payouts for users in Russia | Russia |
| MaxMind, Inc. and ipapi.co | Country-level Geo-IP lookup for local pricing | US |
| Resend Inc. | Transactional email delivery (verification, OTP, invites, account notices) | US |
| Expo (650 Industries, Inc.) | Push notification relay between our backend and APNs/FCM | US |
| Functional Software, Inc. ("Sentry") | Error and crash reporting, with PII redaction | US / EU |
| Telegram Messenger Inc. | Internal alerts to our operations team. No user personal data is sent to Telegram - only aggregated counts and operational health metrics | Global |
| Competent authorities | Where required by law (court order, lawful subpoena, law-enforcement request) | Varies |
We sign data-processing agreements with our vendors where applicable. Where a transfer occurs from the EEA or the UK to a country without an adequacy decision, we rely on the European Commission Standard Contractual Clauses (EU SCCs, 2021 version) and the UK International Data Transfer Addendum, with supplementary technical measures (encryption in transit and at rest, access controls).
We do not sell your personal information. We do not disclose it for behavioural advertising. We do not share it with data brokers.
8. International data transfers
SYLAR is a global service and your data may be processed outside your country of residence. The principal storage location is Singapore (Supabase ap-southeast-1); other processing happens in the US and EU as listed in §7. We rely on the legal mechanisms summarised in §7 to lawfully transfer data internationally.
9. Retention
We keep your information only as long as we need it to operate the Service or to comply with law.
| Category | Retention |
| Account, profile, business profile | While your account exists |
| Bookings, reviews, chat messages, portfolio media, CRM records | While the owning account exists |
| Subscription receipts and payment events | 7 years after the transaction (tax law) |
| Self-employed payout records (Russia) | 4 years after the last transaction (Article 23 NK RF) |
| Refresh tokens (hashed) | 30 days after issuance |
| Server logs | 90 days |
| Audit log of administrator actions | 90 days |
| Brute-force / rate-limit signals | 30 days |
| Push notification tokens | Until invalidated by Apple/Google or until you revoke them |
| Support correspondence | 2 years |
| Image moderation scores and decisions | 90 days for accepted media; permanently for rejected media (to enforce future blocks) |
When you delete your account, we begin a 30-day undo window - you can sign back in within that period to cancel the deletion. After 30 days, your data is removed from our active systems. Routine backups (taken by Supabase) are not selectively edited; data may persist in encrypted backups for up to a further 30 days, after which it is overwritten by backup rotation.
Some data must be kept beyond account deletion to satisfy legal obligations (the rows marked "tax law" or "Article 23 NK RF" above). Where we keep data after deletion, we remove direct identifiers from it where possible.
10. Your rights
Depending on where you live, you may have any of the rights listed below. We honour them regardless of where you are.
- Access - request a copy of the personal data we hold about you. In-app: Profile → Settings → Export data.
- Rectification - correct inaccurate data. Most fields are directly editable in the app; for the rest, write to us.
- Erasure - delete your account and associated data. In-app: Profile → Settings → Delete account. Effective in 30 days.
- Restriction and objection - limit or stop our processing of your data, in particular processing based on legitimate interests.
- Portability - receive your data in a structured, machine-readable format. The in-app export delivers JSON.
- Withdraw consent - for any processing that relies on consent.
- Not be subject to a solely automated decision with significant effects - see §11 on the moderation classifier.
- Lodge a complaint with your local data-protection authority.
To exercise any right, contact privacy@sylar.app. We respond within 30 days. Where the request is complex, we may extend the response window by up to two further months and tell you why.
11. Automated decision-making
Two automated systems can make decisions that affect your use of the Service:
- Image moderation classifier (§4.7). If the classifier scores an upload above its rejection threshold, the upload is blocked and not visible to anyone. You can challenge the result by writing to support@sylar.app and a human moderator will review the decision. We retain the original file long enough to perform that review.
- Anti-fraud and rate-limiting. We automatically block requests that look like brute-force, scraping, or abuse. If you are incorrectly blocked, write to support@sylar.app.
We do not use automated profiling to make decisions about your creditworthiness, eligibility for the Service beyond the cases above, or any other decision producing legal or similarly significant effects.
12. Marketing and communications
- Transactional messages - booking confirmations, security alerts, password resets, payout status, subscription renewal notices. We send these because they are required to operate the Service. They cannot be unsubscribed from.
- In-app notifications you opt into - booking reminders, chat pings, review requests. You can disable categories at any time: Profile → Settings → Notifications.
- Messages from a business to its clients - businesses can send push notifications and email to their own clients through SYLAR (the CRM "mass notifications" feature). The business is the controller of those messages; you can opt out by replying to the business or, if it stops responding, by contacting us.
- Marketing from SYLAR itself. We do not currently send marketing communications. If we ever do, you will be asked to opt in beforehand and you will be able to opt out from every message.
13. Security
We apply industry-standard safeguards to protect your information:
- Passwords hashed with bcrypt; we never store them in plain text.
- Two-factor authentication available on all accounts; mandatory for administrators, moderators, and anyone who submits self-employed payout data.
- TOTP secret encrypted at rest with AES-256-GCM.
- All connections to the Service are encrypted with TLS 1.2 or higher; data at rest is encrypted by our infrastructure providers (Supabase, Cloudflare R2).
- Per-app permission middleware enforces that only you, or a person you have granted access, can reach your data.
- Rate limiting, webhook signature verification, anti-replay checks on payment webhooks, and atomic refresh-token rotation.
- Step-up re-authentication is required before any operation that touches money or sensitive personal data (password change, email change, KYC submission, payout request).
- Secrets rotation, least-privilege credentials, and an audit log of every administrator action.
- Strict HTTP security headers (HSTS, CSP, X-Frame-Options) on every response.
- Automated dependency vulnerability scans and prompt patching of critical issues.
No system is perfectly secure. If you believe your account has been compromised, write to security@sylar.app as soon as you can.
14. Cookies and similar technologies
The SYLAR mobile applications do not use cookies - they are not browser-based.
The SYLAR website at sylar.app uses your browser's localStorage to remember your language preference. It does not use cookies, advertising trackers, or analytics scripts.
15. Use of artificial intelligence
We are deliberate about how AI is and is not used in SYLAR.
- We use a content-classifier model to flag obviously unsafe images. This is described in §4.7 and §11.
- We do not train, retrain, or fine-tune any AI model on the content you create inside SYLAR - your messages, photos, reviews, and CRM notes are not used as training data, by us or by anyone we share infrastructure with.
- We do not generate content for businesses on their behalf using large language models or similar systems. Earlier versions of the Service offered AI-generated business specs; that feature was removed in 2026 and the codebase no longer integrates with any third-party large-language-model provider.
16. Russian residents
If you are located in the Russian Federation, you should be aware:
- Our infrastructure is hosted outside Russia, principally in Singapore. By creating an account and using the Service, you consent to the cross-border transfer of your personal data (transboundary transfer under Article 12 of Federal Law 152-FZ) to those locations.
- Self-employed payout data (§4.8) is handled additionally in cooperation with YooKassa (NBCO YuMoney LLC), which is registered in Russia.
- You have the rights described in §10, including the right to withdraw consent at any time and the right to appeal to Roskomnadzor.
17. California residents (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, the right to delete it, the right to correct inaccurate information, the right to limit our use of sensitive personal information, and the right to opt out of "sale" or "sharing" of personal information. We do not sell or share your personal information within the meaning of the California Consumer Privacy Act. To exercise your rights, write to privacy@sylar.app.
18. Changes to this Policy
We may update this Policy from time to time. If we make changes that materially expand how we collect or use your data, we will notify you via the app, by email, or both, at least 14 days before the change takes effect. The "Last updated" date at the top of this page always reflects the current version. Older versions are kept on file and available on written request.
19. Contact
For any privacy or data-protection question:
We respond within 30 days.