Last updated: 18 April 2026 · Effective: 18 April 2026
The English version of this document is the legally binding one. Translations are provided for your convenience only - if there is any conflict, the English text controls.

Privacy Policy

At a glance

1. Who we are

The service known as SYLAR is operated by Sylar Moser, sole proprietor (the "operator", "we", "us"). The operator can be reached at:

In this Policy, "the Service" means the SYLAR mobile applications for iOS and Android, the SYLAR website at sylar.app, and the backend infrastructure that powers them.

2. Scope

This Policy applies to:

It does not apply to:

3. The two roles we play

SYLAR is a B2B-leaning platform: most data flows through it because a business is using it to manage its own work. That creates two distinct roles under European data-protection law (GDPR), Russian law (152-ФЗ), and similar regimes elsewhere.

3.1 We are the controller of your account data

For data that belongs to you personally - your email, password, name, avatar, the businesses you operate, the bookings you make, your device tokens, your account preferences - we determine why and how that data is processed. We are the controller. This Policy describes that processing.

3.2 We act as a processor for clients-of-business data

When a business uses SYLAR to keep records about its own clients - contact details, visit history, free-form notes such as colour formulas or allergies, custom fields, tags, mass notifications - that data belongs to the business and is processed under the business's instructions. The business is the controller; we are the processor.

If you are a client whose information was added by a business inside SYLAR (for example, the salon you visit keeps a CRM record on you), your primary point of contact for any data-protection request is that business. We will support the business in honouring your request, but we cannot release, modify, or delete client records on behalf of the business without its instruction.

A short Data Processing Addendum, available on the website, governs the processor relationship and is incorporated by reference into the SYLAR Terms of Service that every business owner accepts when creating an account.

4. Information we collect

4.1 Account and profile information

When you create a SYLAR account, we collect:

If you sign in with Google or Apple, we receive the identifiers and profile fields those providers send us (email, name, optional avatar). We never receive your Google or Apple password.

4.2 Content you create inside the Service

4.3 Booking and payment data

4.4 Communications you send to us

4.5 Device and technical information

4.6 Approximate location

4.7 In-app moderation signals

Every image you upload to a public surface (gallery, portfolio, review attachment) is automatically scanned by a content-classifier running inside our infrastructure to detect obviously unsafe content (nudity, weapons, hate symbols). The classifier produces a numerical score that determines whether the upload is accepted, queued for human review, or rejected. We retain the scores and the resulting moderation decision.

4.8 Self-employed payout data (Russian market only)

If you opt in to receive referral payouts as a Russian self-employed person ("самозанятый") under regime 422-ФЗ (НПД), we additionally collect:

Submitting this data also requires that you have enabled two-factor authentication on your account. We rely on legal obligation (tax compliance) and contractual necessity (paying you what you have earned) as the legal basis for this processing.

We retain self-employed payout records for four years after your last transaction, as required by Article 23 of the Russian Tax Code.

5. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. SYLAR is a B2B platform; if you are a business that takes appointments for minors (for example, a kids' haircut), the minor's parent or guardian must consent to your collection of any data, and you remain the controller of that data. If you believe we have inadvertently collected personal information from someone under 16, contact privacy@sylar.app and we will delete it.

6. Legal bases for processing (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar law, we rely on the following bases under Article 6 GDPR:

7. Subprocessors and recipients

We use the following named third parties to deliver the Service. The list below is current as of the "Last updated" date at the top of this Policy; we will update this Policy when we change subprocessors.

RecipientPurposeRegion
Supabase Inc.Primary database, authentication store, file storage for avatars and mediaSingapore (APAC)
Cloudflare Inc.Object storage (R2) for large media, CDN, DDoS protection, DNSGlobal edge
Railway Corp.Backend application hosting and Redis (cache, queues, rate-limit store, OTP store)US / EU
Apple Inc.App Store distribution, in-app purchases, Sign in with Apple, push notifications (APNs)Global
Google LLCGoogle Play distribution, in-app billing, Google Sign-In, push notifications (FCM)Global
Paddle.com Market LimitedSubscription billing for users outside Russia (web checkout, fallback)UK / EU
NBCO YuMoney LLC ("YooKassa")Subscription billing and self-employed payouts for users in RussiaRussia
MaxMind, Inc. and ipapi.coCountry-level Geo-IP lookup for local pricingUS
Resend Inc.Transactional email delivery (verification, OTP, invites, account notices)US
Expo (650 Industries, Inc.)Push notification relay between our backend and APNs/FCMUS
Functional Software, Inc. ("Sentry")Error and crash reporting, with PII redactionUS / EU
Telegram Messenger Inc.Internal alerts to our operations team. No user personal data is sent to Telegram - only aggregated counts and operational health metricsGlobal
Competent authoritiesWhere required by law (court order, lawful subpoena, law-enforcement request)Varies

We sign data-processing agreements with our vendors where applicable. Where a transfer occurs from the EEA or the UK to a country without an adequacy decision, we rely on the European Commission Standard Contractual Clauses (EU SCCs, 2021 version) and the UK International Data Transfer Addendum, with supplementary technical measures (encryption in transit and at rest, access controls).

We do not sell your personal information. We do not disclose it for behavioural advertising. We do not share it with data brokers.

8. International data transfers

SYLAR is a global service and your data may be processed outside your country of residence. The principal storage location is Singapore (Supabase ap-southeast-1); other processing happens in the US and EU as listed in §7. We rely on the legal mechanisms summarised in §7 to lawfully transfer data internationally.

9. Retention

We keep your information only as long as we need it to operate the Service or to comply with law.

CategoryRetention
Account, profile, business profileWhile your account exists
Bookings, reviews, chat messages, portfolio media, CRM recordsWhile the owning account exists
Subscription receipts and payment events7 years after the transaction (tax law)
Self-employed payout records (Russia)4 years after the last transaction (Article 23 NK RF)
Refresh tokens (hashed)30 days after issuance
Server logs90 days
Audit log of administrator actions90 days
Brute-force / rate-limit signals30 days
Push notification tokensUntil invalidated by Apple/Google or until you revoke them
Support correspondence2 years
Image moderation scores and decisions90 days for accepted media; permanently for rejected media (to enforce future blocks)

When you delete your account, we begin a 30-day undo window - you can sign back in within that period to cancel the deletion. After 30 days, your data is removed from our active systems. Routine backups (taken by Supabase) are not selectively edited; data may persist in encrypted backups for up to a further 30 days, after which it is overwritten by backup rotation.

Some data must be kept beyond account deletion to satisfy legal obligations (the rows marked "tax law" or "Article 23 NK RF" above). Where we keep data after deletion, we remove direct identifiers from it where possible.

10. Your rights

Depending on where you live, you may have any of the rights listed below. We honour them regardless of where you are.

To exercise any right, contact privacy@sylar.app. We respond within 30 days. Where the request is complex, we may extend the response window by up to two further months and tell you why.

11. Automated decision-making

Two automated systems can make decisions that affect your use of the Service:

We do not use automated profiling to make decisions about your creditworthiness, eligibility for the Service beyond the cases above, or any other decision producing legal or similarly significant effects.

12. Marketing and communications

13. Security

We apply industry-standard safeguards to protect your information:

No system is perfectly secure. If you believe your account has been compromised, write to security@sylar.app as soon as you can.

14. Cookies and similar technologies

The SYLAR mobile applications do not use cookies - they are not browser-based.

The SYLAR website at sylar.app uses your browser's localStorage to remember your language preference. It does not use cookies, advertising trackers, or analytics scripts.

15. Use of artificial intelligence

We are deliberate about how AI is and is not used in SYLAR.

16. Russian residents

If you are located in the Russian Federation, you should be aware:

17. California residents (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, the right to delete it, the right to correct inaccurate information, the right to limit our use of sensitive personal information, and the right to opt out of "sale" or "sharing" of personal information. We do not sell or share your personal information within the meaning of the California Consumer Privacy Act. To exercise your rights, write to privacy@sylar.app.

18. Changes to this Policy

We may update this Policy from time to time. If we make changes that materially expand how we collect or use your data, we will notify you via the app, by email, or both, at least 14 days before the change takes effect. The "Last updated" date at the top of this page always reflects the current version. Older versions are kept on file and available on written request.

19. Contact

For any privacy or data-protection question:

We respond within 30 days.