Privacy Policy
Last updated: 16 August 2026
This policy explains what personal data we process when you use SessionPilot, why, and what you can do about it. It covers our own processing as a controller. Where we process data on a customer’s behalf as a processor, the Data Processing Addendum applies.
1. What we collect
| Category | Examples | Why |
|---|---|---|
| Account data | Email address, display name, hashed password, role, account status | To create and secure your account and authenticate you |
| Subscription data | Plan tier, seat count, status, billing period end | To grant the entitlements you paid for and enforce plan limits |
| Encrypted content | Ciphertext blobs of profiles, folders and warmed sessions | To sync between your devices and team. Stored as ciphertext only |
| Team and audit records | Workspace membership, roles, access-control entries, a hash-chained log of membership and access events with the acting user and timestamp | To operate team features and give you a tamper-evident record of who did what |
| Public keys | Your public encryption and signing keys; your private keys only ever as ciphertext we cannot unwrap | So team members can seal data to each other |
| Operational data | IP address, timestamps, request metadata, error logs, rate-limit counters | Security, abuse prevention, debugging and service reliability |
| Enquiries | What you send us through the contact form | To respond to you |
2. What we deliberately cannot collect
This is the part that distinguishes SessionPilot, and we want to be precise about it rather than slogan-like:
- Your passphrase never leaves your device. The encryption key is derived from it locally. We do not receive it, store it, or have any means of recovering it.
- Profile and session contents reach us already encrypted. Cookies, local storage, fingerprints, proxy credentials and notes inside a profile are ciphertext to us.
- Team sharing does not give us access. A workspace key is sealed individually to each member’s public key. The server relays sealed envelopes it cannot open.
- We do not track your browsing. The websites you visit inside a profile are not reported to us; that traffic goes directly from your machine (or your proxy) to the site.
The honest consequence, stated plainly: because we cannot read your content, we also cannot recover it for you, and we cannot inspect it to verify it is lawful. Both follow from the same design.
3. Legal bases
Where the UK/EU GDPR or similar law applies, we rely on:
- Performance of a contract — account, subscription, sync and team features.
- Legitimate interests — securing the service, preventing abuse and fraud, keeping operational logs, and defending legal claims. We balance these against your rights.
- Legal obligation — tax, accounting, and responding to lawful requests.
- Consent — where we ask for it, such as optional communications. You can withdraw consent at any time.
4. Who we share with
We do not sell personal data and we do not share it for advertising. We use a small number of sub-processors to run the service — hosting and infrastructure, payment processing, and email delivery. Each is bound by contract to protect the data and to process it only on our instructions. The current list is available on request through the contact form, and is maintained under the Data Processing Addendum.
We may disclose information where legally required, or where necessary to protect the rights, property or safety of any person. Where we are permitted to tell you about such a request, we will.
5. How long we keep it
- Account and subscription data — for as long as the account exists, then for the period needed to meet tax and accounting obligations.
- Encrypted content — until you delete it or close the account. Deleted items leave a tombstone so the deletion propagates to your other devices; tombstones are purged after 180 days.
- Audit records — retained while the workspace exists, because their value is that they cannot be quietly rewritten.
- Operational logs — kept for a limited period appropriate to security and debugging, then deleted or aggregated.
6. Security
Beyond the client-side encryption described above, we use TLS in transit, hashed passwords with a modern password-hashing function, scoped access tokens, role-based access control, and rate limiting on authentication. Team membership and access changes are recorded in a hash-chained, signed audit log. Details are on the Security page. No system is perfectly secure, and we do not claim otherwise.
7. International transfers
Our infrastructure and sub-processors may be located outside your country. Where personal data is transferred internationally we rely on an appropriate safeguard, such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy;
- Have inaccurate data corrected;
- Have data erased, subject to our legal obligations;
- Restrict or object to certain processing;
- Receive your data in a portable format;
- Withdraw consent where processing is based on it; and
- Complain to your local data-protection authority.
Ask through the contact form and we will respond within the period the law requires. Note that we cannot produce a readable copy of your encrypted content — only the ciphertext — because we hold no key for it.
9. Children
The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.
10. Changes
We will update this policy as the service evolves. Material changes will be notified to account holders where practicable, and the date at the top always reflects the current version.