SISU PRIVACY POLICY
Effective date: 27 July 2026
This Privacy Policy explains how personal information is handled in connection with Sisu, the accountability app and related website operated by VILJAMAA, ERIK MINH, ABN 47 575 207 237, Australia (Operator, we, us, or our). Contact: support@getsisu.app. Website: https://getsisu.app.
We handle personal information as described in this Policy. We aim to do so consistently with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and good-practice APP-style disclosures. This Policy is not a certification, audit result, or guarantee of a particular compliance outcome.
This Policy covers personal information handling only. Social outcomes, stakes, voting, payouts, and liability between users are governed by the Sisu Terms of Use. If there is a conflict about product rules for stakes or votes, the Terms control those topics.
1. Who we are and scope
Sisu is a technology platform for adults (18+) who form Squads with friends, set Goals, put a financial stake behind Goals via Stripe, upload proof photos, vote pass or fail, and settle outcomes through Stripe Connect Express. Google sign-in and Apple sign-in are used (via Supabase Auth). Local device notifications or reminders may be used, and push delivery may use Expo’s notification infrastructure where enabled.
This Policy applies to personal information we handle through the Sisu iOS and Android applications, our website at https://getsisu.app, support channels (including support@getsisu.app), and related services we operate.
Governing law context: Australia. The Operator is based in Australia (New South Wales context for the Terms). Privacy complaints may be raised with us and, where applicable, with the Office of the Australian Information Commissioner (OAIC).
2. Important positioning — please read
Proof and Squad activity are not private from Squad members. By uploading proof or participating in a Squad or Goal, you understand that relevant Squad members can see proof, votes, stakes, Goal status, and related activity needed for the accountability product.
We are not a confidential mediator. We do not operate a private dispute-investigation service between friends. We may review content only as needed for platform security, legal compliance, payment-rail abuse, app-store rules, or to operate or fix the service — not to decide “fairness” between users.
Any in-app “Wallet” UI is informational history of facilitated Stripe activity. It is not a custodial stored-value account. We do not hold user cash balances as a bank, escrow agent, or custodian.
We do not sell your personal information. We do not use third-party analytics SDKs or crash-reporting SDKs in the app at this time. We do not use personal information for marketing communications. The website at https://getsisu.app is hosted via Cloudflare and may involve Cloudflare’s standard hosting, security, and CDN processing; we do not run separate website analytics tools. If these practices change, we will update this Policy.
Personal information may be processed on servers outside Australia (including outside Australia via our providers). We use providers under contracts and appropriate safeguards as applicable.
3. What personal information we collect
Depending on how you use Sisu, we may collect and process:
Information you provide
• Account and profile details associated with sign-in (such as name, email address, user identifier, and avatar if provided by Google, Apple, or Supabase Auth).
• Squad and Goal content you create or edit (titles, descriptions, stakes, deadlines, recurrence settings, status, quit/exit related records).
• Proof photos or images and related metadata you upload for Goal completion or voting flows.
• Votes and related choices you make in the app.
• Support communications you send to support@getsisu.app.
• Notification preferences and permission states where the product records them.
Information from Squad activity
• Squad membership, roles (leader/member), invite codes, and Squad-related activity.
• Proof, votes, stakes, Goal status, and outcome records visible to relevant Squad members as part of the product.
• Timestamps and status history for Goals, votes (including pass/fail and exit-related votes), and stake/penalty approvals as implemented.
Information from Google, Apple / authentication
• Identifiers and profile fields returned by Google or Apple sign-in via Supabase Auth (such as name, email, subject/user id, and avatar URL if provided).
Information from Stripe / payments
• Payment-related records needed to run Stripe flows (for example authorization/hold references, charge/payout status, and wallet-style history of amounts received or paid as displayed in-app).
• Limited identifiers and status data needed to connect your account to Stripe Connect Express onboarding and payouts.
• We do not store full payment card numbers. Card data is handled by Stripe. Stripe Connect onboarding and verification data is processed by Stripe under Stripe’s terms and privacy policy.
Automatically collected technical data
• Device and app technical data reasonably needed to run the service (for example device type, operating system, app version, and logs).
• Crash or diagnostic data: we do not use a third-party crash-reporting SDK at this time. Limited technical logs may still be generated by the app, device OS, or hosting providers as needed to operate the service.
• Analytics: we do not use a third-party analytics SDK at this time.
4. How we collect it
• Directly through the app (forms, Goal setup, uploads, votes, settings).
• Through Google sign-in, Apple sign-in, and our authentication / database provider: Supabase.
• Through Stripe when you authorize stakes, complete Connect onboarding, or receive/pay amounts via payment rails.
• Through device permissions you grant (for example photo library/camera access for proof uploads; notification permission for reminders).
• Through support email to support@getsisu.app, handled via Lark Mail.
• Through hosting and infrastructure logs on Render (app backend) and Cloudflare (website).
• Through the website at https://getsisu.app, subject to Cloudflare’s standard hosting, security, and CDN processing. We do not run separate website analytics tools.
5. Why we collect it (purposes)
We collect and use personal information to:
• Provide, operate, maintain, and improve the reliability of Sisu.
• Authenticate users and maintain accounts.
• Enable Squads, Goals, proof uploads, voting, and related product workflows.
• Process payments and payouts via Stripe (including Connect Express) and display related history in-app.
• Show informational payment/history UI (including any Wallet-style screen).
• Provide customer support and respond to requests.
• Protect the platform and payment rails against fraud, abuse, security incidents, and clear platform misuse.
• Comply with law, payment-provider rules, and Apple/Google app distribution requirements.
• Send or schedule notifications where you grant permission. This may include on-device local notifications and, where enabled, push notifications delivered using Expo’s notification services. Notification delivery can fail, be delayed, or be disabled by you or the device.
We do not use personal information for marketing communications. We may send operational or service messages (for example, responses to support requests, or launch-related notices to people who signed up on the website notify list).
6. When we disclose information
We may disclose personal information:
To other Squad members (by product design)
Relevant Squad members may see your display name/profile information as shown in-app, Goal details, stakes, proof you upload, votes, outcome records, and related Goal activity needed for accountability. This is not a “private” channel between you and us. We do not disclose information to mediate social disputes for users; Squad visibility exists because that is how the product works.
To service providers
• Stripe (payments and Connect).
• Supabase (authentication, database, and storage as configured).
• Render (app backend hosting/API).
• Lark Mail (support and operational email).
• Apple and Google as app distribution platforms (to the extent required for distribution, purchases if any, and platform rules).
• Cloudflare (website hosting, CDN, and related security infrastructure).
To authorities and for legal reasons
Where required or permitted by law, court order, regulator request, or to protect rights, safety, or the integrity of the service and payment rails.
Business transfers
If we are involved in a merger, acquisition, restructuring, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy or a successor policy with notice where required.
We do not sell personal information.
7. Payments and Stripe
Payment card data is handled by Stripe. The Operator does not store full card numbers. Stripe Connect onboarding and identity/verification information is processed by Stripe. We may store limited payment status information and identifiers needed to operate the app (for example authorization/hold references, charge/payout status, and history shown in-app).
Stripe’s terms and privacy policy apply to Stripe’s processing. Amounts moved between users according to Squad outcomes are facilitated through Stripe payment rails. We are not holding those amounts as escrow or as a custodial wallet balance.
8. Photos and proof content
Proof photos may be sensitive in practice. They may show faces, locations, private spaces, or other personal details. You control what you upload. You must have the rights to upload the content and must not upload unlawful or infringing material.
Proof uploaded for Goals is visible to relevant Squad members for voting and accountability. Do not upload proof you are not willing to share with your Squad.
We may retain proof and related records while needed to operate Goals, accounts, security, payment integrity, and legal/accounting obligations, and then delete or de-identify them when no longer needed, subject to backups and legal holds. See Retention below.
9. Notifications
Sisu may use local on-device notifications or reminders where you grant permission. Where push notifications are enabled, delivery may use Expo’s notification infrastructure (including device push tokens processed by Apple, Google, and Expo as needed to deliver the notification). Notification delivery can fail, be delayed, or be disabled by you or the device. A missed notification does not change privacy rights, but product timing consequences are governed by the Terms.
10. Cookies and website tracking
Our website at https://getsisu.app is served through Cloudflare. We do not run separate website analytics or advertising tracking tools. Cloudflare may process technical data (such as IP address, request metadata, and security/CDN logs) as part of hosting and protecting the site under Cloudflare’s terms. The website notify form stores signup emails in Supabase for launch notification only. The mobile app’s data practices are described in the sections above.
11. Retention
We keep personal information while your account is active and as needed to operate Goals, Squads, payments, security, support, legal compliance, and accounting, and to maintain records related to payment-provider requirements. When information is no longer needed for those purposes, we delete or de-identify it where practicable, subject to backups, legal holds, and records we must keep.
Some information that has been shared into Squad history, or that Stripe holds as a payment processor, may not be fully removable from every system immediately, or may need to be retained for legal or payment-rail reasons.
12. Security
We take reasonable technical and organisational measures designed to protect personal information against misuse, interference, loss, and unauthorised access, modification, or disclosure. No method of transmission or storage is completely secure. We do not promise absolute security.
13. Overseas disclosure
Personal information may be disclosed to or stored by providers outside Australia, including in regions where our hosting, database, auth, email, website, notification, or payment providers operate (for example Supabase, Render, Cloudflare, Stripe, Google, Apple, Expo, and Lark Mail). Exact regions depend on provider configuration. We use providers under contracts and seek appropriate safeguards as applicable.
14. Access, correction, and deletion
You may request access to personal information we hold about you, request correction of inaccurate information, or request deletion where appropriate, by emailing support@getsisu.app. We will respond within a reasonable period.
We may refuse a request where permitted or required by law — for example where information must be retained for legal, payment, or accounting reasons; where providing access would unreasonably impact another individual’s privacy; where a request is frivolous or vexatious; or where information is held by Stripe as an independent controller/processor for its own purposes and must be requested from Stripe.
Privacy requests are about personal information handling. They are not a process to reverse Squad votes, stakes, or payment outcomes. Those matters are governed by the Terms.
Sisu is operated from Australia and is not directed at users in the European Economic Area (EEA), UK, or Switzerland at this time. This Policy describes Australian privacy practices. If that changes, we will update this Policy with any additional disclosures required.
15. Children’s privacy
Sisu is for adults 18 years and older only. It is not directed at children. We do not knowingly collect personal information from individuals under 18. If you believe a person under 18 has created an account, contact support@getsisu.app so we can take appropriate steps.
16. Third-party services
Sisu uses third-party services including Google and Apple (sign-in), Stripe (payments/Connect), Apple and Google app stores (distribution), Supabase (auth/database/storage), Render (backend hosting), Cloudflare (website), Lark Mail (email), Expo (app build/distribution tooling and notifications where enabled), and related infrastructure providers. Their services are governed by their own terms and privacy policies. This Policy does not control how those third parties process information as independent services.
17. Relationship to the Terms of Use
• Joining a Squad means sharing certain personal information and proof with other members.
• We do not investigate user-to-user fairness disputes. Privacy requests do not reverse Squad votes or stakes.
• For stakes, voting finality, payments, Wallet meaning, liability, and Operator role limits, see the Terms of Use.
18. Changes to this Policy
We may update this Privacy Policy by posting a revised version on the website or in the app, or by providing notice. The effective date will be updated. Continued use after an update means you acknowledge the revised Policy. If you do not agree, stop using Sisu and request account closure where available.
19. Complaints
If you have a privacy complaint, contact support@getsisu.app and describe the issue. We will consider the complaint and respond within a reasonable period.
If you are not satisfied with our response, you may be able to contact the Office of the Australian Information Commissioner (OAIC) — see https://www.oaic.gov.au — where the Privacy Act applies to your complaint.
20. Contact details
Operator: VILJAMAA, ERIK MINH
ABN: 47 575 207 237
Australia
Email: support@getsisu.app
Website: https://getsisu.app
Summary of key providers: website https://getsisu.app (Cloudflare); app backend on Render; auth, database, storage, and website notify-list storage on Supabase; support email via Lark Mail; payments via Stripe; sign-in via Google and Apple; notifications may use Expo push infrastructure where enabled. No third-party analytics or crash-reporting SDKs. No marketing use of personal information.