Privacy policy
Sinterly is operated by Kademos Labs, based in the United Kingdom. This page says plainly what data we hold, why, where it lives, and how to have it deleted. It follows the same rule as everything else on this site: mechanisms, not aspirations.
What we hold, and why
Trial requests. If you use the trial form we store the email address and any company name you give us, so a real person can contact you. That is the form's only purpose. If you never become a customer, ask and the row is deleted.
Accounts. For each user of a tenant we hold a name, an email address, a role, and authentication data (password hash and multi-factor enrolment) managed by our authentication provider. We never see or store your password in plain text.
Findings data. Your tenant's security findings are scanner output you chose to send us: vulnerability titles, severities, CVE/CWE identifiers, affected file paths and line numbers, and — where a scanner emits them — taint traces and fix versions. Sinterly ingests findings, never your source code. Scanner author/committer fields are stripped before storage. You control this data: it exists so the product can prioritise it for you, and for no other purpose.
Operational logs. Application logs (request paths, error detail, run summaries) are kept for operating and debugging the service. They are not used for analytics or profiling, and we run no third-party trackers on the product or this site.
Where it lives
The production database is hosted in London (AWS eu-west-2) by Supabase. Application servers run in Amsterdam on Fly.io. Raw ingest archives are stored with Cloudflare R2. Secrets are managed in Doppler. Trial-request and operational notification emails are sent via Google (Gmail). Each of these processors sees only what its role requires.
Tenant isolation
Every row of tenant data carries its tenant identity and is guarded by database-enforced row-level security — one tenant can never read another's data. The isolation is covered by an automated test suite run against the real database. Integration credentials you store (for example a Jira API token) are encrypted with AES-256-GCM before they reach the database, with the key held outside the database provider, and are never displayed again after saving.
Retention and deletion
Raw scanner payloads are archived out of the live database after their retention window. When a trial ends and you do not continue, we delete your tenant — findings, raw ingest data, stored credentials, users and authentication records — within 30 days of the end date, and confirm by email when it is done. You can request deletion earlier at any time, and you can export your findings from the dashboard before deletion.
Your rights
Under UK GDPR you have the rights of access, rectification, erasure, restriction, portability and objection. Write to security@sinterly.com and a real person on the team answers. If you are unsatisfied you may complain to the Information Commissioner's Office (ICO).
Changes
If this policy changes materially while you hold an account, we tell you by email before the change takes effect.
Last updated 16 July 2026.