Privacy Policy
Last updated: July 19, 2026
1. Who we are and what this covers
Sinon (“Sinon”, “we”, “us”) operates a security-awareness platform that lets organizations run authorized simulated phishing campaigns against their own people and measure the results. This policy explains what personal data we handle and how.
Our platform involves two different relationships, and it matters which one applies to you:
- When you visit our site or hold an account (a customer admin, or a website visitor), we are the controller of your personal data and this policy governs it.
- When a customer uploads employee data to run campaigns, that customer is the controller and we act only as their processor. How that data is handled is governed by our Data Processing Agreement.
2. Data we collect
Account & visitor data (we are the controller)
- Account details: your work email, password (stored only as a secure hash), company name, industry, and role.
- Authorization records: confirmation that you are permitted to test the people you upload, and when you confirmed it.
- Billing details: handled by our payment processor; we receive limited billing metadata, never full card numbers.
- Essential cookies: a session cookie to keep you signed in. We do not run advertising or third-party analytics trackers.
Employee / campaign-target data (we are the processor)
- Target details our customers upload: name, email, department, position, and locale.
- Campaign & interaction data: whether a simulated email was sent, delivered, opened, clicked, submitted, or reported, plus timestamps, a hashed IP address, and browser user-agent.
- What we never collect: when someone submits a simulated form, we record only that a submission happened. We never capture, store, or transmit the credentials or values they typed.
3. How we use data
- To provide the service: create accounts, generate simulations, send campaigns, and produce reports.
- To secure the platform: authenticate users, keep an audit trail, and prevent abuse.
- To communicate with you about your account, security, and service changes.
- To meet legal and accounting obligations.
We do not sell personal data, and we do not use employee data to train AI models.
4. Legal bases (EU/UK GDPR)
Where GDPR applies, we rely on: contract (to provide the service you sign up for), legitimate interests (to secure and improve the platform), legal obligation (e.g. accounting), and consent where specifically requested. For employee data processed on a customer’s behalf, the customer is responsible for the lawful basis of the testing.
5. Sub-processors we share data with
We use a small number of vetted providers to run the service. We do not sell data or share it for advertising.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and file storage — where account and campaign data is hosted. | Account data, employee data, campaign & tracking data |
| OpenAI | Generates simulated phishing content and report drafts from the briefs and metrics you provide. | Campaign briefs, company profile, aggregated metrics |
| Amazon Web Services (SES) | Delivers the simulated emails your campaigns send. | Recipient email addresses, message content |
| Paddle | Processes subscription payments as merchant of record. | Billing name, email, payment details (held by Paddle, not by us) |
6. International transfers
We serve customers globally, so personal data may be processed in countries other than your own, including by the sub-processors above. Where data leaves the EU/UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. Data retention and your control
Customers control their data. You can update or delete account, employee, and campaign data at any time through the platform or by contacting us. When you delete data it is removed from active systems, and residual copies are purged from backups on our normal backup cycle. When an account is closed, we delete the associated personal data except where we must keep limited records to meet a legal obligation.
8. How we protect data
- Data is encrypted in transit and at rest.
- Each customer’s data is isolated with row-level security so tenants cannot see each other’s data.
- Simulated form submissions never store the values entered.
- Every authorization and sensitive action is written to an audit trail.
No system is perfectly secure, but we work to protect your data using industry-standard measures.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, restrict, or object to the processing of your personal data, and to withdraw consent. If you are in the EU/UK you may also lodge a complaint with your data-protection authority. If you are a California resident, you have rights under the CCPA/CPRA, including the right to know, delete, and correct, and the right not to be discriminated against for exercising them — and note that we do not sell or “share” personal information as those terms are defined.
If the data is about an employee tested by one of our customers, please contact that organization (the controller); we will refer your request to them.
To exercise any right, contact us at [contact email — add before launch].
10. Children
Sinon is a workplace tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
11. Changes to this policy
We may update this policy as the service evolves. When we make material changes we will revise the “Last updated” date above and, where appropriate, notify account holders.
12. Contact us
Questions about this policy or your data? Reach us at [contact email — add before launch]. See also our Authorized Use Policy and Data Processing Agreement.