Template. This document is a starting point and has not been reviewed by counsel. Have a qualified lawyer review it before launch.

Privacy Policy

Last updated July 3, 2026

silobase is the Salesforce Sandbox Email Safety Ledger. It is an upload-only static analyzer: you upload a Salesforce metadata export and it maps every path that could send email. This policy explains what data we collect, how the detector and the explainer use it, and what we never touch. The data controller for this service is {{TODO: confirm legal operating entity — likely Peakure LLC}}.

What silobase reads — and what it never touches

silobase reads metadata only. Stating the boundaries plainly, up front, because they define the whole privacy posture:

  • It never reads email content, CRM records, or contact data. It parses the structure of a metadata export, not the data inside your org.
  • It never writes back to your org.
  • It never sends email. It maps the paths that would send — Flows, workflow rules, email alerts, Apex senders, approval emails, org-wide sender and deliverability settings — and never triggers one.
  • Recipient resolution is heuristic. v1 is upload-only, with no live-org OAuth connection, so silobase infers who a path would address rather than querying your live org.
  • It is not a Salesforce product, is not endorsed by Salesforce, is not Mailtrap, and is not a live-org connection.

Data we collect

DataWhy we have it
Uploaded Salesforce metadata exports (zip / SFDX source)The file you upload to scan. Stored in Supabase file storage, bucket metadata-uploads. This is metadata describing components — not email content or contact records.
Account details (name, email)Authentication and account management, handled through Supabase.
Billing detailsPayment and subscription processing, handled by Stripe. We do not store full card numbers on our systems.
Org / sandbox identifiersThe org and sandbox labels you enter so a scan and its ledger can be organized.
Cookieless analyticsVercel Analytics measures page usage. It is cookieless — it does not set tracking cookies or build a cross-site profile of you.

How we use it

  • Run the deterministic detector against your uploaded metadata to produce the blast-radius manifest, the safe-test plan, the deliverability checklist, and the exportable evidence ledger.
  • Authenticate you and keep your scans and ledger tied to your account.
  • Process one-time and subscription payments through Stripe.
  • Send transactional email — receipts, account and scan notifications — through Resend.

We do not sell your data, and we do not use your uploaded metadata to train models. We use it to run the scan you asked for.

How the detector and the Claude explainer share data

Two components handle a scan, and they see different things:

  • The deterministic detector owns risk classification. It parses your metadata and decides which paths are risky. Its output is a set of findings.
  • The Anthropic Claude API is the explainer. It is given the detector's findings — not your raw metadata export, not your org data — and it writes the plain-language explanations of each detected risk and drafts the safe-test plan from those findings.

In short: classification is deterministic and local to our detector; Claude only explains what the detector already found, working from findings rather than your raw upload.

Subprocessors

We rely on a small set of third-party services to run silobase — Supabase (database, auth, and file storage), Stripe (payments), Vercel (hosting and cookieless analytics), Resend (transactional email), and the Anthropic Claude API (risk explanations). Each one, and what it processes, is listed on the subprocessors page.

Data retention and deletion

Uploaded metadata can be deleted. You can remove an uploaded export, and you can request deletion of your account data by emailing privacy@silobase.io. When you delete an upload, we remove it from the metadata-uploads bucket. We keep account and billing records for as long as your account is active or as needed to meet legal and accounting obligations. {{TODO: define default retention period for uploaded metadata and account records}}

Security

Only the measures that are actually in place:

  • The application is hosted on Vercel.
  • Data is stored in Supabase, with encryption at rest as provided by Supabase.
  • Authentication runs through Supabase, with optional two-factor / authenticator (2FA) available on your account.
  • Row-level security is applied on our data tables.
  • Analytics is cookieless.

We do not currently hold formal compliance certifications and do not claim any. See the security page for the current posture, and report any vulnerability to security@silobase.io.

Your rights (GDPR / CCPA)

Depending on where you live, you may have the right to access, correct, delete, export, or object to the processing of your personal data, and to withdraw consent. These are process rights we honor — not a certification. To exercise any of them, email privacy@silobase.io and we will respond. More detail on how requests are handled is on the GDPR / CCPA page.

International data transfers

Our subprocessors may process data in regions outside your own. Where personal data is transferred across borders, we rely on an appropriate legal transfer mechanism. {{TODO: SCC mechanism — confirm the standard contractual clauses / transfer basis relied upon}}

Children

silobase is an operational tool for Salesforce administrators and consultants. It is not intended for anyone under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us data, contact privacy@silobase.io and we will delete it.

Changes to this policy

We may update this policy as the product changes. When we make a material change, we will update the last-updated date at the top of this page. Continued use after a change means you accept the updated policy.

Contact

Questions about this policy? See Contact or read the Privacy Policy.
    Privacy Policy — silobase