This policy explains what personal data Sisterra collects, why, who processes it on our behalf, how long we keep it, and what rights you have. It covers the Sisterra app inside Telegram, the Sisterra bot, and this website (hello.sisterra.app).
We wrote it to be read, not scrolled past. If anything is unclear, write to us: privacy@sisterra.app.
1. Who is responsible for your data
The data controller is Individual Entrepreneur Galina Litvinova (ID 304783045), Tbilisi, Krtsanisi district, Nino and Ilia Nakashidze Street N 1 (ex Avlevi), Building N 3l, Apartment N 3, Georgia (in this policy — “we”).
Contact for anything related to your data: privacy@sisterra.app.
2. What we collect
Account data. Your Telegram user ID, Telegram username and display name — Telegram provides these when you sign in. If you link a Google or Apple sign-in, we also store that provider’s account identifier and the e-mail address it reports.
Profile you fill in. Name, date of birth, country and city, goals, interests, the “about” text, your profile photos, and your public @handle. You decide what goes into your profile; everything except the required basics is up to you. If anything you choose to write reveals sensitive information about you, we process it only because you chose to share it (see section 3).
Verification selfie. One selfie taken during verification — section 4 describes exactly what happens to it.
Activity. Likes (follows), matches, and the messages you exchange after a match — we store messages to deliver the conversation to both of you. Also your notification preferences and interface language.
Technical data. Server logs (which can include IP addresses and basic device information), a short-lived online status, and view/click events for the partner-catalog cards inside the app, linked to your account ID.
What we do not do. No advertising trackers or third-party ad SDKs. No selling or renting of personal data. No precise geolocation. No access to your contacts. This website sets no cookies: your theme and language choices stay in your own browser (localStorage), and site analytics (Cloudflare Web Analytics) is cookie-free and does not identify or profile visitors.
3. Why we process it (legal bases under the GDPR)
- Running the service — account, profile, feed, likes, matches, chat, notifications: necessary to perform our contract with you (Art. 6(1)(b) GDPR).
- Verification and safety — keeping Sisterra a verified, women-only space: performance of the contract as described in the Terms, and our legitimate interest in protecting the community (Art. 6(1)(f)).
- Optional profile details — interests, goals, “about”, extra photos: your consent (Art. 6(1)(a)), given by filling them in. If something you share falls under special categories of data, we rely on your explicit consent (Art. 9(2)(a)) — sharing it is always your choice, never a requirement.
- Technical logs and telemetry — operating, debugging and securing the service: our legitimate interest (Art. 6(1)(f)).
You can withdraw any consent at any time — by editing or removing the data in the app, or by writing to us.
4. Identity verification, honestly
Every profile passes verification before anyone else can see it. Here is the whole process, without embellishment:
- You take a selfie in the app.
- A human moderator compares the selfie with your profile photos and approves or declines the profile. If declined, you see the reason and can submit a new selfie.
- There is no automated facial recognition. No biometric algorithms, no face-matching software, no third-party identity-verification vendors. Under the GDPR, a photograph analysed by a person — not by specific technical means — is not biometric data in the Art. 9 sense. We still treat the selfie with elevated care: it is stored in access-restricted storage, used only for verification, and never shown to other users.
- Every verification decision is made by a person. There is no automated decision-making with legal or similarly significant effect (Art. 22 GDPR).
- Moderators review selfies in a private moderation channel on Telegram, so the selfie transits Telegram’s infrastructure on its way to the moderator.
If we ever introduce automated face-matching, we will update this policy and ask for your explicit consent before it applies to you.
5. Who processes data on our behalf
We do not sell or share your data for advertising. The following providers process data for us, under their data-processing agreements incorporating the EU Standard Contractual Clauses where data leaves the EEA:
| Provider | What for |
|---|---|
| Railway Corp. (USA) | Cloud hosting of our servers and databases |
| Cloudflare, Inc. (USA) | Photo and media storage, network routing, cookie-free analytics for this website |
| Telegram | The platform Sisterra runs on: sign-in, bot messages and notifications, delivery of verification selfies to the moderation channel |
| Elastic N.V. (Elastic Cloud, EU — Frankfurt) | Technical logs and performance telemetry |
| Growth Book, Inc. (USA) | Feature flags — receives technical identifiers, not your profile |
If you link Google or Apple sign-in, Google LLC or Apple Inc. act as independent providers of that sign-in, under their own privacy policies.
6. How long we keep data, and deletion
We keep your data while your account exists. There is no cool-down, no grace period and no “soft delete”:
- You can delete your account in the app at any moment (Settings → Delete account), or by writing to privacy@sisterra.app.
- Deletion starts immediately. Your profile, photos (including the verification selfie), likes, matches, your conversations (removed for both participants), verification records and notification data are erased from all our systems by an automated process that begins the moment you confirm. Photo files are removed from media storage by the same process; a scheduled cleanup sweeps any stragglers within hours.
- What can briefly outlive deletion: rotating server logs and encrypted database backups, which expire automatically within 30 days and are never used to restore a deleted account.
7. Your rights
Under the GDPR you can, at any time:
- access the data we hold about you and receive a copy (data portability);
- correct inaccurate data — most of your profile you can edit directly in the app;
- delete your account and data (see section 6);
- restrict or object to processing based on legitimate interest;
- withdraw consent for anything based on consent;
- complain to your data-protection supervisory authority.
Write to privacy@sisterra.app — we respond within 30 days. To protect your data we may ask you to confirm the request from the Telegram account the Sisterra account belongs to.
8. Age
Sisterra is for adults. You must be at least 18 years old; the app enforces this when a profile is created. We do not knowingly process data of anyone under 18 — if you believe we do, tell us and the account will be removed.
9. Changes to this policy
When this policy changes, we announce it in the app or via the bot before the change takes effect and update the version, effective date and “last updated” at the top. If a change requires new consent, we ask for it — continued silence is not consent.
10. Contact
Individual Entrepreneur Galina Litvinova (ID 304783045), Tbilisi, Krtsanisi district, Nino and Ilia Nakashidze Street N 1 (ex Avlevi), Building N 3l, Apartment N 3, Georgia privacy@sisterra.app — data requests and this policy sisterra@sisterra.app — everything else