Sisterra
LanguageEN
ThemeLightDarkAuto

Theme

Legal

Privacy Policy

Version 1.0 · Effective: 5 August 2026 · Last updated: 5 August 2026

This policy explains what personal data Sisterra collects, why, who processes it on our behalf, how long we keep it, and what rights you have. It covers the Sisterra app inside Telegram, the Sisterra bot, and this website (hello.sisterra.app).

We wrote it to be read, not scrolled past. If anything is unclear, write to us: privacy@sisterra.app.

1. Who is responsible for your data

The data controller is Individual Entrepreneur Galina Litvinova (ID 304783045), Tbilisi, Krtsanisi district, Nino and Ilia Nakashidze Street N 1 (ex Avlevi), Building N 3l, Apartment N 3, Georgia (in this policy — “we”).

Contact for anything related to your data: privacy@sisterra.app.

2. What we collect

Account data. Your Telegram user ID, Telegram username and display name — Telegram provides these when you sign in. If you link a Google or Apple sign-in, we also store that provider’s account identifier and the e-mail address it reports.

Profile you fill in. Name, date of birth, country and city, goals, interests, the “about” text, your profile photos, and your public @handle. You decide what goes into your profile; everything except the required basics is up to you. If anything you choose to write reveals sensitive information about you, we process it only because you chose to share it (see section 3).

Verification selfie. One selfie taken during verification — section 4 describes exactly what happens to it.

Activity. Likes (follows), matches, and the messages you exchange after a match — we store messages to deliver the conversation to both of you. Also your notification preferences and interface language.

Technical data. Server logs (which can include IP addresses and basic device information), a short-lived online status, and view/click events for the partner-catalog cards inside the app, linked to your account ID.

What we do not do. No advertising trackers or third-party ad SDKs. No selling or renting of personal data. No precise geolocation. No access to your contacts. This website sets no cookies: your theme and language choices stay in your own browser (localStorage), and site analytics (Cloudflare Web Analytics) is cookie-free and does not identify or profile visitors.

  • Running the service — account, profile, feed, likes, matches, chat, notifications: necessary to perform our contract with you (Art. 6(1)(b) GDPR).
  • Verification and safety — keeping Sisterra a verified, women-only space: performance of the contract as described in the Terms, and our legitimate interest in protecting the community (Art. 6(1)(f)).
  • Optional profile details — interests, goals, “about”, extra photos: your consent (Art. 6(1)(a)), given by filling them in. If something you share falls under special categories of data, we rely on your explicit consent (Art. 9(2)(a)) — sharing it is always your choice, never a requirement.
  • Technical logs and telemetry — operating, debugging and securing the service: our legitimate interest (Art. 6(1)(f)).

You can withdraw any consent at any time — by editing or removing the data in the app, or by writing to us.

4. Identity verification, honestly

Every profile passes verification before anyone else can see it. Here is the whole process, without embellishment:

  • You take a selfie in the app.
  • A human moderator compares the selfie with your profile photos and approves or declines the profile. If declined, you see the reason and can submit a new selfie.
  • There is no automated facial recognition. No biometric algorithms, no face-matching software, no third-party identity-verification vendors. Under the GDPR, a photograph analysed by a person — not by specific technical means — is not biometric data in the Art. 9 sense. We still treat the selfie with elevated care: it is stored in access-restricted storage, used only for verification, and never shown to other users.
  • Every verification decision is made by a person. There is no automated decision-making with legal or similarly significant effect (Art. 22 GDPR).
  • Moderators review selfies in a private moderation channel on Telegram, so the selfie transits Telegram’s infrastructure on its way to the moderator.

If we ever introduce automated face-matching, we will update this policy and ask for your explicit consent before it applies to you.

5. Who processes data on our behalf

We do not sell or share your data for advertising. The following providers process data for us, under their data-processing agreements incorporating the EU Standard Contractual Clauses where data leaves the EEA:

Provider What for
Railway Corp. (USA) Cloud hosting of our servers and databases
Cloudflare, Inc. (USA) Photo and media storage, network routing, cookie-free analytics for this website
Telegram The platform Sisterra runs on: sign-in, bot messages and notifications, delivery of verification selfies to the moderation channel
Elastic N.V. (Elastic Cloud, EU — Frankfurt) Technical logs and performance telemetry
Growth Book, Inc. (USA) Feature flags — receives technical identifiers, not your profile

If you link Google or Apple sign-in, Google LLC or Apple Inc. act as independent providers of that sign-in, under their own privacy policies.

6. How long we keep data, and deletion

We keep your data while your account exists. There is no cool-down, no grace period and no “soft delete”:

  • You can delete your account in the app at any moment (Settings → Delete account), or by writing to privacy@sisterra.app.
  • Deletion starts immediately. Your profile, photos (including the verification selfie), likes, matches, your conversations (removed for both participants), verification records and notification data are erased from all our systems by an automated process that begins the moment you confirm. Photo files are removed from media storage by the same process; a scheduled cleanup sweeps any stragglers within hours.
  • What can briefly outlive deletion: rotating server logs and encrypted database backups, which expire automatically within 30 days and are never used to restore a deleted account.

7. Your rights

Under the GDPR you can, at any time:

  • access the data we hold about you and receive a copy (data portability);
  • correct inaccurate data — most of your profile you can edit directly in the app;
  • delete your account and data (see section 6);
  • restrict or object to processing based on legitimate interest;
  • withdraw consent for anything based on consent;
  • complain to your data-protection supervisory authority.

Write to privacy@sisterra.app — we respond within 30 days. To protect your data we may ask you to confirm the request from the Telegram account the Sisterra account belongs to.

8. Age

Sisterra is for adults. You must be at least 18 years old; the app enforces this when a profile is created. We do not knowingly process data of anyone under 18 — if you believe we do, tell us and the account will be removed.

9. Changes to this policy

When this policy changes, we announce it in the app or via the bot before the change takes effect and update the version, effective date and “last updated” at the top. If a change requires new consent, we ask for it — continued silence is not consent.

10. Contact

Individual Entrepreneur Galina Litvinova (ID 304783045), Tbilisi, Krtsanisi district, Nino and Ilia Nakashidze Street N 1 (ex Avlevi), Building N 3l, Apartment N 3, Georgia privacy@sisterra.app — data requests and this policy sisterra@sisterra.app — everything else