← Silloa

Draft — not yet reviewed by counsel.

These pages describe accurately what Silloa collects and does today, so they are a useful starting point. They are not legal advice and have not been reviewed by a lawyer. Do not rely on them, and do not launch publicly on them without review — tobacco, age-gating and consumption-data rules all bite here.

Privacy

Last updated 27 August 2026.

Silloa is a cigar journal and a room full of people. That means we hold two different kinds of thing: the account you signed up with, and the record of hours you chose to keep. This page lists both, field by field, because a privacy policy that describes categories instead of columns is a policy nobody can check.

What we store

Your account

Your profile and preferences

What you log

Technical

Product analytics

We measure how the product is used, on our own servers, with no third-party analytics anywhere. Each event stores its name, a few coarse properties about the step it belongs to, your user id once you are signed in, and a random anon_id your browser generates — kept so that the install funnel can be joined to the account it eventually becomes. What an event may never carry is what you consumed: the cigar, the bottle and the hour are excluded by the type of the code that writes these rows, so attaching one fails to compile.

Error reports

When something breaks we store the message, the stack trace, the page path with its query string stripped, and your user id if you were signed in. It is used to fix defects and nothing else.

Abuse protection

To stop flooding and brute force we keep short-lived counters whose keys contain your IP address or your email address, lower-cased. They hold a count and a window, never a request or its contents, and the scheduled cleanup deletes windows older than 24 hours.

Polls and bookmarks

Which option you chose on a poll, and anything you bookmark — the post, product or encyclopedia entry, and when you saved it. Your saved list is yours; nobody else can see it.

Who can see it

Your shelf is yours. Your sittings are private by default and are seen by others only at the visibility you set on each one: private, your room, or public. Your profile, your public sittings, and anything you post on a board are visible to anyone — including people who are not signed in, once public pages open.

Blocks, mutes and reports are stored, and moderation reads them: a block records who blocked whom, and a report records what you flagged and what you said about it.

We do not sell your data, and we do not hand it to advertisers. When advertising exists on Silloa, an advertiser will buy access to a segment and receive counts — never a user, a list, or a record. That is a locked product decision, not a preference, and it is the reason the advertising model works the way it does.

Direct messages

Direct messages are one-to-one, and they are stored. A conversation lives in our database from the moment the first message is sent. Anyone may send you a single message; it waits in Requests, and they cannot send another until you accept.

Messages are kept for 90 days after a conversation goes quiet, and are then deleted. Reporting a message stops that clock, so a moderator can still read what was said when they come to answer it. Deleting a message for yourself is immediate; deleting it for everyone leaves a marker saying it was deleted, in the place it was. Deleting your account removes your side — the other person keeps their copy of what you sent them, the same way a letter works.

Nobody at Silloa reads your messages. If you report one, a moderator reads that conversation. There is no third option. A moderator who cannot see what was said is deciding blind, and that is not moderation. We would rather you knew this from us than found it out.

Who can message you

Messages are one to one. There are no group conversations on Silloa, so nobody can put you in a thread with someone you blocked. A first message from a person you do not follow arrives as a request rather than in your chats, and they cannot send a second one until you accept it. A business may open a conversation only where you already have something with it — an order, a booking, a claimed ticket — and only about that. Anything else from a business is something you turned on for that business, and can turn off.

How long they are kept

Delete a message for yourself and it leaves your view for good. Delete it for everyone and it is replaced by a placeholder for both of you, the way a deleted message works in a channel — the text goes, the stored copy outlives it. That stored copy is kept for 90 days past the last message in the conversation and is then genuinely deleted, unless a message in it has been reported, in which case the conversation is kept while the report stands. The report is what makes keeping it necessary, so the report is what triggers it.

One thing people are surprised by, so it is here rather than in a support email: deleting your account removes your side of a conversation. The other person keeps their copy of what you sent them, because it is their conversation too, and nobody can unsend a letter.

Who processes it for us

How long we keep things

Analytics — which screens got used, not what you looked at — are deleted after 400 days. Crash reports are deleted after 90 days. Notifications are deleted after 180 days. Direct messages are deleted 90 days after a conversation goes quiet, unless one of them is reported.

The staff audit log is kept indefinitely, on purpose. It records who suspended an account, who took something down and who read a reported conversation. A record that answers for our decisions is not one we should be able to quietly age out, and how long it should live is a question we would rather answer properly than pick a number for.

What you can do

Children

Silloa is for adults 21 and over. We do not knowingly keep data from anyone younger, and an account found to belong to someone under 21 is removed.

Questions: legal@silloa.com (mailbox not yet provisioned — see the draft banner).