Privacy
Last updated 27 August 2026.
Silloa is a cigar journal and a room full of people. That means we hold two different kinds of thing: the account you signed up with, and the record of hours you chose to keep. This page lists both, field by field, because a privacy policy that describes categories instead of columns is a policy nobody can check.
What we store
Your account
- First name, last name, and middle name if you gave one
- Username, email address, phone number
- Your password, hashed with bcrypt — we cannot read it, and neither can anyone who steals the database
- Date of birth, kept because the 21+ rule is enforced on our servers and we have to be able to show that it was
Your profile and preferences
- Bio, location, interface language
- Default visibility for new sittings
- Notification preferences and your chosen theme
What you log
- Sittings — the cigar, the occasion, what you drank with it, your verdict, your notes, when it started, and the visibility you chose for it
- The shelf — what you own, how many, what you paid, where you bought it, and rest-clock dates
- The room — who you follow, your votes, comments, board threads and replies
Technical
- A session cookie when you are signed in
- A cookie recording that you passed the 21+ gate. It stores only that you passed — if you are not signed in, we do not keep the date you typed
- Web push subscriptions (a browser endpoint and its keys) if you turn on rest alerts
- Accounts you deliberately link, such as YouTube — the provider and your id there, never your password
Product analytics
We measure how the product is used, on our own servers, with no third-party analytics anywhere. Each event stores its name, a few coarse properties about the step it belongs to, your user id once you are signed in, and a random anon_id your browser generates — kept so that the install funnel can be joined to the account it eventually becomes. What an event may never carry is what you consumed: the cigar, the bottle and the hour are excluded by the type of the code that writes these rows, so attaching one fails to compile.
Error reports
When something breaks we store the message, the stack trace, the page path with its query string stripped, and your user id if you were signed in. It is used to fix defects and nothing else.
Abuse protection
To stop flooding and brute force we keep short-lived counters whose keys contain your IP address or your email address, lower-cased. They hold a count and a window, never a request or its contents, and the scheduled cleanup deletes windows older than 24 hours.
Polls and bookmarks
Which option you chose on a poll, and anything you bookmark — the post, product or encyclopedia entry, and when you saved it. Your saved list is yours; nobody else can see it.
Who can see it
Your shelf is yours. Your sittings are private by default and are seen by others only at the visibility you set on each one: private, your room, or public. Your profile, your public sittings, and anything you post on a board are visible to anyone — including people who are not signed in, once public pages open.
Blocks, mutes and reports are stored, and moderation reads them: a block records who blocked whom, and a report records what you flagged and what you said about it.
We do not sell your data, and we do not hand it to advertisers. When advertising exists on Silloa, an advertiser will buy access to a segment and receive counts — never a user, a list, or a record. That is a locked product decision, not a preference, and it is the reason the advertising model works the way it does.
Direct messages
Direct messages are one-to-one, and they are stored. A conversation lives in our database from the moment the first message is sent. Anyone may send you a single message; it waits in Requests, and they cannot send another until you accept.
Messages are kept for 90 days after a conversation goes quiet, and are then deleted. Reporting a message stops that clock, so a moderator can still read what was said when they come to answer it. Deleting a message for yourself is immediate; deleting it for everyone leaves a marker saying it was deleted, in the place it was. Deleting your account removes your side — the other person keeps their copy of what you sent them, the same way a letter works.
Nobody at Silloa reads your messages. If you report one, a moderator reads that conversation. There is no third option. A moderator who cannot see what was said is deciding blind, and that is not moderation. We would rather you knew this from us than found it out.
- The read is scoped to the message you reported and the messages immediately around it — enough to judge it in context, not the whole history
- The read is recorded in our staff audit trail, as a read, against the person who did it
- There is no staff screen that opens a conversation without a report attached. No listing, no search, no looking up a member's messages
Who can message you
Messages are one to one. There are no group conversations on Silloa, so nobody can put you in a thread with someone you blocked. A first message from a person you do not follow arrives as a request rather than in your chats, and they cannot send a second one until you accept it. A business may open a conversation only where you already have something with it — an order, a booking, a claimed ticket — and only about that. Anything else from a business is something you turned on for that business, and can turn off.
How long they are kept
Delete a message for yourself and it leaves your view for good. Delete it for everyone and it is replaced by a placeholder for both of you, the way a deleted message works in a channel — the text goes, the stored copy outlives it. That stored copy is kept for 90 days past the last message in the conversation and is then genuinely deleted, unless a message in it has been reported, in which case the conversation is kept while the report stands. The report is what makes keeping it necessary, so the report is what triggers it.
One thing people are surprised by, so it is here rather than in a support email: deleting your account removes your side of a conversation. The other person keeps their copy of what you sent them, because it is their conversation too, and nobody can unsend a letter.
Who processes it for us
- Amazon Web Services — hosting, database, storage, scheduled jobs (US)
- Amazon CloudFront, which tells our servers the coarse country and region your request arrived from. We use it only to decide which shops can legally reach you, and we do not store it
- YouTube, when a video is embedded. Embeds use youtube-nocookie.com, but watching a video is still an interaction with Google
- Your browser's push service (Apple, Google, Mozilla) if you enable notifications
How long we keep things
Analytics — which screens got used, not what you looked at — are deleted after 400 days. Crash reports are deleted after 90 days. Notifications are deleted after 180 days. Direct messages are deleted 90 days after a conversation goes quiet, unless one of them is reported.
The staff audit log is kept indefinitely, on purpose. It records who suspended an account, who took something down and who read a reported conversation. A record that answers for our decisions is not one we should be able to quietly age out, and how long it should live is a question we would rather answer properly than pick a number for.
What you can do
- Edit your profile and preferences at any time in Settings
- Change any sitting's visibility, or delete the sitting
- Export everything — Settings → Your data, as JSON or CSV. The file names what it leaves out
- Delete your account — not built yet. There is no self-service route and, until a monitored contact address exists, no reliable one to ask through either. We would rather say that than name a mailbox nobody is reading
Children
Silloa is for adults 21 and over. We do not knowingly keep data from anyone younger, and an account found to belong to someone under 21 is removed.