Privacy Policy
Last updated: August 7, 2026
The short version
SilentSuite is an end-to-end encrypted sync service for calendars, contacts, and tasks. Your data is encrypted on your device before it reaches our servers. We cannot read, analyze, or share your encrypted data. This is by design, not just by policy.
1. Controller
The controller responsible for data processing on this website is:
SilentSuite
E-Mail: info@silentsuite.io
2. What data we collect
2.1 Website, documentation, and hosted signup measurement
We use self-hosted Plausible Analytics, a cookieless tool without persistent visitor identifiers, on silentsuite.io and docs.silentsuite.io, and only on the hosted app commercial funnel: signup, plan selection, checkout start, and provider return. The sole authenticated exception is one Subscription Management Entry event on the exact /settings/subscriptionroute. Authenticated PIM routes and interactions remain untracked.
Analytics uses fixed canonical paths without query strings or fragments, fixed event names, low-cardinality categories, and fixed canonical service origins for recognized referral sources only. Unknown referrer origins are not sent. Browser events describe anonymous intent or return, never confirmed payment. We never send form values, account identifiers, referrer paths, queries, fragments, or PIM data. Delivery infrastructure may transiently observe network metadata, such as IP address and user agent, while handling a request. Access to Plausible and CDN logs is restricted, and retention and anonymization settings are reviewed as part of the production analytics deployment checklist. Self-hosted apps and instances do not enable hosted analytics. Fonts are self-hosted; no requests are made to Google or other third-party font services.
2.2 Newsletter subscription
When you subscribe to our newsletter, we collect:
- Email address (required)
- Name (optional)
- Consent confirmation
We use a double opt-in process to comply with GDPR. After you submit the subscription form, we send a confirmation email containing a signed link. Your subscription only becomes active once you click that link. Confirmation links expire after 48 hours. If the link expires, you can subscribe again to receive a new one.
We use Resend to send transactional and newsletter emails. Your email address is used solely to send you product updates and announcements about SilentSuite. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw consent at any time by using the unsubscribe link in any email, replying with "unsubscribe", or emailing us at info@silentsuite.io.
2.3 silentsuite.io service (app.silentsuite.io)
SilentSuite is available as a web app, an Android mobile app, and a CalDAV bridge for use with existing calendar and contacts clients. When you use the service, we process:
- Account data: Username, hashed authentication public key, account creation timestamp. This is necessary for account operation.
- Encrypted data: Your calendar events, contacts, and tasks are stored as encrypted blobs. We have no technical ability to decrypt this data. The encryption keys never leave your device.
- Metadata: Sync timestamps, collection membership, and sync tokens. This metadata is necessary for the sync protocol to function.
- Server logs: IP address and request timestamps may be logged temporarily for security and abuse prevention. Logs are rotated automatically.
Legal basis: Art. 6(1)(b) GDPR (contract performance) for account and encrypted data. Art. 6(1)(f) GDPR (legitimate interest) for security logs.
Billing derives identity-free aggregates from necessary billing records and is the authority for paid-conversion counts. We never join Plausible and Billing at the user level. These fixed-category aggregates do not use PIM plaintext or calendar, contact, or task content as an analytics input.
2.4 Payment processing
Card payments are processed by Stripe. Crypto payments are processed by BTCPay. Your card details are handled entirely by Stripe and are never stored on or transmitted to our servers. We receive only the transaction reference, plan type, and billing status needed to provision access. Legal basis: Art. 6(1)(b) GDPR (contract performance).
2.5 Private operator notifications
We may send minimized operational summaries to a private Telegram destination for service monitoring. These messages use fixed, coarse categories and do not contain PIM plaintext, calendar, contact, or task content. Telegram processes the message and delivery metadata under its own privacy terms.
2.6 Android app permissions and local data
The SilentSuite Android app uses Android's account, calendar, contacts, and task sync interfaces so it can sync your selected SilentSuite collections with compatible apps on your device. The app may request access to contacts, calendars, notifications, network state, and related sync settings when those features are needed.
Contacts, calendar events, and tasks are processed on your device to provide sync. When synced through the hosted silentsuite.io service, their contents are encrypted before upload and stored on our server as encrypted data. SilentSuite does not use the Android app to collect advertising identifiers, show ads, or sell personal data.
Our clients are tracker-free: they do not include advertising trackers or use PIM plaintext or content for analytics.
3. Where data is stored
The silentsuite.io sync service is hosted on secure, GDPR-compliant infrastructure. Your encrypted data never leaves the EU. The landing page and documentation site are served via Cloudflare's global CDN. You may also choose to self-host the SilentSuite server for complete data sovereignty.
4. Data sharing
We do not sell, trade, or share your personal data with third parties. We use the following processors:
- Cloud hosting provider (EU): server hosting
- Cloudflare, Inc. (US, with EU data processing): website and documentation hosting and CDN
- Resend: transactional and newsletter email delivery
- Stripe: payment processing
- BTCPay: crypto payment processing
- Plausible Analytics (self-hosted): privacy-friendly, cookieless website, documentation, and hosted commercial-funnel analytics
- Telegram: delivery of minimized private operator notifications when this monitoring channel is enabled
- Google Play: Android app distribution, installation, update, and Play Console reporting when you install the app through Google Play
5. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Request deletion of your data
- Restrict or object to processing
- Data portability (export in ICS, VCF, or ZIP formats)
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
To exercise any of these rights, email us at info@silentsuite.io.
6. Data retention
Newsletter subscriber data is retained until you unsubscribe or request removal. Account data and encrypted sync data are retained for the duration of your account. Server logs are retained for a maximum of 30 days. When you delete your account, all associated data is permanently removed.
7. Cookies
The silentsuite.io website, docs.silentsuite.io documentation site, and hosted commercial-funnel measurement do not use cookies. Plausible Analytics is cookieless. The silentsuite.io service uses authentication tokens stored in your application. These are not browser cookies.
8. Self-hosting
SilentSuite offers a self-hosted option. When you run your own server, your data never touches our infrastructure. This privacy policy applies only to services operated by SilentSuite (the hosted service, this website, and the documentation site). Self-hosted instances are under your own control and responsibility.
9. Changes to this policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. For significant changes, we will notify subscribers and registered users via email.
Start privately
Try SilentSuite for seven days without a card.
Start free