Privacy Policy
Last updated: February 20, 2026
The snapshot: Your private content is yours. We encrypt it at rest, we never sell it, and we do not use it to train AI models that serve other people. Google Calendar events (if you connect one) are read-only and used only inside your own silo.
Who we are
My Silo is a service of East Tactics LLC, a limited liability company organized under the laws of the State of Utah, USA. In this policy "we", "us", and "My Silo" all refer to East Tactics LLC. We're the data controller for the personal information described below. Contact us any time at mysilo@send.easttactics.com.
What we collect
• Account info — your name, email, and password (stored as a bcrypt hash, never in plain text). Optional profile fields (display name, avatar).
• Content you upload — documents, notes, media, and other materials that train your silo.
• Conversations — questions asked of your silo, the answers generated, and metadata (timestamps, model used, tokens spent).
• Kid profile data — display names, ages, avatars, PIN hashes, chore lists, and daily question limits that a parent-role account sets up for a minor child in their household silo.
• Google Calendar data — if you choose to connect Google Calendar, we receive event titles, times, locations, and calendar list membership. Read-only. Details in the Google User Data section below.
• Usage & telemetry — pages viewed, features used, API calls, error reports, and basic device/browser info needed to run the service, prevent abuse, and bill correctly.
• Payment data — Stripe processes all card transactions. We store only the last-4 digits, brand, and billing address needed to render receipts. We never see or store your full card number or CVV.
How we use it
We use your data to (1) provide the My Silo service (create your silo, generate answers, sync your calendar, run chore workflows), (2) process payments and calculate the platform fee, (3) enforce our Terms and prevent abuse, (4) send you transactional email you need to run your account (password resets, invites, payment receipts, security alerts), (5) fix bugs and improve reliability, and (6) comply with legal obligations. Our legal bases (GDPR Art 6) are: performance of a contract for anything you actively use, legitimate interest for fraud prevention and analytics, and consent for anything optional you explicitly enable (Google Calendar sync, marketing email, etc.).
Google user data (Calendar integration)
When you connect a Google Calendar, My Silo requests the following Google OAuth scope: https://www.googleapis.com/auth/calendar.readonly. This scope is read-only — we cannot create, edit, or delete anything on your Google Calendar. We use the data exclusively to:
• Display your upcoming events inside your own silo's AI Calendar view.
• Let your silo's AI assistant answer questions like "what's on my agenda today?" and "when am I free this weekend?".
• Detect scheduling conflicts against chores or family events you've added inside My Silo.
We store Google-issued OAuth refresh tokens encrypted at rest so the sync keeps working without re-authorizing. You can disconnect the calendar at any time from within My Silo (which deletes our copy of the tokens) or from your Google Account at myaccount.google.com/permissions (which revokes our access even if you never open My Silo again).
Limited Use compliance
My Silo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not use Google user data for serving advertisements, we do not transfer Google user data to third parties except as necessary to provide or improve My Silo (and never for advertising), no humans read your Google user data except (a) with your explicit consent, (b) for security investigations, (c) to comply with law, or (d) when the data has been de-identified and aggregated.
Children under 13 (COPPA & GDPR-K)
My Silo is not intended for children under 13 as independent account holders. The service is designed for adults. Our Kid Profile feature exists so a verified parent or guardian (over 18) can set up display names, chore lists, and daily question limits for their own children inside their own family silo — the parent is the account holder, and the child interacts with the silo only through the parent-owned account under the parent's supervision.
We do not knowingly collect personal information directly from children under 13. Kid Profile data is provided by the parent, not the child. If you believe we have inadvertently collected personal data from a child under 13, contact mysilo@send.easttactics.com and we will delete it within 30 days. In the EU, the equivalent age threshold is 16 unless your Member State has set it lower — same practice applies.
How we protect it
Sensitive data (AI-provider API keys, Google OAuth tokens, kid PIN hashes, payment tokens) is encrypted at rest with per-record keys. Passwords are stored as bcrypt hashes with per-user salts. All traffic between your browser and My Silo is HTTPS-only. Access to production data is restricted to a small number of authorized personnel on a need-to-know basis, with all access logged. We follow a "least access" architecture so that, going forward, no one — including My Silo staff — can read your private content without an explicit, logged event.
Who processes your data on our behalf (subprocessors)
We rely on the following categories of subprocessors to run the service. Each one processes data under its own privacy terms, and we've listed the direct link so you can read them.
• Cloud hosting & database — MongoDB Atlas + our cloud infrastructure provider (US-based). Stores your account and content data.
• Payments — Stripe. Card details, billing.
• AI providers you connect — OpenAI, Anthropic, Google (Gemini). Prompts and (when you provide your own key) responses. Each provider processes your data under its own terms.
• Google Calendar API — if you connect it. Same Google privacy policy applies.
• Email delivery — a transactional email provider (used for password resets, invite emails, receipts).
International data transfers
We're based in the State of Utah, USA. If you're accessing My Silo from outside the United States, your data will be transferred to and processed in the US. Where required (EU/EEA/UK), we rely on the Standard Contractual Clauses adopted by the European Commission (Art 46 GDPR) or the equivalent UK IDTA. You can request a copy of these clauses at mysilo@send.easttactics.com.
How long we keep it
• Account data — while your account is active, plus up to 90 days after account deletion for backup and audit-log purposes.
• Content in your silo — while your account is active. Deleted within 30 days of account termination.
• Google Calendar OAuth tokens — while the connection is active. Deleted within 30 days of you disconnecting.
• Google Calendar event content — cached briefly (up to 24 hours) for performance; not stored long-term. Re-fetched on demand.
• Payment records — 7 years, as required by US tax and financial-records law.
• Anonymized analytics — indefinitely, in de-identified form only.
Your rights
Depending on where you live, you have some or all of the following rights, which you can exercise at any time by emailing mysilo@send.easttactics.com (we'll confirm your identity first, then respond within 30 days):
• Access — get a copy of the data we hold on you.
• Correction — fix anything that's wrong.
• Deletion — close your account and remove your data (subject to legal retention on payment records).
• Portability — receive your data in a machine-readable format.
• Restriction / objection — pause or object to certain processing.
• Withdraw consent — for anything you consented to (e.g. disconnect Google Calendar).
• Complain — if you're in the EU/UK, you can complain to your local supervisory authority. If you're in California, you can complain to the California Privacy Protection Agency.
California residents (CCPA/CPRA)
In the past 12 months we have collected the categories of personal information described above (identifiers, commercial info, internet activity, professional info if you use the Creator features, and — if you connect it — Google Calendar content). Sources: directly from you when you sign up, use the service, or connect an integration. Purposes: as described in "How we use it" above.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. There is no "Do Not Sell" opt-out because there is nothing to opt out of — we simply do not do it. You have the right to know, delete, correct, and limit use of sensitive personal information (which we do not use for inferential purposes about you). To exercise any right, email mysilo@send.easttactics.com.
Breach notification
If we discover a security breach affecting your personal information, we will notify you and the appropriate regulatory authorities within 72 hours of confirming the breach where required by GDPR Art 33, state breach-notification laws, or as required by any other applicable law. The notice will describe what happened, what data was affected, what we're doing about it, and what you can do to protect yourself.
Cookies and local storage
We use essential first-party cookies and browser local storage to (1) keep you signed in across visits, (2) remember UI preferences like dark mode and the theme you picked, and (3) attribute referral traffic to the correct creator so revenue-share works. We do not use third-party advertising cookies. We do not track you across sites.
Changes to this policy
We may update this policy from time to time. Non-material changes take effect when posted (the "Last updated" date changes above). Material changes — anything that meaningfully expands what we collect, how we use it, or who we share it with — will be announced in-app and by email at least 30 days before they take effect. If you continue using My Silo after a change takes effect, you accept the updated policy; if you disagree, you can close your account before the effective date.
Contact
Privacy questions, requests, or complaints: mysilo@send.easttactics.com. We aim to reply within 5 business days. Postal mail can be sent to East Tactics LLC, State of Utah, USA — email us for the current address.