← Back to Senshin

Privacy Policy

Last updated: 21 September 2026 · Version 3.2 · Terms of Service

Two pipes. Your project — names, RAID text, files, exact pounds — stays in your workspace and is used to run Senshin, including Sensei. Separately, if you allow it at create or close, we keep an anonymous picture of how programmes like yours run and finish (bands, counts, outcomes). That picture is how peer comparison and a durable industry dataset are built. We do not sell personal data. We do not train foundation models on your project text.

1. Who we are (controller)

The data controller is Alex Sakpoba, trading as Senshin (senshin.io), a UK sole trader.

Privacy: privacy@senshin.io

When you put other people's data into a project (colleagues, stakeholders, vendors), you are usually the controller of that data and we are your processor. That relationship is in the Data Processing Agreement.

2. What we collect

Account data

Name, email, organisation, role and timezone, so we can create the account and bill it. Sign-in is by an emailed code, Google or Apple, as offered on the sign-in screen.

At sign-up we may derive an approximate location (country and city) from the connection's IP address, then discard the address. We keep only the country and city, not the address.

Project delivery data

What you enter or import to run a project: names, dates, methodology, RAID, finance, people and RACI, activities and dependencies, files and artefacts, Briefs and SteerCo packs, and comments you leave in the product.

Sensei and product telemetry

On our own systems we keep a record that an analysis ran (who, which project, which depth, whether you accepted or dismissed a nudge). That is our audit trail, not a copy of the prompt at the model provider. Usage telemetry (pages, features, device class, timing) is first-party. Optional analytics cookies are off unless you consent — see the Cookie Policy.

Billing

We do not store card numbers. Our payment provider processes payment. We store the customer reference, plan, seat count and invoice metadata we need to run the subscription.

3. How we use it and on what legal basis

PurposeDataLegal basis (UK GDPR)
Run the product and your accountAccount, project dataContract
Sensei analysis and the BriefProject data you have enteredContract
Billing, refunds, invoicesEmail, plan, payment referencesContract; legal obligation (tax)
Security and abuse preventionSession tokens, limited connection dataLegitimate interests
Service email (trial ending, receipts)Email, nameContract
Industry picture (how programmes run and finish)Banded numbers, categories, outcome codes — never names or textConsent — asked at create and at close; stop any time in Settings → Privacy
Optional analytics cookiesUsage eventsConsent
Service planningApproximate location (country, city) at sign-upLegitimate interests
The industry picture. If you allow it, we first keep a short staging row (still attributable, so we can delete it if you stop). When five similar programmes exist we strip every handle and mix the numbers into an anonymous pool — health, budget band, RAID velocity, and the finish line (on time / late / over / cancelled). A comparison is only shown at that floor. Stopping deletes staging; the mixed pool cannot be unbaked. That pool improves Senshin's judgement, powers peer comparison, may later be published as aggregated industry statistics, and transfers with the business if Senshin is sold. Full list: Settings → Privacy, or /api/user/data-consent/what-we-collect.

4. How Sensei processes data

  1. Deterministic checks run on our infrastructure (schedule, budget, RAID, people, governance). That stage does not send your data to a model provider.
  2. New project files. We first read the file ourselves (cells, Gantt, tables). Running prose that still needs a language model is sent to an AI processing provider.
  3. Chat and narrative. To answer you in Sensei chat, or to turn live signals into readable analysis, we send the relevant project context to an AI processing provider under contract. Our main AI route is configured to use only providers that do not keep or train on what they are sent.

We do not use your project text, names or files to train foundation models. We cannot control a provider if they break their contract; we choose providers and settings to make that a breach of theirs, not our default. The anonymous industry picture (numbers and outcome codes you allowed) is how Senshin's own judgement gets sharper — that is not a foundation-model training set.

Each paid seat includes £2 of AI use per month. Past that, Sensei uses the built-in deductions instead of a paid model. See Fair Use and the Terms.

5. How we keep it safe

Your data is held with trusted hosting and storage providers. It is encrypted in transit (TLS) and at rest, and access is controlled and limited to your workspace.

6. Who we share with

We do not sell personal data. We do not use advertising networks. The anonymous industry picture is not personal data once mixed; we do not sell your project.

We use trusted service providers (processors) to run Senshin, for hosting and storage, content delivery and security, sign-in, payments, email and messaging, and AI processing, and, where they are switched on, support and analytics tools. They handle personal data only on our instructions and under written terms. We will tell you which providers we use if you ask: privacy@senshin.io. The processor terms are in the DPA.

7. How long we keep it

8. Your rights

Under UK GDPR you can ask to access, correct, erase, restrict, port, or object. Email privacy@senshin.io. We respond within 30 days.

You can also complain to the ICO.

In-product: Settings for export and account delete; Settings → Privacy for benchmarking.

9. Cookies

Necessary cookies run the session. Optional analytics and marketing cookies are off until you consent. Full list: Cookie Policy.

10. Mobile app

If you install the iOS or Android wrapper: a local encrypted copy can sit on the device for offline use; we do not back that copy up to iCloud or Google Drive. Push notification tokens are stored against the account so we can send alerts you have asked for. Biometrics stay on the device. Deleting the app does not delete the server account — use Settings → Delete my account for that.

11. Children

Senshin is a professional tool. It is not for anyone under 18. We do not knowingly collect children's data.

12. International transfers

Some of our providers may handle data outside the UK. Where they do, we rely on an adequacy decision or the UK Addendum to the EU Standard Contractual Clauses.

13. Security

Session cookies are httpOnly and Secure where the site is served over HTTPS. Access inside the product is limited to your workspace. Report vulnerabilities to security@senshin.io. We do not claim a named certification (for example SOC 2) that we do not hold.

14. Changes

Material changes are notified in the product and by email with at least 14 days' notice. The date at the top is the current version.

15. Contact

Alex Sakpoba, trading as Senshin
privacy@senshin.io · security@senshin.io · alex@senshin.io