← Back to Senshin

Privacy Policy

Last updated: 11 July 2026 · Version 2.1 · Terms of Service

Your project data is yours. We process it to power AI analysis — never to train models, never to sell, never to share beyond what's needed to run the service.

1. Who we are

Senshin is operated by Alex Sakpoba, trading as Senshin (senshin.io), a UK sole trader. We build an AI-powered Project Delivery Operating System for professional project managers, programme managers, and delivery leads.

The data controller is Alex Sakpoba, trading as Senshin (senshin.io). Contact: privacy@senshin.io

2. What we collect

Account data

When you sign up: name, email address, organisation, role, and timezone. This is Tier 1 data — the minimum needed to create your organisation.

At sign-up we also derive your approximate location (country and city only) from your connection's IP address, then discard the address — it is never stored with your account. We use this solely to plan where to host data storage so your data can live closer to you.

Project delivery data

Everything you enter to manage your projects:

AI interaction data

Every AI analysis run is logged: trigger source, AI depth level (Observe/Advise/Challenge), signals produced, recommendations generated, confidence scores, and your response (accepted/dismissed). This powers the immutable audit trail.

Usage data

Pages visited, features used, timestamps, device type, browser, and session duration. Collected via first-party telemetry only — no third-party analytics trackers.

3. How we use your data

PurposeData usedLegal basis
Operating the platformAccount, project dataContract performance
AI analysis & reasoningProject, RAID, finance, people dataContract performance
Signal computation (29 dimensions)All project dataContract performance
Improving the productAnonymised usage dataLegitimate interest
Anonymised benchmarkingIrreversibly anonymised project shape — budget band, methodology, phase, health, numeric ratios (no identifiers)Legitimate interest
Service communicationsEmail, nameContract performance
Billing and paymentsEmail, plan dataContract performance
Security and fraud preventionIP address, session tokensLegitimate interest
Data-storage region planningApproximate location (country/city, derived at sign-up; IP discarded)Legitimate interest
Anonymised benchmarking — your right to object. We derive irreversibly anonymised benchmarks from project data so you can compare your delivery against peers, and so we can improve Senshin. Budgets are reduced to bands, every identifier is stripped, and a result is only ever shown when at least five projects share a cohort — so it can never be traced back to you or your organisation. Our lawful basis is legitimate interest, and you have an absolute right to object: turn benchmarking off in Settings → Privacy at any time, which stops it and deletes every anonymised snapshot already held.

4. AI processing — how it works

Senshin's reasoning engine operates in two stages:

  1. Deterministic reasoning (runs on our servers) — extracts signals across schedule, budget, RAID velocity, resource, and governance dimensions. No data leaves our infrastructure for this stage.
  2. LLM narrative generation — to turn those signals into human-readable analysis, recommendations, and challenge-mode scrutiny, your project context is sent to large language models through OpenRouter, an AI gateway. Every request carries a strict data policy (data_collection: deny) that instructs OpenRouter to route only to model providers that do not log, retain, or train on the request. A Google Vertex AI (Gemini, London region) path is retained as a fallback.
We never use your data to train AI models — and we route only to providers that don't either. No AI provider retains your project content after generating a response. This is enforced on every request, not left to a provider's default.

5. Where your data lives

All data is stored and processed in the europe-west2 (London) region on Google Cloud Platform:

All storage is encrypted at rest (AES-256) and in transit (TLS 1.3). Private IP networking between services — no data traverses the public internet within our infrastructure.

6. Who we share data with

We do not sell your data. We do not share it for advertising. Data is shared only with these processors:

ProcessorPurposeLocation
Google Cloud PlatformInfrastructure, storage, fallback AI processingLondon (europe-west2)
OpenRouterAI model routing — no-logging, no-training, no-retention policy enforced on every requestUS gateway → no-retention providers
Firebase AuthenticationIdentity and sign-inEU
StripePayment processingEU/US
SendGrid (Twilio) / BrevoTransactional email (primary and fallback)EU/US

Each processor operates under a Data Processing Agreement compliant with UK GDPR. See our DPA for details.

7. Data retention

8. Your rights under UK GDPR

You have the right to:

To exercise any right, email privacy@senshin.io. We respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

9. Cookies

We use minimal cookies — only what's needed to run the service:

CookiePurposeDuration
ss_tokenSession authenticationSession
ss_user_idUser identificationSession
ss_consent_v1Cookie consent preference1 year
ss_settingsDisplay preferences (theme, density)1 year

No advertising cookies. No third-party trackers. Analytics cookies are optional and only set with your explicit consent. See our Cookie Policy for the full table.

10. Mobile app

If you use the Senshin iOS or Android app, the following additional data processing applies:

CategoryWhatWhere stored
On-device dataA local copy of your project data for offline access, stored in an encrypted SQLite databaseYour device only — never backed up to iCloud or Google
Push notification tokenA device token issued by Apple (APNs) or Google (FCM) so we can send you alertsOur server, linked to your account
Biometric dataWe use your device's Face ID, Touch ID, or fingerprint sensor via the platform's Passkey/WebAuthn API. We never receive, store, or transmit biometric data — authentication happens entirely on your deviceYour device only (secure enclave)
OTA updatesThe app checks Capgo for web-layer updates. Your app version and platform are sent; no personal data is transmittedCapgo (EU)

You can revoke push notifications at any time in your device settings. Deleting the app removes all on-device data. Your server-side account and data are unaffected by app deletion — use Settings → Delete my account to remove those.

11. Security

Report security vulnerabilities to security@senshin.io.

12. Children

Senshin is a professional tool for project delivery. It is not intended for users under 18. We do not knowingly collect data from minors.

13. International transfers

Your data is primarily processed in the UK (London). Where sub-processors operate outside the UK (Stripe, SendGrid), transfers are protected by Standard Contractual Clauses (SCCs) or UK adequacy decisions.

14. Changes to this policy

We may update this policy. Material changes will be communicated via in-app notification and email with at least 14 days notice. The "Last updated" date at the top always reflects the current version.

15. Contact

Alex Sakpoba, trading as Senshin (senshin.io)
United Kingdom
Privacy: privacy@senshin.io
Security: security@senshin.io
General: {{SUPPORT_EMAIL}}