🚀limited beta -

    🚀limited beta -

    Privacy Policy

    Last updated: 7 March 2026

    This Privacy Policy explains how sidething Ltd ("sidething", "we", "our", or "us") collects, uses, and protects your information when you use our website, app, and related services (collectively, the "Service").

    By using sidething, you agree to this Privacy Policy. If you do not agree, please stop using the Service.

    sidething Ltd is registered in England and Wales (Company Number 16834072) with its registered office at 14/2E Docklands Business Centre, 10-16 Tiller Road, Canary Wharf, London, E14 8PX, United Kingdom.

    1. Definitions and Interpretation

    1.1. Data — any information you provide to sidething or that we collect in connection with your use of the Service.

    1.2. Data Protection Laws — all applicable privacy and data protection laws, including the UK GDPR and the Data Protection Act 2018.

    1.3. User — any person accessing or using the Service who is not employed by sidething or providing services on its behalf.

    1.4. Website — sidething.com and any related subdomains (including app.sidething.com).

    2. Scope

    2.1. This Privacy Policy applies to sidething Ltd and Users of this Service.

    2.2. It does not apply to third-party sites or services linked from sidething.

    2.3. For the purposes of data protection laws, sidething Ltd is the data controller responsible for how and why your personal data is processed.

    3. Data We Collect

    3.1. sidething may collect and process the following types of data:

    • Account Information — name, email address, and password.
    • Profile and Business Information — business type, goals, traction signals, and other details you provide during onboarding or profile setup.
    • Payment Data — billing name, email, and payment method (handled securely via Stripe; card details never touch our servers).
    • Usage Data — activity logs, task completion data, feature usage, and login events.
    • Device and Technical Data — browser type, operating system, and IP address.
    • Communications Data — messages, forms, or feedback you send us.
    • User Content — uploads, responses, tasks, habits, roadmaps, or wins you create or share on sidething.
    • AI Interaction Data — messages and content you submit to AI-assisted features, including chat conversations, task descriptions, and voice recordings.
    • Notification Data — push notification subscription endpoints and notification preferences, if you enable browser notifications.

    4. How We Collect Data

    4.1. Directly from you — when you register, update your account, use AI-assisted features, contact us, or use sidething's features.

    4.2. Automatically — through technical logs and local analytics.

    4.3. Through platform features — when you interact with AI tools, create tasks, participate in Inner Circles, or use other collaborative features within the Service.

    5. How We Use Your Data

    5.1. sidething uses your data to:

    • Provide and maintain your account;
    • Process payments and manage subscriptions;
    • Power AI-assisted features such as personalised guidance, task interpretation, and roadmap generation;
    • Improve the platform's performance and experience;
    • Communicate important updates and billing notifications;
    • Send marketing emails (only if you have opted in via our newsletter);
    • Deliver push notifications (only if you have granted permission in your browser);
    • Monitor and protect platform security;
    • Comply with legal and regulatory obligations.

    5.2. We do not sell or rent your data.

    5.3. We do not use third-party ad tracking or behavioural targeting.

    6.1. Our legal bases for processing your data under the UK GDPR include:

    • Contractual necessity — to provide the Service you signed up for, including AI-assisted features;
    • Legitimate interest — to improve, secure, and operate sidething;
    • Legal obligation — to meet financial and compliance requirements;
    • Consent — for marketing communications and optional features such as push notifications.

    7. Data Sharing and Third Parties

    7.1. We only share data with trusted service providers who help us operate sidething. Our current sub-processors include:

    ProviderPurposeData Involved
    SupabaseHosting, database, authentication, file storage, and real-time messagingAccount data, content, files, session data
    StripeSecure payment processingBilling name, email, payment method (tokenised)
    NetlifyWebsite and app hostingRequest logs, IP addresses
    ResendTransactional email deliveryEmail address, name, notification content
    FlodeskNewsletter email delivery (opt-in only)Email address, subscriber segment
    AnthropicAI language model provider (see Section 8)Content submitted to AI features
    OpenAISpeech-to-text transcription (see Section 8)Voice recordings submitted for transcription
    CloudflareBot protection (Turnstile)IP address, browser signals (no personal identifiers)
    EndorselyAffiliate referral attribution (cookieless)Referral source data (no personal identifiers)

    7.2. Each provider processes data under data protection agreements consistent with UK GDPR requirements. You may request details of these agreements by contacting us.

    7.3. We never share your data with advertisers or social media platforms.

    7.4. We maintain an up-to-date list of sub-processors. If you would like to be notified of changes to this list, email support@sidething.com.

    8. AI-Assisted Features

    8.1. sidething includes AI-assisted features that help you plan, build, and track progress on your side project. These features use third-party AI language model providers to process the content you submit.

    8.2. What data is processed: When you use AI-assisted features, the content you provide (such as chat messages, task descriptions, business context, and profile information relevant to your query) may be sent to our AI providers for processing. Voice recordings submitted for transcription are sent to our speech-to-text provider.

    8.3. How AI providers handle your data: Our AI providers process your data solely to generate responses to your requests. Under our agreements with these providers:

    • Your data is not used to train or improve their general AI models;
    • Data is processed in accordance with their enterprise data handling policies;
    • Data is not shared with other customers or third parties.

    8.4. AI output accuracy: AI-generated content (such as suggested roadmaps, task estimates, and guidance) is provided as a starting point and should not be treated as professional advice. You are responsible for reviewing and verifying any AI-generated output before relying on it.

    8.5. Automated processing: Some features involve automated decision-making, such as generating personalised roadmaps or estimating task effort. These automated suggestions are designed to assist you and can be modified or overridden at any time. If you have concerns about automated processing, you may contact us to request information about the logic involved or to request human review of a specific decision.

    9. Data Retention

    9.1. We retain your data while your account is active or as long as required by law.

    9.2. You may request deletion of your account at any time.

    9.3. Upon account deletion, your data is removed from the live system. Encrypted backups may persist for up to 30 days before being permanently erased.

    9.4. Payment and financial data are retained for six years to meet legal requirements.

    9.5. Images uploaded in chat are automatically deleted after 90 days unless associated with an admin account.

    9.6. AI interaction logs are retained for the purpose of providing you with conversation history and improving your experience. These are deleted when your account is deleted.

    10. Local Storage and Analytics

    10.1. sidething does not use tracking cookies. We do not use any third-party analytics services such as Google Analytics.

    10.2. Authentication: Your login session is managed using tokens stored in your browser's local storage (not cookies). These tokens are used solely to keep you signed in.

    10.3. Analytics: We collect basic, anonymised usage analytics (such as page views and feature usage) using a custom, client-side system. This data is stored locally in your browser and is not transmitted to any external analytics service.

    10.4. Consent preferences: If you interact with consent prompts, your preference is stored in your browser's local storage.

    10.5. You can clear local storage through your browser settings at any time, though this will sign you out of your account.

    11. Your Rights

    11.1. Under UK GDPR, you have the right to:

    • Access and obtain a copy of your data;
    • Correct inaccuracies;
    • Request deletion of your data;
    • Restrict or object to processing;
    • Request data portability;
    • Withdraw consent for marketing at any time;
    • Request information about automated decision-making (see Section 8.5).

    11.2. To exercise your rights, email support@sidething.com.

    11.3. If you are unhappy with how we handle your data, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.

    12. Data Security

    12.1. We use technical and organisational measures to safeguard your data, including:

    • Encrypted data storage through Supabase;
    • Encrypted payment handling via Stripe (card details never touch our servers);
    • Secure, encrypted email delivery;
    • Row-level security on all user-facing database tables;
    • Access controls and security logging for internal tools.

    12.2. Despite these safeguards, no system is completely secure. You acknowledge that data transmission over the internet carries inherent risks.

    12.3. If you suspect unauthorised access to your account, contact support@sidething.com immediately.

    13. International Data Transfers

    13.1. Some of our service providers may process data outside the UK or European Economic Area (EEA).

    13.2. Whenever data is transferred internationally, we ensure adequate protection through Standard Contractual Clauses, adequacy decisions, or equivalent safeguards in line with UK GDPR.

    13.3. You can request more details about these safeguards by contacting us.

    14. User Content Visibility and Privacy Mode

    14.1. By default, your activity and content on sidething (such as wins, uploads, and responses) are visible only within your Inner Circle or specific collaboration spaces.

    14.2. sidething offers an optional Stealth Mode, allowing you to control visibility or pseudonymise your public profile.

    14.3. You can enable or disable Stealth Mode at any time in your account settings.

    14.4. sidething cannot guarantee complete anonymity for content you voluntarily share publicly.

    15. Business Changes and Ownership Transfers

    15.1. If sidething Ltd undergoes a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction.

    15.2. Any new owner will continue to handle your data under terms consistent with this Privacy Policy.

    15.3. You will be notified if ownership or control changes in a way that materially affects your data rights.

    16.1. sidething may include links to other websites or third-party resources.

    16.2. We do not control those sites and are not responsible for their privacy practices.

    16.3. You should read the privacy policies of any third-party websites you visit.

    17. Policy Updates

    17.1. We may update this Privacy Policy from time to time.

    17.2. When changes are made, we will post an updated version at sidething.com/privacy and notify users by email or in-app notice if the updates are material.

    17.3. Continued use of the Service after an update means you accept the revised terms.

    18. Contact Us

    18.1. For questions, complaints, or data requests, contact us at:

    sidething Ltd 14/2E Docklands Business Centre, 10-16 Tiller Road Canary Wharf, London, E14 8PX, United Kingdom

    Email: support@sidething.com

    19. Governing Law

    19.1. This Privacy Policy is governed by the laws of England and Wales.

    19.2. Any disputes arising from it will be handled exclusively by the English courts.