Date of last update:
Privacy policy
This policy covers what data Sherlo collects, how it is used, and what rights you have over it.
1. Introduction
By accessing or using our Service, you agree to this Privacy Policy.
For the purposes of this Privacy Policy:
- "Service": Sherlo, including all its features, functionalities, and associated services.
- "User": Any individual or entity that creates an account and uses the Service. A User can be a member of multiple Teams simultaneously and can have different roles (Team Owner or Team member) in different Teams.
- "Team Owner": The User who creates a Team, manages Team membership, and is responsible for payment and billing.
- "Team": A group of Users who have access to shared Projects within the Service, managed by a Team Owner.
- "Project": A workspace within a Team that contains Tests and related testing data for a specific application. Multiple Projects can exist within a single Team.
- "Build": A compiled version of a React Native application submitted to the Service for testing purposes.
- "Test": An automated evaluation process within a Project that compares Snapshots between its Builds to detect visual changes.
- "Snapshot": A full capture of a specific view or state within a Build, including the view's screenshot, component metadata (such as dimensions, colors, fonts, and layout information), and other UI-related properties.
- "Review": A piece of user-generated content that contains a decision on Snapshot correctness (approved or reported) and optional comments providing feedback or explanations.
- "Subscription": A paid plan that determines Team access to Service features, Snapshot allocations, and historical data retention periods.
Sherlo is a service operated by Devine, a company registered in Poland under registration number PL8522703785. Our registered office is located at ul. 5 Lipca 15/11, 70-376 Szczecin. For inquiries, please contact us at contact@devine.team.
2. Data processing and storage
What we collect
- Personal Information: When you sign up for Sherlo, we collect your email address. Your password is securely handled through our authentication service and is never directly stored by us. Additional profile information may be collected as you use the Service.
- Billing Information: When you subscribe to a paid plan, we collect payment and billing information. Payment processing is handled securely by Stripe, our payment processor. Sherlo may store the last 4 digits of your credit card, billing name, and billing address for record-keeping purposes. Full credit card numbers are never stored by Sherlo.
- Builds: Submitted for testing purposes, including compiled versions of your applications.
- Snapshots: Includes screenshots, component metadata, and UI properties.
- Git Details: For each Build, the branch name, commit hash, commit message, and repository name.
- Analytics Data: Collected through Google Analytics, Microsoft Clarity, and Hotjar to understand how the Service is used and to improve it. Clarity and Hotjar may record user sessions (clicks, scrolls, and page interactions).
- User Reviews: Your Reviews on Snapshots.
- Technical Data: Such as IP addresses, browser types, operating systems, and other similar information.
How we use your information
- Service Provision: To operate, maintain, and provide features of the Service.
- Support and Troubleshooting: To reproduce and fix problems you report, and to check Sherlo releases against your Project before they ship. For this, our staff may make a short-lived support copy of the part of one Project the work needs (build records, Snapshots, the newest Builds, Review state, and git details). Member identities are replaced with stand-ins in the copy. The copy stays inside our AWS account, or on a Sherlo machine for the length of one test run, is tied to one piece of work, and is deleted when that work ends, and within 30 days at most.
- Improvement: To understand how users interact with the Service and to develop new features.
- Communication: To send you updates, promotional materials, and respond to your inquiries.
- Security: To protect against unauthorized access, attacks, or other security incidents.
- Compliance: To comply with legal obligations and enforce our Terms of Use.
Legal basis for processing
Our legal basis for collecting and using your personal information depends on the context:
- Consent: Where you have given clear consent for us to process your personal data.
- Contract: The processing is necessary for a contract we have with you.
- Legal Obligations: To comply with the law.
- Legitimate Interests: For our legitimate interests, provided your rights do not override these interests.
Data retention
While your account is active
- Builds: Only the latest Build for each platform (iOS, Android) per Project is kept.
- Tests, Snapshots, and Reviews: Retained as long as the Project remains active.
- Users: Retained until your account is deleted.
- Analytics Data: Aggregated data is retained indefinitely with anonymized user data.
- Support Copies: Kept only for the piece of work they were made for, and deleted when it ends, and within 30 days at most.
After cancellation or downgrade
- 30-Day Retention Period: After subscription cancellation or automatic downgrade due to non-payment, your account data (including Projects, Snapshots, Reviews, Builds, and Tests) is retained for 30 days.
- Deletion on Request: You can ask us to delete all your data at any time by contacting us at contact@sherlo.io. We will remove it within 30 days of your request, including any live support copy.
- Data Export: During the 30-day retention period, you may request a data export as described in the "Data export requests" section below.
Data sharing and disclosure
We may share your information with third parties in the following circumstances:
- Service Providers: Such as Amazon Web Services for storage and authentication (S3, Cognito), Vercel for website hosting, Sentry for error tracking, Google (Analytics, BigQuery, YouTube) for analytics, reporting and the embedded product demo, Microsoft Clarity and Hotjar for analytics and session recordings, CookieYes for consent management, and Stripe for payment processing.
- Legal Requirements: When required by law or to protect our rights.
- Business Transfers: In the event of a merger, acquisition, or sale of assets.
- With Your Consent: For any other purposes disclosed at the time of collection.
Cookies and consent
We use cookies for the purposes set out in the "How we use your information" section above, and the tables below give the purpose of each individual cookie. On sherlo.io a consent banner (provided by CookieYes, our consent service) lets you accept, reject, or customize non-essential cookies before they are set; visitors in the EU/EEA, UK, and Switzerland are asked for opt-in consent. You can change or withdraw your choice at any time via the Cookie preferences link in the website footer.
If your browser or an extension blocks our consent service, the banner, the footer link, and the cookie tables below won't appear - the same protection also blocks our analytics tools, so in that case no non-essential cookies are set at all.
The tables below list all cookies in use and update automatically:
Cross-border data transfers
Sherlo uses third-party service providers that may process your data outside the European Union:
- Amazon Web Services (AWS): For data storage and hosting infrastructure.
- Google (Analytics, BigQuery, YouTube): For analytics, reporting and the embedded product demo.
- Microsoft (Clarity): For analytics and session recordings.
- Hotjar (Contentsquare): For session recordings.
- Vercel: For website hosting.
- Stripe: For payment processing.
These services may transfer and process your data in countries that may not provide the same level of data protection as your home country. Where applicable, we ensure compliance with GDPR requirements through the use of Standard Contractual Clauses (SCCs) and other appropriate safeguards to protect your personal data.
Security measures
We implement a variety of security measures to maintain the safety of your personal information:
- Access Control: Limited access to personal data to authorized personnel only.
- Encryption: Data is encrypted in transit and at rest where appropriate.
- Security Practices: We use industry-standard security practices to safeguard your information.
- Regular Monitoring: Continuous monitoring and updates to address emerging security threats.
Important security notes
- No System is 100% Secure: Despite our best efforts, no method of transmission over the internet or electronic storage is completely secure. You acknowledge that data transmission carries inherent risks.
- User Responsibility: You are responsible for maintaining the confidentiality of your login credentials and for all activities that occur under your account. Use strong passwords and do not share your account access with unauthorized individuals.
Data breach notification
In the event of a data breach that compromises your personal information, we will notify you within 72 hours of becoming aware of the breach, where required by law. We will provide information about:
- The nature of the breach.
- The types of data affected.
- Steps we are taking to address the breach.
Where appropriate, we may also advise you on protective actions you can take, such as changing your password or monitoring your accounts for suspicious activity.
3. Your data rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request access to your personal data.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data.
- Restriction of Processing: Request to limit the processing of your data.
- Data Portability: Request to receive your data in a structured, commonly used format.
- Objection: Object to the processing of your data under certain circumstances.
- Withdrawal of Consent: Withdraw consent where processing is based on consent.
Data export requests
To request an export of your personal data, please contact us at contact@sherlo.io. We will process your request and deliver the data export through email within 5 business days. The export will include all personal data we hold about you in a structured, commonly used format.
To exercise any other data rights, please contact us at contact@sherlo.io. We may require additional information to verify your identity before processing your request.
4. Children's privacy
Our Service is not intended for individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently received such information, we will delete it promptly.
5. Changes to this Privacy Policy
We may update this Privacy Policy at any time. Changes become effective when posted on sherlo.io, unless stated otherwise. We will notify you of significant changes through in-app popups and email to the Team Owner's registered address. Continued use of the Service after changes means you accept the new Privacy Policy.
If you don't agree, stop using the Service before changes take effect. For paid subscriptions, you may cancel and get a prorated refund for unused time if you don't accept the new Privacy Policy.