← Back to Login

Privacy Policy

Last updated: March 2026

1. Who We Are

WYRILO is a single-user business dashboard for self-employed workers. You are both the data controller and the operator of this application. This policy explains how your business data and your clients' personal data are handled.

2. What Data We Collect

The application stores the following data in your Supabase database:

  • Your account: Email address (used for login via OTP)
  • Business settings: Company name, address, email, phone, logo, VAT details
  • Clients: Name, email, phone, notes
  • Jobs: Address, service type, dates, price, status, notes
  • Invoices: Invoice number, amount, status, linked jobs

3. Why We Process Data

All data is processed under legitimate interest (Article 6(1)(f) GDPR) — you need client and job details to run your business. No data is collected for marketing or profiling purposes.

4. Where Data Is Stored

All data is stored in your Supabase project database. Supabase uses PostgreSQL with Row Level Security (RLS) ensuring only you can access your own data. Auth session cookies are essential for functionality and do not require consent.

5. Third-Party Sharing

No personal data is shared with third parties. There are no analytics trackers, advertising pixels, or marketing tools integrated into this application.

6. Cookies

This application uses only essential cookies for authentication (Supabase session). No tracking, analytics, or advertising cookies are used. Under GDPR/PECR, essential cookies do not require consent.

7. Your Rights (GDPR Articles 15–22)

As the application owner, you can exercise these rights directly:

  • Right of Access: Use "Download My Data" in Settings to export all your data as JSON
  • Right to Erasure: Use "Delete Account" in Settings to permanently remove all your data
  • Right to Rectification: Edit any record directly through the dashboard
  • Client Data Erasure: Use "Anonymize" on the Clients page to remove personal data while preserving financial records

8. Data Retention

Data is retained for as long as your account exists. UK tax law requires financial records to be kept for at least 6 years. When you delete your account, all data is permanently removed via cascading database deletion.

9. Security

Data is protected by:

  • Passwordless authentication (email OTP — no stored passwords to leak)
  • Row Level Security on all database tables
  • HTTPS encryption in transit
  • Supabase infrastructure security (SOC 2 Type II compliant)

10. Changes to This Policy

Any changes to this privacy policy will be reflected on this page with an updated date.