Privacy Policy
Last updated: October 2, 2026
1. Data Controller
Puida Oy (Business ID: 2918901-1)
Ruopankatu 2 B 5
15100 Lahti, Finland
Email: support@sulle.fi
Website: sulle.fi
2. Collected Personal Data
Sulle collects and processes as little personal data as possible. Collected data:
- Phone number — your account's unique identifier and used for finding contacts. Your number is stored securely and used to prevent abuse. It is verified by a text message you send from your phone to our number; the message is received by a phone we operate on a Finnish mobile subscription (Telia), and no SMS service provider processes your number on our behalf.
- Profile name and status message — information visible to other users, which you can choose freely. It is stored on the server in plaintext, because other devices have to be able to display it.
- Profile picture — an optional picture, stored in file storage located in Finland. Unlike your messages, a profile picture is not encrypted device-to-device: it is an image other people's devices have to be able to display, so we are technically able to open it.
- Group names and descriptions — a group's name and description are stored on the server in plaintext so that its members can see them. The content of messages sent in the group is still encrypted device-to-device.
- Device data — device ID, the name the device chose for itself, public encryption keys, and when the device was last connected to the server. We do not collect the device model or the operating system version.
- Push identifiers — the identifiers issued by Apple and Google that let us wake your device when a message or call arrives. The notification itself carries no message content and no sender name, and the identifiers are deleted when your account is deleted.
- Encryption keys — public keys to enable device-to-device encryption of messages.
- Payment and subscription data — if you renew on sulle.fi: your email address, the date until which your account is paid for, and the payment records that Stripe keeps on our behalf. See section 12.
3. Data We Do Not Collect
The Sulle application does not collect or process the following data:
- Message content — all messages, images, videos, and audio files are encrypted device-to-device. The server only processes encrypted data, which it cannot read.
- Call content — audio and video calls are encrypted device-to-device.
- Location data
- Your contact list — your phone's address book is never uploaded to our servers.
- Advertising identifiers or tracking data
- Usage analytics or telemetry data
- Processing by artificial intelligence — no AI reads, summarises or classifies your messages or your profile, nothing sent through Sulle is processed by AI models, and we do not train language models on messages, profiles or usage data or hand them to anyone who does.
The Sulle application collects no analytics and sends nothing on its own. The one thing that can leave your device is a diagnostic report you send yourself — see section 6. Measuring the website is a separate matter and is based on consent — see section 13. We use no advertising identifiers and no advertising analytics in either.
4. Purpose and Basis for Processing Personal Data
We process personal data for the following purposes:
- Providing the service — creating your account, routing messages, and enabling calls. Basis for processing: performance of a contract (GDPR Art. 6(1)(b)).
- Security — preventing abuse and protecting the service. Basis for processing: legitimate interest (GDPR Art. 6(1)(f)).
- Billing — renewals paid on sulle.fi. Basis for processing: performance of a contract (GDPR Art. 6(1)(b)).
We do not process your personal data for advertising, profiling, or other purposes.
5. Device-to-Device Encryption
Sulle uses a secure protocol (X3DH key agreement and the Double Ratchet algorithm) to encrypt all messages. The purpose is that only the sender and the recipient can read the content of the messages. Puida Oy does not manage the encryption keys and cannot decrypt the messages.
Media files (images, videos, files) are encrypted with the AES-GCM algorithm on the device before sending. The server only processes the encrypted file, and the encryption key is never sent to the server.
6. Data Retention and Location
All server-side data is stored on servers located in Finland. The servers, databases, file storage and call relays run on infrastructure we rent from Hetzner Online GmbH in Hetzner's data centre in Finland, and we operate them ourselves.
There is one exception: push notifications. To wake your device when a message arrives, your device's push identifier has to be handed to Apple's notification service (APNs) or Google's (Firebase Cloud Messaging), and those companies process it outside the EU and EEA as well. The notification itself carries no message content and no sender name. Apart from this and the payment processing described in section 12, no data is transferred outside the EU/EEA.
- Encrypted messages wait on the server in a per-device queue until the recipient's device fetches them. The row expires automatically 30 days after the message was sent — so a message that has already been fetched may still sit on the server, encrypted, for that period. We are unable to read it at any point.
- Your account data (phone number, profile name, encryption keys) is stored for as long as your account is active.
- Diagnostic reports, if you send one from the app, are kept for at most 14 days.
- A local copy of your messages is stored only on your own device in an encrypted SQLite database. Puida Oy has no access to your device's local database.
7. Disclosure of Data
We do not sell, rent, or disclose your personal data to third parties for marketing purposes.
We may disclose information only if required by Finnish law under a decision by a competent authority. Because messages are encrypted device-to-device, we cannot disclose the content of messages even based on an official request.
Processors
We use the following processors, each bound by a data processing agreement:
- Hetzner Online GmbH (Germany) — hosting of all Sulle servers, databases, file storage and call relays, in Hetzner's data centre in Finland.
- Apple Inc. — push notification delivery to iPhones (APNs), and billing of iPhone subscription renewals.
- Google LLC — push notification delivery to Android phones (Firebase Cloud Messaging).
- Stripe Payments Europe, Ltd. (Ireland) — processing of renewals paid on sulle.fi.
Hosting, storage and call relays are in Finland. Push identifiers are processed by Apple and Google also outside the EU/EEA, and Stripe may transfer payment data to the United States under the EU-U.S. Data Privacy Framework and standard contractual clauses. No other data leaves the EU/EEA.
8. Your Rights
Under the EU General Data Protection Regulation (GDPR), you have the following rights:
- Right of access to your data — you can request a copy of the data stored about you.
- Right to rectification — you can update your profile information directly in the application.
- Right to erasure — you can delete your account, in the app or on our website. What that removes is set out below.
- Right to restriction of processing
- Right to data portability
- Right to object to processing
Deleting your account
Your account becomes unreachable straight away: messages are no longer delivered to it, it cannot be found by phone number or name, it shows no presence, and your devices are signed out. There is then a 7-day window in which the deletion can be cancelled from any of your own devices, and every other device is told when deletion starts. After that window the erasure happens and cannot be undone. It is completed without undue delay, and within 30 days at the latest.
Erased: the account record; every device and its push notification identifiers; encryption keys and prekeys; conversation participation; blocked lists; settings; call participation records; profile pictures; encrypted backups; encrypted archive transfers; partially uploaded media; phone verification records; and the records of messages you have sent.
Kept: entries in the cryptographic identity chain, which record that a device was added to or removed from an account. They contain no message content, no phone number and no name. We keep them for security and abuse prevention. Deleting an account issues a new account identifier, so these entries no longer point at any living account.
Abuse reports: reports that other users made about your account may be kept for up to 90 days after your account is deleted, so that our team can complete a safety review. If you reported someone and then delete your account, your identity and your own words are removed from the report.
Kept by law: if you have paid a renewal on sulle.fi, the invoice and payment records (email address, amount, date) are retained for six years after the end of the financial year, as the Finnish Accounting Act requires. They contain no phone number and nothing about your use of the service.
Kept to prevent double use of a purchase: on Android, Google tells us that the app was bought but not when, so we keep a hashed form of your phone number together with the date your first year started, for 13 months from that date and also after deletion. It lets us refuse a second free year for the same number; the hash cannot be turned back into the number.
Expires on its own: a message still queued for a recipient who has not come online, and the photos, videos and files you have sent once they have finished uploading. These are not erased by your deletion. They are stored encrypted, we cannot read them, and they are discarded automatically 30 days after they were sent.
Groups: groups you were in continue without you. Your membership is removed; the group and its other members are not affected.
Beyond our reach: messages already delivered to other people are on their devices and are not ours to delete, as is the history on your own device, which goes when you remove the app.
Step-by-step instructions for both routes are on the Account & data deletion page.
Exercising your other rights
Contact support@sulle.fi. We will respond to your request within 30 days.
You also have the right to lodge a complaint with the Data Protection Ombudsman: tietosuoja.fi.
9. Data Security
We protect personal data with appropriate technical and organizational measures. These include, among others:
- Device-to-device encryption in all communication
- Encrypted data traffic to the server (TLS)
- Local database encryption on the device
- Encryption key management on the users' own devices — the server does not manage private keys
10. Contact Form
The information you send through the contact form on sulle.fi — name (optional), email address, subject (optional) and the message itself — is processed solely to answer your enquiry. The basis for processing is legitimate interest (GDPR Art. 6(1)(f)): we reply to the messages sent to us.
Messages are processed on Puida Oy's own Tiuha service and are deleted automatically after 90 days. We do not use the information for marketing, and we do not link it to your Sulle account.
To prevent abuse, submissions pass through an automated human-verification check (Torjua Verify, Puida Oy's own service), which keeps a hashed form of the IP address for at most 30 days and sets no cookies. The form also limits how many messages can be sent from one IP address. The form does not accept file attachments.
11. Waitlist
You can leave your email address on the waitlist to be notified when Sulle arrives in the app stores. We store your address, the consent you gave, and which app store you were interested in.
The basis for processing is your consent (GDPR Art. 6(1)(a)). Signing up is confirmed by a separate confirmation email, so your address is not added to the list unless you confirm it yourself. You can unsubscribe at any time using the link in every message, which removes your address from the list.
The list is maintained on Puida Oy's own Tiuha service, and signing up passes through the same automated human-verification check as the contact form. We do not use the address for anything other than this notification, and we do not disclose it to third parties.
12. Subscription Payments
The first year of Sulle is paid in the Apple App Store or Google Play. Apple or Google processes that payment and holds your payment details. We receive a signed confirmation that the app was bought, and when, so that we can start your twelve months. We do not receive your name, your card or your store account.
On iPhone, renewals are an Apple subscription. Apple processes the payment and holds your payment details; we receive Apple's signed notices that the subscription was started, renewed, refunded or cancelled, with a transaction identifier and dates, so that we can extend or end your service. We receive no name, card or Apple ID.
Renewals are paid on sulle.fi. Payments are processed by Stripe Payments Europe, Ltd. (Ireland), acting as our processor. Stripe receives the email address and card details you enter; we never see the card. Stripe may transfer data to Stripe, Inc. in the United States under the EU-U.S. Data Privacy Framework and standard contractual clauses. On our own servers we store only the date until which your account is paid for and Stripe's reference numbers for the customer and the subscription. Your email address and your payment history stay at Stripe, where we can view them; they are not copied to your Sulle account, and nothing on our servers links your account to an email address. Stripe does not receive your phone number or anything about your use of Sulle.
The basis for processing is performance of a contract (GDPR Art. 6(1)(b)). Invoices and payment records are kept for six years after the end of the financial year, as required by the Finnish Accounting Act, also after your account has been deleted. The email address is used for receipts and for Stripe's notices before the next charge, not for marketing. If you have never renewed on sulle.fi, we hold no email address for you.
13. Cookies and Tracking
The Sulle application uses no cookies and contains no analytics or tracking. This has not changed.
The Sulle website (sulle.fi) stores only what it needs to function: the cookie choice you make, and the contact form's spam protection. These require no consent, because the site does not work without them.
We also measure visitor numbers and site usage, but only with your consent. We use Vahti analytics, developed by Puida Oy and hosted by us in Finland. We use no third-party analytics tools, share nothing with third parties, and transfer no data outside the EU. If you consent, a randomly generated identifier is stored in your browser for one year; it is not linked to your identity or to your Sulle account. The data collected is the page address, the referring page, your browser and device type, and the country derived from your IP address.
No analytics is loaded before you have consented. If you choose “Necessary only”, the site never contacts the analytics server at all. You can withdraw or change your consent at any time from the Cookie settings link in the footer. The legal basis for this processing is consent (GDPR Art. 6(1)(a)).
14. Children's Privacy
Sulle is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If you notice that a minor has created an account, please contact us at support@sulle.fi, and we will delete the account.
15. Changes to the Privacy Policy
We may update this privacy policy from time to time. Significant changes will be announced in the application. By continuing to use the service after the changes, you accept the updated privacy policy.
16. Contact Information
For questions regarding privacy, please contact:
Puida Oy
Email: support@sulle.fi
Website: sulle.fi