Your data. Your rules.
Privacy Notice
Sirko.ai is designed to act only on your instructions, use the minimum data needed for the task, and keep every user's connected services isolated.
Last updated: 5 August 20261. Who operates Sirko.ai
Sirko.ai is a service offered by Mitchell Strategic Solutions Group. For privacy questions, access requests, corrections, exports, objections, or deletion requests, contact info@mitchellgroup.eu.
2. What data Sirko may process
Sirko processes only the categories needed for features you choose and permissions you grant. Depending on your setup, these may include:
- account and channel identifiers used to verify that a message belongs to the correct Sirko profile;
- messages, voice-note transcripts, commands, replies, preferences, reminders, and facts you explicitly ask Sirko to remember;
- selected data from connected services, such as calendar events, email, files, contacts, tasks, music, or smart-home controls;
- device data requested through the optional Sirko Mobile Plugin, such as a current location or a specific on-device action;
- privacy-safe operational metadata needed for security, reliability, rate limits, and troubleshooting.
Sirko does not ask for provider passwords. Connections use revocable permission tokens issued by the relevant provider.
3. Why data is used
Data is used to:
- answer your requests and perform actions you authorize;
- maintain your selected preferences, reminders, and connected services;
- protect the service, prevent cross-user access, and investigate technical failures;
- comply with applicable legal obligations and respond to your privacy requests.
Sirko does not sell personal data and does not use private connected data for advertising.
4. Connected services and processors
A requested task may require data to pass through the messaging platform you use and the provider whose service you connected. Sirko currently relies on providers including Cloudflare for application infrastructure, OpenAI for selected AI and speech functions, Meta/WhatsApp or Telegram for messaging, and Google or other providers for integrations you explicitly enable. Route or public-internet questions may also use the relevant mapping or web service.
Only the data needed for the requested operation is sent. Provider processing is also governed by that provider's terms and privacy notice.
5. Google user data
If you connect Google, Sirko accesses only the Google services and permissions you select during consent. These can include Gmail messages and drafts, calendar events, Drive file metadata, contacts, and basic account identity. Sirko uses this data only to provide user-facing features that you request, such as finding and summarising email, preparing a draft, checking or managing your calendar, finding a file, or resolving a contact.
Task-relevant Google data may be processed by Sirko's contracted infrastructure and AI providers solely to produce the feature you requested. Google user data is not sold, used for advertising, transferred for unrelated purposes, or used to train or improve a general-purpose or non-personalised AI model. Human access is prohibited except when you explicitly request support for specific data, when needed to investigate abuse or a security incident, or when required by law.
Who Google user data may be shared with
Sirko may share, transfer, or disclose the minimum necessary Google user data only to the following recipients and only for the stated purposes:
- Cloudflare, which hosts and secures Sirko's application, encrypted storage, network delivery, queues, and abuse-prevention infrastructure;
- OpenAI, when an AI or speech feature is needed to fulfil the user's request, for example to interpret a command, summarise selected content, or prepare a requested response;
- the user's selected messaging provider, such as Meta/WhatsApp or Telegram, when Sirko delivers the requested result to that user through the channel the user chose;
- Google, when Sirko sends an authorised API request or applies a user-requested change to the connected Google account;
- another service explicitly selected by the user, only when the user requests a cross-service action that requires the relevant data to be transferred to that service;
- authorised support or security personnel, only under a specific user-authorised support grant, when necessary to investigate abuse or a security incident, or when disclosure is required by applicable law.
These recipients act only as needed to provide, secure, or support the user-requested Sirko feature. Sirko does not disclose Google user data to advertising networks, data brokers, or unrelated third parties; does not sell it; and does not use it for advertising, creditworthiness, lending, or unrelated profiling. Google user data is not transferred to train or improve a general-purpose or non-personalised AI model.
Google connection tokens are encrypted and retained only while the integration remains connected. Task results may appear in your encrypted Sirko conversation history under the retention periods below. Short-lived caches are isolated per user and removed automatically. Disconnecting Google revokes or removes the local connection; deleting your Sirko profile removes the associated stored Google-derived data according to the deletion process.
Sirko's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. Retention and deletion
- encrypted conversation history is normally retained for 30 days;
- durable preferences, reminders, and facts remain until you change or delete them;
- group context and pending private-disclosure requests expire after 24 hours;
- temporary audio links and precise current-location results expire after 24 hours or are deleted sooner after use;
- expired confirmations, temporary jobs, and short-lived caches are removed automatically.
You may disconnect an integration at any time. To request an export or deletion of your Sirko profile and associated data, email info@mitchellgroup.eu from your verified account. Sirko will verify the request before deleting data or revoking connected-service tokens.
7. Security and user separation
Sirko uses verified channel identities, tenant-bound access checks, encryption in transit, platform encryption at rest, and additional authenticated encryption for sensitive application fields. Connection tokens and private data are not placed in public logs. Private group requests cannot directly access an owner's connected sources.
No internet service can promise absolute security. Sirko minimizes exposure through least-privilege access, short retention, revocable connections, rate limits, and tested isolation boundaries.
8. Mobile Plugin
The optional Sirko Mobile Plugin responds only to explicit, authenticated requests. It does not read chats, browsing history, or screen contents and does not create passive location history. Precise location is requested only for a current-location, route, or explicitly started visible workout feature.
9. Your choices and rights
You can ask what Sirko remembers, correct it, remove it, disconnect providers, request a portable export, or request deletion. Where applicable, you may also object to or restrict processing and lodge a complaint with your local data-protection authority.
10. Changes to this notice
Material changes will be shown on this page with a new update date. If a change requires new permissions or materially different use of connected data, Sirko will request fresh consent before enabling it.