JSONsilo

Privacy Policy

Last updated: 2 September 2026

This policy explains what information JSONsilo collects when you use the site and service, how it is used and shared, and the controls you have over it.

1. Who we are

JSONsilo (“JSONsilo”, “we”, “us” or “our”) is a hosted JSON store that you can query over HTTP. The service is operated by Jairon Landa as sole operator. This policy covers the marketing site at jsonsilo.com, the console at console.jsonsilo.com and the API at api.jsonsilo.com.

For the purposes of the EU and UK GDPR, we are the “data controller” for account and site data. For the JSON you store in a silo, you are the controller and we act as your “data processor” — we process that content only to run the service and on your instructions.

If you have any question about this policy or your data, contact us at hello@jsonsilo.com.

2. Information we collect

2.1 Information you give us

  • Account information. When you register through the console we collect your email address, an authentication identifier, and any name or profile details you choose to provide. Sign-up and login are handled by Firebase Authentication (a Google service), which stores your email address and password credential on our behalf. JSONsilo receives your Firebase account identifier and email address; we never see or store your password.
  • Silo content. The JSON documents you create, upload, edit or query, together with their metadata (silo name, visibility, chosen region, timestamps). You decide what goes into a silo; please do not store sensitive personal data you do not need to.
  • Billing information. If you buy a paid plan, our payment provider (LemonSqueezy) collects your payment details and billing address and shares limited information with us — your plan, billing country, the last four digits and brand of your card, and invoice records. We never receive or store your full card number.
  • Support and other communications. Messages, feedback and attachments you send us by email or other channels.

2.2 Information we collect automatically

  • Log and technical data. When you use the site or call the API, our infrastructure provider (Cloudflare) processes request metadata such as IP address, timestamp, user agent, referring page, the endpoint requested and the response status. This is used to route and cache requests, enforce rate limits and protect against abuse. Requests to the console API are rate limited per IP address.
  • Account activity log. We record the actions you take on your silos — the action, the silo identifier and name, and the time — against your account identifier, so you can review recent activity in the console.
  • Request analytics. We count the API requests made to each silo, recording the silo, the account that owns it, the HTTP method and the response status. No IP address and no part of your request or response content is stored with these counts. We use them to apply plan limits and to show you the request charts in the console.
  • Error diagnostics. If something breaks, Sentry captures the error, its stack trace and the endpoint involved, plus a sample of performance data. It is configured not to attach personal data such as IP addresses, cookies or request bodies.
  • Bot protection. Sign-up and sign-in are protected by Cloudflare Turnstile. Solving the challenge sends a verification token and your IP address to Cloudflare so it can confirm the request is not automated.
  • Site analytics. The marketing site at jsonsilo.com uses Google Analytics 4, only if you accept it in the cookie banner shown on your first visit, to understand how the site is used — which pages are visited, how visitors arrive, and coarse device and country information. It sets the cookies described in section 6 and sends Google your IP address to derive an approximate location; Google Analytics 4 does not log or store that IP address. We have not enabled Google Signals, advertising features or cross-device tracking, and we do not use this data to build advertising profiles. If you decline, or simply ignore the banner, the Google Analytics script is never requested and none of this is collected. The console and the API run no analytics scripts.

3. How we use your information

  • To provide, operate, secure and maintain the service.
  • To create and administer your account and authenticate you.
  • To process payments, manage subscriptions and send invoices and billing notices.
  • To enforce plan limits, rate limits and our Terms of Service.
  • To monitor performance, debug errors and improve the product.
  • To respond to your support requests and send you service messages about security, changes and availability.
  • To detect, investigate and prevent fraud, abuse and activity that violates our terms or the law.
  • To comply with legal obligations and enforce our legal rights.

Legal bases (EU / UK)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract — to provide the service you have signed up for, including hosting your silos and processing payments.
  • Legitimate interests — to secure the service, prevent abuse, keep aggregate analytics and diagnostics, and communicate with you about the service, in each case balanced against your rights.
  • Legal obligation — to keep tax and accounting records and to respond to lawful requests.
  • Consent — where we ask for it, for example any optional marketing email. You can withdraw consent at any time.

4. How we share your information

We do not sell your personal information or your silo content, and we do not share it for advertising. We share information only with the service providers that make JSONsilo work, and where the law requires it:

  • Cloudflare — hosting, edge compute, request caching, DNS, bot protection (Turnstile) and network security. Cloudflare also holds the request analytics described in section 2.2 and short-lived cached copies of silo responses. See the Cloudflare Privacy Policy.
  • Turso — the managed SQLite database that stores your silo content, silo metadata, API key records, activity logs and subscription records. See the Turso Privacy Policy.
  • LemonSqueezy — our payment provider and merchant of record for paid plans. See the LemonSqueezy Privacy Policy.
  • Sentry — error monitoring and diagnostics. See the Sentry Privacy Policy.
  • Firebase Authentication (Google) — account creation, login and session management. Your email address and password are stored by Firebase on our behalf. See the Firebase Privacy and Security documentation.
  • Google Analytics (Google) — usage measurement on the marketing site only, as described in section 2.2. See Google’s Privacy Policy and how Google Analytics uses data.
  • Email delivery — account emails such as address verification and password resets are sent by Firebase Authentication; billing emails, including receipts and renewal notices, are sent by LemonSqueezy.

We may also disclose information:

  • to comply with a law, regulation, legal process or enforceable governmental request;
  • to enforce our Terms of Service, including investigating potential violations, or to protect the rights, property or safety of JSONsilo, our users or the public;
  • in connection with a merger, acquisition, financing or sale of assets, in which case we will require the recipient to honour this policy and will notify you of any change of controller.

5. Your silo content

You control what you store in a silo and who can read it. New silos are private and can only be read with a key you hold; you can choose to make a silo public, in which case anyone with the URL can read it without authentication. We access silo content only to operate the service (for example to serve, cache or query it on request), to provide support you ask for, or where we are legally required to.

Caching. To keep reads fast we cache silo responses and query results for a short period. Creating, updating or deleting a silo clears its cached copies immediately.

Regions. The region you pick for a silo selects the API hostname it is served from and is a plan feature; it is a routing and access choice, not a data residency guarantee. Silo content itself is held in a single managed database, currently hosted in Tokyo, Japan, and is served worldwide from our edge network. If you have data residency requirements, contact us before storing data that is subject to them.

Deletion. Deleting a silo removes its content and metadata from the database and clears its caches. Backup copies taken before the deletion may persist until they age out.

6. Cookies and similar technologies

  • Essential cookies. The console sets two strictly necessary cookies to keep you signed in: a session cookie holding your signed session credential, and a refreshToken cookie used to renew it. Neither can be read by scripts, both are sent over HTTPS only, and both are restricted so they cannot be used for cross-site request forgery. You can clear them by signing out. The console does not work without them, so they are not optional.
  • Bot protection. Cloudflare Turnstile may set a clearance cookie on sign-in and sign-up pages to record that a challenge was solved. It is used for security, not tracking.
  • Analytics cookies. The marketing site at jsonsilo.com asks, in a banner on your first visit, whether it may set two first-party Google Analytics cookies: _ga, which holds a randomly generated identifier for your browser, and _ga_0270MZJQ9G, which holds session state. Google’s default lifetime for both is about two years. Neither is set unless you accept. Declining is one click and costs you no functionality; if you decline after previously accepting, we expire both cookies and stop loading the script. Your choice is remembered in your browser’s local storage, not in a cookie, and you can change it at any time from the Cookie settings link in the footer. These cookies are never set on the console or the API.
  • No advertising or cross-site tracking cookies. We set no advertising or cross-site tracking cookies on any of our properties, and we do not sell or share what analytics collects.
  • Third-party cookies. When you go through checkout, LemonSqueezy may set its own cookies under its policy. Sentry does not set advertising cookies.

7. Data retention

  • Silo content is kept until you delete the silo. Deleting it removes the content and its metadata from our database and clears its caches.
  • Account data. Deleting your account from the console removes your login record (email address, password credential and account identifier) from Firebase Authentication. You must delete your silos first — account deletion is refused while any silo remains. Records tied to your account identifier that are not part of your login — API key records, activity log entries and subscription records — are removed or anonymised on request; email hello@jsonsilo.com and we will action it.
  • Activity log entries are written for silo and plan actions. The console only shows you the current day’s entries; older entries are pruned on a rolling basis.
  • Request analytics (section 2.2) expire automatically after about 90 days. How far back the console lets you query them depends on your plan.
  • Edge request logs held by Cloudflare for routing, caching and abuse prevention are retained short-term on that provider’s schedule.
  • Billing records are retained for as long as tax and accounting law requires (generally up to 7–10 years). LemonSqueezy keeps its own records as merchant of record.
  • Error diagnostics in Sentry are retained on that provider’s default schedule (typically 90 days).
  • Site analytics collected by Google Analytics are retained for the period set on our Google Analytics property; Google’s default for user-level and event-level data is 2 months. Google retains its own aggregate reporting for longer under its policy.
  • Cached copies expire on their own within hours, and immediately when you change or delete the underlying silo. Backups age out on a rolling schedule.

8. Security

All traffic to the site, console and API is encrypted in transit with TLS, and session credentials are held in HttpOnly, host-only cookies that scripts cannot read. Account passwords are held and hashed by Firebase Authentication — JSONsilo never sees or stores them. Sign-in and sign-up are protected by bot challenges, every plan is rate limited, and signing out everywhere invalidates every existing session on every device. Access to production systems is limited to the operator and protected by strong authentication.

Your API keys and management keys are credentials: they are stored so the service can verify them, they are shown to you in the console, and anyone holding one can read the silos it grants access to. Treat them as secrets, rotate them if exposed, and prefer management keys with a short expiry. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; if we become aware of a breach affecting your personal data we will notify you and any regulator as required by law.

9. International data transfers

JSONsilo runs on globally distributed infrastructure. Silo content and account records are held in a managed database currently hosted in Tokyo, Japan (AWS ap-northeast-1), and are served worldwide from Cloudflare’s edge network, which means data is processed in whichever country the request is served from. Our other providers (Cloudflare, Turso, Google — Firebase Authentication and Google Analytics — LemonSqueezy, Sentry) operate in the United States and elsewhere. Where personal data moves out of the EEA or the UK, the transfer is covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses (and the UK Addendum) with the relevant provider. As explained in section 5, a silo’s region is a routing choice and not a data residency guarantee.

10. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, restrict or object to certain processing, and withdraw consent. You can do most of this from the console, or by emailing hello@jsonsilo.com. We will respond within the time the law allows and will not discriminate against you for exercising these rights.

Opting out of site analytics. The simplest route is the cookie banner: choose Decline, or withdraw a previous acceptance from the Cookie settings link in the footer, and the Google Analytics script is not loaded at all. You can also stop it by installing Google’s opt-out browser add-on, by blocking cookies for jsonsilo.com, or by using a browser or extension that blocks analytics scripts. Nothing on the site or in the service depends on these cookies, so refusing them costs you no functionality.

If you are in the EEA or the UK you also have the right to complain to your local data protection authority. If you are in California, we do not sell or share personal information as those terms are defined under the CCPA/CPRA, and you may exercise your access and deletion rights through the same contact.

11. Children

Our Terms of Service require you to be 18 or older (or the age of majority where you live). JSONsilo is not directed to children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the service changes or the law requires. When we do, we will revise the “last updated” date above and, for material changes, give notice by email or a notice in the console before the change takes effect. Continuing to use the service after that means you accept the updated policy.

13. Contact

Questions, requests or complaints about privacy: hello@jsonsilo.com.