Privacy

Last updated 15 August 2026

1. Who we are

Isola is operated from the United Kingdom. For UK GDPR, we are the data controller for account data and the processor for the figures teams enter. Contact: isola@sundappleapp.com

2. What we hold

  • Account: your name, email address, and a hash of your password. We never store the password itself.
  • Financial: the splits your team agreed, payout figures entered, expenses, advances, and what has been paid.
  • Payment references: if you record a payment, whatever reference you type. We suggest a bank reference; we do not ask for and do not want account numbers.
  • Discord: your Discord user ID, only if you link an account. Nothing else from Discord — Isola cannot read your messages, your servers, or your member lists.
  • Technical: a session cookie so you stay signed in, and server logs.

We do not hold tax identification numbers, bank account details, or identity documents.

Payment files

A payment file contains each contributor’s name, the amount they are owed, and a payment reference — data you already hold in Isola, arranged in a format your bank reads.

No bank account details are involved. Isola has never asked for a sort code, account number or IBAN, does not store them, and does not put them in the file. Those fields are left for you or your bank to complete.

We record that a file was downloaded, by whom, how many people it covered and the total, in the team’s audit trail alongside every other action. We do not keep a copy of the file itself.

3. Why we hold it

To perform the contract with you — running the product you signed up for. Nothing here is used for advertising or profiling, and we do not sell or share it with anyone for their own purposes.

4. Who else sees it

  • Your team. The owner sees balances owed across the team. Contributors see only their own account. One contributor cannot see another's statement.
  • Our hosting provider, who stores the data on our behalf under contract.
  • A payment processor, if you subscribe. They handle card details; we never see them.

Nobody else.

5. Where it lives

On servers in the United Kingdom or European Economic Area. If that ever changes we will say so here first.

6. Keeping and deleting it

This is the part worth reading properly, because there is a real tension and we would rather set it out than gloss over it.

Isola's value comes from the ledger being append-only. Entries are never edited or deleted; a correction is a new entry that reverses an old one. That is what makes it possible to show what your team agreed in September when you are arguing about it in December.

That sits awkwardly with the right to erasure. Our position:

  • You can ask us to delete your account — name, email, password hash, Discord link — and we will.
  • We will not delete ledger entries, because they are also your collaborators' financial records and because financial records carry retention obligations. Your entries are anonymised against a contributor reference instead of your name.
  • Records are kept for as long as required for accounting purposes, currently six years, then deleted.

If that trade-off is not acceptable to you, export your statement and close your account before you have anything credited.

7. Your rights

You can ask for a copy of what we hold, correction of anything wrong, deletion as described above, or a portable export. The last one needs no request: your statement of account exports as CSV from your own page, on any plan, at any time, including if the team stops paying.

If you think we have handled your data badly, tell us first, and you can complain to the Information Commissioner's Office at ico.org.uk.

8. Cookies

One cookie, to keep you signed in. It is HttpOnly, SameSite=Strict, and Secure. There is no analytics, no tracking, and no advertising cookie, which is why there is no cookie banner.

9. Security

Passwords are hashed with scrypt. Sign-in attempts are rate limited. Everything travels over HTTPS. Sessions expire and are invalidated when you reset your password.

No system is perfect. If we ever have a breach affecting your data we will tell you and the ICO within the time the law requires.

10. Changes

If we change anything material here we will tell you by email rather than quietly updating the page.

Deleting a team

A team owner can delete a team entirely. Isola refuses while anyone is still owed money, because deleting the record of a debt is not housekeeping. Everyone else on the team is emailed once it is done, and their own accounts are unaffected.

Deleting your account

You can delete your account at any time from your account screen. Under UK GDPR you also have the right to a copy of everything we hold about you, which the same screen provides as a file.

What is destroyed: your name, email address, password, sessions, and any linked Google or Discord account.

What is kept: the figures on your team’s books, without your name on them. Two reasons. A team’s accounts only reconcile when everyone’s figures are present, so removing yours would make your former colleagues’ statements wrong. And UK law requires business records to be kept, which Article 17(3)(b) of the UK GDPR permits as an exception to erasure.

After deletion, the entries show an anonymous placeholder. You cannot be identified from them, and the same placeholder is not reused, so you cannot be recognised across teams.

If you are the only owner of a team that still has other people in it, you will be asked to make somebody else an owner first. Otherwise they would lose access to their own records.