Privacy Policy
Version 1.0 · August 7, 2026
Sunmetry is a monitoring platform for industrial solar power plants: the sunmetry.com website, the app.sunmetry.com web application, a phone app and a desktop app. Access is invite-only — there is no public sign-up.
This policy explains what data we process, why, who we share it with, and what your rights are. We collect the minimum, show no ads, sell no data and use no advertising trackers.
At a glance: what happens to your data
| Data | Why | Shared with | How long |
|---|---|---|---|
| Account: name, work email, role, phone (if provided) | Sign-in and operation of the service, invitations, password recovery | No one | Duration of the contract + up to 6 months |
| Sign-in and language cookies | To keep you signed in and show your language | No one | From 12 hours to 1 year |
| Push subscription and Telegram (enabled by you or your administrator) | Alert notifications and reports | Delivery services: Google, Apple, Mozilla, Telegram | Until the channel is turned off |
| Telemetry and coordinates of your company's plants | Monitoring and yield forecasting under the contract with your company | Open-Meteo — coordinates, for weather forecasts | Defined by the contract with the client company |
| Questions to the AI assistant in Telegram (text and voice) | The assistant's answer about your plant | OpenAI — at the moment of your request | Processed to produce the answer |
| Technical logs: IP address, sign-in events | Security and troubleshooting | No one | Limited period needed for diagnostics |
We do not collect payment details, advertising identifiers or your devices' geolocation. We never sell data or share it for advertising.
1. Who we are and what this policy covers
Data controller: [РЕКВИЗИТЫ ОПЕРАТОРА: ФОП/ООО, адрес — ждут подтверждения]. Privacy contact: info@sunmetry.com.
This policy covers the sunmetry.com website, the app.sunmetry.com web application, the phone and tablet app installed from the website, and the Sunmetry desktop apps for Windows and macOS. They all work with the same data and the same account.
2. Our roles: controller and processor
For user accounts, cookies and notification subscriptions we are the data controller: we decide why and how to process them and are accountable to you.
Plant telemetry, coordinates, production figures and credentials for third-party metering portals are uploaded to the service by the client company, which remains the owner of that data. We process it only on the company's instructions under our contract with it (as a processor). That processing is governed by the client contract; this policy describes it briefly, for transparency.
If you are an employee or contractor of a client company and have questions about your plant's data, please contact your company first — decisions about that data are made by it.
3. Personal data we collect
- —Account: name, work email, role in the system, phone (if entered by the administrator).
- —Sign-in data: IP address, sign-in time, device and browser type — in technical logs.
- —Notification subscriptions: the browser push subscription address and/or Telegram chat identifier — when these channels are enabled (push — only by you; Telegram — by you or your administrator).
- —Questions to the AI assistant: text and voice messages you send to the Telegram bot yourself (voice is transcribed to text).
- —Support correspondence: emails to info@sunmetry.com.
We do not collect: payment details (there are no payments in the app), advertising identifiers, your devices' geolocation, or data from your contacts and files.
4. Plant data and telemetry
This is technical equipment data, not data about people. We group it into categories:
- —Performance data: generation, power, currents, voltages, meter readings.
- —Equipment data: inverter and meter models, serial numbers, plant configuration and coordinates.
- —Events: faults, warnings, equipment logs.
By itself such data is not personal. However, where a plant is owned by an individual, its coordinates and output may indirectly identify them, so we protect telemetry as strictly as personal data: encryption in transit, role-based access, isolation between clients.
Credentials for third-party monitoring and metering portals are provided by the client company; our staff enter them on its instructions. We store them encrypted and use them solely to automatically collect that company's data.
5. How and on what grounds we use data
- —Providing the service — sign-in, plant views, reports. Basis: performance of a contract.
- —Alert notifications and reports. Push is enabled only by you (basis: consent). Telegram is linked by you or your company's administrator — the bot only starts messaging after you press Start yourself (basis: consent). Major-fault notifications and reports are also duplicated by email — recipients are assigned by your company's administrator (basis: performance of a contract).
- —AI assistant in Telegram: your questions (text and voice) are processed to produce an answer about your plant. It runs only on your request. Basis: performance of a contract.
- —Security and diagnostics: sign-in and technical event logs. Basis: our legitimate interest in protecting the service and client data.
- —Service emails: invitations, password recovery, address verification. Basis: performance of a contract.
We do not use data for advertising, do not profile users, and make no automated decisions with legal effects on you.
6. Cookies and local storage
We use strictly necessary cookies only — the service cannot work without them. There are no advertising or analytics cookies, so no consent banner is required.
- —sunmetry_token — signs you in; lives 12 hours.
- —sunmetry_session — renewable session marker; up to 30 days.
- —sunmetry_lang and NEXT_LOCALE — selected language; up to 1 year.
- —sunmetry_refresh — renews your sign-in without re-entering the password (not accessible to scripts); up to 30 days.
- —sunmetry_station — last selected plant; up to 180 days.
The app also keeps an interface cache on your device (for poor connectivity) and display preferences. All of it is removed when you clear browser data or uninstall the app.
7. Who we share data with
We do not sell data and do not share it for marketing. Data is seen only by the infrastructure providers the service cannot run without:
- —Hostinger International Ltd — server hosting and email service (our emails are sent through it).
- —Push delivery services of Google, Apple and Mozilla — only if you enable push; they deliver an encrypted notification to your device.
- —Telegram — if Telegram is linked (by you or your administrator) and you pressed Start with the bot; the bot sends notifications to your chat.
- —OpenAI — only when you use the AI assistant in Telegram: it processes your question (including voice transcription) and the plant data needed for the answer.
- —Open-Meteo — a weather forecasting service: it receives plant coordinates to compute yield forecasts.
- —Map services OpenStreetMap, Esri and RainViewer — when you open the map or rain radar, your browser requests map imagery directly from them: they see your IP address and the requested map area.
Data is disclosed to public authorities only upon a lawful, properly issued request.
8. International data transfers
The service's servers are located in a Hostinger data center in the United States. Data is transferred there to the extent necessary to perform the contract with you and your company (for users in Ukraine — in accordance with Article 29 of the Law of Ukraine “On Personal Data Protection”).
For clients from the EEA and the UK, transfers will additionally be protected by Standard Contractual Clauses (SCC) — see the regional supplement below.
9. Retention
- —Accounts — for the duration of the contract with your company, then up to 6 months (for access recovery and final settlement), after which they are deleted or anonymized.
- —Telemetry and plant data — the period is defined by the client company's contract; on termination the data is returned or deleted at its choice.
- —Technical logs — a limited period needed for diagnostics and security incident investigation.
- —Backups — a limited period, after which they are replaced by newer ones; deleted data disappears from backups as they rotate.
10. Security
Data travels only over encrypted channels (HTTPS/TLS). Passwords are stored as irreversible hashes. Metering portal credentials are stored encrypted and are accessible only to the system collection process. User access is role-based; clients' data is isolated. No security is absolute, but in the event of an incident affecting your data we will notify you and, where required, the regulator within the timeframes set by law.
11. Your rights
You have the right to: know what data of yours we process; obtain a copy; correct inaccuracies; delete data (absent a legal need to keep it); restrict processing; object to processing based on legitimate interest; withdraw consent (push is turned off in the settings; Telegram — via your administrator or by blocking the bot); receive your data in a portable format.
How to exercise them: write to info@sunmetry.com from your account email. We reply within 30 days; for complex requests the period may be extended by another 30 days with notice.
If you are a client company's employee and the request concerns plant data, we will forward it to your company — decisions about that data are made by it.
12. Regional supplements
Ukraine
Processing complies with the Law of Ukraine “On Personal Data Protection” No. 2297-VI. You have all rights under Article 8, including the right to know about processing, access, rectification and erasure. Complaints may be filed with the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua) or in court.
EEA and United Kingdom
For EEA/UK users, the legal bases are listed in Section 5 (contract — Art. 6(1)(b) GDPR, consent — 6(1)(a), legitimate interest — 6(1)(f)). You may lodge a complaint with your country's supervisory authority. International transfers are protected by Standard Contractual Clauses (SCC). A data processing agreement (DPA) is concluded with EEA client companies.
United States (California)
We do not sell personal information and do not share it for cross-context behavioral advertising — and have not done so in the preceding 12 months. We voluntarily extend access, deletion and correction rights to California residents — via the same address, info@sunmetry.com, without discrimination for exercising them.
13. Children
Sunmetry is a work tool for companies. The service is not intended for anyone under 18, and we do not knowingly collect their data.
14. Changes to this policy
The version and date appear at the top of this page. We will notify users of material changes in advance by email or an in-app notice. Continued use of the service does not substitute for consent where the law requires separate consent.
15. Contact
Data controller: [РЕКВИЗИТЫ ОПЕРАТОРА: ФОП/ООО, адрес — ждут подтверждения].
For any privacy question: info@sunmetry.com. We respond within 30 days.