selfmanaged

Privacy policy

Draft for review: we’re still checking this page before selfmanaged opens to the public. Last updated 24 September 2026.

Who we are

selfmanaged is run by Lettings Management Ltd (company number 12072778, registered office 31 High Street, Lyndhurst, SO43 7BE). We’re registered with the Information Commissioner’s Office as a data controller, registration number ZA763400. For anything about personal data, email privacy@selfmanaged.co.uk. We haven’t appointed a data protection officer; that address reaches the person responsible.

Two kinds of personal data

We handle two kinds of personal data, and our role differs for each.

Your account: your name, your email address and how you use selfmanaged. We decide how this is used, so for it we are the controller, and this policy explains what we do with it.

Your records: the properties, tenancies, tenants, rent, notices, certificates, pet requests, repairs, photos, conversations and emails you keep in selfmanaged. You decide what goes in and why. Where data protection law applies to you, you are the controller of your records, and we process them for you, on your instructions, under the data processing terms in our Terms of service. We use your records only to provide selfmanaged to you, to keep it secure and working, and where the law requires it.

What we collect about you

  • When you sign up: your name, your email address and a password. Your password is stored only as a one-way hash by our sign-in provider, Supabase; nobody can read it.
  • For your account: your plan, your trial dates, and the email address we make for you. The first part of that address comes from your name, followed by four random letters and numbers, so anyone you give it to sees your name.
  • When you sign in: the time, and the IP address and browser details of your device, kept with your sign-in session.
  • If you turn certificate reading on or off: who did it, when, and which version of the explanation was on screen. We also count how often you use certificate reading and “Try fetching again”, so we can apply the daily limits.
  • In an evidence file: your user id and sign-in email are recorded on each entry you add.

We don’t take payment details: paid plans aren’t on sale yet. We don’t use analytics or advertising tools, and we don’t track you across other websites.

Your records

What you enter: property addresses; tenancy dates, rent and deposit details; your lead tenant’s name, email address and phone number; rent dates and what you recorded about them; rent increase notices and tribunal dates; certificates (dates, reference numbers, the engineer’s registration number); pet requests and your answers; repairs, their costs, and the trades you use (name, trade, phone, email, registration number); conversations you record (when, how, who, and what was said); and the photos and files you add.

Photos are kept exactly as taken, including any location data your phone stored in them, which is usually where the photo was taken. We keep them unchanged so each file’s fingerprint (SHA-256) still matches the original.

Email to your selfmanaged address

Receiving email isn’t switched on yet. Until it is, email sent to a selfmanaged address stays with Resend, which keeps it for 30 days, and doesn’t reach selfmanaged.

When someone emails your selfmanaged address, we keep: the sender’s address and name; the other addresses it was sent to; the subject and date; the text (any formatting is turned into plain text); the receiving server’s checks on the sender; the original email file, up to 25 MB; and attachments that are PDFs, pictures or plain text (up to 10 an email, 10 MB each).

Emails can contain other people’s personal data, and sometimes sensitive information such as someone’s health. Only forward what matters to the tenancy.

Why we use your data, and our lawful basis

To create and run your account and provide selfmanaged
It is necessary for our contract with you (UK GDPR Article 6(1)(b)).
To keep selfmanaged secure, prevent misuse and fix faults, using sign-in records, IP addresses, service logs and usage limits
Our legitimate interest in running a secure, reliable service (Article 6(1)(f)).
To keep a record of when certificate reading was turned on or off, and what the explanation said
Our legitimate interest in being able to show what was chosen (Article 6(1)(f)).
To answer you when you email us
Our legitimate interest in replying (Article 6(1)(f)), or our contract with you if you have an account.
To meet legal obligations, such as a lawful request from a court or regulator
Article 6(1)(c).

You need to give your name and email address to create an account. Without them we can’t provide one.

Who else handles personal data

Supabase

Supabase stores the database, the files and the sign-in system, and runs the code that receives email. Our project is hosted in London (region eu-west-2). It is provided by Supabase Pte. Ltd. Where data is accessed from outside the UK, Supabase’s data processing addendum covers the transfer with the EU standard contractual clauses and the UK Information Commissioner’s addendum to them.

Vercel

Vercel Inc. (United States) serves the selfmanaged website and the app’s pages to your browser. It receives your IP address and browser details when a page loads. It doesn’t receive your records: those go straight between your browser and Supabase. Vercel takes part in the UK Extension to the EU-US Data Privacy Framework, which UK law approves for transfers.

Resend

Resend (Plus Five Five, Inc., United States) receives every email sent to a selfmanaged address and passes it to us. Emails to selfmanaged addresses arrive at a receiving server in Ireland. Resend says its main processing takes place in the United States, and it keeps received emails for 30 days. Transfers are covered by its data processing addendum (the standard contractual clauses with the UK addendum) and by its participation in the UK Extension to the EU-US Data Privacy Framework.

Anthropic, only if you turn on certificate reading (Premium)

Then the attachment to be read is sent to Anthropic’s AI model, Claude. That is the PDF or photo of the certificate, never the words of the email. Claude sends back the dates, address and certificate number it reads. Our contract is with Anthropic Ireland, Limited. Anthropic’s commercial terms say it may not train its models on what we send. Anthropic deletes what we send within 30 days, unless it needs to keep it longer to enforce its usage policy or because the law requires it. It may be processed outside the UK; the transfer is covered by the UK Information Commissioner’s International Data Transfer Addendum to the standard contractual clauses in Anthropic’s data processing addendum. Certificate reading is off until you turn it on in Account, and you can turn it off there at any time.

Copies of the transfer safeguards

For the transfers that rely on standard contractual clauses (Supabase, Resend and Anthropic), you can ask us for a copy of the safeguards at privacy@selfmanaged.co.uk.

Our replies and notices to you

When we reply to you, or send a notice these terms or the law require, we send it through to be added.

Fonts and code

The fonts and the code library the app and this website use are served from selfmanaged’s own site, through Vercel, so no font service or code host receives your details.

No one else

We don’t sell personal data. We don’t share it with anyone other than the providers above, unless the law requires us to.

Cookies and your browser

selfmanaged doesn’t set cookies, and this website (www.selfmanaged.co.uk) stores nothing in your browser.

When you sign in to the app, it keeps your sign-in session in your browser’s local storage, under the name sb-cyquzsaypfmiqihkorcr-auth-token, so you stay signed in on that device until you sign out. It holds sign-in tokens and your account’s id, email address and name. Signing out removes it.

When you sign up, the app keeps the email address you used in that tab’s session storage, so the “check your email” page can show it and send the link again. It’s removed when you close the tab. The sample keeps everything in the page’s memory, so nothing is saved.

Our database provider’s network (Cloudflare, for Supabase) may set a cookie called __cf_bm on supabase.co when your browser loads a photo or file. It lasts 30 minutes and is used to tell people from automated traffic.

All of these are strictly necessary for the service you asked for, so the law doesn’t require your consent (Privacy and Electronic Communications Regulations 2003, Schedule A1, paragraph 4).

How long we keep it

While your account is open we keep your account and records; selfmanaged deletes nothing on a timer. Evidence files can’t be edited or deleted in the app, because they are a record of what happened. You can’t yet delete individual records yourself. If you need something removed, email privacy@selfmanaged.co.uk and we’ll do it on your instruction.

When your account is deleted, we delete everything in it: your records, every evidence file, your emails and attachments, your photos and files, and your sign-in. Copies remain for a short time after that: in the database’s daily backups for up to 7 days, at Resend for up to 30 days after each email arrived, at Anthropic for up to 30 days after a certificate was read (longer only if Anthropic must keep it to enforce its usage policy, or by law), and in service logs for up to 7 days. How to delete your account.

Service logs, which include IP addresses and the approximate location they imply, are kept for 7 days.

Emails to support@, privacy@ and hello@ are kept while we deal with them and afterwards as a record of what was asked and answered. We don’t yet delete them on a timer, but we will if you ask.

Security

Each account can see only its own records, and the database itself enforces this, not just the app. Photos and files are kept in private storage, and the links the app uses to show them stop working after an hour. The app, the website and our providers talk to each other only over encrypted connections (HTTPS). Email sent to a selfmanaged address is encrypted on the way in when the sender’s mail server supports it. Passwords are stored only as a one-way hash. Nothing in an email you receive runs or loads when you open it: the app shows only its text.

We can technically reach the database to run and fix the service, but we look at your records only if you ask us to, to fix a fault or deal with misuse, or when the law requires it.

Photos and attachments aren’t included in the daily backups, because our storage provider doesn’t back up files on any plan. Keep your own copies of anything important.

Your rights

You have the right to: get a copy of your personal data; have it corrected; have it deleted; restrict how we use it; object to uses based on our legitimate interests; and take the data you gave us, in a machine-readable form, to use elsewhere. Some rights depend on why we hold the data.

To use any of them, email privacy@selfmanaged.co.uk, from the address on your account if you have one. It’s free. We’ll reply within one month. If a request is complex we can extend that by up to two more months, and if so we’ll tell you why within the first month. We may first ask you to confirm who you are. Before we delete an account because of an emailed request, we email the address on it to check the request came from the account holder. You can also delete your account yourself in the app, under Account.

Complaints

If you’re unhappy with how we’ve handled personal data, please tell us first at privacy@selfmanaged.co.uk. We’ll acknowledge your complaint within 30 days and let you know what we’ve done about it.

You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, or by phone on 0303 123 1113.

If your landlord uses selfmanaged

If your landlord uses selfmanaged, they decide what to record about you and why. For that information your landlord is responsible under data protection law, and we act for them. To see, correct or remove what your landlord has recorded, ask your landlord first. If you contact us, we’ll pass your request to them and help them answer it.

Emails you send to your landlord’s selfmanaged address pass through Resend and are kept in selfmanaged for your landlord.

If you email us

If you email support@, privacy@ or hello@selfmanaged.co.uk, we keep your email address, your name, your message and any attachments so we can deal with it. A person reads every email; nothing replies automatically.

Receiving email isn’t switched on yet: until it is, these emails stay with Resend, which keeps them for 30 days, and we read them in Resend’s own service. Once it’s on, they pass through Resend and are stored in selfmanaged’s database in London, where only we can read them.

Marketing and automated decisions

We don’t send marketing emails. We email you only about your account: sign-in emails (to confirm your address, sign in with a link, change your address or reset your password), replies when you write to us, and notices these terms or the law require (such as changes, and a personal data breach).

We don’t make decisions about anyone by automated means that have legal or similarly significant effects. Certificate reading reads dates from a document; you check them, and you can undo them.

Changes to this policy

If we change this policy, we’ll update the date at the top. If a change affects how we use personal data you’ve already given us, we’ll email you before it takes effect.