Skip to content
Serin, Empowering charities, CICs, & small businesses

Trust

How we protect your data

Charities, CICs and community organisations trust Serin with things that matter: how you're governed, what you do, your accounts, your funding applications and your policies. People rightly ask what we do to look after all that. This page is our plain-English answer, and every claim on it describes something that is actually in place. Last reviewed 25 September 2026. It works alongside our Privacy Policy, which covers what we collect and why.

Where your data lives

Serin's data is hosted in the European Union (Frankfurt). Everything travels over an encrypted connection, and stored data and files are encrypted too. Your documents sit in private storage that only your own organisation — and Serin's team, under the rules below — can reach. There is no public address for your files.

One organisation can never see another's

Everything you put into Serin belongs to your organisation, and the rule that separates you from every other organisation is enforced by the database itself — not by hiding things in the interface, which can be worked around. A different charity signing in cannot read, change or delete anything of yours, no matter what they try.

We don't just assume this works: we test it. We created two temporary test organisations and tried every single action the app offers — nearly three hundred of them — as one against the other's records. All were refused, and nothing changed. The test organisations were then deleted.

Who at Serin can see what

Nobody at Serin goes browsing through your organisation's content. Application answers, documents and policies can only be opened through a support access system that is used when you ask for help, logged with a written reason, limited to what the request needs, and expires automatically within 30 days. Some operational details — such as names, members, match results and subscription state — can be seen by our team for running the service; we restrict and review that access, and we'll keep narrowing it where we can.

Your account

You can turn on two-factor authentication with an authenticator app in Settings, and we'd encourage it. Your two-factor secret is stored encrypted, not in plain text.

Passwords are checked against lists of passwords that have appeared in real data breaches, so a compromised password is refused at the door. Repeated failed sign-in attempts are blocked, and sign-in sessions expire after an hour, renewing quietly while you're working.

Files you upload

When you upload a document, we check what the file really is from its contents, not just its name — a file pretending to be a PDF is refused. Files land in a private holding area that nothing can read, and stay there until every check has passed. Only then does the file move into your document library. If a file fails a check — infected, disguised or unreadable — it is deleted, and you're told plainly what happened. Until a file's checks pass, it cannot be downloaded, previewed, read by Serin or used in any feature.

AI, on your terms

Serin uses AI to help draft answers, tidy up dictated text and read documents you ask it to. It only runs when you trigger it, and it only ever works from what you've told Serin or uploaded — it never invents facts about your organisation, and where something is missing it leaves a gap for you to fill.

The AI models Serin uses are set up so that what you send is not kept or used to train anything — it's processed and forgotten. Raw voice recordings are never stored at all: they go straight to transcription in memory, and only the text you choose to keep is saved.

Payments

Subscriptions and the paid review service are handled by Stripe. Your card details are entered directly with Stripe and never reach Serin's servers — we never see or store card numbers.

What we will never do

  • Sell your data, to anyone, ever.
  • Share your answers, documents or profile with funders. Funders never see your organisation's information through Serin.
  • Use advertising or cross-site tracking. Website analytics only load if you say yes on the cookie banner.

Being honest about limits

No online system is perfect, and we won't pretend otherwise or claim certifications we don't hold. What we commit to is knowing exactly how Serin is built, testing it rather than assuming, and telling you plainly when something changes.

If you've found a security problem, or anything here seems wrong, please tell us: info@serin.uk. We take reports seriously and will get back to you quickly.

Questions about your data

For any question about your data — access, correction, deletion or anything on this page — email info@serin.uk or use the Talk to the Serin team form. We reply within one working day.

Related reading: our Privacy Policy and Terms of Service. This page was last reviewed on 25 September 2026.