In plain words
- For your account, billing and our website we decide how data is used. For the people who use your app, you decide and we act only on your instructions.
- We collect little. The website sets no analytics or advertising cookies, and the dashboard uses only the cookies it needs to keep you signed in.
- Values of password, card and ID fields that Stiro recognises stay in the browser. Our AI providers' terms prohibit training on what we send them.
- We never sell personal data or use it for advertising.
- Data is hosted mainly in the United States and accessed from India. Transfers from the EU and UK are covered by the Standard Contractual Clauses.
- Write to privacy@stiro.ai to see, correct or delete your data. We reply within 30 days.
This summary helps you read the document. It is not part of it, and the full text below governs.
1. Who we are
Stiro is run by a sole proprietorship based in India (“Stiro”, “we”, “us”); postal address for notices: available on request from hello@stiro.ai. This policy explains how we handle personal data when you visit stiro.ai, sign up for or use the Stiro dashboard, buy a plan, or contact us, and how Stiro handles data inside our customers’ apps.
Words such as “Customer”, “End User” and “Your App” have the meanings given in our Terms of Service.
2. Our two roles
As a controller. We decide how personal data is used for our own purposes: our website, customer accounts, billing, support, security, and communication with customers. Sections 3 to 11 describe this.
As a processor. When a business installs Stiro in its app, the people using that app (End Users) interact with Stiro. For their data, the business is the controller, and we process the data only to provide the Service on its instructions, under our Data Processing Addendum. If you are an End User, the privacy notice of the app you are using applies, and requests about your data should go to that business. If you contact us instead, we will pass your request to them. Our Data Use page describes this processing in detail.
3. What we collect
When you visit stiro.ai
- Technical data. Our website is served by Cloudflare, which processes your IP address, browser details and the pages you request, to deliver the site and protect it from attacks.
- Campaign tags. If you arrive through a link with campaign tags (such as
utm_source), the site keeps them in your browser’s session storage for that visit and adds them to sign-up links, so we can tell which channels bring customers. They are deleted when you close the tab. - Waitlist. Until sign-ups open, you can leave your email address to hear when they do. We keep the address, when you joined and which form you used, nothing else. The form uses Cloudflare Turnstile to tell people from bots, which looks at technical details of your browser and connection for that check. To stop one network flooding the list, we store a salted one-way hash of your IP address with the entry, never the address itself.
We do not use analytics, advertising or social-media tracking cookies on stiro.ai. The waitlist is the only form on the site.
When you create and use an account
- Account data: your email address and password. We store the password only as a one-way cryptographic hash, never in readable form.
- Workspace data: workspace and site names, the domains you allow, site keys (the secret parts stored encrypted), members and their roles.
- Usage data: the runs made through your sites, with their outcome, timing, task counts and cost, as described on our Data Use page.
- Cookies: the dashboard sets a session cookie to keep you signed in and, if you choose “remember me”, a cookie that lasts up to 14 days. Both are strictly necessary, and there are no others.
- Security data: IP addresses are used briefly, in memory, to limit abuse. We do not store them against your account.
You must give an email address and password to create an account, and billing details to buy a plan. Without them we cannot provide the Service.
When you buy a plan
Our reseller and merchant of record, Dodo Payments, collects your payment details directly. We never receive your full card number. From Dodo we receive your name, email address, billing country and address, tax ID if you give one, and the status of your subscription and payments.
When you contact us
We keep your emails and our replies so that we can help you and keep a record.
4. Why we use it, and our legal bases
| Purpose | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Providing the Service and your account | Account, workspace and usage data | Performance of our contract with you |
| Billing, invoices and tax | Billing and subscription data | Contract and legal obligation |
| Service emails (sign-in links, payment notices, changes to terms) | Email address | Contract and legitimate interests |
| Security, abuse prevention and fraud checks | Technical, security and usage data | Legitimate interests in keeping the Service and our customers safe |
| Understanding which channels bring customers | Campaign tags | Legitimate interests |
| Improving the Service with aggregated, de-identified statistics | Usage data, aggregated | Legitimate interests |
| Telling you once when sign-ups open | Waitlist email address | Consent, given by joining the waitlist, which you can withdraw at any time |
| Occasional product news to business contacts | Email address | Legitimate interests, with an easy opt-out, or consent where the law requires it |
| Meeting legal obligations and defending claims | As needed | Legal obligation and legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights and expectations. You can object at any time (section 9). Under India’s Digital Personal Data Protection Act, 2023, we process your data for the specified purposes you provide it for and for the legitimate uses the Act allows.
5. What we never do
- We never sell personal data or share it for cross-context behavioural advertising.
- We never use data from inside our customers’ apps to train AI models, and we do not allow our AI providers to.
- We never use what we learn about one customer’s app to serve another customer.
- We never make decisions about you based solely on automated processing that have legal or similarly significant effects.
6. Who we share it with
We share personal data only with:
- Our service providers, who process it on our behalf under contract. We list them, with what they do and where, on our Data Use page. For the waitlist, Cloudflare stores the list and runs Turnstile, and Telegram carries a daily summary of new entries to our own private chat.
- Dodo Payments, our reseller and merchant of record, which acts as an independent controller for payments, invoices and tax under its own privacy policy.
- Authorities or others, where the law requires it, or where it is necessary to protect the rights, property or safety of Stiro, our customers or others. We may challenge requests that seem overbroad.
- A successor, if our business is reorganised or transferred. The successor would be bound by this policy.
7. International transfers
We are based in India, and our servers and main providers are in the United States. Your data may therefore be processed outside your country. For personal data from the European Economic Area, the United Kingdom or Switzerland: for data we process for customers, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum and Swiss amendments) in our Data Processing Addendum; for our own data, on the Standard Contractual Clauses or the EU-US Data Privacy Framework in our contracts with service providers.
8. How long we keep it
- Waitlist: kept until we have emailed you once, when sign-ups open, and then deleted. We delete an entry sooner if you ask. The IP hash goes with the entry, the copies in our Telegram chat are deleted at the same time, and the per-network counts used for the abuse limit are deleted after a day.
- Account and workspace data: while your account exists. We delete it within 30 days after you ask us to close your account.
- Usage data: while the workspace exists. It is deleted with the workspace.
- Billing records: as long as tax and accounting law requires, generally up to 8 years.
- Emails with us: up to 3 years after the conversation ends.
- Server logs: a rolling buffer of about 100 MB per server, with the oldest entries overwritten.
- Backups: encrypted nightly backups are kept for 35 days and then deleted automatically. Deleted data may remain in them until then.
9. Your rights
Depending on where you live, you may have the right to:
- access your personal data and get a copy of it;
- correct inaccurate data;
- delete your data (the “right to be forgotten”);
- restrict or object to our processing, including processing based on legitimate interests or used for direct marketing;
- port your data to another service in a common format;
- withdraw consent, where we rely on it, without affecting processing that already took place;
- nominate someone to exercise your rights if you die or become incapacitated (India); and
- complain to a data protection authority, such as your local supervisory authority in the EU, the UK Information Commissioner’s Office, or the Data Protection Board of India. We would appreciate the chance to resolve your concern first.
California and other US states. Residents of California and states with similar laws have the rights to know, delete and correct personal information, and to opt out of its sale or sharing. We do not sell or share personal information and do not use sensitive personal information to infer characteristics. We will not treat you differently for exercising your rights.
How to use them. Email privacy@stiro.ai from the address on your account, or explain how we can verify you. We reply within 30 days, and may extend that where the law allows, telling you why. We may keep data where the law requires us to or where we need it to establish or defend legal claims.
10. Security
We protect personal data with measures suited to the risk, including:
- encryption in transit (TLS) everywhere;
- each workspace’s data isolated from every other’s;
- hashed passwords and encrypted secrets;
- encrypted backups, kept separately and protected against deletion;
- least-privilege access, with multi-factor authentication on administrative accounts.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities where the law requires, without undue delay.
11. Children
Stiro is a business service for adults. It is not directed to children, and we do not knowingly collect children’s personal data as a controller. If you believe a child has given us personal data, write to privacy@stiro.ai and we will delete it.
12. Changes to this policy
We may update this policy as the Service or the law changes. We will show the new date at the top, and for material changes we will email account owners or notify them in the dashboard before the change applies.
13. Contact
Write to us at privacy@stiro.ai. Postal address: available on request from hello@stiro.ai.
Grievance Officer (India). Write to the Grievance Officer at privacy@stiro.ai. We aim to acknowledge complaints within 24 hours and to resolve them within 15 days.
EU and UK. Please contact us directly at privacy@stiro.ai.