Privacy Policy
Operated by Steaded, LLC · Last updated June 2026
Review note. This policy is a template prepared for Steaded, LLC and is not legal advice — have counsel review it before relying on it. Governing law: Delaware. Steaded uses a business mailing address (never a home address), provided on request and in email footers.
Steaded, LLC (“Steaded,” “we,” “us”) builds Steaded Ground — the Original Accountable Architecture. This policy explains what personal information we collect through our website (steaded.ai) and our product (steaded.app), how we use and share it, and the choices and rights you have.
- 1. Scope & our role
- 2. Information we collect
- 3. How we use information
- 4. Legal bases (GDPR)
- 5. Cookies & analytics
- 6. Visit Records (SealedVisit)
- 7. Email & marketing (CAN-SPAM)
- 8. How we share information
- 9. Data retention
- 10. Security
- 11. International transfers
- 12. Your privacy rights
- 13. Children’s privacy
- 14. Changes
- 15. Contact us
1. Scope & our role
This policy covers personal information processed when you visit steaded.ai, request a demo, use the public demo at steaded.app, or otherwise interact with us. It does not change the terms of any separate agreement you have with us.
Controller vs. processor. For our website, demo, and direct communications, Steaded is the controller of your personal information. For a dedicated client instance, the customer that operates the instance is the controller of the data it puts in, and Steaded acts as a processor on that customer’s behalf under our agreement (a Data Processing Addendum is available on request).
2. Information we collect
Information you give us
- Demo & contact. When you request a demo or email us, we receive your email address and anything you choose to include.
- Demo access. The public demo uses a lightweight email gate; we collect the email address you enter to grant access.
- Account information (instances). For a real instance, an administrator provisions users (name, email, team) and people may set profile details.
- Content you submit. Records, documents, messages, and other content entered into the product.
Information collected automatically
- Usage & device data. IP address, browser/device type, pages viewed, and timestamps, primarily in server and security logs.
- Analytics. We use privacy-friendly, cookieless, aggregate web analytics (Vercel Web Analytics); it does not track you across sites.
3. How we use information
- Provide, operate, secure, and improve the website and product.
- Respond to demo requests, inquiries, and support.
- Send transactional messages (e.g., access, account, and service notices).
- Send marketing communications where permitted — see section 7.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our terms.
AI features. AI in the product only ever receives data the acting user is entitled to see, and inputs submitted to our AI provider are not used to train its models under that provider’s commercial API terms. We do not sell personal information.
4. Legal bases (GDPR / UK GDPR)
Where the GDPR applies, we rely on: consent (e.g., optional marketing); performance of a contract (providing the service you request); legitimate interests (operating, securing, and improving our services); and legal obligation. You may withdraw consent at any time.
5. Cookies & analytics
Our website is designed to minimize tracking. Our analytics are cookieless and aggregate. We may use a small number of strictly necessary cookies or local storage to operate the site and the demo (for example, to remember demo access); these are not used for cross-site advertising.
6. Visit Records (SealedVisit)
Some pages on steaded.ai run a feature we call SealedVisit: a small script, running entirely in your browser, that keeps a hash-chained ledger of your visit — things like the pages and sections you view and the elements you click — and shows that ledger to you live, on the page, as it’s recorded.
Here is exactly what that means today, plainly:
- It runs client-side, in your browser. The hash chain is built and verified on your device, using the same tamper-evident chaining approach that runs inside the Steaded product.
- In the current version, this data stays in your browser. The visit ledger is stored in your browser’s localStorage and is not transmitted to or collected on our servers.
- It is not used for tracking, advertising, or profiling. It exists so you can watch, in real time, what a tamper-evident record of ordinary browsing looks like.
- It is separate from the demo email gate. If a page asks for your email to grant demo access (see “Demo access” in section 2), that email address is stored by us so we can recognize you on return visits — it is not part of the SealedVisit ledger described here.
- It may change. If a future version of the site sends any part of this ledger to our servers, or changes how it’s stored, we will update this section first — we are not committing here to anything beyond what is described above.
This section is a factual, current-state description of a demonstration feature, not a promise about future functionality. If you have questions about SealedVisit or want it disabled on your device, contact us using the details in section 15.
7. Email & marketing communications (CAN-SPAM)
We send commercial email only to people who have requested information or otherwise opted in, and we comply with the U.S. CAN-SPAM Act and applicable email laws. In our marketing emails we will:
- Use accurate “From,” “Reply-To,” and routing information and a non-deceptive subject line.
- Identify the message as a marketing communication where required.
- Include a valid physical postal address (a business mailing address — never a home address).
- Provide a clear way to unsubscribe, and honor opt-out requests promptly (within 10 business days).
Transactional or relationship messages (such as access, account, security, or service notices) are not marketing and may still be sent after you opt out of marketing. To opt out, use the unsubscribe link in any marketing email or contact admin@steaded.ai.
8. How we share information
We share personal information only as needed to run the service: with service providers (subprocessors) that host and support the platform, listed on our Trust & Infrastructure page; to comply with law or valid legal process; to protect rights, safety, and security; and in connection with a business transfer (e.g., merger or acquisition), subject to this policy. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
9. Data retention
We keep personal information for as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements, then delete or de-identify it. Because the platform maintains a tamper-evident, append-only audit, certain records are retained for integrity and compliance purposes; for instances, retention follows the customer’s configuration and our agreement.
10. Security
We use technical and organizational measures appropriate to the risk, including TLS/HTTPS in transit, encryption at rest by our database provider, single-tenant isolation per instance, default-deny access controls, and a hash-chained audit. No method of transmission or storage is 100% secure, but we work to protect your information and to respond to incidents.
11. International transfers
We are based in the United States and our providers may process data in the U.S. and other countries. Where required, we rely on appropriate safeguards (such as the EU Standard Contractual Clauses) for international transfers.
12. Your privacy rights
EU/UK (GDPR). Subject to law, you may request access, correction, deletion, restriction, or portability of your personal data, object to certain processing, and withdraw consent. You may also lodge a complaint with your supervisory authority.
California (CCPA/CPRA). Subject to law, you may request to know, delete, or correct your personal information, and to opt out of “sale” or “sharing.” We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising your rights.
To exercise any right, email admin@steaded.ai. We will verify your request and respond within the time required by law. If your data is held within a client instance, we will refer your request to that customer (the controller).
13. Children’s privacy
Steaded Ground is a business product not directed to children, and we do not knowingly collect personal information from children under 16 (or under 13 in the U.S.). If you believe a child has provided us information, contact us and we will delete it.
14. Changes to this policy
We may update this policy as the product and the law evolve. We will revise the “Last updated” date above and, for material changes, provide additional notice where appropriate.
15. Contact us
Questions or requests about privacy? Contact Steaded, LLC at admin@steaded.ai (postal address available on request).
This Privacy Policy is provided as a template and is not legal advice. Steaded, LLC should have qualified counsel review and adapt it to its actual data practices and the laws that apply before relying on it.