1. Information We Collect
1.1 Information you provide directly
- Account information — name, email address, password, and business name when you register
- Billing information — payment method details processed securely by Stripe; we do not store raw card numbers
- Invoice and client data — invoice numbers, amounts, due dates, client names, and client email addresses you upload or import
- Communications — emails or messages you send to our support team
1.2 Information collected automatically
- Usage data — pages visited, features used, clicks, and time spent in the app
- Device and browser data — IP address, browser type, operating system, and device identifiers
- Log data — server logs, error reports, and activity timestamps
- Cookies and similar technologies — session tokens, authentication cookies, and analytics identifiers; see Section 7
1.3 Information from third-party integrations
If you connect a third-party accounting or payment platform, we receive data from that platform subject to your authorisation and their own privacy policies:
- QuickBooks / Xero — invoice records, client contact details, and payment status
- Stripe / PayPal — payment confirmation events and transaction metadata
- Resend — email delivery status and bounce/open events for chase emails we send on your behalf
2. How We Use Your Information
- Provide and operate the Services — draft and send invoice chase emails on your behalf, manage your approval queue, and track invoice status
- Process AI-generated content — your invoice data is sent to Anthropic's Claude API to generate chase email drafts; see Section 4
- Process payments — transmit billing data to Stripe to manage your subscription and overage charges
- Communicate with you — send service updates, billing notifications, onboarding emails, and support responses
- Improve the Services — analyse usage patterns to fix bugs and build new features
- Comply with legal obligations — retain records as required by applicable law
- Prevent fraud and abuse — detect and investigate misuse of the Services
3. How We Share Your Information
We do not sell your personal information. We share it only as described below.
3.1 Service providers
We share data with vendors who help us operate the Services, each bound by confidentiality obligations:
- Anthropic (Claude API) — invoice context data for AI draft generation; see Section 4
- Stripe — billing and subscription management
- Supabase — database and authentication infrastructure
- Railway — backend hosting and API proxy
- Resend — transactional email delivery
3.2 Legal requirements
We may disclose information if required by law, subpoena, court order, or to protect the rights, property, or safety of Steward AI, our users, or the public.
3.3 Business transfers
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a different privacy policy.
3.4 With your consent
We may share your information for any other purpose with your explicit consent.
4. Anthropic Claude API — AI Processing
- Data minimisation — we send only the invoice fields necessary to generate a contextual draft; we do not send your Stripe keys, QuickBooks tokens, or account credentials to Anthropic
- No training on your data — as of the date of this policy, Anthropic does not use API inputs to train its models by default; refer to Anthropic's current policy for confirmation
- Draft approval is always yours — AI-generated drafts are shown to you for review and approval before any email is sent to your client
5. Data Retention
- Account data — retained for the duration of your account and for 90 days after deletion, then permanently deleted
- Invoice and client data — retained while your account is active; you may delete individual invoices at any time from within the app
- Chase email logs — retained for 12 months for audit trail purposes, then deleted
- Billing records — retained for 7 years as required by US tax law
- Anonymised analytics — may be retained indefinitely in aggregated, non-identifiable form
6. Your Rights — California Residents (CCPA)
Because we are based in California and serve California residents, the California Consumer Privacy Act (CCPA) applies to our handling of your personal information. As a California resident, you have the following rights:
- Right to know — request disclosure of what personal information we collect, use, disclose, or sell about you
- Right to delete — request deletion of your personal information, subject to certain exceptions
- Right to correct — request correction of inaccurate personal information we hold about you
- Right to opt out of sale — we do not sell your personal information, so this right is not currently applicable
- Right to non-discrimination — we will not discriminate against you for exercising your CCPA rights
To exercise these rights, contact us at privacy@getstewardai.app. We will respond within 45 days.
7. Cookies
We use the following types of cookies and similar technologies:
- Strictly necessary — session tokens and authentication cookies required to log you in and keep you logged in
- Functional — preferences such as monthly vs. annual billing toggle
- Analytics — aggregated usage data to understand how users interact with the Services
You may disable cookies in your browser settings, but doing so may prevent some features from working correctly.
8. Data Security
We implement industry-standard security measures including:
- TLS/HTTPS encryption — all data in transit is encrypted
- Supabase Row Level Security — database access controls enforced at the row level
- API key isolation — Anthropic and Stripe API keys are stored server-side only and never exposed to the browser
- Access controls — employee access to production data is restricted and logged
No method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
9. Children's Privacy
The Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, contact us at privacy@getstewardai.app and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top and, for material changes, notify you by email or a prominent notice in the app. Continued use of the Services after the effective date of an updated policy constitutes your acceptance.
11. Contact Us
- Privacy email — privacy@getstewardai.app
- Legal email — legal@getstewardai.app
- Mail — Steward Labs LLC, Santa Clara County, California