Steadrun Privacy Policy
Last updated: 2026-09-08 · Draft for legal review (PIPEDA / Ontario).
中文摘要:我们只收集运营所需的最少信息:你的账户信息、你的公司契约、任务与事件日志、可核验证据链接、从你连接的账户只读同步的数据(如 Stripe 收款记录)、以及你的客户发给你的邮件与线索(为了替你回复)。不卖数据,不用你的数据训练模型。你可随时导出或要求删除。
1. Who we are
Steadrun (a sole proprietorship operating in Ontario, Canada) provides an automated operations service. We are the controller of the personal information described here. Contact: privacy@steadrun.com (until the domain is live: steadrun@aurora-studio.net).
1A. Your Company's data is yours
Everything the Services hold about a company you enroll — its contract, tasks, events, evidence, metrics, transactions, leads, messages, outputs — belongs to you. For that data we act as your service provider (processor), processing it only to operate the Services for that company as you direct; we are the controller only of your own account and billing information. You can inspect all of it on the company's account page, export it at any time (exports never contain credentials), and have it deleted when you leave. We do not use it to train or fine-tune AI models and we do not sell it.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account (we are controller) | your name, email, billing details (handled by Stripe; we never see card numbers) | to run your account and bill you |
| Company Contracts (yours; we are processor) | the JSON manifests you write: capabilities, channels, offers, gates | to operate your Company |
| Operational records | tasks, events, evidence links, metrics, alerts, morning and weekly reports | to run the Service and show you what it did |
| Connected-account data (read-only where possible) | Stripe charges and customer emails, YouTube statistics, hosting status | reconciliation, signals, health checks |
| Leads and messages | emails your customers or prospects send to the inbox you connect, form submissions from pages we host for you | to identify leads and reply on your behalf |
| Technical | timestamps, task durations, API costs | reliability and cost control |
We collect this information from you, from the accounts you connect (using the tokens you grant), and from people who contact your Company.
3. What we do not do
- We do not sell or rent personal information.
- We do not use your data or your customers' data to train AI models.
- We do not access your connected accounts beyond the scope you granted; payment access is read-only except for creating products, prices, and payment links you asked for.
- We do not send commercial email to anyone without a lawful basis (CASL: express or implied consent; inbound inquiry; existing business relationship).
4. How we use information
To operate the Service; to reply to messages sent to your Company; to reconcile payments and compute signals; to produce your reports; to detect abuse and keep the Service reliable; to bill you; and to comply with law.
5. AI processing
Parts of the Service use large language models (currently Anthropic's Claude via the Claude API or Claude Code). Prompts may include your Company Contract, operational state, and the text of messages the Service is replying to. Model providers process this data under their own terms; we select providers that do not train on API inputs by default.
6. Sharing
We share information only with: service providers needed to run the Service (model providers, email delivery, hosting, payment processing), each bound to use it only for that purpose; the third-party platforms you connect, when the Service acts on your behalf there; professional advisers; and authorities when required by law. If Steadrun is sold or merged, information may transfer to the successor under this Policy.
7. Retention
Operational records are kept while your account is active and for 12 months after, then deleted, except where we must retain them by law (for example billing records, 7 years). You may request earlier deletion of leads and messages at any time.
8. Your rights
Under PIPEDA and similar laws you may access, correct, export, or ask us to delete your personal information, and withdraw consent for future processing (which may end the Service). Email privacy@steadrun.com; we respond within 30 days. You may complain to the Office of the Privacy Commissioner of Canada.
9. Security
Tokens are stored in a restricted directory with file permissions limited to the operating user and are never written to logs, reports, or the event ledger. Payment secrets are read from your own configuration files and never copied. Reports and evidence links are stored locally on the operator's machine and, where you enable hosting, in your own accounts. No method of storage is perfectly secure; tell us immediately at the address above if you suspect a breach.
10. International transfers
We operate from Canada. Model providers and email delivery may process data in the United States. Where required we rely on contractual safeguards.
11. Cookies
Pages we host for you are static and set no tracking cookies. Form submissions are sent to your inbox and are not stored on the hosting platform.
12. Changes
We will post changes here and, for material changes, email you. Continued use after the effective date is acceptance.