Legal
Privacy Policy
Styr is built for operators who care about trust. This policy explains exactly what data we collect, why we collect it, and the choices you have.
Last updated · February 26 2026
1Data we collect
We collect only what is required to run Styr and serve you well:
- Account data — full name, work email, hashed password, business name.
- Operational data — the KPIs, decisions, outcomes, tasks, signals, and integration metadata you create.
- Integration tokens — credentials for Stripe, Shopify, GA4, Xero, HubSpot, etc. Always encrypted at rest with Fernet (AES-128 + HMAC-SHA-256). Never logged, never returned over the API.
- Product analytics — anonymised usage events to improve the product (PostHog).
We do not sell your data. We do not profile users for advertising. We do not share operational data with third parties.
2How we use it
Your operational data drives the Service: it powers the AI assistant, the deterministic signals engine, decision recommendations, and the memory/learning loop. AI calls run on regulated infrastructure (Claude Sonnet 4.5 via Emergent's LLM proxy); prompts include only the business context strictly needed to answer the question.
3Sub-processors
We use a small set of vetted sub-processors:
- MongoDB Atlas — primary database (encrypted at rest, TLS in transit).
- Emergent — hosting, LLM proxy, deployment infrastructure.
- Namecheap PrivateEmail — transactional email (password resets, invites).
- PostHog — anonymised product analytics.
We will notify you in-product before adding any new sub-processor that touches your data.
4Retention
Your data is retained for as long as your account is active. If you close your workspace, you have 30 days to export anything you need. After that, records are permanently deleted (except records we must keep for legal or accounting reasons, such as invoices).
5Your rights
You can, at any time:
- Access a copy of your personal data.
- Correct anything inaccurate.
- Export the full Trust Audit envelope from Settings → Trust & transparency.
- Delete your workspace.
- Object to a processing activity, or withdraw consent.
Email platform@styrbiz.com and we will respond within 14 days.
6Security
We follow industry best-practice: bcrypt password hashing, rotating JWT access tokens, encrypted integration credentials, TLS 1.2+ in transit, principle of least privilege on sub-processors, daily backups. If a breach occurs that materially affects you, we will notify you within 72 hours.
7Cookies
Styr only uses cookies that are strictly necessary to keep you signed in (HTTP-only session token). We do not use marketing or tracking cookies. PostHog analytics runs in identified-only mode for signed-in users.
8Contact
Privacy questions go to platform@styrbiz.com. See also our Terms & Conditions for the legal framework.