1. Who we are
Steadframe is an AI workforce platform operated under SPOI Systems. In this policy, "Steadframe," "we," and "our" refer to the operator of the Steadframe service available at steadframe.com.
Privacy questions and data requests can be sent to support@steadframe.com.
2. Information we collect
- Account information: name, email address, authentication records, organization, and workspace membership.
- Company information: business profile, onboarding answers, company website address, public website content selected during onboarding, instructions, FAQs, approved examples, uploaded documents, and other knowledge supplied to AI employees.
- Connected-service information: mailbox or social account identifiers, usernames, granted permissions, and encrypted OAuth credentials.
- Work content: emails, attachments, support conversations, social post drafts, and related metadata processed at your direction.
- Usage and security information: employee activity, audit events, errors, timestamps, device and request information, and service diagnostics.
- Billing information: membership status, plan, and transaction references. Payment-card details are handled by Stripe and are not stored by Steadframe.
- Connected OpenAI API information: when you opt in, we store your OpenAI API key in encrypted form plus connection and usage-limit status so eligible AI work can run against your API account. The key is never returned to the browser after connection.
3. How we use information
We use information to:
- provide, configure, and operate the AI employees selected by the customer;
- build a draft company knowledge profile from customer answers and authorized public website content;
- read authorized content, prepare drafts, generate posts, and perform approved actions;
- retrieve the correct private company knowledge for each organization;
- maintain account access, billing, security controls, audit history, and customer support;
- run eligible text work through a connected OpenAI API account, apply the advertised billing discount, and fall back to Steadframe-managed processing when enabled;
- detect abuse, diagnose failures, protect the service, and comply with legal obligations; and
- improve reliability and product performance using limited operational information.
We do not sell personal information. Customer content is not used to advertise to users. Company knowledge and connected-account content are processed only to provide the requested service.
4. AI processing
Steadframe sends the minimum relevant content needed for a task to AI model providers, including OpenAI. The selected company's instructions and retrieved knowledge may be included with that task. Information from one organization is not intentionally included in another organization's AI context.
AI can make mistakes. Steadframe provides approval and activity controls, and customers are responsible for selecting appropriate autonomy settings and reviewing consequential output.
5. Google, Microsoft, and Meta data
When a customer connects Gmail, Microsoft Outlook, or Instagram, Steadframe receives only the access authorized on that provider's consent screen. We use that access to perform the features requested by the customer, such as reading eligible messages, creating drafts, reading calendar availability, creating approved meeting invitations, or publishing approved social content.
Access tokens are encrypted at rest and are not placed in AI prompts. Customers can revoke access through the connected provider and may request deletion using our data-deletion instructions.
6. Service providers
We use service providers to operate Steadframe, including Supabase for database and authentication services, Railway for hosting, OpenAI for AI processing, Stripe for payments, and Google, Microsoft, and Meta for customer-authorized integrations. These providers process information under their own terms and privacy commitments and only as needed to provide their services to us or to the customer.
7. Legal bases and sharing
Where applicable under data-protection law, we process information to perform our contract with the customer, based on consent for connected services, for legitimate interests such as security and product reliability, and to meet legal obligations. We may disclose information to service providers, when directed by the customer, during a business transfer, or when required to protect rights, safety, or comply with law.
8. Retention and deletion
We retain account and workspace information while the service is active and as reasonably necessary to provide the service, resolve disputes, maintain security records, and meet legal obligations. Deleting an employee removes its stored configuration and associated operational data according to the product's deletion flow. Customers may request account or connected-service data deletion at any time. Limited billing or security records may be retained where legally required.
9. Security and international transfers
We use organization-level access controls, encrypted credentials, authenticated requests, and audit records to protect information. No online service can guarantee absolute security. Our providers may process information in countries outside the customer's country; where required, transfers are made using recognized legal safeguards.
10. Your rights
Depending on location, individuals may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent. Contact us to exercise these rights. You may also complain to your local data-protection authority.
11. Children and changes
Steadframe is a business service and is not intended for children. We may update this policy as the service changes. Material updates will be posted on this page with a revised date.