1. What we collect
We collect only what we need to provide and improve Stategram:
- Account data: name, email, organization name, billing details (handled by Stripe).
- Service data: state machine definitions you author, object state pointers, decision receipts, and webhook URLs you configure.
- Usage data: API request metadata (timestamps, response codes, endpoint), IP address, browser/SDK version, error logs.
- Marketing data: if you sign up for our waitlist or product updates, your email address and the source you came from.
We do not store the contents of business records (proposals, refunds, support tickets, customer PII) unless you explicitly include them in evidence fields.
2. Legal basis (GDPR)
- Contract — to provide the service you've signed up for.
- Legitimate interest — to keep the service secure, prevent fraud, and improve performance.
- Consent — for product marketing emails (you can withdraw consent any time).
- Legal obligation — for accounting, tax, and lawful regulator requests.
3. How we use it
- Operate the Stategram service and evaluate transitions you request
- Authenticate you and protect your account
- Send transactional notifications (approvals, alerts, receipts)
- Send product updates and tips (only if you opt in)
- Diagnose issues, monitor abuse, and improve reliability
- Comply with legal obligations
We do not sell your data. We do not use customer data to train AI models.
4. Sub-processors
We use a small set of vetted sub-processors. The current list is published on our Security & Trust page. We give 30 days' notice before adding or replacing a sub-processor.
5. Data location and retention
Data is stored in the EU (Hetzner, Falkenstein, Germany — network zone eu-central) by default. US residency is available on request for Enterprise customers. Account and service data is retained while your account is active. Receipts are retained per your plan's receipt history limit (90 days, 1 year, or longer for Enterprise). Backups are kept for 30 days. After deletion, data is purged from active systems within 30 days and from backups within 60 days.
6. Your rights
Under GDPR you have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. To exercise any of these, email [email protected]. We respond within 30 days. You also have the right to lodge a complaint with a supervisory authority — the lead authority for Stategram is the Estonian Data Protection Inspectorate (aki.ee).
7. Cookies
We use a minimal set of strictly-necessary cookies for authentication and security. We do not use third-party advertising or cross-site tracking cookies. We use first-party analytics only to measure landing-page performance (page views, session length, button clicks) — no profile is built across sessions.
8. Security
See Security & Trust for technical detail. In short: TLS 1.3 in transit, AES-256 at rest with envelope encryption, MFA for all employee access, and signed receipts you can independently verify.
9. Children
Stategram is not directed to children under 16. We do not knowingly collect data from children.
10. Changes
If we make material changes to this policy, we will notify account holders by email at least 14 days before the change takes effect. Non-material edits will be reflected by updating the "last updated" date below.
11. Contact
- Privacy questions / data requests: [email protected]
- General contact: [email protected]
- Postal: Ideevoog OÜ, Tallinn, Estonia