No data selling GDPR rights included CAN-SPAM compliant Per-tenant database isolation

01 Data We Collect

We collect only the data necessary to provide and improve the Sturna platform:

We do not collect browsing history, device identifiers beyond standard server logs, or any data unrelated to platform operation.

02 How We Use Your Data

Your data is used exclusively for the following purposes:

We do not use your personal data for profiling, advertising, or any purpose unrelated to operating Sturna.

03 LLM Processing

Your intent text is processed by AI models via third-party APIs — OpenAI and Anthropic. When you submit an intent, it may be:

What this means: Your intent text leaves our infrastructure and is processed by external AI providers (OpenAI, Anthropic) as part of normal service operation. These providers have their own privacy policies, which we encourage you to review:

OpenAI: openai.com/privacy

Anthropic: anthropic.com/privacy

We do not control how these providers process or retain your data once transmitted. Intent text is transmitted in plain text for routing and execution purposes.

04 Data Storage & Security

All user data is stored in a PostgreSQL database (Neon) with the following security measures:

No data is stored in plain text beyond what is required for service operation.

05 Data Retention

We retain your data for as long as your account is active. Retention periods:

Data deletion on request: You may request deletion of your personal data at any time by contacting privacy@sturna.ai. We will delete your personal information within 30 days of verification, subject to any legal retention obligations (e.g., billing records).

06 Cookies

We use only the cookies necessary to operate the service:

Session cookies: Used for authentication when you sign in via magic link. These are essential for the service to recognize your session. They are temporary — deleted when you close your browser.

No third-party tracking cookies: We do not use third-party tracking cookies, advertising cookies, or analytics cookies from external services. We do not track you across websites.

If you have an account, you can expect one session cookie set on login. No persistent tracking cookies are set for marketing or advertising purposes.

You can disable cookies in your browser, but this may affect your ability to log in and maintain an active session.

07 Third-Party Services

We use the following third-party services as part of our infrastructure. Each has its own privacy policy:

We do not share your personal data with any other third parties beyond what is required for service operation.

08 Your GDPR Rights

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:

To exercise any of these rights, contact privacy@sturna.ai. We will respond within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

09 CAN-SPAM Compliance

All marketing emails sent from Sturna comply with the CAN-SPAM Act:

Transactional emails (account notifications, billing confirmations) are not subject to the unsubscribe requirement but will still include our contact information.

10 We Never Sell Your Data

Explicitly: Sturna does not sell, rent, trade, or otherwise transfer your personal data to third parties for their own marketing or advertising purposes. Ever.

The only circumstances under which your data is shared with third parties are:

We do not build advertiser profiles, sell data to data brokers, or use your data for any commercial purpose beyond operating Sturna.

11 Contact

For privacy-related questions or to exercise your rights, contact our privacy team:

Email: privacy@sturna.ai

We aim to respond to all privacy inquiries within 5 business days.

For general questions: hello@sturna.ai