Effective date: July 26, 2026
Privacy Policy
This policy explains which data stays on your device, which account data is hosted, when providers process feature content, and how to export or delete data.
Data we collect
- On your device: the desktop keeps protected authentication material; device, permission, hotkey, and interface settings; and a bounded encrypted completed-session pending-write outbox needed to finish cloud sync. After the service acknowledges a session, that payload is not retained as browsable offline history. Optional meeting recordings are device-only until you delete them and do not automatically sync to other devices.
- Hosted account data: email, verification state, authentication records, basic profile details, subscription status, usage balances, and billing state needed to operate your account.
- Encrypted session history: completed Coach and Meeting sessions, including transcript text, generated answers, and reports, sync to your authenticated account. Records are tenant-scoped and encrypted at rest.
- Optional synced data: selected settings and knowledge documents are hosted through your account. Synced documents may include the full text you add.
- Feature processing: audio, transcript text, typed prompts, screen captures, or context documents are sent only when you request a feature that needs that content, such as transcription, AI suggestions, screen analysis, translation, or a meeting report.
- Diagnostics: app version, operating system, configured API host, capture state, redacted errors, and crash details may be used for reliability and support. Support reports are designed to exclude conversation content and credentials.
How we use data
We use hosted data to authenticate your account, meter entitled usage, manage subscriptions, sync session history, settings, and documents across devices, prevent abuse, respond to support requests, and improve reliability.
Conversation content is processed to deliver the feature you requested. We do not use raw interview or meeting content for advertising or public marketing without explicit permission.
Service providers
SteadySay uses service providers for cloud hosting, AI models, transcription, email delivery, support, and payment processing. AI and transcription providers receive content only for the requested feature. Stripe-hosted pages handle checkout and billing management; SteadySay stores subscription and usage state but does not collect card details through this site.
Your controls
- You can download a JSON export of hosted account, subscription, usage, synced settings, synced documents, cloud session history, and product-event data from the signed-in web account.
- You can add or delete individual synced knowledge documents, or delete the entire synced document set, from the web account.
- You can review and delete individual synced sessions, or delete all synced session history, from the signed-in web account. Deleting cloud records does not automatically delete optional device-only meeting recordings.
- You can request support-assisted account deletion by contacting privacy@steadysay.com. Deletion is not instant when billing, fraud, dispute, or legal retention requires a limited record.
- You can choose not to enable microphone, screen, or system audio permissions, although some features may not work.
Retention and security
Cloud session history is currently retained for 365 days from its latest successful sync unless you delete it sooner. Completed-session pending-write data remains only until cloud acknowledgement or an explicit discard. Protected authentication and device settings remain until sign-out, app reset, or local app-data removal; optional device-only meeting recordings remain until you delete them or remove local app data. Hosted account, subscription, usage, and support records are retained as needed for the service, fraud prevention, compliance, refunds, and disputes. Synced settings and documents remain until you delete them or complete an account-deletion request. Data is protected in transit; cloud session history is encrypted at rest using service-managed encryption keys that are stored separately from application data.
Contact
For privacy requests, email privacy@steadysay.com. Include the account email so the request can be matched to the correct account.
For legal notices, email legal@steadysay.com. SteadySay is operated from India, with formal business details provided before paid checkout is enabled.