Stery AI

Privacy Policy

Last updated: 22 September 2026

This policy explains what personal data Stery AI ("the Service", "we") collects, why, who else processes it, how long it is kept and how you can have it removed. It covers the web application at https://stery.ai, the Telegram bots operated by agents you create, and the API and MCP interfaces of the Service.

The Service is operated by Eduard Karnaukh, an individual developer, as the data controller. Contact for any privacy question, data access or deletion request: [email protected]. We answer within 30 days.

1. What data we collect

Account data

Your email address, a bcrypt hash of your password (never the password itself), your display name and username if you set one, your interface language, your role in the Service, and — if you use Telegram — your Telegram user id and the ids of chats where an agent bot talks to you. Accounts are created by the operator on request; there is no public sign-up.

Content you create

Companies, projects, board columns, tasks and their comments, attached files, goals, reminders and routines, time logs, notes kept in the memory of a company, a project or an agent, and the configuration of the agents themselves (title, instruction, model settings). This content is visible to you, to the members of the company it belongs to, and to the agents you grant access to.

Conversations

Messages you exchange with an agent in a task thread or through that agent's Telegram bot, and the transcript, plan, log and result of every agent run. These are stored so that a conversation can be resumed and so that you can audit what an agent did.

Credentials you entrust to us

Secrets you store for a company (API keys, tokens) and OAuth access and refresh tokens for connectors you sign in to, including Google. Values are encrypted at rest with AES-256-GCM and are never returned by any interface of the Service — they can only be replaced or deleted. Agents receive them as environment variables or connector credentials at run time and never see them in their prompt; anything an agent writes out is passed through a redactor that replaces secret values before it is stored or sent.

Data from services you connect

When you connect a third-party service (for example Google Calendar or Gmail), the Service retrieves data from it on your behalf while an agent is running — see section 2.

Technical data

IP address, browser user agent, request time and path in server logs, kept for security and abuse prevention (rate limiting of sign-in attempts relies on it). We use two cookies: an httpOnly session cookie holding your signed authentication token, and a cookie remembering your interface language. There are no analytics, advertising or third-party tracking cookies.

2. Google user data

Connecting a Google account is optional and always initiated by you, in the Connectors tab of a company. The Service acts as an OAuth client of Google's official Calendar and Gmail MCP servers and requests only the scopes of the access level you pick:

  • openid, email — to show which Google account a connector is signed in as.
  • calendar.readonly or calendar — to read your calendar, and, at the higher level, to create or change events when you ask an agent to.
  • gmail.readonly, gmail.compose, gmail.modify — to read mail you point an agent at, prepare drafts, and organise messages (labels, read state). Gmail's MCP server has no send capability, so the Service cannot send mail from your account.

How it is used. Google data is fetched only while an agent you instructed is running, and only to produce the answer or the action you asked for. It is placed in the context of that run and may therefore appear in the run transcript, in a task comment or in a Telegram reply that the agent writes for you — in your own workspace, visible to you and to the members of the company that owns the connector. It is not used for any other purpose.

How it is stored. We do not build a copy of your mailbox or calendar. Access and refresh tokens are stored encrypted (AES-256-GCM) and are refreshed automatically; message and event content is not stored beyond what ends up in the run transcript described above.

How to revoke. Delete the connector in the Service — its stored tokens are deleted with it — or revoke access at any time at myaccount.google.com/permissions.

Stery AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular: we do not sell Google user data, do not use it for advertising or any form of profiling, do not transfer it except to the service providers listed in section 4 as needed to run the features you asked for, and do not use it to develop, improve or train generalised AI or machine-learning models. Humans do not read your Google data; the operator would access it only with your explicit permission, or where required by law or to investigate a concrete security incident.

3. Processing by AI models

The work in Stery AI is done by AI agents powered by Anthropic's Claude. When an agent runs, the material it needs — your instruction, the task and its thread, the relevant memory notes, and any data it fetched from a connected service on your instruction — is sent to Anthropic for inference and the result is written back into your workspace. Anthropic processes this as our service provider under its commercial terms, which do not permit training models on it. If you never start an agent run, no content leaves the Service for this purpose.

4. Why we process data, and who else touches it

We process your data to provide the Service you signed in for (performance of a contract), to keep it secure and abuse-free, including rate limiting and server logs (legitimate interest), and to comply with legal obligations. Where a feature needs a third-party account, the legal basis is your consent, given by connecting that account, and withdrawn by disconnecting it.

We do not sell personal data and do not use it for advertising. Data is shared only with:

  • Anthropic PBC (United States) — model inference for agent runs, as described in section 3.
  • Google LLC — only the services you connect yourself, and only the calls needed to serve your request.
  • Telegram FZ-LLC — delivery of the messages your agents send you, if you use the Telegram side of the Service.
  • Contabo GmbH, European Union (France) — the servers the Service and its database run on.
  • Cloudflare, Inc. — DNS, TLS termination and protection against attacks; it sees request metadata such as your IP address.
  • Any other MCP server or API you connect as a connector — what it receives is determined by the tasks you give the agents you grant it to.
  • Authorities, where we are legally required to disclose data.

Some of these providers are located outside the European Economic Area, mainly in the United States. Such transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard offered by the provider.

5. How long we keep it

  • Account, content, conversations and run history: for as long as your account exists. You can delete individual items yourself at any time.
  • Connector tokens and secrets: until you delete the connector or secret, or your account.
  • Server logs: up to 30 days.
  • After an account is deleted, its data is removed from the live database promptly and no later than 30 days; copies may remain in operational backups for a short further period before they are overwritten.

6. Security

  • All traffic is served over HTTPS with HSTS; the site cannot be framed.
  • Passwords are hashed with bcrypt; sessions are signed tokens in httpOnly cookies.
  • Connector tokens and company secrets are encrypted at rest with AES-256-GCM.
  • Every request is filtered by company membership, so one tenant cannot read another's projects; what an agent may do is limited by the tools it was granted, not by instructions in its prompt.
  • Sign-in and OAuth endpoints are rate limited, and the servers are firewalled.

No system is perfectly secure. If a breach affects your data, we will notify you and, where required, the competent supervisory authority without undue delay.

7. Your rights

Under the GDPR you may request access to your personal data, correction of it, its deletion, restriction of or objection to its processing, and a copy in a portable format. You may also withdraw a consent you gave, and lodge a complaint with your national data protection authority. To exercise any of these, write to [email protected] from the address on your account; we reply within 30 days and do not charge for it.

8. Children

The Service is a professional tool and is not directed at children. We do not knowingly create accounts for anyone under 16.

9. Changes to this policy

If this policy changes, the date at the top of the page changes with it, and material changes are announced to account holders by email before they take effect.

10. Contact

Eduard Karnaukh[email protected]. See also our Terms of Service.

Privacy Policy · Stery AI