Privacy Policy
LAST UPDATED: 22 JULY 2026
This policy covers both the Steuron website (steuron.com) and the Steuron platform (app.steuron.com). Where the two differ, it says so.
Who We Are
Steuron is operated by STEURON OÜ, registered at Meistri 16, Haabersti, Tallinn 13517, Estonia. We are the data controller for the personal data described here.
For any data protection question or request: privacy@steuron.com
When You Visit the Website
If you only browse steuron.com without requesting an invite, we collect:
- Aggregated visit statistics via Vercel Analytics — page views and referrers, without cookies and without identifying you individually
- Standard server logs kept by our hosting provider, including IP address, for security and reliability
If you request an invite, we collect your name, email address, and the description you provide. We use this solely to review your request and, if you are accepted, to send you an invitation and the information you need to get started. This is pre-contractual communication under Art. 6(1)(b) GDPR, not marketing.
Invite requests that do not lead to an account are deleted within 12 months.
When You Use the Platform
- Account data: name, email address, password (stored hashed), or your Google account identifier if you sign in with Google
- Content you create: tasks, projects, journal entries, deadlines, productivity scores, team members you add
- Technical data: IP address, browser type, device type, session information
- Product usage events: which features you use and when, so we can find where the product breaks
- Payment data, where a paid plan applies: processed by Stripe. We receive confirmation of payment and subscription status. We never see or store your card number.
Analytics During the Closed Beta
While Steuron is in its closed, invite-only phase, we use PostHog for product analytics on the platform. This records which features are used and where users get stuck, so problems can be found and fixed quickly with a small group of users.
The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in operating and improving a service in active development. You may object to this processing at any time by contacting privacy@steuron.com.
How We Use Your Data
- Provide the platform and store the content you create
- Authenticate you and keep your account secure
- Send service messages: invitations, access information, security notices, and changes to these policies
- Process payments where a paid plan applies
- Find and fix problems in the product
- Comply with legal obligations, including accounting law
Legal Basis for Processing
- Contract performance, Art. 6(1)(b): providing the platform, handling invite requests, processing payments
- Legitimate interests, Art. 6(1)(f): security, fraud prevention, product analytics, aggregated website statistics
- Legal obligation, Art. 6(1)(c): accounting and tax records
- Consent, Art. 6(1)(a): where we specifically ask for it, for example non-essential cookies. You may withdraw consent at any time.
Where Your Data Is Stored
Your account and content are stored on Supabase infrastructure in the European Union (Ireland). We use row-level security, encrypted connections, and access controls. Some of our providers are established outside the EU; where they process personal data, they do so under Standard Contractual Clauses or an equivalent transfer mechanism.
Sub-processors
We share data only with providers necessary to operate the service. We do not sell your data.
- Supabase (database, authentication) — EU, Ireland — supabase.com/privacy
- Vercel (hosting, server logs, cookieless analytics) — vercel.com/legal/privacy-policy
- Resend (transactional email delivery) — resend.com/legal/privacy-policy
- PostHog (product analytics, EU Cloud) — posthog.com/privacy
- Stripe (payment processing) — stripe.com/privacy
- Cloudflare (DNS, DDoS protection, performance) — cloudflare.com/privacypolicy
- Google (sign-in, where you choose to use it) — policies.google.com/privacy
Cookies
The platform uses essential cookies for authentication and session management. These are required for the service to work and do not need consent.
The website uses no advertising or cross-site tracking cookies. If we introduce analytics that require cookies, you will be asked for consent first, and nothing non-essential will load until you agree.
Data Retention
- Active accounts: retained while the account is open
- Closed accounts: personal data deleted within 30 days
- Backups: may persist in encrypted backups for up to 90 days
- Invite requests without an account: deleted within 12 months
- Product analytics events: retained no longer than 12 months
- Accounting and invoicing records: 7 years, as required by Estonian law
Your Rights
Under GDPR you have the right to:
- Access: obtain a copy of your personal data
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your data
- Portability: receive your data in a machine-readable format
- Restriction: limit how we process your data
- Object: object to processing based on legitimate interests, including product analytics
- Withdraw consent: where processing is based on consent, without affecting prior processing
We do not use automated decision-making that produces legal effects concerning you. The PP score is calculated from ratings you assign yourself; it is a tool, not a decision made about you.
Exercising Your Rights
Contact privacy@steuron.com. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. We may need to verify your identity before acting. Exercising these rights is free and will not affect your access to the service.
If you are not satisfied with our response, you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee, or with the supervisory authority in your country of residence.
Data Breaches
If a personal data breach occurs that poses a risk to your rights and freedoms, we will:
- Notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it, as required by Art. 33 GDPR
- Notify you without undue delay where the breach is likely to result in a high risk to your rights
- Tell you what happened, what data was affected, and what we are doing about it
Legal Requests
We disclose personal data to authorities only where we are legally required to do so, and only on the basis of valid legal process. Where we are permitted to inform you, we will.
Changes to This Policy
We may update this policy. For significant changes affecting how we process your data, we will notify you by email or in the platform before they take effect. The date at the top of this page always reflects the current version.
Contact
Data protection: privacy@steuron.com
General enquiries: hey@steuron.com
STEURON OÜ, Meistri 16, Haabersti, Tallinn 13517, Estonia