Effective date: July 27, 2026
Privacy Policy
This policy explains which data stays on your device, which account data is hosted, when providers process feature content, and how to export or delete data.
Data we collect
- On your device: the desktop keeps protected authentication material; device, permission, hotkey, and interface settings; and a bounded encrypted completed-session pending-write outbox needed to finish cloud sync. After the service acknowledges a session, that payload is not retained as browsable offline history. Optional meeting recordings are device-only until you delete them and do not automatically sync to other devices.
- Hosted account data: email, verification state, authentication records, basic profile details, subscription status, usage balances, and billing state needed to operate your account.
- Encrypted session history: completed Coach and Meeting sessions, including transcript text, generated answers, and reports, sync to your authenticated account. Records are tenant-scoped and encrypted at rest.
- Optional synced data: selected settings and knowledge documents are hosted through your account. Synced documents may include the full text you add.
- Referral data: a stable invite code and share link assigned to your account; the code, time, and account relationship recorded when another signed-in customer explicitly accepts a referral; the aggregate number of attributed accounts; and the reward status reported for your account. The public invite link contains the code, not your email address or account ID.
- Feature processing: audio, transcript text, typed prompts, screen captures, or context documents are sent only when you request a feature that needs that content, such as transcription, AI suggestions, screen analysis, translation, or a meeting report.
- Diagnostics: app version, operating system, configured API host, capture state, redacted errors, and crash details may be used for reliability and support. Support reports are designed to exclude conversation content and credentials.
How we use data
We use hosted data to authenticate your account, meter entitled usage, manage subscriptions, sync session history, settings, and documents across devices, prevent abuse, respond to support requests, and improve reliability.
Conversation content is processed to deliver the feature you requested. We do not use raw session content for advertising or public marketing without explicit permission.
Referral codes and attribution
If you visit SteadySay through a valid invite link, the site temporarily stores its referral code in the current browser session so the signed-in account page can prefill it for your review. Visiting the link does not create an attribution. The code is sent to SteadySay Cloud only after you choose “Record attribution” while signed in.
When you record attribution, SteadySay stores the referring and referred account relationship, referral code, and attribution time. The relationship is immutable while the referred account exists: the site cannot replace it with a different referrer. This supports attribution integrity, prevents self-referrals and referral cycles, measures aggregate referrals, and allows SteadySay to administer a reward only if an active server-reported rule applies. A referrer sees an aggregate attributed-referral count, not the referred customer’s identity.
Referral rewards are currently disabled. Attribution alone does not issue credits, minutes, cash, or any other reward. The signed-in account always displays the current reward status returned by SteadySay Cloud; if that status cannot be verified, no reward is assumed.
Service providers
SteadySay uses service providers for cloud hosting, AI models, transcription, email delivery, support, and payment processing. AI and transcription providers receive content only for the requested feature. PayPal-hosted pages handle checkout; SteadySay stores subscription and usage state but does not collect card details through this site.
Your controls
- You can download a JSON export of hosted account, subscription, usage, referral, synced settings, synced documents, cloud session history, and product-event data from the signed-in web account. Referral export data includes your invite code and share link, aggregate attributed-referral count, recorded attribution code and time, and current reward status; it excludes internal referrer account IDs.
- You can add or delete individual synced knowledge documents, or delete the entire synced document set, from the web account.
- You can review and delete individual synced sessions, or delete all synced session history, from the signed-in web account. Deleting cloud records does not automatically delete optional device-only meeting recordings.
- You can request support-assisted account deletion by contacting privacy@steadysay.com. There is no automatic or self-service deletion of referral records. Support reviews your invite code, your own attribution, and downstream account links with the rest of the request. Where no documented retention need applies, support removes or de-identifies those account links; a limited record may instead be retained for fraud prevention, a reward or billing dispute, tax or accounting duties, or another legal requirement. Deletion does not recall an invite link already copied by someone else.
- You can choose not to enable microphone, screen, or system audio permissions, although some features may not work.
Retention and security
Cloud session history is currently retained for 365 days from its latest successful sync unless you delete it sooner. Completed-session pending-write data remains only until cloud acknowledgement or an explicit discard. Protected authentication and device settings remain until sign-out, app reset, or local app-data removal; optional device-only meeting recordings remain until you delete them or remove local app data. Hosted account, subscription, usage, referral, and support records are retained while needed to operate the account and preserve billing, referral, fraud-prevention, compliance, refund, and dispute integrity. Referral attribution remains linked while the account exists because it cannot be replaced. During support-assisted deletion, referral data is reviewed for removal or de-identification; limited referral or transaction evidence may remain when required for fraud prevention, disputes, accounting, or law, and is kept only as long as that purpose requires. Synced settings and documents remain until you delete them or complete an account-deletion request. Data is protected in transit; cloud session history is encrypted at rest using service-managed encryption keys that are stored separately from application data.
Contact
For privacy requests, email privacy@steadysay.com. Include the account email so the request can be matched to the correct account.
For legal notices, email legal@steadysay.com. SteadySay is operated from India, with formal business details provided before paid checkout is enabled.