Sten.← Back to site

Legal

Privacy Policy

Last updated: 17 July 2026

This policy explains what personal data Sten collects, why, and the choices and rights you have. We keep it plain-spoken and collect as little as we can.

Two roles. For your account with us, Sten is the data controller. For the visitor conversations and leads handled by the chat widget you place on your own website, Sten acts as a processor on your behalf — you are the controller for your visitors' data and are responsible for having your own privacy notice and lawful basis.

1. Who we are

Sten (“we”, “us”) is an AI chat-widget service at sten-ai.com, operated by Thomas Stenback, based in Finland. For any privacy question, email support@sten-ai.com.

2. Data we collect

Account data

Your email address, name (if given), a securely hashed password, your language preference, and — if you enable two-factor authentication — your 2FA secret (stored encrypted).

Billing data

Payments are handled by Stripe. We store your Stripe customer identifier and subscription status; we never see or store your full card number.

Widget & content you provide

The knowledge base text, greeting, colour, and website URL you enter so your assistant can answer your visitors.

Leads & chat content

When a visitor to your site leaves their email or a message in the chat, we store it and show it to you in your dashboard. Visitor messages are sent to our AI provider to generate a reply. We do not use your or your visitors' content to train AI models.

Google Calendar connection (Front Desk)

If you use Front Desk (in-chat appointment booking) and choose to connect your Google Calendar, we ask Google for your permission to two scopes: see when you are free or busy (calendar.freebusy) and create, edit and delete calendar events (calendar.events). We use this access only to show your real availability to people booking with you and to add, reschedule and cancel the booking events you receive. We store the Google authorisation tokens encrypted at rest (AES‑256‑GCM); we never see or store your Google password, and we never read the rest of your calendar's contents. You can disconnect at any time in your Front Desk settings — which deletes the stored tokens — or revoke access directly at myaccount.google.com/permissions.

Limited Use. Sten's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, do not use it for advertising, and do not allow humans to read it except with your consent, for security, or as required by law.

Technical data

Your IP address and timestamps, used for security, rate-limiting and abuse prevention, plus minimal server logs. Where we keep a record of an IP address in our own database, we store it in anonymised form (the final part of the address removed) so it is no longer tied to an individual.

Advertising measurement

If you reach us through one of our advertisements (for example on Instagram or Facebook) and then build a demo or create an account, we send a server-side event to Meta through its Conversions API so we can measure how our ads perform. This event includes your IP address and, on sign-up, a hashed (irreversibly scrambled) version of your email. It uses no cookies and does not track you across other websites. Legal basis: our legitimate interest in measuring and improving our advertising. You can object at any time by emailing support@sten-ai.com.

3. Cookies

We use only strictly necessary cookies — there are no advertising or cross-site tracking cookies, and no third-party analytics scripts on our pages. Where we reach you through an advertisement, we measure the result server-side without cookies — see Advertising measurement above.

CookiePurposeType
ridKeeps you signed in (session)Essential
csrfProtects against cross-site request forgeryEssential
sten_langRemembers your language choiceFunctional
sten_consentRemembers your cookie choiceEssential

Because these are essential to run the service and remember your preferences, the site works whether you accept or decline in the cookie banner. If we ever add optional cookies (for example analytics), we will only set them after you accept.

4. How we use data

  • To provide and operate the service and authenticate you.
  • To generate AI replies to your visitors from the facts you give the assistant.
  • To capture leads and show them to you.
  • To take payment and manage your subscription.
  • To keep the service secure and prevent abuse.
  • To respond when you contact us.

5. Legal bases (GDPR)

  • Performance of a contract — to provide the service you signed up for.
  • Legitimate interests — security, abuse prevention, and improving the service, balanced against your rights.
  • Consent — where we ask for it (e.g. any future optional cookies), which you can withdraw at any time.
  • Legal obligation — e.g. keeping billing records.

6. Sub-processors

We do not sell your data. We share it only with the vendors that help us run the service:

ProviderPurpose
VultrServer hosting
GroqAI model inference (generates chat replies)
ResendSending transactional email (verification, follow-ups)
CloudflareDNS and email routing
StripePayment processing
Google (Calendar API)Two-way calendar sync for Front Desk bookings — only for the account you explicitly connect
Meta (Conversions API)Server-side advertising measurement — only when you arrive via one of our ads (see Advertising measurement)

7. International transfers

Some providers may process data outside the European Economic Area (for example, our AI provider). Where that happens, transfers rely on appropriate safeguards such as the provider's Standard Contractual Clauses. Contact us for details.

8. Retention

We keep account data while your account is active and for a reasonable period afterwards. Leads remain until you delete them or close your account. Server logs are kept short-term for security. Billing records are kept as long as the law requires.

9. Your rights

Under the GDPR you can request to access, correct, delete, restrict, or port your data, and object to certain processing. You can also withdraw consent at any time. To exercise any of these, email support@sten-ai.com. You have the right to complain to your data protection authority — in Finland, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).

10. Security

We protect data with encryption in transit (HTTPS/TLS), hashed passwords, optional two-factor authentication, encrypted 2FA secrets and encrypted backups, and strict access controls. No system is perfectly secure, but we take reasonable measures and keep improving them.

11. Children

Sten is a business tool and is not directed at children. It is not intended for anyone under 16.

12. Changes & contact

We may update this policy; we'll change the “last updated” date above and, for material changes, tell you. Questions or requests: support@sten-ai.com.