SteadyOp
TermsPrivacySupport
Open workspace →
STEADYOP PRIVACY

Privacy Statement

How SteadyOp handles account information, imported business data, operations mail, documents, and AI-assisted work.

Effective September 8, 2026 · Last updated September 8, 2026
ON THIS PAGE1. Scope and controller2. Data we collect3. Workspace data and operations mail4. Why we use data5. Legal bases6. How data is shared7. AI and document processing8. Retention and deletion9. Security10. International transfers11. Your choices and rights12. Cookies and local storageDevice notifications13. Children14. Changes to this statement15. Contact

1. Scope and controller

This Privacy Statement explains how SteadyOp, a Fyniche product (“SteadyOp,” “we,” “us,” or “our”), processes personal data when you visit our website, use the SteadyOp service, import business data, upload a document, use the operations mailbox, or contact us.

For customer workspace content, the customer normally determines why the data is processed and SteadyOp acts as its processor. For account administration, service security, billing, product operations, and our website, SteadyOp generally acts as controller.

2. Data we collect

  • Account and organization data, such as name, email address, organization, role, authentication identifiers, mailbox handle, and account preferences.
  • Imported business data, including spreadsheets, CSV files, PDFs, images, documents, contacts, schedules, and related metadata that you choose to upload.
  • SteadyOp Native records, mailbox messages, prompts, drafts, approvals, agent results, schedules, inventory movements, OCR text, and audit history.
  • Technical and usage data, such as IP address, device and browser information, timestamps, security events, feature activity, model/token usage, and diagnostic logs.
  • Support, billing, and communications data you provide when contacting us or managing a subscription.

3. Workspace data and operations mail

SteadyOp stores business records and import metadata in a workspace scoped to the customer organization. Uploaded files are kept in private object storage and linked to the resulting records where appropriate.

The built-in operations mailbox uses Resend to send and receive mail for the organization-specific address. Incoming mail is routed by the recipient address, and outgoing mail is sent only after an authorized user or approved workflow requests it.

4. Why we use data

  • Provide, personalize, and maintain the service and connected workflows.
  • Authenticate users, enforce workspace permissions, and prevent fraud or abuse.
  • Run requested AI analysis, document recognition, search, drafts, automations, and approved actions.
  • Maintain source-linked records, audit trails, usage accounting, reliability, and support.
  • Comply with law, enforce agreements, and protect users, SteadyOp, and third parties.
  • Improve product quality using service telemetry and feedback. We do not sell personal data or use workspace content for targeted advertising.

5. Legal bases

Where the GDPR or similar law applies, we process personal data as necessary to perform our contract with you; based on legitimate interests in operating, securing, supporting, and improving the service; with consent where required; and to comply with legal obligations.

You may withdraw consent at any time, but withdrawal does not affect processing already performed lawfully.

6. How data is shared

We share data only as needed with service providers that support hosting, storage, email delivery, authentication, analytics, customer support, and AI processing; during a business transaction subject to appropriate safeguards; or when required by law or necessary to protect rights and safety.

The service uses Cloudflare for hosting and object storage, Supabase for the workspace database, Clerk for authentication and account management, Resend for email delivery and receiving, Stripe for payments, and OpenRouter to route AI requests to model providers. The AI provider receiving a request depends on the configured model and routing. Browser push services also deliver notifications when you enable them.

7. AI and document processing

Prompts, authorized source context, and uploaded images or documents may be sent to configured AI providers to complete the task you request. We limit the data sent to what is reasonably needed and instruct document-reading systems to treat uploaded content as untrusted evidence rather than instructions.

Steady is an AI assistant, not a human operator. AI output and extracted fields can be incorrect and should be reviewed. Consequential actions are subject to workspace controls and approval rules. Your prompts and the workspace context needed for a task are processed by the configured AI routing and model providers.

8. Retention and deletion

We retain personal data for as long as needed to provide the service, maintain security and audit records, meet legal obligations, resolve disputes, and enforce agreements. Retention varies by data type and customer settings.

Unconfirmed private document uploads may be removed automatically after a limited review period. Registered records and their source documents remain until deleted under the workspace’s controls or an applicable request, subject to legal and security requirements.

9. Security

We use measures designed to protect data, including access controls, workspace scoping, server-side credentials, encrypted transport, private object storage, bounded uploads, rate limits, security headers, audit records, and confirmation gates. No method of storage or transmission is completely secure.

10. International transfers

SteadyOp and its providers may process data outside your country. Where required, we use recognized safeguards such as adequacy decisions, standard contractual clauses, or another lawful transfer mechanism.

11. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to complain to a supervisory authority. Workspace administrators may fulfill requests involving customer-controlled workspace data.

  • Edit or delete imported workspace records using organization controls.
  • Export operational records and the Work Ledger where available.
  • Request account or personal-data assistance through privacy@steadyop.com or support@steadyop.com. Removing individual records or deleting a sign-in account does not necessarily remove all related workspace, billing, or provider records; contact us for a request covering those systems.
  • Object to direct marketing or unsubscribe using the link in a marketing message.

12. Cookies and local storage

We use cookies or similar storage needed for authentication, security, preferences, and reliable operation. If optional analytics or marketing technologies are introduced, we will provide notices and choices required by law.

Device notifications

Device notifications are optional and require browser permission. When enabled, we store a push subscription endpoint and delivery keys linked to your workspace membership. Your browser’s push provider handles delivery. Alerts use a generic new-message notice and a message identifier rather than the email subject or body. You can disable notifications in your browser settings. The optional in-app sound preference is stored on your device.

13. Children

SteadyOp is a business service and is not directed to children under 18. We do not knowingly collect personal data from children through the service.

14. Changes to this statement

We may update this Privacy Statement as the service or law changes. We will post the revised statement with a new effective date and provide additional notice for material changes where required.

15. Contact

Privacy questions and rights requests can be sent to privacy@steadyop.com. General support is available at support@steadyop.com or on our Support page.

SteadyOp

Your operation. Running steady.

TermsPrivacySupportSign in