Last updated: 19 September 2026.

Privacy Policy

This policy describes how Steinkauz AI processes personal data when you use our websites, create an account or use Steinkauz Cloud.

The controller and contact details are provided in the Legal Notice.
Privacy contact: contact@steinkauz.ai

No data protection officer has been appointed. Please address privacy enquiries to the controller at contact@steinkauz.ai.

1. Roles under the GDPR

We distinguish between two roles:

  1. We act as controller for data that we process for our own purposes. This includes, in particular, account and organisation data, billing, website operations, security, fraud prevention, legal obligations and — with consent — audience measurement.
  2. We act as processor for content that you or your organisation enter into or upload to Steinkauz Cloud (in particular chat histories, file attachments, API payloads and organisation-specific control settings). This processing takes place on the instructions of the relevant organisation and is governed by the Data Processing Agreement.

Steinkauz Cloud uses organisation-based tenants. The organisation to which you belong is generally the controller for content processed within the organisation. Members act on behalf of that organisation.

Private Deployment (self-hosted): Where you operate Steinkauz on your own infrastructure, you are the controller for that instance. This policy then applies only to our publicly accessible websites and to entering into a contract with us, not to your own installation.

2. Data we process

2.1 Website and contact

  • Usage data (IP address, date and time, page visited, referrer, user agent)
  • Information you provide by email or contact form
  • Consent status for optional measurement (c15t)

2.2 Account, organisation and access

  • Email address, display name, authentication data
  • Organisation membership, roles, invitations
  • API key metadata (not the key's plaintext after issuance)
  • Access keys to model providers that you supply (stored in encrypted form and decryptable to execute your model calls)
  • Login, security and abuse prevention logs

Authentication uses self-hosted Better Auth. You may optionally sign in with Google (Google OAuth). In that case, Google provides us with the profile data required for authentication (usually email address and name).

2.3 Billing

  • Billing name and address
  • Optional VAT identification number
  • Payment status, subscription status, invoice metadata
  • Withdrawal and checkout consents (timestamp, IP address, user agent, text version)
  • Cancellation and withdrawal declarations (name, email address, contract identification, declaration content and time of receipt)

Stripe receives card details. We do not store full card numbers.

2.4 Use of Steinkauz Cloud (processing on your behalf)

  • Chat messages and associated metadata
  • Uploaded files (object storage)
  • Platform API requests and usage metadata
  • Organisation-specific settings, such as security and routing policies

Steinkauz does not sell inference. Model calls use keys or endpoints that you supply (BYOK) or a gateway operated by you. The respective model providers are then processors of your organisation, rather than our sub-processors in the same sense. We transmit the content you instruct us to send to your chosen provider.

We do not train our own models on your content.

2.5 Optional measurement and technical operational data

If you consent to the measurement category, we use PostHog (EU cloud) and Vercel Analytics / Speed Insights to analyse page views, interactions, errors and loading times. Client-side and browser-related measurement requires this consent. Technical identifiers and, for signed-in users, account associations may be processed.

Independently of this optional browser measurement, we process technical operational data to provide, diagnose and monitor the Platform API and to process payment events. This data is also transmitted to PostHog. It includes, in particular, user, organisation, session, request and API key identifiers, the selected model and provider, token quantities, costs, durations, status and error information, and technical payment event identifiers. This data is not necessarily anonymous. Recording of prompt and response bodies is disabled in LLM telemetry.

PurposeLegal basis
Providing the website and service, accounts, organisations and supportArticle 6(1)(b) GDPR (contract) or Article 6(1)(f) (legitimate interest in operating the website)
Billing, tax and commercial lawArticle 6(1)(b) and (c) GDPR
Security, abuse and fraud prevention, technical operational monitoring and error analysisArticle 6(1)(f) GDPR
Processing customer content in the cloudProcessing under Article 28 GDPR on documented instructions; the relevant controller determines the legal basis for the content
Optional audience and performance analyticsArticle 6(1)(a) GDPR and section 25(1) TDDDG
Necessary storage and access on terminal equipment (session, preferences, security, consent status)Section 25(2) TDDDG

Legitimate interests: secure operations, traceability of billing transactions and prevention of abuse. You may object to processing based on legitimate interests unless there are overriding compelling legitimate grounds.

4. Cookies and similar technologies

We use c15t (self-hosted on our marketing website) to manage consent.

  • Necessary: Authentication (Better Auth), consent status, language, appearance and technical storage required for the service. These are necessary for operations.
  • Measurement: Only with consent (PostHog client, browser-related server measurement, Vercel Analytics / Speed Insights).

You may withdraw your consent at any time using the privacy settings link in the footer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

5. Recipients

Recipients may include:

  • Processors engaged by us; see Sub-processors
  • Inference or gateway providers selected by you (on your instructions)
  • Persons to whom you make content accessible using the sharing feature; recipients may pass a sharing link on to others
  • Payment service provider Stripe
  • Authorities where we are legally required to disclose data
  • Advisers (tax, legal, IT), where necessary and subject to confidentiality

6. Transfers to third countries

Some service providers also process data outside the EU or EEA. A European hosting or email sending region does not generally exclude such transfers. The relevant providers and publicly documented transfer arrangements are set out in the Service Provider List.

Where an applicable adequacy decision exists, a transfer may be based on Article 45 GDPR. This includes the EU-US Data Privacy Framework (DPF), provided the recipient and the processing are covered by a valid certification. Otherwise, appropriate safeguards under Article 46 GDPR are required, in particular standard contractual clauses (SCCs), supplemented by additional measures where necessary.

The linked service provider list identifies the providers' published transfer arrangements. You may request information about the applicable safeguards at contact@steinkauz.ai.

7. Retention periods

  • Account and organisation data: For the duration of the user relationship; subsequently deleted or anonymised unless statutory retention obligations require otherwise.
  • Chat and session content in the cloud: By default, deletion in the daily cleanup run after 30 days since the last message. Orphaned messages are also removed. Stored content snapshots of model and tool calls are removed by default after 30 days from creation or request, respectively.
  • Uploaded files: By default, deletion in the daily cleanup run after 30 days from upload, regardless of whether the associated conversation remains in use.
  • Usage, security and billing metadata: Content deletion does not automatically delete all records of usage, policy decisions or billing. This data is retained only for as long as necessary for the respective operational, evidentiary or statutory retention purpose.
  • Billing and tax records: Depending on the type of record, generally eight years for accounting vouchers, ten years for books and financial statements, and six years for other records subject to retention requirements; the start of these periods and any extensions are governed by statutory provisions (section 147 AO and, where applicable, section 257 HGB).
  • Checkout and withdrawal consents: For the duration of the contract and the applicable subsequent limitation and evidentiary periods.
  • Measurement data: Until the analytical purpose no longer applies or until deletion following a justified erasure request. When consent is withdrawn, we stop further collection that depends on consent; previously transmitted data is not automatically deleted retroactively as a result.

For contact and support enquiries, the relevant criterion is resolution of the matter; where records are needed to pursue or defend claims, the applicable limitation period applies. Data in any backup copies is overwritten as part of the relevant backup cycle; it is not available for normal product use. You may send erasure and access requests to our privacy contact.

8. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time with effect for the future.

You may lodge a complaint with a supervisory authority, in particular our competent authority, the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, or the authority at your place of residence.

For content that we hold solely as a processor, please address access and erasure requests to the relevant organisation (controller). We assist the organisation in accordance with the DPA.

9. Required information

We cannot perform the contract without an email address and — for a paid cloud subscription — billing details. The VAT identification number is optional. Without it, we charge statutory VAT in accordance with the rules applicable to your address (no net reverse-charge treatment for intra-EU B2B transactions without a valid VAT identification number).

10. Automated decisions

We do not use solely automated decision-making with legal effects within the meaning of Article 22 GDPR.

11. Changes

We update this policy when processing activities or the legal framework change. The version published on this page applies.