Privacy policy
STET is a review tool: your coding agent pushes work to stet.fyi and you approve it or send it back. This page says what we process about you while that happens, why, where it goes, and for how long.
In short
- We keep your email address, a hash of your password, the content your agents push, your reviews, and a record of each sign-in.
- It lives on our own server in Germany, behind Cloudflare. Email goes out through Amazon SES in Ireland. Payments run through Stripe and Link. Mail to [email protected] lands in a mailbox at Migadu in Switzerland.
- Accounts stay until you ask us to delete them. Archived content is deleted after a plan-dependent period (Free: 30 days, mini: 30 days, ultra: kept indefinitely). Request logs are kept for 30 days, backups for up to 14 days.
- No analytics, no tracking, no cookie banner. Questions: [email protected].
Who is responsible
Benjamin HerzigTürkenstraße 23
13349 Berlin
Germany
Email: hello@stet.fyi. You can write to us in German or English.
We have no data protection officer; German law requires one only from 20 people (§ 38 BDSG).
What we process, and why
Visiting the site
Every request to stet.fyi passes through Cloudflare, which terminates the connection and forwards it to our server. Cloudflare sees the request in full: your IP address, headers, and the page you asked for, and keeps its own edge logs under its own privacy policy. Legal basis: Art. 6(1)(f) GDPR. Our interest: keeping the site reachable and defending it against attacks without exposing our own server to the internet.
Our server logs each request: your IP address, the method, the path, the time, a request id, the code that handled it, and the request parameters. Security tokens in links (password reset, email verification, file downloads, shared views) are replaced before the lines are written, and text you or your agent submit in forms (review notes, answers, headlines, descriptions, names, messages) is filtered out. The log is stored twice: a rolling copy on the server itself, capped at about 10 MB, and a copy in our log store on another machine we run in Germany, kept for 30 days. Legal basis: Art. 6(1)(f). Our interest: finding and fixing errors, and investigating abuse.
We also record traces for 14 days: the method, host, path, query string, browser user agent, status code, timing, and the shape of each database query without its values. Traces carry no IP address, and the same link tokens are stripped from them. Metrics record only which page template was hit, the status code and the duration, and hold no personal data. Both stay on hardware we run. Legal basis: Art. 6(1)(f). Our interest: performance monitoring and debugging.
We run no analytics and load no third-party fonts or scripts, with one exception on the enterprise contact page (see below).
Creating an account and signing in
Signing up takes an email address and a password. We store the password as a bcrypt hash, never in plain text, and send a verification link that is valid for 2 days. Legal basis: Art. 6(1)(b), the account you asked for.
If someone tries to sign up with an address that already has an account, the form answers the same way either way and we email the address's real owner instead. If that owner is you, your address reached us from whoever typed it. Legal basis: Art. 6(1)(f). Our interest: stopping anyone from finding out which addresses have accounts, and warning you.
Each sign-in creates a session record: an id, the IP address and browser user agent at that moment, and timestamps. A session ends 30 days after sign-in or after 14 days without activity, whichever comes first; expired records are deleted daily. The IP address and user agent are kept as a security record for the session's lifetime and are not used for anything automated. Signing out, changing your password (your other sessions), resetting it (all sessions) and a block on the account end sessions early. Legal basis: Art. 6(1)(b) for staying signed in; Art. 6(1)(f) for the IP address and user agent. Our interest: being able to tell sessions apart if an account is misused.
A password reset sends a link that is valid for 15 minutes. The request form answers the same way whether or not the address has an account. Legal basis: Art. 6(1)(b).
In settings you can change your email address (we ask you to verify it again), change your password, store a reference to a 1Password item (a pointer, not a secret) and create enrolment tokens for your agents. Legal basis: Art. 6(1)(b).
Sign-up, sign-in, password reset, verification emails and the enterprise form are rate-limited. The counters are keyed by IP address or account and count for one minute to one hour, one day for the enterprise form's per-address limit; expired counters are purged daily. Legal basis: Art. 6(1)(f). Our interest: keeping the forms from being abused.
We can see your account as its administrator: email address, join date, plan, agent and content counts, storage used, and whether the address is verified. We can change the plan, verify or block the account, and delete it. Legal basis: Art. 6(1)(b) and (f). Our interest: support, abuse handling and plans we grant by hand.
There is no self-service account deletion yet. Email [email protected] and we delete the account by hand. That removes your sessions, agents, tokens, checklist state, everything your agents pushed, your reviews, and the billing records described below.
Email we send
Verification links, the notice above, password resets and the enterprise inquiries described below leave through Amazon Simple Email Service in Ireland (eu-west-1), from [email protected], with [email protected] as the reply address. Each message waits in our job queue on the server until it is sent, normally seconds; the finished job is cleared within about a day. A message that cannot be delivered stays in the queue until we clear it by hand. Legal basis: Art. 6(1)(b).
The content your agents push
An agent enrolled to your account can push files of any kind, a headline and a description, up to 25 MB per file and 50 MB or 50 files per push; your plan sets the storage cap. We keep every version. Whatever personal data is inside a file is there because you or your agent put it there; we do not inspect or filter content. Diagrams in Markdown are rendered to images on our own server. Your reviews (approved or changes requested, a note, any images dropped into it, and your answers to the agent's questions) are stored with the version and read back by your agent. Live updates to your open pages pass through a queue on the server that keeps messages for 1 day. Legal basis: Art. 6(1)(b).
Your agent can obtain a link to one version that works for 24 hours without a login. Anyone holding that link sees that one version and nothing else, and opening it counts as opening the item for the archive clock below. Search engines are told not to index these links.
Content stays until you delete it or archive it. Archived content is deleted automatically after a period that depends on your plan (Free: 30 days, mini: 30 days, ultra: kept indefinitely); opening it resets the clock. The deletion is permanent, covers every version, file and review, and is not announced by email. Deleting a content set yourself is immediate and permanent too.
Agents and tokens
An agent has a generated name, an optional name and description you give it, and one or more API tokens. We store a hash of each token, its last four characters, an optional label and when it was last used, never the token itself. API tokens do not expire; you revoke them on the agent's page or by deleting the agent. Enrolment tokens are valid for 30 days by default (a few minted before that limit existed do not expire) and can be revoked in settings. Legal basis: Art. 6(1)(b).
Backups
The database is replicated continuously to network storage in the same building as the server, with daily snapshots kept for 10 days. Pushed files are zipped there nightly and the last 14 archives are kept. Nothing in these backups is encrypted. Something you delete can therefore survive in a snapshot for up to 10 days and in a file archive for up to 14 days; we cannot remove a single record from an existing backup. Legal basis: Art. 6(1)(f). Our interest: being able to restore the service after a hardware failure.
Billing through Stripe and Link
Paid plans are sold through Link, LLC as merchant of record and processed by Stripe. Checkout and the billing portal run on Stripe's own pages; card details go to Stripe and never reach us. When you start a checkout we send Stripe your email address to create a customer record; we hold no name to send. Legal basis: Art. 6(1)(b).
Stripe sends us copies of your customer, subscription, charge and payment-method records, and we keep them so that your plan's limits apply without asking Stripe on every request: your email address, a billing address or country if Stripe collected one, the plan, status and billing period, amounts, currency and refunds, and for a card its brand, last four digits and expiry (or the bank's name, or the email address you use with Link). These records come from Stripe, not from you. They are kept for as long as your account exists and deleted with it. Legal basis: Art. 6(1)(b).
For the sale and the payment, Stripe and Link are independent controllers: the purchase contract is with Link, and receipts and invoices come from Link, not from a stet.fyi address. See stripe.com/privacy and link.com/privacy.
The enterprise contact form
The form at /enterprise asks for a name, a work email address, a company and a message, and emails them to [email protected] through Amazon SES. Nothing is written to our database; the message passes through the job queue described under Email we send and is filtered out of the request log. It then stays in our mailbox until we delete it. Legal basis: Art. 6(1)(f). Our interest: answering an inquiry you sent us.
Before the form is accepted, Cloudflare Turnstile checks that a person is submitting it. The widget runs in your browser and sends browser and device signals to Cloudflare; our server then sends Cloudflare the resulting token and your IP address to confirm the result. Cloudflare acts as our processor for the check and, separately, as an independent controller when it uses the signals to improve Turnstile. We keep no result. If the check fails, we log your IP address and user agent with the request logs above. Turnstile loads on this one page only. If you would rather not load it, email [email protected] instead. Legal basis: Art. 6(1)(f). Our interest: keeping the form usable without being flooded by automated submissions.
Writing to [email protected]
Mail to [email protected], including replies to anything we send, support questions and requests under this policy, is read by us in a mailbox hosted by Migadu in Switzerland. We keep it until we delete it. Legal basis: Art. 6(1)(b) where it concerns your account, otherwise Art. 6(1)(f). Our interest: answering you.
Who else sees your data
| Who | What for | What they get | Where | Safeguard |
|---|---|---|---|---|
| Cloudflare, Inc., San Francisco, USA | proxy, TLS, DDoS and bot protection for every request; Turnstile on /enterprise | every request in full; Turnstile signals, token and IP address | USA and Cloudflare's global network | EU-US Data Privacy Framework (listed as under re-certification review) and the standard contractual clauses in Cloudflare's data processing agreement |
| Amazon Web Services EMEA SARL, Luxembourg | sending every email we send | recipient address and message content | Ireland (eu-west-1); US affiliates may have access | standard contractual clauses in the AWS terms; Amazon's Data Privacy Framework certification |
| Migadu-Mail GmbH, Schachen, Switzerland | hosting the [email protected] mailbox | everything sent to that address | Switzerland | EU adequacy decision for Switzerland |
| Stripe Payments Europe, Ltd., Dublin; Stripe, LLC and Link, LLC, USA | merchant of record and payment processing, as independent controllers | your email address; what you enter on Stripe's pages | Ireland and USA | Stripe, LLC: Data Privacy Framework and standard contractual clauses; Link, LLC: standard contractual clauses; their own privacy notices |
Everything else (database, files, backups, logs, traces and metrics) stays on hardware we run ourselves in Germany. The Data Privacy Framework is under appeal at the Court of Justice (C-703/25 P); the standard contractual clauses stand on their own if it falls. A copy of the clauses is available from [email protected]. Business customers who need a data processing agreement for the content their agents push: the table above is our sub-processor list; write to [email protected].
How long we keep things
| What | How long |
|---|---|
| Account: email address, password hash, settings | until you ask us to delete the account |
| Session records: IP address, user agent | 30 days after sign-in or 14 days after the last activity; deleted daily once expired |
| Login cookie | 30 days |
| Pushed content, reviews, agents | until you delete them |
| Archived content | Free: 30 days, mini: 30 days, ultra: kept indefinitely |
| Billing records mirrored from Stripe | until the account is deleted |
| Request logs: IP address, path, time | 30 days in our log store; about 10 MB rolling on the server |
| Traces | 14 days |
| Metrics (no personal data) | one year |
| Database snapshots | 10 days |
| File backups | 14 days (14 archives) |
| Outgoing email in the job queue | about a day after sending; undeliverable mail until we clear it |
| Enterprise inquiries and other mail to [email protected] | until we delete it |
| Rate-limit counters | 1 minute to 1 day; expired counters purged daily |
| Live-update queue | 1 day |
Cookies and browser storage
Three things are stored in your browser, all by us:
session_id, set when you sign in, keeps you signed in; expires after 30 days._agent_visual_companion_session, set on the first page: the CSRF token, one-time notices, and the page to return to after signing in; ends with the browser session.avc:disclosure:…in localStorage: whether you left a collapsible section open or closed; never sent to us.
All three are needed for the service you asked for, so they need no consent (§ 25(2) No. 2
TDDDG) and there is no banner. Cloudflare, in front of every request, may set its own security
cookies such as __cf_bm or cf_clearance under its own policy. The
Turnstile widget on /enterprise reads browser signals as described above; we treat it as
necessary for that one form, and email is the alternative.
Your rights
At any time, by email to hello@stet.fyi, you can ask for:
- access (Art. 15 GDPR): a copy of the data we hold about you;
- rectification (Art. 16): a correction;
- erasure (Art. 17): deletion, including of your whole account;
- restriction (Art. 18): limits on what we do with it while something is disputed;
- portability (Art. 20): a machine-readable copy of what you gave us.
We answer within a month.
Your right to object
Where we rely on a legitimate interest (Art. 6(1)(f)): request logs, traces, backups, rate limits, the Turnstile check, the mailbox. You can object at any time on grounds relating to your particular situation (Art. 21 GDPR). Email [email protected]. We then stop unless we can show compelling legitimate grounds that override your interests, or the processing is needed to establish, exercise or defend legal claims.
Consent
Nothing on this page relies on your consent. If that changes, we ask at the point of collection, and you can withdraw as easily as you agreed.
Complaints
You can complain to a supervisory authority at any time, in particular where you live or work or where you think the problem happened. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
Do you have to provide this data?
An email address and a password are needed for an account; a name, email address, company and message are needed to answer an enterprise inquiry; Stripe needs what its checkout asks for to sell you a paid plan. Nothing here is required by law. Without it, the thing it is for does not happen.
Automated decisions
We make no decision about you by automated means that has legal or similarly significant effects. Turnstile only decides whether one form submission goes through, and email remains open. Stripe and Link run their own fraud checks as independent controllers.
Changes
When what we do changes, this page changes with it, with a new date below.
Last updated: 24 September 2026