Back to Interstrata
Legal

Privacy Policy

How Interstrata handles your data. The short version: your data is yours, we minimize what we collect, and our custody system puts you in control of encryption.

Last updated: March 2026

Overview

Interstrata provides an accountability layer for AI workflows. We process data you import (conversation exports, agent logs) to extract structured insights (decisions, commitments, events) and build your continuity timeline. This policy explains what data we collect, how we use it, and the controls you have over it.

Our core principle is data minimization: we collect the minimum data necessary to provide the service, and our custody system lets you choose who can decrypt your content — including an option where we cannot access it at all.

What we collect

Account information

Email address, name, and authentication credentials when you create an account. Payment information is processed by Stripe and never stored on our servers.

Imported content

Conversation exports and agent logs you upload for processing. This content is encrypted according to your selected custody profile.

Extracted artifacts

Structured data generated by our extraction engine: decisions, commitments, assumptions, events, actors, and threads. These are derived from your imported content and stored under the same custody profile.

Usage data

Anonymous analytics (via Plausible, a privacy-focused analytics provider): page views, feature usage patterns, and performance metrics. No personally identifiable information is included in analytics.

Trust receipts

Hash-linked records of privileged actions (custody changes, recovery events, Safe Mode triggers). These are minimal by design — they contain timestamps, action types, and cryptographic hashes, not content.

What we don't collect

We do not capture by default: raw message content beyond what you explicitly import, full URLs or query strings from browsing, precise location data, contact graphs, or any data from AI platforms you haven't connected. We do not sell your data to third parties. We do not serve advertising. We do not use your content to train AI models.

Custody profiles

Interstrata provides three custody profiles that determine who can decrypt your content. You choose your profile during onboarding and can change it at any time.

Profile A: Local Vault (Self-custody)

Only you hold the keys. Interstrata cannot decrypt your content under any circumstances. Recovery depends entirely on your own backups.

Profile B: Cloud Vault (Assisted E2EE) — Default

End-to-end encrypted. We store only encrypted data and wrapped keys. Recovery is possible through recovery codes, recovery keys, or trusted contacts.

Profile C: Managed Vault (Enterprise)

Service-managed encryption with strict internal controls. Supports standard account recovery, admin restore, and enterprise compliance workflows.

How we use your data

We use your data to: provide and improve the Interstrata service, extract structured insights from your imported content, generate accountability reports and incident binders, send service-related communications (account security, product updates), and maintain system security and prevent abuse.

We do not use your content for: training machine learning models, advertising or marketing profiling, sale to third parties, or any purpose beyond providing and improving the service you've subscribed to.

Third-party services

We use a limited set of third-party services: Supabase (infrastructure and database hosting, US-based), Stripe (payment processing), Vercel (application hosting), Plausible (privacy-focused analytics, EU-based), and LLM providers (for extraction processing — content is sent to LLM APIs in accordance with your custody profile). We do not share your data with any other third parties.

Data retention

Your imported content and extracted artifacts are retained for as long as your account is active. You can delete specific content or your entire account at any time. Upon account deletion, content objects are removed within 30 days. Trust receipts may be retained in redacted form (timestamps and hashes only, no content) where legally required. Backups are purged within 90 days of deletion.

Your rights

Regardless of jurisdiction, you have the right to: access your data (export your vault at any time), correct inaccurate data, delete your data (with clear "what remains" summary), restrict processing, port your data (encrypted export bundles), and withdraw consent for optional processing.

For users subject to GDPR, UK GDPR, or comparable regulations: we process personal data under legitimate interest (service provision) and consent (optional features). You may exercise your rights by contacting privacy@interstrata.ai or through the Settings panel in the application. We respond to all requests within 30 days.

Children's privacy

Interstrata is not intended for use by anyone under 16. We do not knowingly collect personal information from children. If we discover we have collected data from a child, we will delete it promptly.

Changes to this policy

We will notify you of material changes via email and/or in-app notification at least 30 days before they take effect. Non-material clarifications may be made at any time. The "last updated" date reflects the most recent revision.

Contact

For privacy-related inquiries: privacy@interstrata.ai. For data subject requests: use the Settings panel in the application or email privacy@interstrata.ai. We respond within 30 days.