Legal · Privacy
Privacy Policy
What we collect, what we do with it, and the commitments we hold ourselves to. Written to match how Stillport actually works — a fleet that reads on your behalf and drafts work you approve.
Last updated: 3 August 2026
Who we are
Stillport (“Stillport,” “we,” “us”) provides an AI “fleet” that connects to the tools a business already uses — such as Shopify, Google Analytics, Search Console, Gmail, Meta, Stripe, and GitHub or Bitbucket — mostly read-only, and drafts work (email replies, social posts, ad analyses, pull requests) that the business owner reviews and approves in Clearance. Nothing sails without clearance: nothing sends, posts, merges, or spends without the owner’s explicit approval.
This Privacy Policy explains what personal and business data we process, why, and the rights you have. It applies to the Stillport application and marketing site at stillport.ai.
What data we collect
We collect and process three broad categories of data:
- Account data. The information needed to create and secure your account — your email address (verified at signup), authentication details, workspace and business profile, and the goals and standing orders you give your fleet.
- Connected-source data. When you connect a source, your fleet reads business and analytics data on your behalf through that provider’s API — for example order and store data, web and search analytics, email content you ask it to draft replies to, ad performance, payment summaries, and code repositories. Access is scoped read-only or draft-only wherever the provider supports it.
- Usage & telemetry. Operational logs and diagnostics generated as you use the service — requests, errors, feature usage, and similar records used to run, secure, and improve the product.
How we use your data
We use the data above to:
- operate and secure the service and your account;
- read your connected sources on your behalf and draft work — briefings, replies, posts, analyses, and pull requests — for you to approve in Clearance;
- turn your corrections into standing orders that live in your tenant and improve the drafts your fleet produces for you;
- send service and account communications (such as email verification and important notices);
- diagnose problems, prevent abuse, and meet legal obligations.
Our commitments
These are core promises, not marketing lines. They hold by default and are non-negotiable:
- Your data is never used to train models. Your data and the learnings your fleet builds stay private to your tenant.
- Per-tenant isolation. Your data is private to your tenant and is not shared with other customers. Standing orders live in your tenant alone.
- We do not sell your data. We do not sell personal or business data, and we do not share it for third-party advertising.
- Human-in-the-loop by design. Stillport drafts; you approve. Nothing acts against a connected source without your clearance.
Third-party processors
We rely on third parties to deliver the service. These fall into two groups, and we share only what each needs to do its job:
- Sources you connect. The providers you authorize (for example Shopify, Google Analytics, Search Console, Gmail, Meta, Stripe, GitHub, and Bitbucket). Your fleet accesses them under the scopes you grant — read-only or draft-only — and their own terms and privacy policies govern the data held on their side.
- Infrastructure & operations. Providers that host and run the service, such as cloud infrastructure (e.g. DigitalOcean) and transactional email (e.g. AWS SES for signup verification). We also use model providers (e.g. Anthropic) to generate drafts: the content your fleet reads — including email message content when you ask it to draft a reply — is sent to the model provider to produce that draft. As stated above, your data is not used to train models, by us or by them.
The specific providers in use may change as the product evolves. We will keep this list honest and current.
Google Workspace data & Limited Use
When you connect a Google source, Stillport requests only the scopes needed for the features you enabled — for example reading Analytics and Search Console reports, or reading your mailbox and composing replies in it. Where a Google feature drafts on your behalf, the relevant message content is sent to our model provider to produce that draft for you, and is not retained by the provider to train models.
Stillport’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Specifically, Google Workspace user data obtained through these scopes:
- is used only to provide or improve the user-facing features you enabled, and is not used for any other purpose;
- is not used for advertising, and is never sold or transferred to data brokers or information resellers;
- is not used to develop, improve, or train generalized or non-personalized AI and/or ML models — it is used only to serve your own request, at the moment you make it;
- is not transferred to any third party that uses it to develop, improve, or train such models;
- is read by a human only where you explicitly ask us to, where you have given us permission for a specific support issue, where it is necessary for security purposes such as investigating abuse, or where required by law.
Data retention & deletion
We keep account and connected-source data for as long as your account is active and as needed to provide the service. When you disconnect a source, we delete its stored access tokens. When you close your account, we delete or anonymize your data within a reasonable period, except where we must retain limited records to meet legal, security, or accounting obligations. You can export your data before you leave.
Security
The most sensitive thing we hold is the set of credentials that let your fleet read your connected sources, so we protect them with specific, named mechanisms rather than good intentions:
- Encryption in transit. The application and the marketing site are served only over HTTPS using industry-standard TLS, with certificates issued and renewed automatically. Every call your fleet makes to a connected provider’s API is made over HTTPS as well.
- Encryption at rest for credentials. OAuth tokens and provider credentials are encrypted with AES-256-GCM — authenticated encryption, so tampering is detected rather than silently accepted — under a 256-bit data encryption key belonging to your tenant alone. That per-tenant key is never stored in the clear: it is itself wrapped by a versioned master key, so master keys can be rotated and old records re-wrapped without re-authorising your sources.
- Records bound to their owner. Each encrypted credential is cryptographically bound to the tenant and the specific connection it belongs to. An encrypted token cannot be moved to another tenant or another connection and still decrypt — the attempt fails outright.
- Access control. Data is isolated per tenant, queries are scoped to your tenant, and access to production systems is restricted to the small number of people who need it to operate the service.
- Least privilege. We request the narrowest OAuth scopes a feature needs, and they are read-only or draft-only wherever the feature allows. Where a feature does act — sending an approved mail reply, or applying an approved ad change — the scope that permits it is requested only for that feature and is exercised only on a change you have cleared.
- Deletion. When you disconnect a source we delete its stored access tokens, as described under Data retention & deletion above.
No system is perfectly secure, but we work to protect your data commensurate with its sensitivity and to respond quickly if something goes wrong. If you believe you have found a security issue, write to privacy@stillport.ai.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Within the product you can view your connected sources, disconnect them, export your data, and delete your account. To make any other request, contact us at privacy@stillport.ai. We will not discriminate against you for exercising these rights.
Cookies
We use cookies that are necessary to run the service — for example to keep you signed in, to remember preferences such as your theme, and to remember your answer to the question below.
We also use Google Analytics to understand which pages people find useful, and it sets its own cookies. It does not run unless you say yes. On your first visit we ask, and until you choose “Allow” we do not load Google’s script at all — nothing is requested from Google and no analytics cookie is set. If you decline, that stays true indefinitely.
When it is on, Google Analytics receives the page you are viewing and standard technical details such as your browser and approximate location, with IP anonymisation enabled. We never send it your business data: no email address, no account or organisation identifier, no card contents, no chat messages, and no details of the accounts you have connected. Addresses of pages inside the app are stripped of identifiers before they are sent, so Google sees the shape of a page rather than which of your records you were looking at. We have not enabled Google’s advertising or personalisation features.
To change your mind, delete this site’s cookies in your browser and reload — we will ask again. Your choice is otherwise remembered for about six months.
Children's privacy
Stillport is a business tool and is not directed to children. It is not intended for use by anyone under the age of 16 (or the minimum age required in your jurisdiction), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
International transfers
We and our processors may store and process data in countries other than the one you live in. Where data is transferred across borders, we rely on appropriate safeguards to protect it consistent with this policy and applicable law.
Changes to this policy
We may update this policy as the product and our practices evolve. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Continued use of the service after an update means you accept the revised policy.
Contact
Questions about this policy or your data? Write to privacy@stillport.ai.
This document is a draft prepared by Stillport and has not yet been reviewed by legal counsel. It does not constitute legal advice.