Privacy Policy
How steek.ai collects, uses, and protects personal data. We are EU-hosted and aligned with the GDPR. We never sell your data, and — in keeping with the product — we don't fabricate or embellish it.
1. Who we are
steek.ai (“steek”, “we”, “us”) provides GEO / AI-visibility analytics. steek.ai is operated from Estonia (EU); the data controller is the operator of steek.ai, and full legal-entity and registered-address details are available on request. For any privacy question, contact us at privacy@steek.ai.
2. The data we process
- Account data — your name, email address and authentication details when you sign up (handled by our auth provider).
- Billing data — subscription and payment information, processed by our payment provider. We do not store full card numbers.
- Website & waitlist data — the email address you submit to run a free check or join the waitlist.
- Usage data — logs, device/browser information and product-usage events used to operate and improve the service.
- Customer content — the brands, domains, prompts and settings you configure. For data you ask us to track on your behalf, you are the controller and steek acts as your processor.
3. How and why we use it (legal bases)
- To provide the service — performance of our contract with you (GDPR Art. 6(1)(b)).
- To bill and prevent fraud — contract and our legitimate interests (Art. 6(1)(b), (f)).
- To improve and secure the product — legitimate interests (Art. 6(1)(f)).
- To send service and, where permitted, marketing messages — consent or legitimate interests; you can opt out at any time.
- To meet legal obligations — Art. 6(1)(c).
4. Sub-processors
We share data only with vendors that help us run the service, under data-processing agreements. These currently include our cloud hosting and database/auth provider, our payment processor, our email provider, and our web-analytics provider. A current list is available at privacy@steek.ai. steek does not sell personal data.
5. Cookies
We use strictly-necessary cookies for authentication and a limited set of analytics cookies to understand product usage. You can control non-essential cookies through your browser or our cookie settings where offered.
6. International transfers
Your data is hosted in the EU. Where a sub-processor processes data outside the EEA, we rely on adequacy decisions or Standard Contractual Clauses.
7. Data retention
We keep personal data for as long as your account is active and as needed to provide the service, then delete or anonymise it, subject to legal retention requirements (e.g. accounting records).
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent. To exercise any of these, email privacy@steek.ai. You also have the right to lodge a complaint with your supervisory authority (in Estonia, the Data Protection Inspectorate / Andmekaitse Inspektsioon).
9. Security
We use industry-standard technical and organisational measures to protect personal data, including encryption in transit and access controls. No system is perfectly secure, but we take reasonable steps and notify affected users of breaches as required by law.
10. Children
steek is a business tool and is not directed to children under 16. We do not knowingly collect their data.
11. Changes to this policy
We may update this policy; we'll change the “last updated” date above and, for material changes, notify you. Continued use after an update means you accept the revised policy.
12. Contact
Questions or requests: privacy@steek.ai.