Privacy Policy

    Last updated August 08, 2025

    This privacy notice for Strama AI Inc ("we," "us," or "our") describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:

    • Visit our website at https://strama.ai, or any website of ours that links to this privacy notice

    • Engage with us in other related ways, including any sales, marketing, or events

    Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at support@strama.ai.

    SUMMARY OF KEY POINTS

    This summary provides key points from our privacy notice, but you can find out more details about any of these topics by using the table of contents below.

    • What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.

    • Do we process any sensitive personal information? We do not process sensitive personal information.

    • Do we collect any information from third parties? We may collect information from public databases, marketing partners, social media platforms, and other outside sources.

    • How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

    • In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties.

    • How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the Internet or information-storage technology can be guaranteed to be 100 % secure.

    • What are your rights? Depending on where you are located geographically, applicable privacy law may give you certain rights regarding your personal information.

    • How do you exercise your rights? Submit a data-subject access request or contact us directly.

    For full details, please read the entire privacy notice below.


    TABLE OF CONTENTS

    1. WHAT INFORMATION DO WE COLLECT?

    2. HOW DO WE PROCESS YOUR INFORMATION?

    3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?

    4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

    5. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

    6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

    7. HOW LONG DO WE KEEP YOUR INFORMATION?

    8. HOW DO WE KEEP YOUR INFORMATION SAFE?

    9. DO WE COLLECT INFORMATION FROM MINORS?

    10. WHAT ARE YOUR PRIVACY RIGHTS?

    11. CONTROLS FOR DO-NOT-TRACK FEATURES

    12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

    13. GOOGLE API DISCLOSURE

    14. DO WE MAKE UPDATES TO THIS NOTICE?

    15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

    16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

    1. WHAT INFORMATION DO WE COLLECT?

    Personal information you disclose to us

    In Short: We collect personal information that you provide to us.

    We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, participate in activities on the Services, or otherwise contact us.

    Personal Information Provided by You
    The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include:

    • Names

    • Email addresses

    • Usernames

    • Passwords

    Sensitive Information
    We do not process sensitive personal information.

    Payment Data
    We may collect data necessary to process your payment if you choose to make purchases, such as your payment-instrument number and the associated security code. All payment data is handled and stored by Stripe (https://stripe.com/privacy).

    Social-Media Login Data
    We may offer you the option to register with us using your existing social-media-account details (e.g., Facebook or X). If you choose to do so, we will collect certain profile information as described in HOW DO WE HANDLE YOUR SOCIAL LOGINS?.

    All personal information you provide must be true, complete, and accurate, and you must notify us of any changes.

    Information automatically collected

    In Short: Some information — such as your IP address and/or browser and device characteristics — is collected automatically when you visit our Services.

    We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information such as IP address, browser characteristics, operating system, language preferences, referring URLs, device name, country, location, usage patterns, and other technical details.

    The information we collect includes log and usage data, device data, and location data. You may opt out of location-data collection by disabling your device's location settings, though some functionality may be limited.

    Google API

    Our use of information received from Google APIs adheres to Google's API Services User Data Policy, including the Limited Use requirements.

    Information collected from other sources

    We may collect limited data from public databases, marketing partners, social-media platforms, and other outside sources to enhance our services and update our records.

    2. HOW DO WE PROCESS YOUR INFORMATION?

    We process your information to facilitate account creation, deliver services, respond to inquiries, request feedback, send marketing communications, protect our Services, evaluate and improve offerings, identify usage trends, and determine campaign effectiveness.

    We only process your personal information when we have a valid legal reason, such as consent, legal compliance, contractual necessity, protection of rights, or legitimate business interests.

    4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

    We may share information with vendors, consultants, service providers, contractors, or agents who perform services on our behalf. Categories include:

    • Allow Users to Connect to Third-Party Accounts — Google, Microsoft, Unipile

    • Cloud Computing Services — PlanetScale, Amazon Web Services (AWS), Azure OpenAI Service, OpenAI, Anthropic, Google Cloud, Vercel

    • AI Services — Anthropic, OpenAI, Google

    • Invoice & Billing — Stripe

    • User Account Registration & Authentication — Google OAuth 2.0, Microsoft OAuth 2.0

    • Web & Mobile Analytics — Amplitude, PostHog

    • Website Hosting — Vercel

    We may also share information during business transfers (e.g., merger or acquisition).

    5. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

    Yes. Our AI features rely on third-party providers Anthropic, OpenAI, and Google. Data is processed in line with this notice.

    6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

    If you register using a social-media account, we receive certain profile information to authenticate you and operate the Services. We do not control how third-party providers use your data.

    7. HOW LONG DO WE KEEP YOUR INFORMATION?

    We keep personal information only as long as necessary for the purposes outlined in this notice unless law requires otherwise. When no longer needed, we delete or anonymize the data.

    8. HOW DO WE KEEP YOUR INFORMATION SAFE?

    We implement reasonable technical and organizational security measures but cannot guarantee absolute security.

    9. DO WE COLLECT INFORMATION FROM MINORS?

    We do not knowingly collect data from children under 18. If such data is discovered, we delete it promptly.

    10. WHAT ARE YOUR PRIVACY RIGHTS?

    Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal data, opt out of marketing, withdraw consent, and submit complaints. To exercise these rights, submit a data-subject access request or email support@strama.ai.

    11. CONTROLS FOR DO-NOT-TRACK FEATURES

    We currently do not respond to DNT signals.

    12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

    Yes. California and other-state residents have rights under applicable laws, including access, deletion, correction, and opt-out rights. We have not sold or shared personal data in the past 12 months.

    13. GOOGLE API DISCLOSURE

    Strama's use of information received from Google APIs will adhere to Google's API Services User Data Policy, including the Limited Use requirements. Data obtained via Google Workspace APIs is not used to train generalized AI/ML models.

    14. DO WE MAKE UPDATES TO THIS NOTICE?

    Yes. We update this notice as necessary, with changes indicated by the "Revised" date above.

    15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

    Email: support@strama.ai
    Mail: Strama AI Inc., PMB 1289, 447 Sutter St Ste 405, San Francisco CA 94108, United States

    16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

    Submit a data-subject access request via our DSAR portal or email support@strama.ai.