Privacy Policy
Last updated 30 July 2026
Stratos is a private internal tool used by one company to run its own operations. It has no public sign-up, no consumer users, and it does not collect personal data from visitors, advertising audiences, or the customers of any platform it connects to.
Who this covers
Stratos (“the app”) is operated privately by its workspace owner. Access is by invitation only, and everyone with an account is a member or contractor of the operating company. There is no version of this app available to the general public.
What data the app holds
- Account data for invited members: name, email address, profile photo, and authentication data handled by our identity provider.
- Business records that members create in the app: notes, tasks, documents, contacts, financial entries, files, and advertising material.
- Connected-service credentials (for example email mailboxes and advertising platform tokens), encrypted at rest with AES-256-GCM and never displayed back in full.
- Operational logs necessary to run and secure the service.
Meta (Facebook and Instagram) data
The app connects to the Meta Marketing API to manage the operating company’s own advertising accounts. That connection is authorised by the account owner from within Meta Business Settings and can be revoked there at any time.
Through that connection the app:
- reads aggregate performance figures for its own ads — impressions, clicks, spend and similar metrics;
- uploads its own advertising artwork and copy, and creates ads in its own ad accounts.
The app does not request, receive, store, or process personal data about Facebook or Instagram users. It does not read profiles, messages, friend lists, audiences, or customer lists, and it does not use any Meta data for advertising profiling, resale, or transfer to third parties.
Who else processes this data
The app runs on third-party infrastructure. Each provider processes data only to deliver its service to us:
- hosting and edge delivery;
- a managed database and file storage provider;
- a transactional email provider, for notifications and invitations;
- model providers, for the app’s AI features, on the content a member explicitly submits to them;
- Meta Platforms, for the advertising connection described above.
Data is not sold, rented, or shared for anyone else’s marketing.
Where data is held and for how long
Data is stored on servers in the European Union and kept for as long as the workspace is active. Deleted records go to a recoverable Trash and are purged permanently after 30 days. Backups roll off on their own schedule.
Security
Access requires authentication and, for the workspace, a second factor. Permissions are granted per person and per area of the app. Credentials for connected services are encrypted at rest, and access to stored secrets is logged.
Your rights
Anyone whose personal data is held here may ask for a copy of it, ask for it to be corrected, or ask for it to be deleted. Requests are answered within 30 days. Instructions for requesting deletion are on their own page.
Changes
If this policy changes, the revised version is published on this page with a new date at the top.
Contact
Questions about this policy, or about data held about you: privacy@stratos.im.
