Privacy Policy
Effective 2026-06-16 · Version 2026-06-16
This Privacy Policy explains how [LEGAL: registered entity name] (ABN [LEGAL: ABN]) ("Strata", "we", "us") handles personal information when you use the Strata website, APIs, dashboard, and built-in applications. We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Where the GDPR applies to you, we also honour the rights it provides (see "Your rights").
Information we collect
Waitlist and contact forms
When you submit the developer waitlist or enterprise contact form, we store what you provide (email, and optionally name, company, message) plus basic request metadata (timestamp, the page you submitted from, referring source, campaign parameters, and your IP address, which we use for spam and abuse screening) to respond and to send the updates you have asked for.
These forms are protected by Cloudflare Turnstile, which screens out automated (bot) submissions. To do this, Cloudflare processes limited technical information from your browser, as described in the Cloudflare Turnstile Privacy Addendum. Turnstile runs invisibly in the background and is not used for advertising.
Account information
To run your account we store your email, name, organization, and authentication identifiers. Sign-in and passwords are handled by a managed identity service operated within our cloud infrastructure; we never store or have access to your password. You can also choose to sign in through an external identity provider (listed on our Sub-processors page), in which case we receive the email address and name it returns to create or match your account, and never receive your password.
Sign-in security
If you turn on two-step verification, we store what we need to check your second factor: a secret for your authenticator app, one-time backup recovery codes (kept only as hashes, never in readable form), and any passkeys you register (a public key and credential identifier; the matching private key stays on your device and is never sent to us). We also record which sign-in and security methods are active on your account. When one of these settings changes, we send a notification email to help you spot activity you did not authorize.
Gateway / API usage: metadata only
When you use Strata purely as an API gateway, we relay your requests to the managed infrastructure that hosts the model and record only technical usage metadata: the model called, token counts, latency, status, and any attribution tags you attach. In this mode we do not store the content of your prompts or the model's responses. Your content is not used to train models, by us or by the infrastructure that serves them.
Content within built-in applications
Some Strata applications exist to work directly with your content and therefore store that content so the feature can function:
- StrataChat stores your conversation history (messages, threads, projects) so you can return to it.
- StrataBench stores the prompts you save and the inputs, outputs, and rankings of the benchmark runs you create.
- StrataSwarm stores your run records and the artifacts a run generates; detailed step logs and a run's working files are automatically deleted after a retention period, and draft intake data expires within about 24 hours.
In all cases this content remains yours: you can export or delete it (see "Your rights"). Any current or future built-in application follows the same principle: content is stored only to provide the feature, remains yours, and can be deleted.
Web search within built-in applications
Some built-in applications can search the web at your request. When you use web search, your search query (and the pages it returns) are processed by third-party search and content-retrieval providers listed on our Sub-processors page. Queries are sent only when you invoke web search, and are not linked by those providers to your Strata account.
Billing
Payments are processed by our payment processor (listed on the Sub-processors page). We store billing identifiers and metadata; we do not store full card numbers.
Cookies
We use cookies only to run the dashboard, never for third-party advertising or analytics. These are: a session cookie that keeps you signed in (longer-lived if you choose "remember me"); an optional cookie that remembers your email address on a device so you do not have to retype it; and short-lived cookies used only to carry you through the sign-in, two-step verification, passkey, and single sign-on steps.
How we use information
- To provision, operate, and improve the Services.
- To detect, prevent, and investigate abuse, fraud, spam, and security incidents (including rate limiting and screening of automated submissions).
- To provide support: our staff may view your account and usage records when helping you or your organization.
- To respond to enquiries and send transactional emails, including sign-in security notifications, billing and Credits alerts such as low-balance and payment notices, and budget alerts (you can opt out of non-essential emails).
- To send waitlist and launch updates you have requested (you can unsubscribe at any time).
- To process payments and meet tax and accounting obligations.
- To comply with law and enforce our Terms and Acceptable Use Policy.
We do not use your prompts, responses, or application content to train models, and content sent to models is not used by our infrastructure providers or the model vendors to train their models. We do not sell personal information or use it for third-party advertising.
Sub-processors and sharing
We do not sell personal information. We share information with the service providers that help us operate Strata (principally our cloud infrastructure provider and our payment processor) under contractual data-protection terms, only as needed to provide the Services. The current list is on our Sub-processors page.
International transfer
Our infrastructure runs on AWS in [LEGAL: AWS region]. Where information is disclosed to recipients outside Australia, we take reasonable steps to ensure it is handled consistently with the APPs.
Retention
We retain account and usage metadata for the life of your account. Built-in-application content is retained until you delete it (subject to the automatic expiries noted above for StrataSwarm). We retain records we are legally required to keep (for example, tax invoices) even after you delete other data. You can request deletion at any time.
Your rights
You may request access to the personal information we hold about you, ask us to correct it, or ask us to delete it, and request a copy in a portable form. Contact [LEGAL: privacy contact email] and we will respond within a reasonable time and within any period the law requires.
Security
We protect information with encryption in transit, access controls, and managed authentication. You can add two-step verification and passkeys to your account for stronger protection, and organizations can require two-step verification for their members. No method of transmission or storage is completely secure, but we take reasonable steps to protect your information.
Children
Strata is not intended for anyone under 16, and we do not knowingly collect their information.
Complaints
If you have a privacy concern, contact us first at [LEGAL: privacy contact email]. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Changes and contact
We may update this policy; material changes will be reflected by the effective date above. Questions: [LEGAL: privacy contact email].
This document is provided for transparency and may be updated; the effective date above reflects the current version.