Privacy, in plain words.
This is the whole policy, not a summary of one. It says what we hold, why, where it lives and for how long. Short on time? Read only the bold line under each question.
Version 1.0In force from 21 September 2026Vyana Compute, New Delhi, India
- We hold what you type at sign-up, and the records your agents send.
- No ads, no selling data, no trackers on this site or in the product.
- Your prompts and outputs never enter our search index.
- Your signing key cannot be exported, by us or by anyone.
- Ask for a copy or for deletion by email. A person answers.
You are reading the bold lines only. They are part of the text, and they are accurate, but the detail under each one still applies.
Whose data is it, and who is responsible for it?
There are two kinds of data in Stratl. We are responsible for the first. You are responsible for the second, and we only handle it on your instructions.
Data about you
Your email, name, company and sign-in details. Vyana Compute decides how this is used, within this policy, and answers for it.
In legal terms we are the data controller, or data fiduciary.Data your agents record
Decision records about your customers, applicants or systems. It is yours. You decide what is sent, how long it is kept and who sees it. We store, sign and serve it back to you.
In legal terms you are the controller and we are your processor.Stratl is built and operated by Vyana Compute, based in New Delhi, India. You can reach the people responsible for privacy at hello@stratl.ai. If your company needs a written data processing agreement, write to us and we will work one out with you.
We use data about you because we need it to provide the service you signed up for, and we keep security data such as IP addresses because we have a legitimate interest in keeping the service safe.
What do you hold, why, where, and for how long?
Ten things, listed below. Pick one to see why we have it, where it lives, how long it stays and who can see it.
Email address
The address you sign in with.
- Why
- To sign you in with a one-time code, and to tell you things about your workspace, such as a security notice or a change to this page. No newsletters unless you ask for them.
- Where
- Our account database. It also passes through our email provider each time a code is sent.
- How long
- For as long as your account exists. Removed within 30 days of a deletion request.
- Who can see it
- You, and the few people at Vyana Compute who run Stratl.
Profile and workspace
Your name, job title and company. The workspace name and custody region. The optional answers at sign-up: industry, company size, use cases and stack.
- Why
- To set up the workspace, create its signing key in the right region, and tailor the getting-started guide. During early access we also read these to understand who is using Stratl.
- Where
- Our account database.
- How long
- For as long as the workspace exists. Removed within 30 days of a deletion request.
- Who can see it
- People in your workspace, and the people who run Stratl.
Sign-in codes
The six-digit codes we email you. We store a keyed hash of each code, never the code itself, together with the IP address that asked for it.
- Why
- To sign you in without a password, and to slow down anyone guessing codes. A code works for 10 minutes and five attempts.
- Where
- Our account database.
- How long
- A used or expired code cannot sign anyone in, and its row is deleted automatically 24 hours after it expires or is used.
- Who can see it
- Nobody can read a code back. The people who run Stratl can see that one was requested, when, and from which IP address.
Your session
One cookie, stratl_session. We store a hash of it with your browser's user-agent string, your IP address and the time it was last used.
- Why
- To keep you signed in, and so a session that is not yours can be spotted and ended.
- Where
- The cookie lives in your browser and cannot be read by scripts. The hash lives in our account database.
- How long
- 30 days, or until you sign out. Expired sessions are deleted automatically.
- Who can see it
- The people who run Stratl.
Invitations
When a workspace invites someone: the invited email address, the role, who sent it, and a hash of the link's token. The token itself is never stored.
- Why
- So the right person can join the right workspace in the right role, and so nobody can join with a forwarded link unless they can also receive email at that address.
- Where
- Our account database. The email passes through our email provider.
- How long
- Seven days if unused, then the link is dead and the row is deleted a month later. An accepted invitation stays as the record of who invited whom until the workspace is deleted.
- Who can see it
- The workspace's owners and admins, and the people who run Stratl.
Ingest keys
For each key: a hash, the last four characters, the name you gave it, who created it and when it was last used. The key itself is shown once and never stored.
- Why
- So your agents can write records. Ingest keys can write and can never read.
- Where
- Our account database.
- How long
- Until the workspace is deleted. A revoked key stays listed as revoked, so the history of who could write remains intact.
- Who can see it
- People in your workspace, and the people who run Stratl.
Decision records
What your agents send: fingerprints of content, and metadata. That means subject identifiers such as an order or applicant number, the names of agents, models and tools, policy names and versions, approver identifiers (often an email address), outcomes and timestamps.
- Why
- This is the service: to sign, chain, store, search and hand back evidence. We use records for nothing else.
- Where
- The signed record is in Amazon S3 in your custody region. A searchable copy of the metadata is in our index database, which runs in one location for all workspaces.
- How long
- For as long as your workspace's retention policy says, and indefinitely if none is set. A person at Vyana Compute carries out deletion when you ask, because the service itself has no permission to delete, and only for records the policy allows: a legal hold placed by your workspace blocks deletion of what it covers until it is lifted. If a retention lock was set on the storage, locked objects cannot be removed until the lock expires.
- Who can see it
- People in your workspace. Our operators look only when you ask for help, or when a fault cannot be fixed any other way.
Original content
Prompts, responses and payloads, only if you choose to send them so they can be re-hashed against the record later.
- Why
- So a verifier can confirm that a fingerprint in a record really belongs to this content.
- Where
- Amazon S3 in your custody region, filed under its own fingerprint. It never enters the search index.
- How long
- The same as decision records.
- Who can see it
- People in your workspace, through the record it belongs to. Our operators, only as described for records.
Notices to affected people
When you ask Stratl to draft a notice for an affected person, the record's fields and fingerprints may be sent to Anthropic's Claude to write the draft. Original content is never sent. If you choose to send the approved notice by email, the person's email address and the notice go through our email provider, and the provider's message id is kept on the notice.
- Why
- To produce a first draft in plain language. Every sentence has to cite a field in the record, or the draft is discarded and a built-in template is used. A person approves a notice before it goes anywhere.
- Where
- Anthropic processes the request. The draft is stored with your record.
- How long
- The draft is kept with the record. We do not control how long Anthropic keeps request data; their terms for API customers apply.
- Who can see it
- People in your workspace.
Logs
Request logs at our hosting providers: IP address, path, time and status. Application logs of events and errors, which include your email address when a sign-in code is sent. Logs never contain record content.
- Why
- To keep the service running, find faults and investigate abuse.
- Where
- At the hosting providers listed below.
- How long
- For each provider's standard log retention. We do not copy logs anywhere else.
- Who can see it
- The people who run Stratl.
Emails you send us
Whatever you write to us, and your address.
- Why
- To answer you.
- Where
- Our mailbox.
- How long
- For as long as the conversation is useful. Ask and we will delete it.
- Who can see it
- The people at Vyana Compute who answer email.
Signing keys are not personal data, but people ask. Each workspace's key is created inside AWS KMS in its custody region and cannot be exported. It is kept for as long as records signed with it may need to be verified, and is never deleted early.
What will you never do with it?
We do not sell data, show ads, run trackers, or train models on what you send.
Sell or rent data
Not yours, and not the data about the people your agents make decisions about.
Show ads or build ad profiles
There is no advertising anywhere in Stratl.
Run trackers or analytics scripts
There are none on this website or in the product. Nothing follows you around.
Train models on your data
We do not use your records or content to train any model.
Put raw content in our index
The index holds fingerprints and metadata. Originals stay in the custody bucket.
Hold a signing key
Keys are created inside AWS KMS and cannot be exported by anyone.
Who else handles my data?
Six companies, each for one job. None of them may use your data for their own purposes.
We also hand data over when the law requires it. If that ever concerns your workspace we will tell you first, unless we are legally forbidden to. If Stratl is ever sold or merged, this policy continues to apply to your data until you are told otherwise and given the chance to leave.
Where is it kept, and does it cross borders?
Your records, content and signing key stay in the custody region you chose at sign-up. Account data and the search index live in one location for everyone, which may be outside your country.
The custody region live today is India (AWS ap-south-1). The search index holds fingerprints and metadata, including subject identifiers and agent names. If that metadata must stay in a particular country for you, Stratl is not ready for that workload yet, and the early access page says so.
Where data moves between countries, we rely on our providers' standard contractual protections. Ask us if you need the details for a particular provider.
How do you protect it?
Encryption in transit, hashed secrets, a signing key nobody can export, and a service that has no permission to delete your records. We do not have a SOC 2 report yet.
- All traffic uses TLS. Records and content in Amazon S3 are encrypted at rest, with every version kept.
- Sign-in codes, session tokens and ingest keys are stored as hashes. We could not read them back if we wanted to.
- The session cookie cannot be read by scripts. Ingest keys can write and never read.
- Every query is scoped to one workspace. A request for another workspace's record gets the same answer as a record that does not exist.
- The service may ask KMS to sign and may write to S3. It may not export, delete or disable a key, or delete a stored object.
If we find that your data was accessed by someone who should not have had it, we will tell every affected workspace owner without undue delay, and no later than 72 hours after we confirm it, with what we know and what we are doing.
What can I ask you to do?
See it, fix it, delete it, or object. Email us. A person answers within 30 days, and it costs nothing.
Get a copy
Everything we hold about you, in a form you can read.
Email usFix something
If anything about you is wrong or out of date.
Email usDelete it
Your account, or the whole workspace with its records.
Email usObject or complain
Tell us to stop using your data in some way, or tell us we got it wrong.
Email usDeleting a workspace removes its account data and search index within 30 days, and its records and content from storage, subject to any retention lock. Export the evidence bundles you need first. Bundles you have exported are yours and keep verifying without us. Copies in database backups, where they exist, age out on our host's backup schedule.
We may need to confirm that a request really comes from you, normally by replying to the address on the account. You also have the right to complain to the data protection authority where you live. We would like the chance to put it right first.
What if an AI decision was about me, and the company uses Stratl?
Ask that company first. The record belongs to them, and they decide what happens to it. We will help them answer you.
If a company used Stratl to record a decision about your order, application or account, that company controls the record. We hold it on their instructions and cannot hand it to you, change it or delete it on our own. If you write to us, we will pass your request to the company concerned where we can identify it, and tell you that we have.
Records normally hold fingerprints and identifiers rather than what you wrote or what the AI answered. The company may have sent the originals to be stored next to the record, in which case they are held in that company's custody region.
Does this website use cookies or track me?
No. This website sets no cookies and loads no analytics or third-party scripts. The product sets one cookie, to keep you signed in.
Fonts are served from our own domain, so reading this page tells nobody but our host that you were here. The host sees your IP address because that is how web pages are delivered.
The product remembers two preferences in your browser's local storage: light or dark theme, and whether the sidebar is collapsed. They never leave your browser.
Is Stratl for children?
No. Stratl is a tool for companies, and accounts are for adults acting for one.
We do not knowingly create accounts for anyone under 18. If you believe a child has signed up, write to us and we will remove the account.
What happens when this page changes?
If a change matters, we email every workspace owner at least 14 days before it takes effect. The history is below.
Fixing a typo or making a sentence clearer does not count as a change that matters. Collecting something new, sharing data with someone new, or changing what you or we are committed to does. If you do not agree with a change, you can export your evidence and close your workspace before it takes effect.
v1.021 September 2026First version, published with private early access.
Something unclear, or wrong?
Write to us and a person will answer. If a sentence here can be read two ways, tell us and we will fix the sentence.