Data handling overview
Draft: not reviewed by legal counsel. Do not rely on this text for compliance decisions until counsel sign-off.
This page gives a short overview of how Steinkauz AI handles your data. For legal details, see the Privacy Policy and related Legal pages.
Workspace isolation
In Steinkauz Cloud, your data is organized by organization tenant:
- Conversations, files, API keys, provider settings, and routing policy belong to the organization.
- A tenant may have one member or many. Conversations stay private to each member by default.
Switching in the organization switcher changes which organization you access. See Organizations.
For organizations that must run the application themselves, Steinkauz AI offers Private Deployment (customer-hosted private cloud and on-premises) by direct arrangement. Shared Cloud is EU-region hosted, not a sovereign cloud. The application and its data services then run in an organization-controlled environment, with infrastructure and identity integration agreed during onboarding. See Deployment options.
What we store
- Chat history and messages: Scoped to your active organization so you can see history and continue threads. Stored in line with encryption at rest and retention policies.
- Membership and settings: Email, authentication, roles, billing, subscription, and preferences (provider configuration, routing matrix, per-chat sensitivity).
- Usage and activity data: Model usage from web chat and API Access, including token counts, costs, timing, and policy decisions. Used to show usage and activity, enforce optional Budgets, and operate the service.
In organizations, conversations are private to each member by default (including in the owner/admin sidebar). Owners and admins may review usage in Usage & Activity; only owners can inspect other members’ prompt/message content for audit.
What we do not do
We do not use your content to train our own AI models. We do not sell your data. Our business is your subscription, not monetizing your conversations or personal data.
Sending data to AI providers
When you chat, your prompts (and sometimes responses) are sent to the AI provider that serves the model you chose. Each provider has its own privacy policy and data practices.
For stricter control, use data routing policy: an execution environment on each provider, a D×E routing matrix on chat and the Platform API, and Auto or Manual sensitivity per chat thread, enforced before each request. Zero data retention is a setting on a customer-owned Vercel AI Gateway connection. It is not a Steinkauz AI certification.
With BYOK, you send data to providers whose keys you configured; you are responsible for their terms and policies.
Your control
You can delete data and manage settings for your active organization. Restrict providers via BYOK provider configuration (and Gateway provider configuration for a customer-owned Vercel AI Gateway). The routing matrix blocks chat and API requests when effective data sensitivity and the provider’s execution environment are not allowed.
Organization owners and admins configure policies for organizations. See Members, roles & invites.
Programmatic access (API Access)
When you call API Access from your own software:
Your application ──HTTPS──► Steinkauz AI /v1 ──► Your configured AI providers- Authentication uses a Steinkauz AI API key (Bearer token) created in Settings → API Keys for the active organization.
- Prompts and completions follow the same D×E routing as web chat, subject to the API routing policy on each key.
- Activity records for API requests appear in Usage & Activity alongside chat activity, with API key attribution.
- See the Privacy Policy for metadata we store about API usage.
For encryption and technical safeguards, see Encryption at rest.