Privacy
Privacy
Stenlio reads sources you connect and keeps a copy of what it read, so every claim it makes can be traced to its evidence. This page says what that copy contains and how long it lives.
Last substantive change:
The data, item by item
- What is read
- The repository you install the GitHub App on, your public website, and any optional source you connect (Stripe, PostHog, Search Console). Nothing is read before you connect it.
- What is copied
- Repository trees, sampled file contents, and crawled page HTML are stored by Stenlio as snapshots in a private object bucket, keyed by a hash of their own content. This is how a finding can be traced back to the evidence it came from.
- What is not copied
- Card data, payment methods, raw customer records, and session recordings. Stripe and PostHog are read as aggregate snapshots only.
- Where the database sits
- Postgres holds the pointer to each snapshot, its content hash, a bounded summary, and a status — never the raw payload in a column.
- Credentials
- Per-company integration credentials are encrypted and unreachable from models, browser clients, logs, and other companies on the platform.
- Retention
- Deleting a company disables workflows, revokes content authorisation, deletes credential references, and cancels queued work before any external call. Source objects and snapshots are deleted within 30 days.
- What leaves Stenlio
- One thing: a draft pull request in the directory you registered, opened only after an owner or admin approves it. Nothing else is written to any external system.
| What is read | The repository you install the GitHub App on, your public website, and any optional source you connect (Stripe, PostHog, Search Console). Nothing is read before you connect it. |
|---|---|
| What is copied | Repository trees, sampled file contents, and crawled page HTML are stored by Stenlio as snapshots in a private object bucket, keyed by a hash of their own content. This is how a finding can be traced back to the evidence it came from. |
| What is not copied | Card data, payment methods, raw customer records, and session recordings. Stripe and PostHog are read as aggregate snapshots only. |
| Where the database sits | Postgres holds the pointer to each snapshot, its content hash, a bounded summary, and a status — never the raw payload in a column. |
| Credentials | Per-company integration credentials are encrypted and unreachable from models, browser clients, logs, and other companies on the platform. |
| Retention | Deleting a company disables workflows, revokes content authorisation, deletes credential references, and cancels queued work before any external call. Source objects and snapshots are deleted within 30 days. |
| What leaves Stenlio | One thing: a draft pull request in the directory you registered, opened only after an owner or admin approves it. Nothing else is written to any external system. |
Why a copy exists at all
An agent that cites a source it no longer holds cannot be checked. Snapshots are what make a finding auditable after the page has changed or the file has moved, and they are what let a disagreement be resolved by looking rather than by arguing with a summary. The trade is that Stenlio holds a copy, which is why retention and deletion are stated above rather than left implicit.
Scope of this page
This is the product privacy summary for the founding cohort, describing the shipped system. The complete policy and data-processing terms are presented before a production account is activated. Security covers the permissions and the write path in more detail.