Trust / Privacy

What we see. What we never see.

A privacy policy written to be read, not just filed. The list of what StandIn never collects is longer than the list of what it collects. Both lists are below.

Last updated 24 October 2026

01 · The Promise

Continuity, not surveillance.

The business model decides the shape of the product. Ours is subscription, paid by organizations that want their people's context to outlive the workday. That model does not require watching the people using it, and is actively harmed by it.

StandIn does not monitor people. StandIn does not track presence. StandIn does not read private messages. Those three sentences are not a marketing choice. They are an architectural constraint we enforce on ourselves.

02 · Collected

What we collect.

Three categories. Nothing beyond them.

  1. i

    Account information

    Name, work email, organization membership, and role. Used for sign-in, attribution, and access control. Nothing is enriched from third-party data brokers.

  2. ii

    Published content

    Briefs and handoffs you explicitly write and publish. Plus metadata you allowlist from connected systems: issue titles, PR statuses, calendar shapes. Never full message or document bodies.

  3. iii

    System records

    Audit events (who read whose brief, who changed a setting) and request logs for reliability. These never contain the substance of your content, only the shape of the action.

03 · Never collected

What we never collect.

This list is load-bearing. Each item is a design decision we turned down, not a feature waiting to be built.

  • Keystroke logs, mouse-movement, or typing-cadence metrics
  • Screen recordings, screenshots, or window focus history
  • Content from private DMs, in Slack, email, or anywhere else
  • "Active" / "idle" / "in a meeting" presence signals
  • Inferred sentiment, engagement scores, or productivity rankings
04 · Purpose

How collected data is used.

Data is used to answer work-context questions. The LLM retrieves already-published briefs and allowlisted metadata at query time, generates a grounded response, and discards the context window. We do not use your data to train public AI models, ours or anyone else's, and our LLM vendor contracts forbid it on their side too.

05 · Access

Who can see what.

Project data is visible only to members of that project. Published briefs are visible to the team they were published to. Admins can manage membership and audit access. There is no manager dashboard for watching people. Every read of another person's brief is logged and visible in the audit trail.

06 · Retention

Retention and decay.

Context is ephemeral by default. Personal briefs are retained per your organization's configuration (typically 24 months) and decay in retrieval relevance before hard deletion. You can request deletion of your data at any time, and an admin can delete a user's records within thirty days of a request.

07 · Security

Security posture.

TLS 1.3 in transit. AES-256 at rest. Encrypted integration tokens. Logged audit events. Responsible disclosure welcomed at [email protected]. The full technical breakdown lives on the Security page.

Read the full security FAQ →
08 · Changes

Changes to this policy.

We may update this policy. If we make material changes, especially any that affect the Core Promise above, we will notify you via email and in-app banner. Minor clarifications will be versioned here with a changelog entry. You should not need a lawyer to read this page.