01Who we are
Stazh is operated by the Stazh team (“we”, “us”, or “our”), based in Milan, Italy. We are the data controller for the personal data described here.
For anything in this policy, write to matej1simko@gmail.com.
02What we collect
- Account details. Your email address, and a password if you create one. If you sign in with Google, we receive your name, email address and profile picture from Google.
- Your CV and profile. Documents you upload and the structured details we extract from them — education, experience, coursework — so drafts can be written from your actual background.
- Campaign and outreach data. The companies and contacts you research, the drafts written for you, what was sent, and replies received.
- Gmail access tokens. When you connect Gmail, we store the refresh token needed to send on your behalf and to watch for replies.
- Billing data. Subscription status and credit balance. Card details are handled by Stripe and never reach our servers.
- Technical data. Basic logs needed to operate and secure the service.
03Google user data
This section governs wherever Google data is concerned, and takes precedence over anything more general in this policy.
- We request two Gmail scopes: permission to send mail, and permission to read mail. Reading is used for one purpose only — matching replies to outreach you sent through Stazh, so those conversations appear in your inbox view.
- We do not index, mine, profile or sell your mailbox, and we do not use Gmail content to train any model.
- Nothing is sent from your account without you approving that message, or without you having explicitly enabled automatic follow-ups for a campaign you created.
- Stazh’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- You can disconnect Gmail at any time from Settings, or revoke access from your Google Account. Revoking stops all sending immediately.
04Why we process it, and on what basis
- To provide the service — performance of our contract with you. Finding companies, researching contacts, writing drafts, sending and following up.
- To take payment — performance of a contract, and a legal obligation for tax records.
- To keep the service secure and working — our legitimate interest in preventing abuse and diagnosing faults.
- To contact you about your account — legitimate interest. Marketing email, if we ever send it, is consent-based and always unsubscribable.
05Where contact data comes from
Stazh finds people two ways. It searches a third-party business-contact database (Apollo) for professional details such as name, role, employer and public profile link. And it reads what a company publishes about itself on its own website — the home, about and careers pages — honouring that site’s robots.txt.
We do not scrape LinkedIn. Where profile information appears, it reached us through the contact database above.
If you are a recipient and want to know what we hold about you, or want it removed, write to matej1simko@gmail.com and we will act on it.
06Who we share it with
Only processors who need it to run the service, each under contract and none of them permitted to use your data for their own purposes:
- Supabase — database, authentication and file storage.
- Vercel — application hosting.
- OpenAI — generating draft emails and documents.
- Apollo — business contact lookup.
- Google — sign-in and Gmail sending.
- Stripe — payments.
We do not sell personal data, and we do not share it for advertising.
07International transfers
Some of these providers operate outside the European Economic Area (EEA) and the UK. Where data is transferred, it is protected by an adequacy decision or by Standard Contractual Clauses with the provider.
08How long we keep it
- Account and campaign data — for as long as your account exists.
- After you delete your account — erased within 30 days, except where we must keep something longer by law.
- Gmail tokens — deleted immediately when you disconnect Gmail.
- Billing records — kept for up to 10 years to meet statutory tax and accounting obligations.
09Your rights
Under the General Data Protection Regulation (EU GDPR and UK GDPR), you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent, you can withdraw it at any time.
Write to matej1simko@gmail.com and we will respond within one month. If you are unhappy with the outcome, you have the right to lodge a complaint with your local supervisory authority (in Italy, the Garante per la protezione dei dati personali).
10Security
Data is encrypted in transit and at rest. Access to production systems is restricted and authenticated. Gmail refresh tokens are stored server-side and are never exposed to the browser. No system is perfectly secure, and we will tell you and the relevant supervisory authority without undue delay if a breach affects you.
11Cookies
We set only what the service needs: a session cookie to keep you signed in, and a preference cookie remembering your light or dark theme. There are no advertising or cross-site tracking cookies, which is why you are not asked to dismiss a banner.
12Age
Stazh is for people aged 16 and over. If we learn we hold data on someone younger, we will delete it.
13Changes
If we make a material change we will email account holders and update the date at the top of this page before it takes effect.