Privacy Policy
Last updated: 25 September 2026
This policy explains what personal data Steptree collects, why, and what you can do about it. It covers both this website and the Steptree product at app.steptree.ai.
Who we are
Steptree provides software that records how a business process is performed and turns that recording into documentation, skill files, and agents. For data you upload or record into the product, you are the data controller and Steptree is your processor. For data about your own use of this website and your account, Steptree is the controller.
What we collect
Account data
Your email address, name if you provide one, the workspace you belong to, and your role within it. Authentication is handled by Supabase Auth; if you sign in with Google we receive your email address and profile name from that sign-in, not your Google password.
Recorded process data
When you record a process, we store the resulting steps, screenshots, and the text of the elements you interacted with. This is the most sensitive category of data in the product, so two things are true of it by design: password fields and fields marked secure are never captured by the desktop apps, and email addresses and card numbers are redacted from the recorded text before it is stored. On Pro plans and above, that redaction can be extended with your own text patterns.
Usage and billing data
We record which model calls your workspace makes and how many tokens they consume, in order to meter usage and operate the service. Payment card details are handled by Stripe and never reach our servers.
Website and advertising data
On this marketing website we record page views and clicks on calls to action, and we retain the campaign parameters that brought you here — UTM tags and advertising click identifiers such as gclid, fbclid, and msclkid — in a first-party cookie for up to 90 days. This lets us tell which campaigns lead to sign-ups. In the EEA, UK, and Switzerland none of this runs until you consent; elsewhere you can decline at any time, using the cookie banner or the “Cookie settings” link in the footer, and we honour that choice across steptree.ai and app.steptree.ai.
When you create a workspace, and again if you later upgrade to a paid plan, we tell Meta and Google that the conversion happened so the advertising that brought you here can be measured. That report is sent from our servers, not from your browser, and it carries the advertising click identifier above, the network's own cookie value, your IP address and browser user agent, and a one-way SHA-256 hash of your email address and name — never the address or name themselves. Paid plans additionally include the plan value. We do not send this if you have declined, and in the EEA, UK, and Switzerland we do not send it unless you have consented.
How we use it
- To provide the product: generating Documentation, skills, and agents from your recordings.
- To authenticate you and keep your workspace separate from every other workspace.
- To meter usage, bill correctly, and prevent abuse.
- To measure which marketing campaigns work.
- To send service messages such as invitations, security notices, and receipts.
We do not sell personal data, and we do not use your recorded process data to train general-purpose models.
Model providers
Generating a Document, compiling a skill, running an agent and chatting with Steptree AI all involve sending relevant content to a large language model provider.
On Team plans and above, Steptree AI's chat in the Steptree App can instead use a model running at an address you choose, such as a server on your own network. That conversation then goes to that model rather than to a provider. The choice covers Steptree AI's chat in the Steptree App only. The app still signs in to Steptree over the internet, your recordings are still uploaded to us, and generating a Document or compiling a skill always uses a model provider.
Subprocessors
We rely on the following processors to run the service:
- Supabase — database, authentication, and file storage for recordings and screenshots.
- Vercel — hosting and content delivery for this website and the application.
- Stripe — subscription billing and payment processing.
- Resend — transactional email such as invitations and notifications.
- Anthropic, OpenAI, Google, and DeepSeek — the model providers for the generation steps described above.
- Google — tag management, analytics, and advertising measurement, including conversion reporting from our servers, subject to your consent.
- Meta — advertising measurement, including conversion reporting from our servers, subject to your consent.
- Sentry — error and performance monitoring for our own software. Sentry receives crash reports, error messages, page and request timings, and a pseudonymous account identifier. It does not receive your name, your email address, your IP address, the contents of a recording, a Document, a skill, an agent conversation, or any request or response body.
Session replay
Sentry keeps a short, masked recording of the current session in your own browser’s memory. It is not transmitted unless something goes wrong: an error occurs, you show a clear sign of being stuck — clicking a control repeatedly that isn’t responding, for example — or you send us a support request, in which case the recording accompanies it so whoever answers can see what you saw. On a session where the app works and you ask us nothing, no recording ever leaves your device.
When one is sent, it is masked at capture, in the browser, before transmission. Every piece of text on the page is replaced with a placeholder block, every image and video is blocked, and every field the recorder’s own redaction rules protect is masked again on top of that. What the replay preserves is the shape of the page and where you clicked. It does not preserve what the page said, what you typed, or what any screenshot showed.
Replays are retained for 30 days and are visible only to Steptree staff. They are not used for analytics, profiling, advertising, or any purpose other than diagnosing a fault.
Security
- Data is encrypted in transit with TLS and at rest with AES-256.
- Every tenant-scoped table enforces row-level security in Postgres, so isolation between workspaces is enforced by the database rather than by application code remembering to filter.
- Recording files are stored under a per-tenant storage prefix.
- Credentials and other secrets are encrypted at rest with a per-secret key, so they are unreadable in a database dump or backup.
- Enterprise plans add SSO with SCIM provisioning and audit logs with SIEM export. Data residency and customer-managed encryption keys are not available yet; ask us before relying on either.
No system is perfectly secure, and we do not claim certification we have not completed. If you need our current security documentation for a vendor review, write to support@steptree.ai.
Retention and deletion
Recordings, Documentation, skills, and agents are retained until you delete them or close your workspace. When a workspace is deleted, the database cascade removes every associated row and a storage job removes the recording files and screenshots; this completes within 30 days. You can request an export of your personal data and the content you created at any time, and you can request deletion of your account directly in the product.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. Under the CCPA you also have the right not to be discriminated against for exercising those rights. To exercise any of them, write to privacy@steptree.ai. If we process data on behalf of your employer, we will direct the request to them as the controller.
International transfers
Our infrastructure is operated in the United States and the European Union. Where personal data is transferred out of the EEA or UK, we rely on Standard Contractual Clauses. We cannot currently pin a workspace’s data to a specific region; if you need that, talk to us before signing up rather than after.
Changes
We will update this page when our practices change, and we will change the date at the top when we do. Material changes affecting existing customers will also be sent by email.
Contact
Privacy questions: privacy@steptree.ai. Everything else: support@steptree.ai.