Stijn AI
Legal

Privacy policy

Last updated 1 September 2026.

1. Who we are

Stijn AI provides AI agents billed per run. We are the data controller for the account and billing information below, and a data processor for the content you send through agents. Contact us about privacy at support@stijnai.shop.

2. What we collect

Account data

Your email address, a hashed password and your display name. We require an email so we can reach you about billing and so you can recover the account. We do not verify it at signup and we do not send marketing to it.

Billing data

Records of credit purchases and per-run consumption. Card details are handled entirely by Stripe and never reach our servers; we store only Stripe's transaction identifier and the last four digits it returns for display.

Run content

The inputs you send agents and the outputs they return. Retained 30 days by default so you can review your history, then deleted. Set retention to zero and we keep only metadata.

Run metadata

Agent, timestamp, duration, token count, cost and status. Retained 24 months because billing records must be reconcilable.

Technical data

Server logs with IP address, user agent and requested path, kept 30 days for security and abuse investigation.

3. What we never do

4. Why we are allowed to process it

DataPurposeLawful basis
Account dataProviding the servicePerformance of a contract
Billing dataCharging you, tax recordsContract, legal obligation
Run contentExecuting the run you asked forContract
Run metadataBilling, capacity planningContract, legitimate interests
Technical logsSecurity and abuse preventionLegitimate interests

5. How long we keep it

6. Who we share it with

The current subprocessor list with locations is available on request, and we give 30 days' notice before adding one. We disclose data to law enforcement only on a valid legal instrument, and we will tell you unless prohibited.

7. International transfers

Account data is stored in the EU. Run processing happens in the EU and the US depending on the agent. Where data leaves the EEA we rely on Standard Contractual Clauses. Enterprise accounts can pin processing to one region.

8. Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and complain to a supervisory authority. Email us and we will respond within 30 days. We do not charge for this and there is no process designed to wear you down.

9. Security

Passwords are hashed with bcrypt, API tokens are stored hashed, all traffic is TLS 1.3 and data at rest is encrypted. Access to production requires hardware-backed multi-factor authentication and is logged. The security page has the detail, including what we do not claim.

10. Children

The service is not directed at anyone under 16 and we do not knowingly collect their data.

11. Changes

We will email account holders at least 30 days before a material change. The date at the top always reflects the current version.