Last updated: July 12, 2026
Privacy Policy
This policy explains which data is processed, and why, when you use Steerpod. The short version: we collect only what's needed to run the service, nothing for advertising, and we are technically unable to read your vault contents.
01Scope and data controller
This policy applies to the Steerpod web application, the Steerpod browser extension, and the email notifications they send. The data controller is the operator of the instance where your account lives; the contact route for requests is in the final section.
02Data we collect
Three groups of data are processed to provide the service:
- Account data: your name, email address and an irreversible digest (hash) of your password. Your password is never stored in plaintext.
- Workspace content: projects, renewal records, expenses, monitor definitions, team memberships, and emails sent to a project along with their attachments.
- Technical records: session data, the audit trail (who did what, when) and error logs.
03What we don't collect
We collect nothing for advertising or profiling. We use no third-party advertising or tracking cookies, we don't sell your data, and we don't share it with third parties for marketing.
04The vault and zero-knowledge architecture
Secrets you add to the vault (passwords, API keys and the like) are encrypted before they leave your browser; only ciphertext reaches the server. Nobody — including the Steerpod operator — can read that content without your keys. If you lose both your vault passphrase and your recovery code, that data is technically unrecoverable.
05The browser extension
The Steerpod browser extension brings your vault and your project's operational context to the tab you are on. This policy applies to it in full; what follows is only what is specific to the extension.
- The extension reads the address of the open tab only when you open the extension, and sends it to the server to find the matching credentials and project. The address is not recorded; no browsing history is kept or assembled.
- Your vault passphrase, your biometric data and decrypted secrets never leave your device. Decryption happens inside the extension itself; only ciphertext goes to the server, and only ciphertext comes back.
- A secret copied to the clipboard is read back for one purpose — to erase it once its timer expires, and only if it is still there. Clipboard content is never sent anywhere.
- The fact that a secret was revealed (which record, which device, when) is written to the audit trail. The secret itself is not.
- The extension makes no request to any third party: no analytics, no telemetry, no advertising. It talks to Steerpod's own server and nothing else.
- Data handled through the extension is used only to provide the extension's function. It is not sold, not processed for advertising or profiling, and not transferred to third parties for those purposes.
06Cookies
Only first-party cookies are used: session (pm_session), language (pm_locale), theme (pm_theme) and cookie preference (pm_consent). Each one is described in the Cookie Policy.
07Email processing
If you assign an email address to a project, messages sent to that address and their attachments are stored in the project's inbox and are visible only to members with access to that project. Notification emails are sent through the SMTP server you configure.
08Legal bases for processing
Under GDPR and Turkish KVKK: account and content data are processed to perform the contract; security logs and the audit trail under legitimate interest; optional cookies on the basis of explicit consent.
09Retention and deletion
Your data is kept for as long as your account or workspace exists. When you delete your account or a workspace, the related data is permanently removed; copies in backups rotate out within 30 days at most.
10Security
Transfers are protected with TLS, vault contents and channel configurations are encrypted with AES-256-GCM, sessions are validated server-side and critical actions are written to the audit trail. No system is 100% secure; if we detect a breach, we will inform you without delay.
11Your rights
You have the right to access, rectify, erase and port your data, and to object to processing. Requests are answered within 30 days at the latest.
12Changes and contact
Material changes to this policy are announced in the app or by email. For questions, use the support channel of the organization operating your Steerpod instance.