+
LEGAL ARCHIVE // 01
SOC2 TYPE II // ISO 27001
+
// PRIVACY POLICY & REPOSITORY SOVEREIGNTY

Your code and designs
remain strictly yours.

Stainless Studio is committed to total client privacy, strict non-disclosure, zero unauthorized data sharing, and 100% repository sovereignty.

REVISION: v2.6.4EFFECTIVE: AUGUST 14, 2026✓ GDPR & CCPA COMPLIANT
// SECTION 01

Overview & Global Jurisdiction

Stainless Studio, Inc. ("Stainless", "we", "our") provides async software engineering services, sprint execution, and full-stack product architecture. This Privacy Policy governs how personal data, workspace telemetry, and technical artifacts are collected, processed, and secured.

We adhere to strict data sovereignty frameworks, ensuring compliance with the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and SOC2 Type II trust principles.

CORE COMMITMENT
// SECTION 02

Zero Code Retention & Strict Confidentiality

We enforce an immutable Data Sovereignty Guarantee:

  • Zero Third-Party Sharing: Your OpenAPI specifications, GraphQL schemas, database DDLs, and source code are strictly confidential and never shared, exported, or processed by external third-party services.
  • Direct Repository Access: Engineering workflows push code directly to your private GitHub or GitLab organization with zero external intermediate mirrors.
  • Customer-Dedicated Encryption: All stored project metadata is encrypted with unique AES-256-GCM keys managed via AWS KMS or Cloudflare Key Management.
// SECTION 03

Data Classification & Retention Matrix

The following technical table provides full visibility into our data classification schema:

CategoryCollected FieldsRetention WindowLegal Basis
Account IdentityWork email, Name, GitHub UIDDuration of active accountContract Performance
API TelemetryRequest counts, Latency, Status codesRolling 30 days (aggregated)Legitimate Interest
Schema ASTsEndpoints, Types, DocstringsEphemeral (0 days retention)Contract Fulfillment
Billing RecordsStripe Customer ID, VAT, Invoices7 years (statutory tax requirement)Legal Obligation
// SECTION 04

Third-Party Subprocessors & Infrastructure

We partner with tier-1 enterprise infrastructure providers bound by rigorous Data Protection Agreements (DPAs) with standard contractual clauses (SCCs):

CLOUDFLARE INC.
Global Edge CDN, WAF, Workers Execution
DPA Signed // US & EU Locations
AMAZON WEB SERVICES (AWS)
Encrypted Database Storage & KMS Key Vaults
SOC2 Type II // ISO 27001 Certified
STRIPE PAYMENTS INC.
PCI-DSS Level 1 Billing & Subscription Engine
PCI-DSS Compliant // Tokenized
DATADOG INC.
Real-time Anomaly Detection & Edge Monitoring
Anonymized Telemetry // HIPAA BAA
// SECTION 05

Global Rights (GDPR / CCPA / CPRA)

Regardless of your geographic location, Stainless Studio affords every client full sovereign control over their data:

01 // ACCESS
Request an instant machine-readable JSON export of all account records.
02 // RECTIFY
Update or amend inaccurate credentials and organizational ownership at any time.
03 // ERASURE
Enact permanent right to be forgotten across all active and backup volumes within 48h.
// SECTION 06

Contact Data Protection Officer (DPO)

For regulatory inquiries, custom Data Processing Agreements, or security audits, contact our designated privacy team directly:

STAINLESS STUDIO, INC. — DATA PRIVACY OFFICE
GPG Key ID: 0x8F3A219C // PGP Encrypted Correspondence Supported