Client login
STRID
Legal / Privacy

Privacy policy

Last updated · 12 July 2026

Strid (“Strid”, “we”, “us”) builds an AI operations system for streamers and their teams. We operate the websites start.strid.studio and demo.strid.studio and the Strid platform at strid.studio. This policy explains what personal data we handle across those surfaces, why, where it goes and what you can do about it. It is written to meet the UK GDPR and the EU GDPR.

The short version: we run no advertising, no third-party analytics and no tracking pixels on any of our sites; the marketing site sets no cookies at all; the platform’s primary data storage sits in the EU; and you can reach a human about any of it at oc@strid.studio.

Our two roles

We handle personal data in two capacities, and your rights run slightly differently in each:

  • As a controller — for visits to our sites, inquiries you send us, platform accounts we administer, and our own communications. This policy is the primary document for that data.
  • As a processor — for the content our streamer clients bring into the platform (stream plans, people they work with, community activity around their channels). We process that data on the client’s instructions under our agreement with them. If your question is about data a streamer’s team holds on you, you can go to them or come to us at oc@strid.studio — we’ll route it either way.

Data we collect

Inquiries (this site). The form on start.strid.studio collects your name, email, optional phone number, channel or handle, the platforms you stream on, an audience-size bracket and your message. Your IP address is used transiently to rate-limit the form (at most three submissions per ten minutes); we don’t store it with your inquiry, though like almost every website our hosting providers keep standard, short-lived infrastructure logs that include IP addresses.

Platform accounts. If you have a Strid account: your email address, a password (stored only as a hash by our authentication provider), your display name and role, and the session cookies that keep you signed in.

Operational content (clients). What a client’s team puts into the platform to run their operation: stream plans and briefs, notes and ideas, locations, files they upload, their conversations with the AI producer (including messages from a Discord channel they explicitly connect), and their roster of people they work with — names, handles, contact details, public follower statistics, working notes and, where the client provides or approves them, reference photos.

Community signals. To give clients an operational picture of their audience, the platform ingests public activity around their channels — chat messages, comments and posts from platforms such as Kick, Discord, X, Instagram, TikTok and YouTube — including the author’s public handle, the message text, timestamps and engagement metrics. Section 08 below is specifically for you if you’re one of those community members.

Public streamer research. Separately from any client’s workspace, we maintain a research corpus about public streamers and their published streams — public-source material only (public profiles, stream titles, public statistics) — which makes our planning agents smarter. If you’re a streamer and want your entry corrected or removed, email oc@strid.studio.

Technical and error data. Standard server logs, and error reports via Sentry configured not to attach personal data by default, with a small sample (about 10%) of performance traces and no session replay.

What we don't do

  • We don’t sell personal data, and we don’t share it for advertising.
  • No third-party analytics, advertising identifiers or tracking pixels on any Strid surface.
  • The marketing and demo sites set no cookies. The platform sets only the strictly-necessary sign-in cookies from our authentication provider, plus a few local-storage preferences that never leave your device (theme, layout density, whether you’ve seen a notice or the welcome tour). Because nothing here is optional tracking, there is no cookie banner to click through.
  • We don’t knowingly collect data from children (section 12).

Why we use it (lawful bases)

Processing purposes and their lawful bases
PurposeLawful basis
Answering your inquiry and assessing fitLegitimate interests / steps to enter a contract (Art. 6(1)(b), (f))
Running the platform for clients — accounts, plans, the AI production teamContract (Art. 6(1)(b)); client instructions where we act as processor
Analysing public community activity for a client's operationClient instructions (processor); legitimate interests where we act as controller (Art. 6(1)(f))
Improving the service and its agents from how the platform is usedLegitimate interests (Art. 6(1)(f)); client agreement where it concerns workspace content
Security, debugging, abuse prevention (e.g. rate-limiting, error monitoring)Legitimate interests (Art. 6(1)(f))
Meeting legal obligationsLegal obligation (Art. 6(1)(c))

AI processing

Strid’s producer and specialist agents are powered by third-party AI models accessed over commercial APIs — not consumer chatbot products:

  • Anthropic (Claude) — the reasoning layer. Receives conversations with the producer and the operational context needed to plan (stream data, profiles, community summaries).
  • DeepSeek — the bulk-analysis workhorse. Receives the operational text it is asked to analyse: research queries about people and streamers, public community activity, clip and stream write-ups.
  • fal.ai — image processing. Receives images for background removal and poster composition.

We use these providers under API terms rather than their consumer products, and we don’t permit our data to be used to train their models where the provider offers that control (for one research provider that verification is still in progress — see sections 06–07). Strid itself may use activity within the platform to improve its own agents, as the terms describe. AI output inside the platform is assistive: it feeds plans and suggestions that a human on the client’s team reviews and acts on.

Where data lives (service providers)

Primary storage is in the EU. The services below process data on our behalf:

Service providers and their roles
ProviderRoleLocation
SupabaseDatabase, authentication, file storageEU
Google CloudAPI hostingLondon (europe-west2)
VercelWebsite and dashboard hostingGlobal edge network (US company)
Cloudflare R2Image storageDistributed (US company)
AnthropicAI reasoning (Claude)US
DeepSeekAI research queriesNon-UK/EEA (safeguard verification in progress)
fal.aiAI image processingUS
SentryError monitoringEU/US
DopplerSecrets management (no personal data content)US
DiscordOptional channel integration, at the client's choiceUS

International transfers

Where a provider processes personal data outside the UK or the European Economic Area, we rely on the safeguards the GDPR provides for — adequacy decisions (including the EU–US and UK–US data privacy frameworks where the provider is certified) or standard contractual clauses with the UK addendum — and we keep primary storage in the EU regardless. For one research provider (DeepSeek) we are still completing that safeguard verification, and we limit what it processes in the meantime. The current provider list and locations are in section 06, and you can request a copy of the safeguards that apply to a given transfer at oc@strid.studio.

If you're part of a streamer's community

If you chat, comment or post publicly around a streamer who works with Strid, some of that public activity may be ingested into their operational picture — what the crowd is responding to, what fell flat, what people are asking for. In plain terms:

  • We only ingest content that is already public on the platform you posted it to.
  • We use it to inform that streamer’s operation — never to advertise to you, contact you, or build a cross-site profile of you.
  • It stays scoped to that streamer’s workspace and isn’t shared between clients.
  • You can object or ask for your messages to be removed: email oc@strid.studio with your handle and the platform, and we’ll handle it within a month.

How long we keep things

Retention windows by data category
DataKept for
InquiriesUp to 24 months after our last contact with you, then deleted
Accounts and operational contentThe life of the client relationship, plus a short wind-down for handover, then deleted
Community signalsWhile relevant to the client's operation; removed on valid objection
Error reports (Sentry)90 days
BackupsRolled off automatically on the provider's backup schedule

These windows are the commitments we hold ourselves to; fully automated purging is still being built, so if you want something gone sooner, ask — deletion requests are honoured ahead of these windows wherever we don’t have a legal reason to keep the data.

Your rights

Under the UK and EU GDPR you can ask us for access to your data, correction, deletion, restriction, a portable copy, or to object to processing based on legitimate interests. Email oc@strid.studio — we respond within one month, and we don’t charge for it.

You can also complain to a supervisory authority: the ICO in the UK (ico.org.uk) or your local authority in the EU. We’d appreciate the chance to fix it first.

Security

  • Encryption in transit (TLS) and at rest with our storage providers.
  • Every client’s workspace is kept isolated by the platform’s data-access layer, and that isolation is checked by an automated test suite that gates every change before it ships.
  • Least-privilege access; production secrets live in managed vaults, not code.
  • We take no payment card data (there is nothing to breach — we don’t process payments on the platform today).

Children

Our sites and platform are for streaming professionals and aren’t directed at children under 16; we don’t knowingly collect their data. Public community content may incidentally include messages from younger viewers of a stream — we don’t attempt to identify or profile them, and we’ll remove such content on request via oc@strid.studio.

Changes and contact

When this policy changes we’ll update it here and revise the date at the top; for material changes affecting platform clients we’ll tell them directly.

Anything unclear, or a request to make: oc@strid.studio. Strid is operated from the United Kingdom.