Legal

Privacy Policy

Effective 25 July 2026

This policy explains what Striq collects, why it is used, who receives it, how long it is kept, and the choices available to individuals and organizations.

For questions or privacy requests, email privacy@striq.ai.

1. Scope and our role

This policy applies to Striq’s websites, product, support channels, and other services that link to it. It does not govern a customer’s own privacy practices or third-party services that a customer chooses to connect.

For account, website, billing, security, and support information, Striq determines why and how the information is handled. For creator files, campaign records, contracts, review notes, and other workspace content submitted by an organization, Striq generally processes the information on that organization’s instructions. The organization remains responsible for its notices, permissions, and lawful basis.

2. Information we collect

We collect information needed to provide a private creator-review and rights-operations workspace.

A. Information you provide

  • Account and profile information. Name, work email address, authentication identifier, organization, role, profile settings, and communication preferences.
  • Workspace content. Campaign briefs, rules, creator details, creator videos, captions, hashtags, contracts, assets, revision requests, reports, comments, reviewer notes, approval history, and related evidence.
  • Billing and transaction information. Plan, subscription status, billing contact, invoices, and limited payment metadata supplied by a payment provider. Striq does not need to store full payment-card numbers.
  • Support and research information. Messages, feedback, survey responses, bug reports, and any files or screenshots you choose to send to support.

B. Information collected through use

  • Service activity. Pages and features used, records opened or changed, reviewer actions, exports, login events, and approximate timestamps.
  • Device, network, and diagnostic data. IP address, browser, device type, operating system, language, referring page, crash data, and security events.
  • Storage and media metadata. File name, type, size, duration, checksum, upload state, storage path, and processing status. Analysis results may include transcripts, detected text, timestamps, scenes, and confidence values.

C. Information from other sources

  • Workspace administrators and collaborators. An organization may add members, creators, campaign contacts, or other people and provide their business information.
  • Connected services. If an authorized administrator enables an integration, Striq receives the information needed to authenticate the connection and perform the requested workflow.
  • Public and commercial sources. We may receive business contact information or publicly available campaign and advertising information where lawful and relevant to the service.

3. How and why we use information

  • Provide the service. Create accounts and workspaces, authenticate users, store records, process files, run configured checks, generate reports, support revision workflows, and maintain decision history.
  • Secure and administer Striq. Apply permissions, prevent unauthorized access, detect abuse, investigate incidents, enforce limits, keep audit logs, and maintain reliable backups.
  • Support and communicate. Answer questions, deliver service notices, respond to requests, provide onboarding, and send product communications that can be opted out of where required.
  • Improve the product. Understand feature performance, fix errors, improve accessibility, and develop functionality using aggregated, de-identified, test, or permissioned data.
  • Meet legal obligations. Respond to valid legal process, preserve records when required, enforce agreements, resolve disputes, and protect Striq, customers, creators, and others.

4. Legal bases

Where a law requires a legal basis, Striq relies on performance of a contract, steps requested before entering a contract, legitimate interests such as security and product administration, compliance with legal obligations, and consent where consent is the appropriate basis.

An organization that uploads creator or campaign information is responsible for identifying its own legal basis and providing any notice or choice required for that processing.

5. Automated processing and model training

Striq may use deterministic rules and configured analysis providers to identify possible matches, omissions, or policy conflicts. These outputs support a reviewer; they are not legal advice, do not guarantee compliance, and do not replace manual final approval.

Private creator drafts, campaign files, and workspace content are not used to train general-purpose models without the organization’s explicit permission. If an optional provider is enabled in the future, its role, data handling, and configuration will be disclosed before use.

6. How information is disclosed

We disclose information only for the purposes described below and do not give one customer access to another customer’s workspace.

  • Authorized workspace users. Owners, administrators, reviewers, and viewers can access information according to their verified membership, role, and workspace configuration.
  • Creators and external recipients. A creator or other invited recipient receives only the campaign, submission, feedback, and upload access allowed by the relevant expiring link or shared report.
  • Service providers. Hosting, authentication, storage, database, email, support, observability, security, and payment providers process information under instructions and contractual restrictions.
  • Professional advisers and transactions. Lawyers, auditors, insurers, lenders, and parties to a financing, acquisition, reorganization, or sale may receive information subject to appropriate confidentiality and legal safeguards.
  • Legal and safety disclosures. We may disclose information when reasonably necessary to comply with law or valid process, enforce agreements, investigate fraud or abuse, or protect rights, safety, and service integrity.

7. Sale, sharing, and advertising

Striq does not sell personal information for money and does not share personal information for cross-context behavioral advertising. Striq does not use private workspace content to advertise third-party products.

If these practices change, this policy and any legally required choice mechanism will be updated before the new practice begins.

8. Cookies and similar technology

Striq uses necessary technologies to keep people signed in, maintain sessions, remember settings, balance traffic, prevent abuse, and understand basic service performance. Optional analytics or communication technologies, if introduced, will be handled according to applicable consent and notice requirements.

Browser controls can limit some technologies, but blocking necessary storage may prevent authentication or other product functions from working.

9. Retention, deletion, and backups

  • Workspace content. Retention follows the organization’s plan and settings, including configurable retention and automatic video-deletion options where available.
  • Account and business records. Account, subscription, invoice, support, and contractual records are kept for the relationship and afterward as reasonably needed for tax, accounting, dispute, and legal obligations.
  • Security and audit records. Login, authorization, analysis, export, and decision logs may be retained longer to prevent abuse, investigate incidents, and preserve an accountable review history.
  • Deletion process. Deleted information may remain in restricted backups for a limited cycle and is not restored to active use except for disaster recovery, security, or legal requirements.

10. Security and incident response

Striq uses measures designed for the nature of the service, including encrypted transport, private storage patterns, signed access URLs, role-based access, workspace authorization, logging, and restricted service credentials. Security controls evolve with the product and risk.

No online service can guarantee absolute security. Customers must protect credentials, review member access, configure sharing and retention, and notify security@striq.ai promptly of suspected unauthorized access.

If an incident affects personal information, Striq will investigate, take reasonable containment and remediation steps, and notify affected customers or authorities when applicable law or contract requires it.

11. International data transfers

Striq and its providers may process information in countries other than the country where it was collected. Where law requires a transfer mechanism, Striq uses an available safeguard such as an adequacy decision, standard contractual clauses, or another recognized mechanism.

Enterprise customers may request available location, subprocessor, and transfer information through the data-processing terms or by contacting privacy@striq.ai.

12. Your rights and choices

Depending on location and the circumstances, a person may have rights over personal information.

  • Request information about processing and obtain access to personal information.
  • Request correction of inaccurate or incomplete information.
  • Request deletion or restriction where the legal conditions apply.
  • Object to certain processing, including direct marketing.
  • Request a portable copy where portability applies.
  • Withdraw consent for future processing when consent is the basis.
  • Appeal or complain to a competent privacy or data-protection authority.
  • Receive equal service and pricing when exercising a privacy right, subject to lawful differences.

If Striq handles information on behalf of a customer, the request should usually be directed to that customer. Striq will support verified customer instructions as required by contract and law.

To submit a request, email privacy@striq.ai. We may verify identity, authority, workspace membership, and the scope of the request before responding. An authorized agent may be required to provide proof of authority.

13. US state privacy disclosures

The categories described in this policy may include identifiers, customer-record information, commercial information, internet or network activity, approximate location derived from IP address, professional information, audio or visual content, and inferences generated for the configured review workflow.

Striq collects and discloses these categories for the business purposes described above. Applicable state law may provide rights to know, correct, delete, obtain a copy, opt out of sale or sharing, limit certain sensitive-information uses, and appeal a denied request. A particular right applies only when the relevant law covers the person, information, and business.

14. Children

Striq is a business service and is not directed to children. Workspace customers must not submit children’s personal information unless they have established the authority, notices, consents, and safeguards required for that campaign and use.

15. Changes and contact

We may update this policy as the service, providers, or law changes. The effective date will be revised, and material changes will receive additional notice where appropriate.

Questions, requests, and complaints may be sent to privacy@striq.ai. Security reports should be sent to security@striq.ai. Contractual data-processing questions may also be addressed through the organization’s workspace owner.