- 01
Information we collect
In shortYour email (and name and picture if you use Google), the things you build with Steed, and how you use the product.
When you create an account, we collect your email address and, if you sign in with Google, your name and profile picture. When you use Steed to build websites or create marketing content, we store that content on your behalf. We also collect usage data (pages visited, features used) to improve the product.
- 02
How we use your information
In shortTo run Steed, email you about your account, make the product better and answer you when you write in. We never sell it.
We use your information to:
- Provide and operate the Steed platform
- Send transactional emails (account setup, password reset)
- Improve and develop new features
- Respond to support requests
We do not sell your personal data to third parties.
- 03
Data storage & security
In shortYour data lives in a database on AWS in Ohio, encrypted in transit and at rest. The full picture is on our security page.
Your data is stored securely using Supabase (hosted on AWS) and Vercel infrastructure. We use industry-standard encryption in transit (TLS) and at rest. Access to production data is restricted to authorized personnel. How we protect your site, your data and your customers is set out in detail on our security page.
- 05
Analytics on Steed-built sites
In shortYour published site counts its own visitors so you can see traffic. It sets no ad cookies and follows nobody across the web.
Sites you publish with Steed include a lightweight, first-party analytics beacon so we can show you traffic in your dashboard — page views, sessions, top pages, and referrers. It sets no third-party or advertising cookies and does not track visitors across other websites. If your published site collects visitor information, you are responsible for disclosing that in your own site's privacy notice.
- 06
Your rights
In shortAsk us for a copy of your data, a correction, or deletion — any time.
You may request access to, correction of, or deletion of your personal data at any time by contacting us at privacy@helm.biz.
- 07
Third-party services
In shortSteed runs on a handful of providers — payments, hosting, AI models, email. Each gets only what it needs. The full list is below.
Steed integrates with third-party services to operate — payments, hosting, AI models, email delivery, and sign-in with Google, among others. Each service has its own privacy policy. We only share the minimum data required for each integration to function. Every provider that processes your data is listed in Subprocessors below, with what it does and what can reach it.
- 08
Subprocessors
In shortThese are the companies that touch your data on our behalf, what each does, and what it can see.
A subprocessor is a provider Steed relies on to run the service, and which may process your data in doing so. This is the complete list as of the date above. We update it when a provider is added or retired.
Provider What for What can reach it SupabaseAWS, us-east-2 (Ohio) Database, authentication and file storage — the system of record for your account, your business and your site's data. Account, business details, site content, members, orders, bookings, uploaded files. Vercel Hosting — helm.biz, the studio, and every site we build for you. Your published site's files and the requests visitors make to it. E2B Isolated sandboxes where your site is built and its code is run before it is published. Your site's source code and the build's inputs, for the life of the build. Anthropic The AI models your Steed team runs on. What you tell your team, your business details and the content of your site, as the model works on them. Ideogram Image generation for your site. Image prompts derived from your business and its brand — never your customers' data. Amazon SES Email delivery — the mail Steed sends you, and the mail your site sends its customers. Recipient addresses and message content. Resend Email delivery for some site notifications.Being retired in favour of Amazon SES. Recipient addresses and message content. Stripe Payments — your Steed subscription, and your customers' payments through your own Stripe account. Billing details for your subscription. Your customers pay your Stripe account directly; Steed reads the result and never holds the money. Google Sign in with Google, and looking up your business's public listing. Your name, email and profile picture if you sign in with Google; your business name and address for the lookup. PostHog Product analytics for Steed itself — which screens are used, where people get stuck. Usage events inside the Steed app. Not installed on the sites we build for you. Sentry Error reporting for Steed itself, so a failure is seen and fixed. Stack traces and the request that failed, which can include an account id. - 09
Changes to this policy
In shortIf something material changes, we tell you by email or in the app.
We may update this policy as Steed evolves. We will notify users of material changes via email or an in-app notice. Continued use of Steed after changes take effect constitutes acceptance of the updated policy.
- 10
Contact
In shortWrite to privacy@helm.biz.
Questions? Email us at privacy@helm.biz.