Last updated: July 26, 2026
Stry, Inc. ("Stry", "we", "us", or "our") operates gostry.com and the Stry platform. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data.
By creating an account or using Stry, you agree to this Privacy Policy. If you do not agree, please do not use the platform.
Stry is a business compliance management platform for small businesses. It helps you upload, organize, and track business documents (licenses, insurance certificates, permits, contracts, and more), monitor expiration dates, manage vendor relationships, coordinate team members, and receive AI-powered insights about your compliance status.
When you create an account, we collect your first and last name, work email address, and password (stored in encrypted form — we never see your plaintext password). You may optionally provide a job title, timezone, profile picture, and communication preferences.
To set up your business profile we collect your business name, entity type (LLC, C-Corp, etc.), state of registration, and industry. You may also optionally provide your EIN, phone number, website, business address, and logo. This information is used to personalize your compliance dashboard and tailor AI recommendations to your state and industry.
When you upload a document, we store the file itself (up to 50 MB per file) in private, access-controlled cloud storage. We also store metadata you provide or that our AI extracts: document name, category, provider, policy number, issue date, expiration date, renewal date, cost, and any notes you add. Uploaded files are never made public. Access is limited to you, your authorized team members, and Stry systems processing the file.
You may enter vendor contracts, technology subscriptions, and other business assets into Stry. We store the names, contact details, contract dates, monthly costs, and renewal information you provide.
When you invite team members, we collect their email addresses and the role you assign them. Invited users who accept create their own account and provide their own name and profile details.
We maintain audit logs of significant actions taken within your account (documents created, updated, or deleted; team changes; settings updates). These logs help you track changes across your organization and are used for security and troubleshooting.
Payment is handled entirely by Stripe. Stry never sees, touches, or stores your credit card number, CVV, or bank details. We store only your Stripe customer ID, subscription plan, billing status, and trial/renewal dates.
When you use the AI Assistant or upload a document for AI extraction, Stry sends relevant data to OpenAI (see Section 4). For document extraction, this includes the document text. For the AI Assistant, this includes your business context (name, state, entity type, document list with statuses and costs, vendor list) and your chat messages. We store AI-generated responses and extracted data in your account.
We do not sell your personal information. We do not use your documents or business data to train AI models.
Stry uses the following sub-processors to operate the platform. Each receives only the data necessary to perform their function.
Handles all user authentication (including Google OAuth), stores your account data in a PostgreSQL database, and stores your uploaded files in private cloud storage. Your session tokens and authentication credentials are managed by Supabase.
supabase.com/privacyProcesses all payments and manages subscriptions. Stripe collects your payment card details directly — Stry never receives or stores this information. Stripe is PCI-DSS Level 1 certified.
stripe.com/privacyWhen you upload a document, its text content is sent to OpenAI's API to extract key compliance data (dates, providers, policy numbers, costs). When you use the AI Assistant, your business context and chat messages are sent to OpenAI to generate responses. We use OpenAI's API under terms that prevent them from using your data to train their models.Document text and chat messages are transmitted over encrypted connections and are subject to OpenAI's API data usage policies.
openai.com/privacyIf you choose to sign in with Google, we receive your Google account email address and name to create or access your Stry account. We do not receive access to your Google Drive, Gmail, or other Google services.
policies.google.com/privacyThe Stry web application is hosted on Vercel's infrastructure. Vercel processes web request logs which may include IP addresses and browser information.
vercel.com/legal/privacy-policyWe do not share your data with any other third parties except as required by law or to protect the rights and safety of Stry and its users.
Stry is a multi-user platform. When you add a team member to your business, they gain access to your business's documents, compliance data, vendors, and activity based on their assigned role (Owner, Admin, Member, or Viewer).
As the business owner, you are responsible for ensuring you have the appropriate authority to add team members and that they are aware their activity within your account is logged. If you are a team member added to someone else's account, your actions within that account are visible to the account owner.
Stry itself does not set advertising or tracking cookies. We use browser storage (managed by the Supabase SDK) to maintain your login session so you do not need to sign in on every visit.
Third-party services embedded in Stry (Supabase, Stripe, Google OAuth) may set their own cookies in accordance with their own privacy policies. These are functional cookies required for authentication and payment processing to work.
We take reasonable technical and organizational measures to protect your data:
No system is completely secure. If you believe your account has been compromised, contact us immediately at support@gostry.com.
We retain your data for as long as your account is active. If you cancel your subscription, your data remains accessible until you delete your account.
When you delete your account, we will delete your personal information and business data from our active systems within 30 days. Some information may be retained in encrypted backups for up to 90 days before being purged, and we may retain records required by law (such as billing records) for up to 7 years.
To request account deletion, email support@gostry.comwith the subject line "Delete My Account."
Depending on where you live, you may have the following rights regarding your personal data:
To exercise any of these rights, email support@gostry.com. We will respond within 30 days.
California residents (CCPA): You have the right to know what personal information we collect, to delete it, to opt out of its sale (we do not sell personal information), and to non-discrimination for exercising your rights.
Stry is a business platform intended for users 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us at support@gostry.com and we will promptly delete it.
Stry operates from the United States. If you access Stry from outside the United States, your data will be transferred to and processed in the US. By using Stry, you consent to this transfer. We rely on our sub-processors' compliance frameworks (including Standard Contractual Clauses where applicable) for international data transfers.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top and notify you by email or an in-app notice if the changes are material. Continued use of Stry after the effective date constitutes acceptance of the updated policy.
For any privacy-related questions, data requests, or to report a concern: