Stainless Studio is committed to total client privacy, strict non-disclosure, zero unauthorized data sharing, and 100% repository sovereignty.
Stainless Studio, Inc. ("Stainless", "we", "our") provides async software engineering services, sprint execution, and full-stack product architecture. This Privacy Policy governs how personal data, workspace telemetry, and technical artifacts are collected, processed, and secured.
We adhere to strict data sovereignty frameworks, ensuring compliance with the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and SOC2 Type II trust principles.
We enforce an immutable Data Sovereignty Guarantee:
The following technical table provides full visibility into our data classification schema:
| Category | Collected Fields | Retention Window | Legal Basis |
|---|---|---|---|
| Account Identity | Work email, Name, GitHub UID | Duration of active account | Contract Performance |
| API Telemetry | Request counts, Latency, Status codes | Rolling 30 days (aggregated) | Legitimate Interest |
| Schema ASTs | Endpoints, Types, Docstrings | Ephemeral (0 days retention) | Contract Fulfillment |
| Billing Records | Stripe Customer ID, VAT, Invoices | 7 years (statutory tax requirement) | Legal Obligation |
We partner with tier-1 enterprise infrastructure providers bound by rigorous Data Protection Agreements (DPAs) with standard contractual clauses (SCCs):
Regardless of your geographic location, Stainless Studio affords every client full sovereign control over their data:
For regulatory inquiries, custom Data Processing Agreements, or security audits, contact our designated privacy team directly: