Skip to content
Legal

Privacy Policy

Effective Date: April 8, 2026

Sterity LLC (“Sterity,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains what information we collect through sterity.co and our services, how we use it, who we share it with, and the choices available to you. By using the services, you agree to the practices described in this policy.

1. Information We Collect

We collect information in three ways: information you provide directly, information collected automatically, and information from third-party sources.

Information You Provide

  • Contact details such as your name, email address, job title, company name, and phone number.
  • Assessment responses, including answers about your firm’s people, processes, tools, workflows, decisions, capacity, and metrics.
  • Voice recordings, if you choose to use voice input during an assessment. Voice input is always optional. Audio is transmitted to a third-party transcription provider (currently OpenAI Whisper) for real-time conversion to text. The transcription provider processes the audio in transit and does not retain your audio recordings after processing. Transcripts are stored in our system for the duration described in Section 6.
  • Ops Room contributions, including messages, actions, pulse check responses, and other content you submit within an Ops Room workspace.
  • Payment information submitted to our third-party payment processor (currently Stripe). We do not store full payment card details ourselves.
  • Communications you send to us, including emails, support requests, and feedback.

Information Collected Automatically

  • Device and browser information such as browser type, operating system, screen size, and language.
  • Usage information such as pages viewed, time spent, referring URL, and interactions with the assessment.
  • Approximate location derived from IP address.
  • Cookies and similar technologies, as described in Section 8.

Information from Third-Party Sources

To enrich the report we deliver to you, we may collect publicly available information about your company from sources such as company websites, business registries, and professional networks. This enrichment is performed automatically after you begin an assessment and is based on the email domain and company name you provide. We use this information solely to provide more relevant and accurate diagnostic reports. We do not purchase personal data from data brokers. You may request that we exclude enrichment data from your report by contacting [email protected].

2. How We Use Information

We use information to:

  • Deliver the assessment, scoring, report, Ops Room services, and any related services you request.
  • Process payments for paid services.
  • Communicate with you about your account, your report, and our services.
  • Improve our methodology, models, and product, including by analyzing aggregate trends across assessments.
  • Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms.
  • Comply with legal obligations and enforce our agreements.
  • With your consent, send you occasional updates about Sterity offerings. You can opt out at any time.

3. AI Processing, Data Transit, and Retention

Our services use artificial intelligence at multiple stages. We use two categories of AI providers, each for a distinct purpose:

  • Large Language Model (Anthropic).We use Anthropic’s Claude models to analyze your assessment responses, generate scores, produce diagnostic summaries and recommendations, facilitate Ops Room conversations, and power related features. Your submitted content is transmitted to Anthropic’s API for processing — it does not stay solely on our own servers. Under our agreement with Anthropic, submitted content is retained for a maximum of 7 days for abuse monitoring and is not used to train Anthropic’s models. We describe this plainly here rather than saying your content “never leaves” our systems, because it does transit a third-party API in the ordinary course of generating your results.
  • Speech-to-Text (OpenAI Whisper).If you use the optional voice input feature, your audio recording is sent to OpenAI’s Whisper service solely for conversion to text. Audio is processed in transit and is not retained by OpenAI after transcription is complete. No assessment analysis or scoring is performed by OpenAI.

AI outputs are diagnostic and informational and should not be treated as professional advice. We may change AI providers in the future; if we do, we will update this policy and ensure that equivalent data protection commitments are in place with any new provider.

4. Automatic PII Redaction — What Is and Isn't Auto-Stripped

Before free-text content (walkthrough transcripts, chat messages, and similar submissions) is stored as durable institutional knowledge in your company’s record, we run it through an automatic filter that strips a defined set of structured personal and sensitive data patterns. Today that filter automatically detects and redacts five categories:

  • Social Security Numbers
  • Email addresses
  • Phone numbers
  • Credit card numbers
  • API keys, bearer tokens, and similar secrets

What this automatic filter does not catch:it is pattern-based, not a general-purpose de-identification engine. Free-text personal details embedded in ordinary prose — a person’s name, a health detail, a salary figure, or a specific client’s commercial terms mentioned in passing during a walkthrough or chat — are not automatically detected or removed by this filter. Content that could contain this kind of detail is routed through human review before it is promoted into a durable, shared knowledge record; that human review step, not the automatic filter, is what catches free-text personal and sensitive detail today. We are working to close this gap with additional automated safeguards, and we describe our current state honestly here rather than overstating what the automatic filter alone accomplishes.

5. How We Share Information

We do not sell your personal information. We do not rent or trade it. We share it only as follows:

  • Service providers (subprocessors) who help us operate the business. The core subprocessors that process your data are Anthropic (AI analysis), Supabase (database and hosting infrastructure), Resend (transactional email delivery), and Stripe (payment processing). We also use OpenAI (voice transcription), Vercel (application hosting), PostHog (product analytics), Sentry (error monitoring), and Upstash (rate limiting). Every subprocessor is bound by a contract that limits its use of your information to providing services to us. A current, complete list of material subprocessors is available upon request by contacting [email protected].
  • Within your organization.If multiple people from your organization participate in assessments, individual responses may be aggregated into a company report that is visible to other authorized participants from your organization. Individual responses may be attributed by role (e.g., “Operations Manager”) but are not attributed by name in aggregated reports. Each participant consents to this when they begin their assessment.
  • Legal and safety reasons, such as to comply with valid legal process, enforce our Terms, protect our rights, or protect the safety of any person.
  • Business transfers. If Sterity is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will require any successor to honor the commitments in this policy.

Client Intelligence Is Private.We do not cross-reference, sell, or share one client’s company-specific information with any other client. Client intelligence is private to the relationship between you and Sterity.

6. Aggregated and Anonymized Data

We may use information you submit to create aggregated, anonymized benchmarks, statistics, and insights that do not identify you or your organization. We will only publish or share aggregated benchmarks that are based on a minimum of five (5) organizations within the same industry segment, so that no individual client can be identified. We may use aggregated, anonymized data for any lawful purpose, including improving our services and producing public research and thought leadership.

7. Data Retention

We retain different categories of information for different periods:

  • Assessment data and reports: Retained for three (3) years from the date of your last interaction with the service, so that you can return to your results and track progress over time.
  • Voice recordings: Audio recordings are not stored by Sterity or our transcription provider. Transcripts derived from voice recordings are retained for the same period as assessment data.
  • Ops Room data: Retained for the duration of your active subscription plus sixty (60) days after expiration or cancellation.
  • Payment records: Retained for seven (7) years to comply with tax and accounting requirements.
  • Usage and analytics data: Retained for twenty-four (24) months from collection.

You can request deletion of your data at any time, subject to the limited exceptions described in Section 10. Upon receiving a valid deletion request, we will delete or anonymize your data within thirty (30) days, except where retention is required for legal, accounting, security, or fraud-prevention reasons.

8. Data Security and Breach Notification

We use reasonable administrative, technical, and physical safeguards to protect information, including encryption in transit (TLS) and at rest, access controls, database-level row-level security policies that isolate one client’s data from another’s, and regular security reviews. No system is perfectly secure, however, and we cannot guarantee absolute security. You are responsible for keeping your own login credentials confidential.

Breach Notification.In the event of a confirmed security breach that compromises your personal information or your organization’s assessment data, we will notify affected clients within seventy-two (72) hours of confirming the breach. Notification will be sent to the email address associated with your account and will include: a description of the incident, the categories of data affected, the measures we have taken to address the breach, and recommended steps you can take to protect yourself. We will also notify any applicable regulatory authorities as required by law.

9. Cookies and Tracking

We use cookies and similar technologies to operate and improve the website. Some cookies are strictly necessary for the site to function (e.g., session management). Others help us understand how the site is used so we can improve it (e.g., PostHog analytics). We do not use third-party advertising cookies or retargeting pixels. You can control cookies through your browser settings, but disabling some cookies may affect how the site works.

10. Your Choices and Rights

You have the following choices regarding your information:

  • Access and correction. You can request a copy of the information we hold about you, or ask us to correct it.
  • Deletion. You can ask us to delete your information. We will honor the request within thirty (30) days unless we are required to retain the information for legal, accounting, security, or fraud-prevention reasons.
  • Marketing opt-out. You can opt out of marketing emails using the unsubscribe link in any marketing message.
  • Voice input. Voice recording is optional. You can complete any assessment using text only.
  • Enrichment opt-out. You can request that we exclude publicly sourced enrichment data from your report.
  • Data portability. You can request an export of your assessment data and reports in a commonly used electronic format.

To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before responding. We will respond to verified requests within thirty (30) days.

Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR), or other regional privacy laws. We will honor those rights to the extent they apply to us. California residents may request disclosure of the categories and specific pieces of personal information we have collected, and may request deletion under the CCPA. We do not sell personal information as defined by the CCPA.

11. Children

Our services are directed to businesses and to adults. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, contact us and we will delete it.

12. International Users

Sterity operates from the United States. If you access the services from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those of your country. By using the services, you consent to this transfer. If you are located in the European Economic Area, we rely on your consent and, where applicable, Standard Contractual Clauses to provide an adequate legal basis for data transfers.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The current version will always be posted at sterity.co. For material changes, we will provide at least thirty (30) days’ advance notice via the email address associated with your account. Your continued use of the services after changes take effect constitutes acceptance of the updated policy.

14. Contact

Questions, requests, or complaints about this Privacy Policy can be sent to:

Sterity LLC
Email: [email protected]
Michigan, USA