Privacy Policy
Last updated: April 13, 2026
1. Introduction
Strata ("we", "our", or "the Service") is a multi-tenant B2B analytics platform. This Privacy Policy describes how we collect, use, store, and protect information when you use the Service.
By using Strata, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
2. Data We Collect
Account Information
When you register, we collect your name, email address, and organization name through our authentication provider (Kinde).
Uploaded Data
You may upload CSV files, spreadsheets, or connect SaaS data sources. This data is stored in your tenant-isolated warehouse and is never shared with other tenants.
Usage Data
We collect anonymized usage metrics (pages visited, features used, query counts) to improve the Service. Error logs may be captured by our error tracking service (Sentry).
Payment Information
Payment details are processed by Stripe and are never stored on our servers. We retain only your Stripe customer identifier and subscription status.
3. Tenant Isolation
Each tenant's data is stored in a dedicated, isolated warehouse. Tenant data is segregated at the storage, query, and API layer. Cross-tenant data access is architecturally prevented through scoped credentials and namespace prefixing.
4. How We Use Your Data
- To provide and maintain the analytics Service
- To process natural-language queries against your data
- To generate ML analyses (forecasting, anomaly detection)
- To send transactional emails (billing, alerts)
- To improve Service reliability and performance
5. Third-Party Services
We use the following third-party services to operate Strata:
- Gemini API (Google) — Powers natural-language query generation and ML model selection. Your query text is sent to the Gemini API; raw data rows are not.
- Kinde — Authentication and session management.
- Stripe — Payment processing and subscription management.
- Sentry — Error tracking and performance monitoring.
- Langfuse — LLM observability and cost tracking.
- Cloudflare — DNS, CDN, R2 object storage, and DDoS protection.
6. AI and Model Training
We do not use your data to train, fine-tune, or improve any AI or machine learning models. Data sent to the Gemini API for query generation is processed under Google's API terms, which prohibit training on API inputs.
7. Data Storage and Residency
All customer data is stored on infrastructure located in the United States. Uploaded files are stored in Cloudflare R2 (US-based). Database records are stored in PostgreSQL on our managed VPS. Tenant warehouses (DuckDB) are stored in R2 and processed on compute in the same US region.
8. Data Retention
We retain your data for as long as your account is active. Upon account deletion, tenant data (warehouse, uploaded files, connectors) is permanently deleted within 30 days. Billing records may be retained longer as required by law.
9. Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, scoped API credentials, and regular security audits. Access to production systems is restricted and logged.
10. Your Rights
- Access — Request a copy of the data we hold about you.
- Deletion — Request deletion of your account and all associated data.
- Portability — Export your data at any time through the dashboard.
- Correction — Update your account information through the dashboard settings.
11. Cookies
We use strictly necessary cookies for authentication and session management. We do not use advertising or tracking cookies.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact
For privacy-related questions or requests, email us at [email protected].