Privacy Policy
Effective date: 26 June 2026 · Last updated: 26 June 2026
Statey ("Statey", "we", "us") provides an agent-native database delivered over the Model Context Protocol (MCP). This policy explains what we collect, how we use and store it, who we share it with, how long we keep it, and your rights. It applies to the Statey service at statey.ai, mcp.statey.ai, and console.statey.ai.
The controller of your personal data is Scott Willman, an individual based in the Netherlands. Contact: privacy@statey.ai.
1. Data we collect
Account & identity data. When you sign up we collect your email address and name, and authentication identifiers, through our authentication provider (WorkOS). We do not store your password — authentication is handled by WorkOS.
Workspace content ("your data"). The collections, schemas, records, and any content you or your agents create, store, query, or modify in Statey. This is your data; we process it solely to provide the service to you. Statey is a storage and tooling layer — we do not send your workspace content to any large language model. Your AI client (e.g. Claude) reads and writes your data through the MCP tools using credentials you control; the model loop runs on your side, never on ours.
Agent & API keys. Credentials we issue for your agents (we store a hashed form of each key, its scopes, and usage metadata — never the secret in plaintext after issuance).
Activity & attribution. Every change in your workspace emits an event record (who, what, which record, when, before/after) used for the activity log, change detection, and metering. This is part of the product, stored within your workspace.
Usage & metering. Counts of tool calls (reads vs. writes) and storage, per workspace, to operate the service and enforce limits.
Technical data. IP address, request metadata, and server logs generated when you connect, collected by our hosting and network providers for security, abuse prevention, and reliability.
Billing data. If and when paid plans are enabled, payment will be processed by Stripe; we will not store full card numbers (Stripe does).
2. How we use your data
- Provide, operate, and secure the Statey service.
- Authenticate you and your agents and enforce access scopes.
- Meter usage and, where applicable, enforce limits and bill you.
- Detect, prevent, and investigate abuse, security incidents, and outages.
- Communicate service, security, and account notices.
- Comply with legal obligations.
We do not sell your personal data, and we do not use your workspace content to train any AI model. Our legal bases under the GDPR are performance of our contract with you (to provide the service), our legitimate interests (security and abuse prevention), and compliance with legal obligations.
3. Where your data is stored & how it is secured
Your data is stored in MongoDB Atlas, hosted on Amazon Web Services in the AWS us-west-2 (United States) region. Each workspace is isolated in its own database. The Statey service runs on Render. Data is encrypted in transit (TLS). Access to production systems is restricted.
4. Third parties we share data with (sub-processors)
We share data only with service providers that help us run Statey, under their respective data-protection terms:
| Provider | Purpose | Data |
|---|---|---|
| WorkOS | Authentication & organization management | Account identity (email, name) |
| MongoDB Atlas (on AWS) | Database hosting | Workspace content |
| Render | Application hosting & logs | Request/technical data |
| Cloudflare | DNS, TLS, network protection, email forwarding | Connection/technical data |
| Stripe | Payment processing (when paid plans are live) | Billing data |
We may also disclose data if required by law, or to protect rights and safety. We do not share your workspace content with AI/LLM providers.
5. Data retention
- Workspace content is retained for as long as your account/workspace is active. On account closure or a deletion request, we delete your workspace databases within 30 days, except where retention is required by law.
- Activity/event logs are retained as part of your workspace data and removed with it.
- Backups are retained for a limited period and overwritten on a rolling basis.
- Account/identity data is removed when you close your account, subject to legal retention requirements.
6. International transfers
Statey is operated from the Netherlands, and your data is stored in the United States (see §3). For transfers of personal data outside the European Economic Area, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses with our sub-processors.
7. Your rights
Under the EU/UK GDPR you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability. You can exercise most of these directly through the Statey tools and console, or by contacting privacy@statey.ai. You also have the right to lodge a complaint with your local data protection authority; in the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
8. Children
Statey is not directed to, and not intended for, individuals under 16. We do not knowingly collect data from children.
9. Changes to this policy
We may update this policy; material changes will be announced at statey.ai and/or by email. The "Last updated" date above reflects the latest version.
10. Contact
Questions or requests: privacy@statey.ai.