Privacy Policy
Last updated: April 15, 2026
1. Overview
Stroby AI Inc. (“we,” “us,” or “our”) operates the website stroby.ai and related services (the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
We are committed to protecting your privacy and handling your data transparently. This policy complies with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable data protection laws.
2. Facebook Login & WhatsApp Business Platform
Stroby uses the Meta WhatsApp Business Platform (via the WhatsApp Cloud API) to communicate with users. When you message Stroby on WhatsApp, we receive and process your WhatsApp phone number and messages to provide our Service.
We do not use Facebook Login or access your Facebook profile. All interactions occur through WhatsApp messaging and our website at stroby.ai.
2.1 Meta Platform Data
Through the WhatsApp Business Platform, we access:
- Your WhatsApp phone number (provided by you during onboarding)
- Messages you send to our WhatsApp Business number
- Message delivery and read status
We do not access your WhatsApp contacts, profile photo, status, or any other WhatsApp data beyond the messages you send directly to us. We do not share Meta Platform Data with third parties except as necessary to provide the Service (e.g., processing messages through our AI).
3. Information We Collect
3.1 Information You Provide
When you use our onboarding chat or interact with the Service, we collect:
- Identity Information: Your name, email address, and WhatsApp phone number.
- Business Information: Company name, role, product description, target customer, niche, budget, and campaign goals.
- Audience Information: Platform, channel name, audience size, engagement rates, content niche, partnership preferences, and pricing.
- Communication Data: Messages exchanged through our chat interface and WhatsApp.
3.2 Information Collected Automatically
When you visit our website, we may automatically collect:
- Device Information: Browser type, operating system, and device identifiers.
- Usage Data: Pages visited, time spent, clicks, and navigation patterns.
- Log Data: IP address, access times, and referring URLs.
4. How We Use Your Information
We use your information for the following purposes:
- Matching: To power our AI matching engine and connect you with relevant businesses, influencers, or other professionals.
- Communication: To send match suggestions, platform updates, and service-related messages via WhatsApp and email.
- Payments: To process transactions via Stroby Pay (our escrow payment system, powered and secured by Stripe Connect) and handle payouts.
- Service Improvement: To analyze usage patterns and improve the platform experience.
- AI Training: To train and improve our AI matching algorithms using anonymized and aggregated data that has been stripped of personally identifiable information.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
5. Legal Basis for Processing (GDPR)
If you are in the EEA or UK, we process your data based on:
- Consent: You consent to data processing when you complete onboarding and agree to these terms.
- Contract Performance: Processing is necessary to provide the Service you requested.
- Legitimate Interests: To improve our Service, prevent fraud, and ensure platform security.
- Legal Obligation: To comply with applicable laws and regulations.
6. Data Sharing & Third Parties
6.1 With Other Users
When we suggest a match, we share relevant Profile information (such as niche, audience description, and general metrics) with the potential match. We do not share your email, phone number, or WhatsApp number with other users unless both parties have explicitly opted in to an introduction.
6.2 Service Providers
We share data with trusted third-party service providers who help us operate the platform:
- Meta / WhatsApp Business Platform (messaging) — delivers WhatsApp messages via the Cloud API.
- Supabase (database hosting) — stores your Profile and platform data.
- Stroby Pay (payments) — our escrow payment system, powered by Stripe Connect, that processes payments and manages fund release.
- Anthropic (AI) — powers our AI matching and conversational features.
- Vercel (hosting) — hosts the Stroby website and API.
These providers process data only as necessary to perform their services and are contractually obligated to protect your information.
6.3 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Stroby, our users, or others.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you request account deletion, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements).
Anonymized and aggregated data used for AI training and analytics may be retained indefinitely as it cannot be linked back to you.
8. Data Deletion
You may request deletion of your account and all associated personal data at any time by:
- Messaging Stroby on WhatsApp with “Delete my account”
- Emailing privacy@stroby.ai with “Account Deletion Request” as the subject
Upon receiving a deletion request, we will delete your personal data from our systems within 30 days. This includes your Profile data, message history, and any associated records. Data that has already been anonymized and aggregated for analytics purposes cannot be deleted as it is no longer linked to your identity.
If you have active transactions in escrow, deletion will be processed after all pending transactions are resolved.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Access controls limiting data access to authorized personnel.
- Regular security reviews of our infrastructure and third-party providers.
- Secure payment processing through Stripe (PCI DSS compliant).
While we take reasonable measures to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (“right to be forgotten”).
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Withdraw Consent: Withdraw previously given consent at any time.
To exercise any of these rights, email us at privacy@stroby.ai. We will respond within 30 days.
10.1 California Residents (CCPA)
California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell your personal information.
10.2 Canadian Residents (PIPEDA)
Canadian residents have the right to access their personal information, challenge its accuracy, and withdraw consent for its collection, use, or disclosure, subject to legal or contractual restrictions.
11. Cookies & Tracking
We use minimal cookies and local storage necessary for the functioning of the Service (e.g., saving your onboarding progress). We do not use third-party tracking cookies for advertising. We may use analytics tools to understand how the Service is used, with data collected in an anonymized manner.
12. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States and Canada, where our service providers operate. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your data during international transfers.
13. Pre-Launch Directory (Shadow Profiles)
To give new users valuable matches from their first day on Stroby, we maintain a pre-launch directory of companies and newsletter creators that publicly identify as newsletter-marketing-relevant. Entries in this directory are compiled from publicly available sources (company websites, publicly listed newsletters, public marketplace data). These profiles are not active user accounts — they are not surfaced to the public, are not included in our public-facing metrics or analytics, and are only used internally by our matching engine to help real users discover potentially relevant partners.
When our matching engine surfaces a directory profile as a potential match to a real user, we will reach out to the directory entity (via publicly listed contact methods) inviting them to activate their profile. If they activate, the match proceeds via our normal double-opt-in flow. If they never activate, their directory entry expires after 180 days of non-engagement and is deleted.
If you are listed in our pre-launch directory and do not wish to be, email privacy@stroby.ai with the name of your company or newsletter and we will remove your entry within 72 hours. We will honor this request permanently — we will not re-add removed entities to future directory compilations.
14. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected data from a minor, please contact us at privacy@stroby.ai and we will promptly delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or WhatsApp at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
16. Contact Us
If you have any questions about this Privacy Policy or your personal data, contact us:
- Email: privacy@stroby.ai
- General inquiries: hello@stroby.ai