Privacy Policy

Last updated · July 30, 2026

This policy explains what personal data Standin processes, why, and the rights you have. It applies to the Standin website and application.

Who is responsible

For your own account and your use of Standin, the publisher named in the Legal notice is the data controller.

For the data you load into your CRM and the emails your copilot handles (your clients' names, messages and contact details), Standin acts as a processor on your behalf: you are the controller of that data, and you decide what is collected and why.

Data we process

Depending on how you use Standin, we process:

  • Account data, through our authentication provider: your name, email address and sign-in credentials.
  • CRM content you enter: records about your clients or cases, which may include names, phone numbers, email and postal addresses, notes, amounts and any field you create, including, if you choose to record it, sensitive information such as health-related notes. You control what goes in.
  • Email data, if you connect a Gmail inbox: the content and metadata (sender, subject, date) of the incoming and outgoing messages the copilot handles, and the secure tokens that let the app read and send on your behalf.
  • Copilot drafts and conversation history, stored so you can review and continue exchanges.
  • Technical and anti-abuse data: sender identifiers and message fingerprints used to block flooding, weekly AI usage counts, and standard server logs.
  • Cookies: a language-preference cookie (functional), your authentication session cookie (essential) and a short-lived security cookie during Gmail connection (essential). Standin sets no advertising or analytics cookies.

Why we process it, and on what basis

We process data to provide the service you asked for:

  • To run your CRM and copilot: performance of our contract with you.
  • To connect and operate your email inbox: your explicit consent, given through Google's consent screen, which you can withdraw at any time by disconnecting the inbox.
  • To secure the service and prevent abuse: our legitimate interest.
  • To meet legal obligations where they apply.

Artificial intelligence

Standin uses AI to generate your CRM structure, draft replies and update records. To do this, the content needed for the task (the relevant messages and record fields) is sent to third-party AI providers that generate the output.

We send only what the task requires. Even so, avoid entering sensitive personal data you don't need. Depending on configuration, some free AI tiers may retain requests; for sensitive use the publisher favours providers offering zero data retention. The copilot never sends an email on its own. You review and approve every reply.

Google user data (Gmail)

Standin's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We access your Gmail only to read incoming messages and send the replies you approve. We do not use Gmail data for advertising, do not sell it, and do not use it to train generalized AI models. You can revoke access at any time from your Google account security settings, or by disconnecting the inbox in Standin.

Service providers (sub-processors)

We rely on the following providers to run Standin. They process data only for that purpose:

  • Clerk: authentication and account management.
  • Neon: database hosting (your CRM and messages).
  • Vercel: application hosting and AI gateway.
  • Google: Gmail access, when you connect an inbox.
  • AI providers (which may include OpenRouter, NVIDIA and Anthropic, depending on configuration): generating replies and CRM structure.
  • Tavily: web search, when the assistant needs public information.

International transfers

Some of these providers are located outside the European Union, including in the United States. Where data is transferred there, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy mechanism.

How long we keep it

We keep your account and CRM data for as long as your account is active. Anti-abuse fingerprints are deleted automatically within an hour. When you delete a record, a workspace or an email inbox, the associated data is deleted. On request, we delete your personal data, subject to any legal retention duties.

Your rights

You can request access to your data, correction, deletion, portability, and object to or restrict certain processing. If you are in California, you can ask what we collect, request deletion, and opt out of any sale or sharing of personal information. We do not sell or share it. To exercise any right, contact us using the address in the Legal notice.

You may also lodge a complaint with your supervisory authority (in France, the CNIL).

Security

We take reasonable technical and organisational measures to protect your data, including access controls and encrypted connections. No system is perfectly secure; we work to improve protection continuously, including encryption of sensitive credentials at rest.

Children

Standin is a professional tool and is not intended for minors. We do not knowingly collect data from children.

Changes

We may update this policy. The date above reflects the latest version; significant changes will be signalled in the app.