Privacy Policy
Last updated · September 19, 2026
This policy explains what personal data Standin processes, why, and the rights you have. It applies to the Standin website and application.
Who is responsible
For your own account and your use of Standin, the publisher named in the Legal notice is the data controller.
For the data you load into your CRM and the emails your copilot handles (your clients' names, messages and contact details), Standin acts as a processor on your behalf: you are the controller of that data, and you decide what is collected and why.
Data we process
Depending on how you use Standin, we process:
- Account data, through our authentication provider: your name, email address and sign-in credentials.
- CRM content you enter: records about your clients or cases, which may include names, phone numbers, email and postal addresses, notes, amounts and any field you create, including, if you choose to record it, sensitive information such as health-related notes. You control what goes in.
- Email data, if you connect a Gmail inbox: the content and metadata (sender, subject, date) of the incoming and outgoing messages the copilot handles, and the secure tokens that let the app read and send on your behalf.
- Copilot drafts and conversation history, stored so you can review and continue exchanges.
- Technical and anti-abuse data: sender identifiers and message fingerprints used to block flooding, weekly AI usage counts, and standard server logs.
- Essential cookies, which cannot be refused because the service would not work without them: your authentication session, your language preference, your light or dark theme preference, and a short-lived security cookie during Gmail connection.
- Analytics trackers, only if you accepted them in the banner: Google Analytics 4 (_ga cookies, 13 months) and Vercel Web Analytics (no cookie, a fingerprint computed server-side and discarded within 24 hours). We set no advertising cookies. You can change your mind at any time through the “Manage trackers” link at the bottom of the page.
- A 30-day referral cookie, if you arrive through a referral link AND you accepted trackers, to credit whoever recommended Standin to you.
- Where your account came from: the word in the link you arrived through (for example “mail-artisan”), with the date and the landing page, recorded on your first visit to the app. No cookie is set for this.
Why we process it, and on what basis
We process data to provide the service you asked for:
- To run your CRM and copilot: performance of our contract with you.
- To connect and operate your email inbox: your explicit consent, given through Google's consent screen, which you can withdraw at any time by disconnecting the inbox.
- To secure the service and prevent abuse: our legitimate interest.
- To meet legal obligations where they apply.
Artificial intelligence
Standin uses AI to generate your CRM structure, draft replies and update records. To do this, the content needed for the task (the relevant messages and record fields) is sent to third-party AI providers that generate the output.
We send only what the task requires. Even so, avoid entering sensitive personal data you don't need. Depending on configuration, some free AI tiers may retain requests; for sensitive use the publisher favors providers offering zero data retention. By default, the copilot never sends an email on its own: you review and approve every reply. Automatic sending is an option you switch on yourself.
When you turn on automatic sending, the first reply that goes out without your review in each conversation ends with a sentence telling the recipient it was written by an AI assistant, as required by the European AI Act (Article 50), in force since August 2, 2026. For the same reason, the phone answering service introduces itself as a virtual assistant.
Google user data (Gmail)
Standin's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We access your Gmail only to read incoming messages and send the replies you approve. We do not use Gmail data for advertising, do not sell it, and do not use it to train generalized AI models. You can revoke access at any time from your Google account security settings, or by disconnecting the inbox in Standin.
If you only authorize sending (the Google gmail.send permission), Standin can neither read nor modify your mailbox: it only uses it to send, from your address, the replies meant for your clients. The related tokens are encrypted, and you can remove the authorization at any time in Standin (Settings, Mailboxes) or from your Google account.
Microsoft user data (Outlook, Hotmail, Microsoft 365)
If your mailbox is hosted by Microsoft, you can authorize Standin to send your replies from your address. Standin then requests only the Microsoft Graph permissions Mail.Send (send email on your behalf) and User.Read (read the account address, to confirm it is the mailbox you added), plus offline_access to keep the authorization active.
If you connect your Outlook calendar (Calendar page), Standin requests, through a separate authorization, the Calendars.ReadWrite permission: to read your events so they show in your CRM calendar and a client is never offered a slot that's already taken, to add the appointments booked in Standin, and to delete the ones Standin created when you cancel them. Standin does not change or delete any other event. You can turn this access off at any time from the Calendar page.
Standin can neither read, modify, nor delete the emails in your Microsoft mailbox. It only uses this access to send the replies meant for your clients. We do not use this data for advertising, do not sell it, and do not use it to train AI models. The related tokens are encrypted, and you can remove the authorization at any time in Standin (Settings, Mailboxes) or from the "Apps and services" page of your Microsoft account.
Service providers (sub-processors)
We rely on the following providers to run Standin. They process data only for that purpose:
- Clerk (United States): authentication and account management.
- Neon (United States): database hosting (your CRM and messages).
- Vercel (United States): application hosting, storage of the photos on your records, and a backup AI gateway (which may pass the request to Anthropic).
- Groq (United States): AI processing of your clients' messages (copilot, assistant, phone) and call transcription. Groq does not train on this data.
- Cerebras, NVIDIA and GitHub Models (United States): backup AI providers for the same tasks, which do not train on this data.
- Google Gemini and OpenRouter (United States): generating your CRM structure and translations, from what you describe about your business. They never receive your clients' messages.
- Google (United States): sending replies from your Gmail inbox and connecting Google Calendar, when you authorize it.
- Microsoft (United States): sending replies from your Outlook mailbox and connecting your Outlook calendar, when you authorize it.
- Resend (United States): receiving the emails you forward to Standin (receiving servers may be located outside the European Union, notably in Japan), and sending the emails Standin sends you (alerts, summaries) as well as its business outreach messages. Replies to your clients leave from your own inbox, not from Resend.
- Twilio (United States): receiving calls for the phone answering service.
- ElevenLabs (United States): synthetic voice for the phone answering service.
- Meta (Ireland and United States): receiving and sending WhatsApp messages, when you connect a number.
- Browser notification services (Google, Apple, Mozilla): delivering notifications to your phone, if you turn them on.
- Tavily (United States): web search, when the assistant needs public information.
- Lemon Squeezy (United States): subscription payments. Lemon Squeezy acts as Merchant of Record: it takes the payment, invoices you and collects taxes. Standin never sees your card details.
- Google Analytics (United States): audience measurement on the public site, only if you accepted it.
- Vercel Web Analytics: page view counting, only if you accepted it.
Business outreach
Standin contacts, by email, businesses likely to be interested in its service. For this purpose we process the business email address, the company name, the trade, the city and, where available, the owner's first name. If you received such a message, here is what concerns you.
- Source: public information only, namely the company's own website, the French government's business directory (annuaire-entreprises.data.gouv.fr) and the OpenStreetMap database.
- Purpose and legal basis: to introduce Standin to you, on the basis of our legitimate interest in making our service known to businesses, in connection with their trade.
- Retention: three years from your last reply, or from collection if you never replied, unless you object sooner.
- Right to object: at any time and without giving a reason, by replying to one of our messages, using the unsubscribe link or writing to contact@standin.site. Your address is then kept on a suppression list for the sole purpose of never writing to you again.
- Replies to our messages reach our contact address and a technical receiving address, which lets us know who replied so that we stop following up with them.
International transfers
Standin's publisher is established in Israel, a country covered by a European Commission adequacy decision: data processed there benefits from a level of protection recognized as equivalent to the Union's, with no further formality. Providers established in the United States (see the list above) rely on the EU-US Data Privacy Framework or on the European Commission's Standard Contractual Clauses. Japan, where the servers receiving forwarded emails may be located, is also covered by an adequacy decision.
How long we keep it
We keep your account and CRM data for as long as your account is active. Anti-abuse fingerprints are deleted automatically within an hour. When you delete a record, a workspace or an email inbox, the associated data is deleted. On request, we delete your personal data, subject to any legal retention duties. Business outreach data is kept for three years from your last reply, or from collection if you never replied.
Your rights
You can request access to your data, correction, deletion, portability, and object to or restrict certain processing. If you are in California, you can ask what we collect, request deletion, and opt out of any sale or sharing of personal information. We do not sell or share it. To exercise any right, email us at contact@standin.site.
You may also lodge a complaint with your supervisory authority (in France, the CNIL).
Security
We take reasonable technical and organizational measures to protect your data, including access controls and encrypted connections. No system is perfectly secure; we work to improve protection continuously, including encryption of sensitive credentials at rest.
Children
Standin is a professional tool and is not intended for minors. We do not knowingly collect data from children.
Changes
We may update this policy. The date above reflects the latest version; significant changes will be signaled in the app.