Privacy Policy

Last updated: 4 July 2026

Who we are

Stevin.AI ("Stevin") is an AI platform operated by WPOT B.V., a company registered in the Netherlands. We help marketing teams and agencies detect campaign issues earlier than regular reporting does.

What data we collect

  • Account data: name, business email, organization, role within your team.
  • Campaign and analytics data: only through OAuth integrations that you initiate (Google Ads, Meta, GA4, etc.). We receive read-only access to campaign metrics, no payment or billing information.
  • Platform usage data: page visits, feature usage, timestamps, to improve the service and detect abuse.
  • Technical data: IP address, browser type, device type for security and debugging.
  • Website and lead context: when you submit a contact or demo form, we store the form details with limited context such as landing page, referrer, UTM parameters, campaign clicks and recently visited pages. We use this to follow up properly and understand which content and campaigns create qualified leads.

Why we use it

  • To give you access to the platform and connected data.
  • To generate signals, alerts and recommendations for your campaigns.
  • To detect and resolve security incidents.
  • To improve the service based on anonymous usage patterns.
  • To qualify website requests and follow up with the right context.

We do not sell personal data. We do not share your campaign data with other Stevin customers. Strict tenant isolation applies per organization.

Retention

We retain account data for as long as you have an active account, plus 12 months after termination for administrative and tax obligations. Campaign data is deleted within 30 days after a platform is disconnected or the service is cancelled.

Subprocessors

We use a limited set of subprocessors, all under a data processing agreement:

  • Supabase (database hosting, EU region): platform data storage.
  • AWS (EU region): application infrastructure.
  • Vercel (EU region): front-end hosting.
  • Resend (EU region): transactional email.
  • Anthropic / OpenAI: for AI features only, with stripped or anonymous prompts where possible; no personal data goes into training datasets.

OAuth integrations (such as Google Ads, Meta, Pinterest, LinkedIn) run directly between you and the platform. We only receive the tokens you authorize.

Your rights

Under GDPR you have the right to access, rectify, erase, restrict, port and object to processing of your data. Send a request to privacy@stevin.ai. We respond within 30 days.

Not satisfied? You can lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

Cookies

On stevin.ai we use necessary cookies for basic functions such as session, language preference and security. Without consent, we do not load Microsoft Clarity and we do not grant Google or advertising platforms permission to use analytics or advertising cookies.

If you choose statistics, we use Google Analytics and Microsoft Clarity to analyze page views, interactions, scroll behavior, clicks, heatmaps and session recordings. If you choose marketing, we use Google Ads and Meta for campaign and conversion measurement. Where relevant, form data is only sent in hashed form for enhanced conversion measurement.

You can choose between necessary, statistics, marketing or accept all through the cookie settings. We do not sell personal data.

Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production data is restricted to specifically authorized employees, with logging and periodic audits.

Changes

We may amend this privacy policy. For material changes we notify active users at least 14 days before the change takes effect.

Stevin.AI is a trade name of WPOT B.V., registered with the Dutch Chamber of Commerce (KvK) under number 87774372, VAT number NL864401954B01. Registered office: Amstenradestraat 25, 4834 JB Breda, Netherlands.

Contact: privacy@stevin.ai