The boring bits, written plainly.
What data Stead collects, where it's stored, what we do with it, and the rules for using the closed beta. No legal pretzel sentences. If anything is unclear, email me.
The summary, before the detail.
Stead stores your account and home data on Supabase servers in the European Union. Your property profile, documents, and chat history are visible only to you, with database-level access controls. Smart features (diagnostics, energy insights, smart home automations) send the relevant context to Anthropic's Claude Haiku model to generate a response, then drop the request. We don't train models on your data, sell it, or hand it to advertisers. You can export or delete everything on request.
The closed beta is provided as is, with no warranty. Things may occasionally break or be wiped. We try hard for that not to happen. If something does go wrong, we'll tell you and fix it.
Last updated: 7 May 2026.
What we collect and why.
1. Who we are
"Stead" is a sole-trader operation run by David, based in Bristol, United Kingdom. For UK GDPR purposes, the data controller is the operator of stead.space, contactable at [email protected].
2. What data we collect
Account data. Your email address, a hashed password (or a Google account ID if you sign in with Google), and a display name if you set one. Sign in timestamps and the IP address of the most recent session for security purposes.
Property data. The information you give us about your home: postcode, address, property type, size, EPC certificate data pulled from the gov.uk register at your request, room layouts, appliances, and any notes you choose to add.
Documents. Files you upload (certificates, warranties, manuals, photos). Stored in Supabase Storage with access restricted to your account via row level security.
Activity data. Maintenance task history, document expiry dates, energy bill entries, smart home automation history, diagnostic chat conversations, and any other actions you take in the app. Used to provide the service and to surface relevant reminders to you.
Smart feature inputs. When you ask the diagnostics chat a question, request a smart home automation, or generate a tailored insight, the relevant property context plus your question is sent to Anthropic's Claude Haiku model. The model returns a response. Neither the request nor the response is retained by the model provider, and your data is not used to train Anthropic's models.
Technical data. Browser type, device type, and approximate region (from IP). Used to make the app work and to debug issues.
3. What we don't collect
We don't collect your contacts, your photo library beyond files you choose to upload, your browsing history, your location in the background, or your social graph. We don't have advertising trackers. We don't run third-party analytics that fingerprint you.
4. Where your data is stored
Supabase (Frankfurt region, European Union) is our primary data store. All database tables enforce row level security so your data is only accessible to your authenticated session. Documents in Supabase Storage have the same access controls.
Anthropic (Claude Haiku model, accessed via API) processes smart feature requests on a per-request basis. No training data is retained. Anthropic's data handling is described at anthropic.com/legal/privacy.
Railway (EU region) hosts a small service that renders official EPC PDFs on demand. Only public EPC reference numbers are sent to it; no personal account data.
Google (if you sign in with Google) provides authentication only. We receive an account ID and an email address, nothing else.
Vercel hosts this marketing site. The app is hosted as a separate deployment. Vercel sees the standard server logs (IP, user agent, page requested) and nothing personally identifying about you unless you fill in a form.
5. Cookies and analytics
The marketing site at stead.space currently uses no analytics or tracking cookies. The Stead app uses cookies only for authentication (keeping you signed in). If we add analytics in future, we'll use a privacy-friendly tool like Plausible that doesn't fingerprint visitors, and we'll update this page first.
6. How we use your data
To provide the service: storing your property profile, surfacing reminders, generating diagnostics responses, sending you the occasional service email if you've asked for one. That's it. We don't profile, target, score, or rank you. We don't sell data to third parties. We don't use your data for marketing other products.
7. Your rights under UK GDPR
You have the right to:
- Access a copy of all your data. Email us and we'll send you a JSON export within 30 days, usually faster.
- Correct inaccurate data. Most things are editable in the app. If something isn't, tell us.
- Delete your account and all associated data. Available in Settings, or by email. Deletion is permanent within 30 days.
- Export your data in a machine-readable format. Same JSON export as the access request.
- Object to certain types of processing. Email us to discuss.
- Withdraw consent for any processing that relies on consent. Email us.
- Complain to the ICO if you think we've handled your data badly. Their address is at ico.org.uk.
8. Data retention
Account data is retained for as long as your account is active. If you delete your account, all data is permanently removed within 30 days, except for anything we're legally required to keep (which is currently nothing, but the law can change).
Backups are kept for 30 days for disaster recovery. After 30 days, deleted data no longer exists in any form.
9. Security
Data in transit is protected with TLS. Data at rest is encrypted by Supabase. Passwords are hashed with bcrypt. Access to the database in production is limited to one operator (David) and audited.
If we ever have a data breach that affects your personal data, we will tell you within 72 hours of becoming aware of it, in line with UK GDPR. So far we haven't had one and we work hard not to.
10. Children
Stead is not intended for users under 16. We don't knowingly collect data from anyone in that age group. If you believe a child has signed up, email us and we'll delete the account.
11. International transfers
Your data is stored in the EU. Smart feature requests are processed by Anthropic, which may operate servers outside the UK and EU. These transfers are covered by standard contractual clauses where applicable.
12. Changes to this policy
If we change this policy in a material way, we'll email registered users and update the "Last updated" date at the top of the page. Minor wording fixes won't trigger a notification.
13. Contact
For anything privacy related, email [email protected] with "Privacy" in the subject line. We aim to respond within 7 days.
The rules for using Stead.
1. The agreement
By creating an account in the Stead app or using any part of the Stead service, you agree to these terms. If you don't agree, please don't use the service. These terms form a legal agreement between you and the operator of Stead.
2. Beta status
Stead is currently in closed beta. The service is provided "as is", without any warranty of any kind. Features may change, break, or be removed. Data may, in extreme cases, be reset or lost. We make every effort to prevent that, but during beta we can't guarantee it. By using the beta you accept that risk.
When the service exits beta, these terms will be updated and you'll be notified. Continued use after the update means you accept the new terms.
3. Your account
You're responsible for keeping your sign in credentials secure. Don't share them, don't reuse them across services, and tell us immediately if you think someone has accessed your account without permission.
One person, one account. You can't share an account with someone else. If two people want to manage the same property, both should have their own account (multi-user property sharing is on the roadmap).
4. Acceptable use
You agree not to:
- Use Stead for anything illegal under UK law
- Upload content that infringes someone else's rights, including copyrighted documents that aren't yours
- Try to break, scrape, reverse engineer, or otherwise interfere with the service
- Use automated tools to extract data from Stead
- Submit deliberately false or misleading data in a way that could harm other users (currently moot since data is private to your account, but the principle stands)
- Abuse the smart features to generate content unrelated to home admin
- Resell access to Stead, or use it to provide a similar service to others
5. Content you upload
You keep ownership of everything you upload to Stead. We need a limited licence to store it, display it back to you, and process it for the purposes of running the service. We don't claim any other rights to it.
You're responsible for making sure you have the right to upload anything you upload. Don't upload other people's certificates, contracts, or documents without their permission.
6. Smart features and the limits of advice
The smart diagnostics chat, tailored energy insights, smart home automation suggestions, and any similar feature are powered by a large language model. They produce useful starting points, not professional advice. Specifically:
- Not safety advice. If you smell gas, see smoke, or suspect electrical danger, leave the property and call the appropriate UK emergency number. Don't ask Stead.
- Not legal advice. The renter rights and landlord obligations content is well-researched but is not a substitute for a solicitor, Shelter, or Citizens Advice when something serious is happening.
- Not financial advice. Energy insights are educational only. They don't account for your specific tariff, contract, or financial circumstances.
- Not building advice. Diagnostic responses don't replace a qualified gas safe engineer, electrician, plumber, or surveyor.
Use Stead's smart outputs as a starting point. Verify anything important with a qualified professional before acting on it.
7. Pricing and billing
During closed beta, all features are unlocked and free. When public beta opens and Stripe billing goes live, the free tier and the paid Pro tier will both be available. Prices and feature limits will be those listed on the pricing page at the time of subscription.
You can cancel a paid subscription at any time. Cancellations take effect at the end of the current billing period. We don't refund unused time on monthly plans, but we do for annual plans on a pro rata basis.
8. Termination
You can delete your account at any time. We may suspend or terminate accounts that breach the acceptable use rules above, or that we reasonably suspect of fraud or abuse. We'll usually warn you first unless the breach is serious.
If we shut Stead down for any reason, we'll give you at least 30 days' notice and a way to export all your data before the lights go off.
9. Limitation of liability
To the extent allowed by law, Stead is not liable for indirect, incidental, or consequential losses arising from your use of the service. That includes lost data, lost time, missed reminders, or any decision you took based on a smart feature output.
For direct losses, our total liability in any 12 month period is capped at the amount you've paid us in that period, or £100, whichever is greater. Nothing in these terms limits liability that can't lawfully be limited (such as for death or personal injury caused by negligence).
10. Changes to these terms
We may update these terms when the service evolves. Material changes will be communicated by email to registered users at least 14 days before they take effect. Minor changes (typos, clarifications) won't trigger a notification but will be reflected in the "Last updated" date at the top of this page.
11. Governing law
These terms are governed by the law of England and Wales. Any dispute that can't be resolved by emailing each other will be settled in the courts of England and Wales.
12. Contact
For anything terms related, email [email protected] with "Terms" in the subject line.
Questions about any of this?
If anything on this page is unclear, ambiguous, or just feels weird, please tell me. Plain language is the goal.