1.Who we are
StewardAI: Leadership Coach is published on the App Store by Social Sips Inc. and operated by Debouillet Inc. This policy explains what the app collects, why, and the control you have over it. It applies to the iOS app and any companion web experience.
2.Information we collect
We collect only what the app needs to work:
- Account information (name, email address, organization)
- Conversation practice transcripts and coaching scores
- ANCHOR framework assessment data
- Meeting notes, recordings and generated summaries you choose to add
- Performance review drafts and feedback you write in the app
- Device identifiers and basic analytics events
We do not sell your personal information, and we do not use it for third-party advertising or cross-app tracking.
3.How we use your information
StewardAI uses your data to deliver AI-powered leadership coaching, score your conversation practice sessions using the ANCHOR framework, generate meeting insights, and build personalized development plans.
Concretely, we process personal data to:
- Create and authenticate your account and keep it secure
- Deliver the features you ask for and save your work across devices
- Provide customer support and respond to your requests
- Process purchases, manage entitlements and prevent payment fraud
- Diagnose crashes, monitor abuse and keep the service reliable
- Send service messages such as receipts, security alerts and policy changes
- Comply with legal, tax and accounting obligations
We never use your content for behavioural advertising, we do not build advertising profiles, and we do not track you across other companies' apps or websites.
4.What we deliberately do not collect
StewardAI is built to collect the minimum needed to function. We do not collect:
- Payment card numbers (handled by Apple)
- Location data
- Health, biometric or precise device data
- The advertising identifier (IDFA)
5.Legal bases for processing (EEA and UK)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — operating your account and delivering the features you request
- Legitimate interests — securing the service, preventing abuse and improving reliability, balanced against your rights
- Consent — optional permissions such as notifications, camera, location and Apple Health, which you can withdraw at any time in iOS Settings
- Legal obligation — retaining tax, accounting and fraud records
Where Debouillet Inc. processes data on behalf of an organization that gave you access to the app, that organization is the controller and we act as its processor under a data processing agreement.
6.Workplace and organization accounts
If you join StewardAI through an employer or team workspace, your organization's administrator can see workspace membership, assigned development plans and aggregate program usage. Administrators cannot read your private practice transcripts unless you explicitly share a session. Where your employer is the data controller, its own privacy notice also applies and we act as a processor under a data processing agreement.
7.Recordings and third-party participants
If you add meeting notes or recordings, you are responsible for obtaining any consent required by the recording laws that apply to you and every participant. Do not upload recordings you are not permitted to share.
8.AI data processing
StewardAI uses large language models (including Anthropic's Claude) to generate its AI features. When you use those features, the content you submit — your prompts, text, and any files or images you attach — is transmitted to our AI provider for processing and returned as a result.
Your content is not used to train third-party foundation models. AI providers process it on our behalf under a data processing agreement and retain it only transiently for abuse monitoring. AI output can be inaccurate; see our Terms for the limits on relying on it.
We do not use AI to make decisions that produce legal or similarly significant effects about you without human involvement. You can stop AI processing at any time by not using the AI features, or by deleting your account.
9.Payments and purchases
In-app purchases and subscriptions are processed by Apple. We receive a purchase receipt and entitlement status; we never receive your payment card details.
10.Service providers
We rely on a small set of vendors, each bound by a data processing agreement:
- Apple — App Store distribution, in-app purchases and push notifications
- Managed cloud platform — authentication, database and file storage
- Anthropic — AI model inference
- Resend — transactional email
11.Push notifications and messages we send
If you enable notifications, Apple issues a push token we use only to deliver the alerts and reminders you configured; you can disable them in iOS Settings at any time. We also send transactional email — receipts, password resets, security notices and material policy changes. These are not marketing, and you cannot opt out of them while your account is active. Any product or marketing email is opt-in and has a one-click unsubscribe link.
12.Analytics and tracking
We collect privacy-preserving product analytics — screen views, feature usage and crash reports — tied to a random installation identifier rather than to advertising IDs. We do not use the IDFA, we do not present an App Tracking Transparency prompt because we do not track you across other companies' apps or sites, and we do not sell or share data for cross-context behavioural advertising. Our companion web pages use no advertising cookies; we honour Global Privacy Control and Do Not Track signals where they are sent.
13.Data retention
We keep your account data for as long as your account is active. When you delete your account, personal data is removed within 30 days. Specific schedules:
- Account and profile records — deleted within 30 days of account deletion
- Content you created — deleted within 30 days of account deletion, or immediately when you delete the item
- AI prompts and outputs — retained with the item they belong to; provider-side abuse-monitoring copies expire within 30 days
- Support correspondence — up to 24 months so we can follow up on recurring issues
- Crash logs and security telemetry — up to 12 months
- Invoice, receipt and tax records — up to 7 years, as required by law
- Anonymised, aggregated statistics that can no longer identify you — retained indefinitely
14.Your rights
Wherever you live, you can request access to your data, correction of it, export of it in a portable format, or its deletion. Residents of the EEA and UK have these rights under the GDPR; California residents have equivalent rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined by California law.
Email privacy@debouillet.com or use the account deletion page to exercise any of them. We respond within 30 days.
15.US state privacy rights
Residents of California, Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws may request to know, access, correct, delete or port their personal data, and may opt out of targeted advertising, sale, or profiling with legal effects. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not profile users in ways that produce legal effects — so there is nothing to opt out of, but you may still exercise every other right.
You may use an authorized agent, and we will never discriminate against you for exercising a right. If we deny a request, you can appeal by replying to our decision email within 30 days; we respond to appeals within 45 days and will tell you how to contact your state attorney general if you disagree.
16.Complaints and supervisory authorities
If you are in the EEA or UK and believe we have mishandled your data, please contact privacy@debouillet.com first — we take complaints seriously. You also have the right to lodge a complaint with your local data protection authority or, in the UK, with the Information Commissioner's Office.
17.Breach notification
If a personal data breach occurs that is likely to affect you, we will notify affected users without undue delay, and notify supervisory authorities within 72 hours where the GDPR requires it, and within the deadlines set by applicable US state breach laws. Our notice will describe what happened, what data was involved and what you should do.
18.Links and third-party destinations
StewardAI may link to sites and services we do not control, including the App Store, our providers' pages and your organization's own tools. This policy does not cover them; review their privacy notices before sharing data with them.
19.Children's privacy
StewardAI is not directed to children under 16, we do not knowingly collect personal information from them, and we do not serve ads or use child data for any secondary purpose. If you believe a child has provided us information, contact privacy@debouillet.com and we will delete it within 7 days and confirm in writing. Where a guardian has enrolled a minor, the guardian may access, correct or delete the minor's records at any time.
20.Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to production data is limited to the small number of staff who need it, and row-level security isolates each account's records. No system is perfectly secure, but we will notify affected users and regulators of any breach as required by law.
21.International transfers
We operate from the United States, and our providers may process data in the United States and other countries. Where required, transfers rely on the European Commission's Standard Contractual Clauses.
22.Changes to this policy
We will post any change here and update the effective date. Material changes will also be announced in the app before they take effect.
23.Contact
Privacy questions and data requests: privacy@debouillet.com. Postal mail can be addressed to Social Sips Inc., c/o Debouillet Inc.

