Privacy Policy

Last updated 19 July 2026

Straticum is a strategic intelligence tool for businesses. To answer a question about your company it has to hold information about your company — so this page sets out exactly what is collected, what is done with it, who else sees it, and how to get it back or have it deleted.

Who this applies to

This policy covers the Straticum web application and its APIs. Two different kinds of people appear in it, and they have different rights here.

  • Users — the people who sign in and use the product. We are the controller of your account information.
  • Company data subjects — people whose information appears inside the content you bring, such as a customer named in a support ticket you have connected. For that content we act as a processor on your behalf: you decide what is loaded and why, and we handle it under this policy and your instructions.

Information we collect

Account and identity

Signing in is handled by Google through Firebase Authentication. We receive and store your email address, your display name and your profile picture URL. You can add a job title, which is used to shape how findings are presented and never to restrict access.

We do not receive or store your Google password. Your session is held in a signed, encrypted cookie.

Your company and its strategic profile

The substance of the product. This is information you enter, import or ask us to generate, and it is held against your company:

  • Company details from onboarding — name, website, industry, size, countries of operation, description and business model.
  • Strategic frameworks and their revision history, including which fields were drafted by AI and which you wrote or corrected.
  • Metrics you record by month, and the health scores derived from them.
  • Objectives, key results, decisions and their supporting rationale.
  • Competitors you add, along with the analysis produced about them.
  • Markets and country assessments, growth opportunities, and canvases.
  • Documents you upload or paste into the knowledge base.

For uploaded documents we store the extracted text only. The original file is deliberately not retained anywhere — not on disk, not in object storage. We also store numeric embeddings of that text so it can be searched by meaning rather than keyword.

Assistant conversations

Questions you ask the assistant, the answers returned, the intermediate steps taken to reach them, the sources cited, and any feedback you leave on an answer. Conversation summaries are kept so a long thread stays coherent.

Connected services

If you connect an integration, we store the access and refresh tokens needed to keep using it. Those tokens are encrypted at rest with a key held outside the database. We also store which account or property you selected, so we do not have to re-list them on every request. The integrations currently available are Google Analytics, RevenueCat and Zendesk.

Support content is a special case. Tickets are the one place in this product where your customers speak in their own words, and they include names, email addresses, phone numbers, order references and sometimes card numbers. That content is redacted before it is stored or sent to a model: identifiers are replaced with placeholders and the substance of the complaint is kept.

Team and organisation

Who belongs to your company workspace, what role they hold, who invited them and when the invitation was accepted. Invitations are stored against the email address they were sent to until they are accepted or revoked.

Activity and usage

A record of changes made in your workspace — who changed what and when — so your colleagues can see how the profile reached its current state. This log is append-only by design and cannot be edited after the fact.

We also record usage events for AI features: which feature ran, token counts and the resulting cost. This is what plan limits and billing are calculated from.

Email preferences and deliverability

Your notification preferences, and a suppression list of addresses that have hard-bounced or marked our mail as spam. Suppression is permanent by design: continuing to send to an address that has rejected us damages deliverability for everybody and is grounds for our mail provider to suspend the account.

Technical data

Standard server logs — IP address, user agent, requested path, timestamp and response status — retained for security, debugging and abuse investigation.

Information we collect about others

Some features read publicly available material about companies that are not our customers. When you add a competitor, we fetch and read their public website to ground the analysis in what they say about themselves today rather than what a model remembers. During onboarding we do the same for your own website to pre-fill your profile.

Only publicly accessible pages are read. We do not attempt to reach anything behind a login, and we do not buy data about companies or individuals from brokers.

How we use information

  • To operate the product — authenticating you, resolving which companies you may see, and rendering your data back to you.
  • To generate analysis: briefings, competitor assessments, growth opportunities, market views and answers from the assistant.
  • To search your knowledge base by meaning, which requires embeddings.
  • To send transactional email — sign-in links, invitations and welcome messages.
  • To enforce plan limits and calculate what is owed.
  • To keep the service secure, investigate abuse, and debug faults.

We do not sell personal information, we do not share it with advertising networks, and we do not run advertising or third-party tracking on the product.

AI processing

Analysis is produced by third-party language models. To answer a question about your business, the relevant parts of your strategic profile, metrics, documents and connected data are sent to the model provider as part of the request.

  • Anthropic — generates briefings, competitor analysis, growth opportunities and assistant answers.
  • OpenAI — produces the embeddings used for knowledge search. Only document text is sent, and no answers are generated.

Both are used through their commercial APIs, under terms that do not permit your content to be used to train their models. Neither is given your account password, your session, or the credentials for any integration you have connected.

Model output is generated text. It can be wrong, and it can state an estimate with more confidence than the underlying evidence supports. It is information to inform a decision, not professional advice — see the Terms of Use.

Who else we share information with

We use a small number of processors to run the service. Each receives only what that job requires.

  • Amazon Web Services — hosting, the database, and email delivery through SES. Our infrastructure runs in AWS data centres.
  • Google (Firebase Authentication) — verifying who you are when you sign in.
  • Anthropic and OpenAI — the AI processing described above.
  • Services you choose to connect yourself, such as Google Analytics, RevenueCat or Zendesk.

Beyond those, we disclose information only where we are legally required to, where it is necessary to establish or defend a legal claim, or to prevent imminent harm. If the business is ever sold or merged, your data may transfer with it; this policy continues to apply until you are told otherwise.

Inside your own workspace, everything is visible to the colleagues you invite, according to their role. That is the point of a shared workspace, and it is worth being deliberate about who you invite.

International transfers

Our providers operate globally, so your information may be processed outside the country you are in — including in the United States and the European Union. Where data leaves South Africa or the European Economic Area, we rely on the transfer mechanisms our providers offer, such as standard contractual clauses.

Retention and deletion

Company data is kept for as long as the company exists in Straticum. Deleting a company removes its profile, metrics, documents, conversations, competitors, decisions, objectives and integration credentials.

Two things deliberately outlive that. Billing records are retained because they are the evidence of what was charged, and suppressed email addresses are retained because forgetting a hard bounce would cause us to send to it again. Neither contains your strategic content.

To delete your user account entirely, or to have data removed sooner, write to hello@straticum.com.

Security

  • All traffic is served over TLS.
  • Integration credentials are encrypted at rest with a key held outside the database.
  • Access is by membership: every read is scoped to a company you belong to, and the check is made in one place rather than per page.
  • Sessions are held in signed, encrypted cookies and verified on every request rather than merely being present.
  • Support content is redacted of personal identifiers before it is stored or sent to a model.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to hello@straticum.com rather than disclosing it publicly, and we will work with you on it.

Cookies

We use cookies that are strictly necessary to run the service: a session cookie that keeps you signed in, and a preference cookie recording which company you are currently viewing. There are no advertising cookies, no analytics cookies and no third-party trackers on the product, so there is nothing here to opt out of.

Your rights

Depending on where you live, you may have the right to access the information we hold about you, correct it, delete it, object to or restrict how it is used, receive a portable copy, and withdraw consent. Exercise any of these by writing to hello@straticum.com. We will respond within the period the applicable law requires.

South Africa (POPIA)

You may object to processing and request correction or deletion of your personal information, and you may complain to the Information Regulator of South Africa.

European Economic Area and United Kingdom (GDPR)

Our lawful bases are: performance of a contract, for operating the service you have signed up to; legitimate interests, for security, abuse prevention and improving the product; and consent, where you connect an optional integration. You may lodge a complaint with your local supervisory authority.

California (CCPA/CPRA)

We do not sell or share personal information as those terms are defined, and we have not done so in the preceding twelve months. You have the right to know what is collected, to delete it, to correct it, and not to be discriminated against for exercising those rights.

Children

Straticum is a business tool and is not directed at children. We do not knowingly collect information from anyone under 18. If you believe a child has provided us with information, contact hello@straticum.com and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top, and for material changes we will tell you in the product or by email before they take effect. The current version is always at https://straticum.com/privacy.

Straticum is owned and operated by Simfolio (Pty) Ltd. Questions about this document, or any request concerning your data, can be sent to hello@straticum.com.