Privacy & Terms

The boring bits, written plainly.

What data Stead collects, where it's stored, what we do with it, and the rules for using the closed beta. No legal pretzel sentences. If anything is unclear, email me.

In short

The summary, before the detail.

Stead stores your account and home data on Supabase servers in the European Union. Your property profile, documents, and chat history are visible only to you, with database-level access controls. Smart features (diagnostics, energy insights, smart home automations, the support chat) send the relevant context to Anthropic's Claude Haiku model to generate a response, then drop the request. We don't train models on your data, sell it, or hand it to advertisers. You can export or delete everything on request. Optional connections you can switch on — a bank import, an HMRC tax link, smart home devices, or a voice assistant — only move data once you set them up, and you can disconnect any of them at any time.

The closed beta is provided as is, with no warranty. Things may occasionally break or be wiped. We try hard for that not to happen. If something does go wrong, we'll tell you and fix it.

Last updated: 27 July 2026.

Privacy policy

What we collect and why.

1. Who we are

"Stead" is a sole-trader operation run by David, based in Bristol, United Kingdom. For UK GDPR purposes, the data controller is the operator of stead.space, contactable at uryyb@fgrnq.fcnpr.

2. What data we collect

Account data. Your email address, a hashed password (or, if you sign in with Google, Apple, or Microsoft, the account identifier and email that provider returns), and a display name if you set one. Sign in timestamps and the IP address of the most recent session for security purposes. If you turn on two-factor authentication, a secret used to verify your authenticator codes plus a set of single-use recovery codes.

Profile and business details. An optional profile photo you upload, and (if you use landlord mode) optional company details you enter to put on your reports and notices: company or trading name, contact name, address, email, phone, company number, and VAT number, plus an optional company logo. The photo and logo are held in Supabase Storage with the same per-account access controls as your documents.

Property data. The information you give us about your home: postcode, address, property type, size, EPC certificate data pulled from the gov.uk register at your request, room layouts, appliances, tenancy details you enter, and any notes you choose to add.

Documents. Files you upload (certificates, warranties, manuals, photos, and any invoice or certificate you attach to a logged service). Stored in Supabase Storage with access restricted to your account via row level security.

Activity data. Maintenance task history and the service-history records you log against a task (date, what was done, the tradesperson contact and cost, and any document you attach), document expiry dates, energy bill entries, the per-property income and expense ledger you keep for rental finances, smart home automation history, diagnostic chat conversations, and any other actions you take in the app. Used to provide the service and to surface relevant reminders to you.

Product usage counts. So we can tell whether Stead is genuinely useful rather than guessing, we keep a small count of two things you do: that you opened the app on a given day, and that you marked a maintenance task complete, together with the date that task was due. Each record holds only your account, which of those two happened, a reference to the item, and the time. No titles, no notes, no document or property content, and nothing that identifies your device or browser. These counts are ours alone: they are never shared, sold, or used for advertising, and no third-party analytics or tracking tool is involved.

Smart feature inputs. When you ask the diagnostics chat a question (optionally attaching a photo of the problem), request a smart home automation, or generate a tailored insight, the relevant property context plus your question, and any photo you attach, is sent to Anthropic's Claude Haiku model. The model returns a response. Neither the request, the attached photo, nor the response is retained by the model provider, and your data is not used to train Anthropic's models. Photos you attach to the diagnostics chat are not stored by us either. Tools such as the possession-notice generator and the calculators run on your device or fill a template from data you have already entered.

Support chat. When you ask a question in the support chat ("Ask Stead"), in the app or on this website, your message is sent, along with Stead's own help material, to Anthropic's Claude Haiku model to write the answer, in the same way as the smart features above. On this website we also send the address and title of the page you have open, so that a question like "does this apply to me?" can be read in context; nothing else from the page is sent, and the app sends no page context at all. Neither the question nor the answer is retained by the model provider. The conversation itself is held only while it is open: we don't store it, and it is gone when you close the chat. We do keep a simple count of the messages you send, so we can keep the service fair for everyone; that count holds no message content. In the app that count is tied to your account. On the website, where you are not signed in, it is tied to a scrambled (hashed) version of your internet address; we never store the address itself, and the hash cannot be turned back into it. The website chat is also protected against automated abuse by Cloudflare Turnstile, which runs its check only when you open the chat (see Cookies, below). If you choose to pass a conversation to a person, the transcript is sent to our support team and stored with your support report, handled like any other support message or feedback you send us; on the website that report also notes which page you were reading, and we ask for an email address so we can reply. The support chat answers questions about Stead; it is not a source of legal, tax, or tenancy advice.

Passkeys. If you set up a passkey to sign in, we store the public part of it (a public key, a credential identifier, and a signature counter) so we can verify you on your next sign-in. The passkey's private key, and the fingerprint, face, or device PIN that unlocks it, never leave your device and are never sent to us — we only ever receive the public key and a signature. This is separate from the on-device app lock, which stays on your device entirely.

Smart home connections. If you connect a smart home, we store what is needed to reach it on your behalf. For a Home Assistant hub, that is the address and access token you provide, held in your property record. For a cloud account you link (Philips Hue, LIFX, SwitchBot, or Shelly), that is the access token or personal key that account gives us so we can list and control your own devices. If you link a voice assistant (Amazon Alexa, Google Home, or Samsung SmartThings) to your Stead account, we act as the sign-in provider: the assistant receives the names, types, and on/off or brightness state of the devices you have connected, and sends back the commands you give it, so it can control them. For voice assistants we store only a hashed reference to the access tokens involved, never the raw token. You can unlink any of these at any time from the smart home screen, or by removing the skill or link inside the assistant's own app.

Bank connections (landlords). If you use landlord mode and connect a bank to auto-fill your rental P&L, we use an FCA-authorised open-banking provider (TrueLayer) to do it. You authorise the connection with your bank, not with us; we never see your bank login. We store the access tokens the provider returns so we can fetch your account list and recent transactions, plus a list of the transaction IDs you have already turned into P&L entries so the same transaction is not suggested twice. The transactions themselves are shown to you to review and categorise; only the entries you choose to keep are saved, as part of your finances ledger. Disconnecting a bank deletes the stored tokens.

HMRC tax connection (landlords). If you connect Stead to HMRC's Making Tax Digital service, we store the access tokens HMRC returns and the National Insurance number you enter, so we can read your filing obligations and submit the income and expense figures you approve. HMRC also requires us to send technical "fraud prevention" details with each request (for example your device's screen size, time zone, and public IP address); this is defined by HMRC, not us. HMRC is an independent controller of anything you file with them. Disconnecting from HMRC deletes the stored tokens and National Insurance number.

Household and sharing. If you invite someone to help manage a property, or to control a chosen set of your smart home devices, we store the invitation and, once they accept, the link between their account and what you shared. A household co-manager can see and edit that property's contents as if it were their own; a device-only sharee can control just the devices you picked and never receives your hub address or tokens. Everyone still needs their own Stead account, and you can revoke a share at any time.

Notification data. Your notification preferences (which reminders you want, by which channel). If you turn on push notifications on the web, the push subscription your browser provides (a delivery endpoint and the keys needed to encrypt a message to it). On the phone app, a push token from your device instead, which we send through Expo's push service and on to Apple's (APNs) or Google's (FCM) push networks to deliver the reminders you asked for. You can turn push off any time in Account → Notifications or in your browser/device settings.

Technical data. Browser type, device type, and approximate region (from IP). Used to make the app work and to debug issues.

Diagnostics data. If the app hits an error, an anonymised crash report (the error message, a stack trace, the app version, and device/OS type) is sent to our error-monitoring provider, Sentry, so we can fix it. These reports aren't linked to your account and don't include the contents of your home data.

3. What we don't collect

We don't collect your contacts, your photo library beyond files you choose to upload, your browsing history, your location in the background, or your social graph. We don't have advertising trackers. We don't run third-party analytics that fingerprint you.

4. Where your data is stored

Supabase (Frankfurt region, European Union) is our primary data store. All database tables enforce row level security so your data is only accessible to your authenticated session. Documents in Supabase Storage have the same access controls.

Anthropic (Claude Haiku model, accessed via API) processes smart feature requests on a per-request basis. No training data is retained. Anthropic's data handling is described at anthropic.com/legal/privacy.

Railway (EU region) hosts a small service that renders official EPC PDFs on demand. Only public EPC reference numbers are sent to it; no personal account data.

Google, Apple, and Microsoft (if you sign in with one of them) provide authentication only. We receive an account identifier and an email address, nothing else.

Sentry (European Union region) receives the anonymised crash and error reports described above so we can diagnose problems. No account data or home content is sent to it.

Cloudflare hosts this marketing site and the Stead app. The host sees standard server logs (IP, user agent, page requested) and nothing personally identifying about you unless you fill in a form.

TrueLayer (an FCA-authorised open-banking provider) connects to your bank when you link one for the rental P&L. You authenticate with your bank directly; TrueLayer passes the account and transaction data back to us to show you. It acts as our provider for that connection, and only when you set it up.

HMRC (HM Revenue & Customs) receives the tax figures you submit through the Making Tax Digital connection, along with the National Insurance number and the fraud-prevention details HMRC's API requires. HMRC is an independent controller of what you file with it. This applies only if you connect to HMRC.

Amazon, Google, and Samsung receive data only if you link a voice assistant (Alexa, Google Home, or SmartThings). They get the names, types, and state of the smart home devices you have connected, and send back your commands, so they can control those devices. Each is an independent controller of what it holds in your assistant account.

Philips Hue (Signify), LIFX, SwitchBot, and Shelly receive the control requests we send on your behalf, using the token or key you provided, only if you link one of these smart home clouds. These are your own accounts with those providers.

Expo, Apple, and Google carry push notifications to the phone app: Expo's push service passes each message to Apple's (APNs) or Google's (FCM) network for delivery to your device. They see the delivery token and the notification, not your account.

5. Cookies and analytics

The marketing site at stead.space uses no analytics or advertising cookies. One functional exception exists: if you open the "Ask Stead" support chat on the site, Cloudflare Turnstile runs an anti-abuse check, which may set a Cloudflare cookie and involves Cloudflare receiving your internet address for that check. It loads only when you open the chat, never on ordinary browsing. The Stead app uses cookies only for authentication (keeping you signed in). We don't use any third-party analytics or tracking tool. We do keep the small first-party counts described under Product usage counts in section 2, which stay in our own database and involve no cookie and no fingerprinting. If we ever add a third-party analytics tool, we'll use a privacy-friendly one like Plausible that doesn't fingerprint visitors, and we'll update this page first.

6. The newsletter

What we collect. If you sign up for the Stead newsletter at stead.space/subscribe, we store the email address you give us, your name if you choose to add one, the boxes you ticked about which mode fits you and which topics you want to hear about, the fact that you ticked the consent box, and the date, IP address, and browser string of the submission. The last two are kept as evidence of when and from where consent was given, nothing else.

Lawful basis: consent. The newsletter goes out on the basis of your consent, given by ticking the consent box on the signup form. That box starts empty, nothing is pre-ticked, and we never add an address that did not ask. The newsletter is separate from your Stead account: holding an account does not put you on the list, and joining the list does not create an account.

What you actually get. One welcome email when you sign up, then roughly one newsletter a month. That is the entire programme. No drip sequence, no daily tips, no "carefully selected partners". We never share, sell, or rent the list.

How to withdraw consent. Every newsletter carries a one-click unsubscribe link in its footer, plus the standard unsubscribe headers that let your email app show its own Unsubscribe button. Either route takes effect immediately, with no confirmation email and no follow-up asking you to reconsider. Leaving is meant to be as easy as joining was. You can also reply to any Stead email, or write to the address in section 14, and we will remove you by hand. Unsubscribing from the newsletter does not touch your Stead account or the reminders you have set up in the app; those are separate and controlled in Account → Notifications.

Who processes it. Newsletter emails are delivered by Resend, our email provider, acting on our instructions. Resend receives your email address, your name if you gave one, and the content of the message, purely to deliver it. The subscriber list itself lives in our own Supabase database in the EU (section 4), not in a third-party marketing platform, and no advertising or tracking pixels are attached to what we send.

Retention. We keep your subscription record for as long as you are subscribed. If you unsubscribe, we keep the address together with the record of your consent and your opt-out rather than deleting it outright, because that is what lets us guarantee you are never emailed again and show that we honoured the request. Ask us and we will erase it completely instead. Newsletter records are held separately from Stead account data, and are removed along with everything else if you ask us to erase your data.

7. How we use your data

To provide the service: storing your property profile, surfacing reminders, generating diagnostics responses, sending you the occasional service email if you've asked for one. And to see whether Stead is actually working: the small usage counts described in section 2 tell us whether reminders get acted on and whether people come back, which is how we decide what to build next. That's it. We don't profile, target, score, or rank you. We don't sell data to third parties. We don't use your data for marketing other products.

8. Your rights under UK GDPR

You have the right to:

  • Access a copy of all your data. You can download it yourself any time from Account → Security → Download my data, which produces a PDF copy and files one in your Documents. You can also email us and we'll send a copy within 30 days, usually faster.
  • Correct inaccurate data. Most things are editable in the app. If something isn't, tell us.
  • Delete your account and all associated data. Use Account → Danger zone → Delete account, which asks you to type DELETE to confirm, or email us. Deletion is permanent within 30 days. Note that the Reset all data option sitting beside it is not an erasure route: it clears the property, room, task, document and contact records you have added but keeps your sign-in and your account, so choose Delete account if you want everything gone.
  • Export your data. The in-app download gives you a PDF of your records; if you need it in a specific machine-readable format (e.g. JSON), ask us and we'll provide it.
  • Object to certain types of processing. Email us to discuss.
  • Withdraw consent for any processing that relies on consent. Email us.
  • Complain to the ICO if you think we've handled your data badly. Their address is at ico.org.uk.

Our ICO registration. Stead is registered with the Information Commissioner's Office as a data controller under registration number ZC150865. You can check the entry yourself on the ICO's public register at ico.org.uk/register. Quote that number if you contact them about us.

9. Data retention

Account data is retained for as long as your account is active. If you delete your account, all data is permanently removed within 30 days, except for anything we're legally required to keep (which is currently nothing, but the law can change).

Backups are kept for 30 days for disaster recovery. After 30 days, deleted data no longer exists in any form.

Unlinking a voice assistant. If you unlink Stead in the Google Home or Samsung SmartThings app, that provider tells us the moment you do, and we revoke every token reference we hold for the link straight away, so it can no longer be used to see or control your devices. Amazon does not send us an unlink signal, so if you disable the Stead skill in the Alexa app the link stops working at Amazon's end, but the references we hold stay on file until you delete your account or ask us to clear them. Those references are hashes rather than the tokens themselves, and they are removed with the rest of your account data if you delete your account. Anything the provider still holds inside your own assistant account stays under their control, so remove the Stead skill or link in their app as well if you want it cleared there too.

10. Security

Data in transit is protected with TLS. Data at rest is encrypted by Supabase. Passwords are hashed with bcrypt. Access to the database in production is limited to one operator (David) and audited.

If we ever have a data breach that affects your personal data, we will tell you within 72 hours of becoming aware of it, in line with UK GDPR. So far we haven't had one and we work hard not to.

11. Age

Stead is intended for adults (18 or over) managing a home or property, and the Terms of Use require you to be 18 to hold an account. We don't knowingly collect data from anyone under 18. If you believe someone under 18 has signed up, email us and we'll delete the account.

12. International transfers

Your data is stored in the EU. Smart feature requests are processed by Anthropic, which may operate servers outside the UK and EU. Some optional connections you choose to turn on — a voice assistant, a smart home cloud, bank import, or phone push delivery — may also involve providers that operate outside the UK and EU. These transfers are covered by standard contractual clauses or the provider's own safeguards where applicable.

13. Changes to this policy

If we change this policy in a material way, we'll email registered users and update the "Last updated" date at the top of the page. Minor wording fixes won't trigger a notification.

14. Contact

For anything privacy related, email uryyb@fgrnq.fcnpr with "Privacy" in the subject line. We aim to respond within 7 days.

Terms of use

The rules for using Stead.

1. The agreement

By creating an account in the Stead app or using any part of the Stead service, you agree to these terms. If you don't agree, please don't use the service. These terms form a legal agreement between you and the operator of Stead.

2. Beta status

Stead is currently in closed beta. The service is provided "as is", without any warranty of any kind. Features may change, break, or be removed. Data may, in extreme cases, be reset or lost. We make every effort to prevent that, but during beta we can't guarantee it. By using the beta you accept that risk.

When the service exits beta, these terms will be updated and you'll be notified. Continued use after the update means you accept the new terms.

3. Your account

You must be 18 or over to create an account and use Stead. This is a condition of using our service and is separate from housing law. In some cases a person under 18 can hold a tenancy (usually through a guarantor or an adult trustee). Stead is simply built for adults managing a home or property.

You're responsible for keeping your sign in credentials secure. Don't share them, don't reuse them across services, and tell us immediately if you think someone has accessed your account without permission. We strongly recommend turning on two-factor authentication in Account → Security.

One person, one account. You can't share a single login with someone else. If two people want to manage the same property, each needs their own account — you can then invite them to co-manage a property, or to control a chosen set of smart home devices, from within the app. You're responsible for who you invite and for revoking a share when it's no longer needed.

4. Acceptable use

You agree not to:

  • Use Stead for anything illegal under UK law
  • Upload content that infringes someone else's rights, including copyrighted documents that aren't yours
  • Try to break, scrape, reverse engineer, or otherwise interfere with the service
  • Use automated tools to extract data from Stead
  • Submit deliberately false or misleading data in a way that could harm other users (currently moot since data is private to your account, but the principle stands)
  • Abuse the smart features to generate content unrelated to home admin
  • Resell access to Stead, or use it to provide a similar service to others

5. Content you upload

You keep ownership of everything you upload to Stead. We need a limited licence to store it, display it back to you, and process it for the purposes of running the service. We don't claim any other rights to it.

You're responsible for making sure you have the right to upload anything you upload. Don't upload other people's certificates, contracts, or documents without their permission.

6. Smart features and the limits of advice

The smart diagnostics chat, tailored energy insights, smart home automation suggestions, possession-notice generator, support chat, and any similar feature are powered by a large language model and/or template engines. They produce useful starting points, not professional advice. Specifically:

  • Not safety advice. If you smell gas, see smoke, or suspect electrical danger, leave the property and call the appropriate UK emergency number. Don't ask Stead.
  • Not legal advice. The renter rights, landlord obligations, and possession-notice content is well-researched but is not a substitute for a solicitor, Shelter, or Citizens Advice when something serious is happening. Any generated possession notice is a draft for solicitor review, not a legally served notice.
  • Not financial advice. Energy insights and the rental P&L are educational only. They don't account for your specific tariff, contract, or financial circumstances, and the P&L is not a substitute for an accountant. If you connect a bank or HMRC's Making Tax Digital service, Stead prepares figures for you to check — you remain responsible for the accuracy and completeness of anything you submit to HMRC.
  • Not building advice. Diagnostic responses don't replace a qualified Gas Safe engineer, electrician, plumber, or surveyor.

Use Stead's smart outputs as a starting point. Verify anything important with a qualified professional before acting on it.

7. Third-party services

Stead depends on third-party providers (listed above): Supabase for storage, Anthropic for the smart features, Resend for email, Cloudflare for hosting, and — only if you turn them on — TrueLayer for bank import, HMRC for tax filing, and your chosen smart home or voice-assistant platforms. We're responsible for choosing them and configuring them sensibly. We're not responsible for outages, data handling, or changes on their side that are outside our control, including on a service you connect with your own credentials. When we change provider in a way that affects you, we'll tell you.

8. Pricing and billing

During closed beta, all features are unlocked and free. When public beta opens and paid subscriptions go live, the free tier and the paid Pro tier will both be available. Prices and feature limits will be those listed on the pricing page at the time of subscription.

You can cancel a paid subscription at any time. Cancellations take effect at the end of the current billing period. We don't refund unused time on monthly plans, but we do for annual plans on a pro rata basis where the law allows.

Mobile subscriptions purchased through the Apple App Store or Google Play are governed by the relevant store's terms in addition to these — refunds and cancellation for those subscriptions are handled by Apple or Google, not by us.

9. Termination

You can delete your account at any time from Account → Danger zone → Delete account. Deletion is permanent within 30 days.

We may suspend or terminate accounts that breach the acceptable use rules above, or that we reasonably suspect of fraud or abuse. We'll usually warn you first unless the breach is serious.

If we shut Stead down for any reason, we'll give you at least 30 days' notice and a way to export all your data before the lights go off.

10. Limitation of liability

To the extent allowed by law, Stead is not liable for indirect, incidental, or consequential losses arising from your use of the service. That includes lost data, lost time, missed reminders, or any decision you took based on a smart feature output.

For direct losses, our total liability in any 12 month period is capped at the amount you've paid us in that period, or £100, whichever is greater. Nothing in these terms limits liability that can't lawfully be limited (such as for death or personal injury caused by negligence, or for fraud).

11. Indemnity

You agree to indemnify and hold harmless the operator of Stead from any third-party claim arising from your breach of these terms or from content you upload to the service — for example, a claim from someone whose document you uploaded without permission.

12. Changes to these terms

We may update these terms when the service evolves. Material changes will be communicated by email to registered users at least 14 days before they take effect. Minor changes (typos, clarifications) won't trigger a notification but will be reflected in the "Last updated" date at the top of this page.

13. Governing law

These terms are governed by the law of England and Wales. Any dispute that can't be resolved by emailing each other will be settled in the courts of England and Wales.

14. Contact

For anything terms related, email uryyb@fgrnq.fcnpr with "Terms" in the subject line.

Questions about any of this?

If anything on this page is unclear, ambiguous, or just feels weird, please tell me. Plain language is the goal.

Email me Suggest a change