Privacy Policy
Last updated: 2026-09-10
Effective date: September 10, 2026
This Privacy Policy explains how Steele Labs LLC ("Steele", "we", "us", "our") collects, uses, discloses, and protects information when you use our website and messaging/voice services (the "Service").
0. Who the account holder is, and who the data is about
Steele is sold to parents. A parent or legal guardian holds the paying account, and the person the schoolwork information is about is their child. Those are two different roles, and this policy uses them throughout: the parent is the customer, the child is the subject.
An account holder must be at least 18. A child does not hold a Steele account of their own: a child does not sign up, does not sign in, and is not contacted by the Service. A parent adds a child to the parent's own account by name, and what Steele records about that child sits on the parent's account, where the parent can review it, correct it, or ask us to delete it. Section 10 says more about how we treat a child's information.
One thing worth being exact about, because it is easy to assume otherwise: Steele cannot reach a child's Google account on its own. We never ask for and never receive a student's password, and the Classroom permissions we use only ever return the signed-in person's own coursework. School data reaches a parent's account only after that access has been granted from the student's own Google account, at Google's own consent screen, and it stops when the access is disconnected or the child is removed from the account.
1. Contact
If you have questions about this Privacy Policy, contact us at support@steelelabs.co.
2. What we collect
We collect information you provide directly, information generated by your use of the Service, and information from integrated services you connect.
2.1 Information you provide
- Contact details: such as your phone number and/or email address.
- Profile details: the name you share with Steele and, where you provide them, your age, grade, and school. Age is used to apply the protections required for minors.
- Payment information: payments are processed by Stripe. We receive your subscription status and billing metadata; we never receive or store your full card number.
- Message content: the text you send us, and any replies we send back.
- Voice content: audio you send or stream to us, and transcriptions derived from that audio.
- Support requests: information you include when you contact support.
- Messaging consent records: if you continue with your phone after the messaging notice, we record that you did, when, which wording you were shown, the page you were on, and the IP address and browser that submitted it. That record is the proof that we had your permission, so we keep it even if you later opt out.
Please do not submit sensitive personal information the Service does not ask for, such as Social Security numbers, government ID numbers, financial account credentials, or medical records.
2.2 Information collected automatically
- Usage data: pages viewed, features used, timestamps, and interaction patterns.
- Device and network data: IP address, browser type, device identifiers, and operating system.
- Log data: diagnostics and error logs to keep the Service reliable and secure.
2.3 Information from integrations (Google)
If you connect a Google account, we receive access tokens and basic account information (such as your email address) as authorized by you, and we request only the access needed for the features you use:
- Classroom(read-only: classroom.courses.readonly, classroom.coursework.me.readonly, classroom.student-submissions.me.readonly): see your classes and your own coursework, due dates, submission state, and grades, to track deadlines and build study help. Steele cannot see another student's work, and cannot submit or change yours.
- Calendar (calendar.events.readonly): read your events to show your schedule. This school connection cannot create, edit, or delete calendar events.
These are the school connection scopes. Steele does not request Gmail, Drive, or Google Docs access. If you connected Google before September 10, 2026 your account may still hold a wider grant, including Gmail; you can remove it by disconnecting Google in your dashboard or at myaccount.google.com/permissions.
The full list, scope by scope, with the reason Steele asks for each one, is at Steele and your Google account.
Limited Use.Steele's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the user-facing features described above; we do not sell or transfer it; we do not use it for advertising; and humans do not read it except with your consent, for security or to debug an issue you report, to comply with law, or in aggregated or anonymized form.
Optional parent calendar sync (calendar.app.created). When a parent chooses Google sync in Calendar settings, Steele creates a separate Steele Family calendar in the parent’s Google account and creates, updates, or removes its mirrored school events. This scope is limited to calendars Steele creates and does not allow editing the child’s school calendar.
A private calendar subscription link is also available. Anyone with that link can read the selected school schedule. Replacing or revoking the link stops future access through the old URL, but calendar apps may retain previously downloaded events. Disconnecting Google sync removes events tracked by Steele and stops future updates; the calendar itself and events you added remain.
Calendar links you paste. You can paste a school, team or class calendar address (an iCal or .ics link) for a child. Steele fetches that address on a schedule and reads the events on it, which become part of that child’s school calendar in Steele. The address is stored encrypted and is not shown again in full or shared; you can remove it at any time, which stops the reads. Only https addresses are accepted. This is a request to whoever publishes that calendar, so their own terms and logs apply.
What that commitment means scope by scope, and the four things Steele will not do with Google data under any circumstances, is written out at Limited Use.
2.4 Information from integrations (Apple Health)
Apple Health is optional and off until you turn it on. It is granted on the iPhone, by iOS, in the Steele app: no website can request it, so the Health row on your dashboard opens the app rather than asking you here. If you allow it, the app reads a daily summary on your device and sends those summary numbers to us. It reads categories you allow, which may include:
- Activity: steps, walking, running and cycling distance, flights climbed, active and resting energy, exercise and stand minutes, and time in daylight.
- Heart and respiratory: heart rate, resting and walking heart rate, heart rate variability, VO2 max, blood oxygen, and respiratory rate.
- Sleep and mindfulness: hours asleep and mindful minutes.
- Body and vitals: weight, height, BMI, body fat, lean mass, waist, body temperature, blood pressure, and blood glucose.
- Nutrition: calories, water, protein, carbohydrates, fat, sugar, fiber, and caffeine.
- Mobility and audio: walking speed, step length, gait asymmetry, six-minute walk distance, and headphone and environmental audio exposure.
- Workouts and basics: recent workouts, and characteristics such as age, biological sex, blood type, wheelchair use, and skin type.
What we do not read. We do not read clinical health records, we never write anything back to Apple Health, and we do not read it in the background: the app sends a summary only while you have it open. We do not use it for advertising, we do not sell it, and we do not use it to develop or train Steele as a product.
Where it goes. We use it to answer you when you ask, and to make your daily brief and check-ins fit the day you are actually having. To do that, the summary is sent to the AI provider that generates that response, under the same terms as the rest of your message content: those calls are routed through OpenRouter, and OpenAI, Groq, and Anthropic are used directly when OpenRouter is unavailable, as described in Section 5. Apple Health cannot tell us that you declined a category rather than having no data in it, so Steele treats every number as approximate and does not give medical advice or diagnoses.
Turning it off. Disconnect Apple Health from the Health section of your dashboard settings, or from the Health screen in the app. Either one deletes the stored summary. To withdraw the iOS permission itself, open the Settings app on your iPhone and go to Privacy and Security, then Health. Deleting your account deletes the summary with it.
3. How we use information
- To provide, operate, and maintain the Service.
- To respond to your requests and messages.
- To authenticate you (including sending one-time passcodes, where applicable).
- To personalize your experience and keep context (preferences, history, and settings).
- To operate, debug, and monitor Steele's own systems (reliability, security, and performance). This does not include using information received from Google APIs to develop, improve, or train Steele as a product. Google user data is used only to provide the user-facing features listed in the Google integrations section.
- To prevent fraud, abuse, and security incidents.
- To comply with legal obligations and enforce our terms.
4. SMS/MMS & voice communications
If you opt in to receive SMS/MMS messages, we may use your phone number and message content to communicate with you, including sending verification messages, service notifications, and replies to your messages. Message frequency varies. Message and data rates may apply.
You can opt out of SMS/MMS at any time by replying STOP. For help, reply HELP or contact us at support@steelelabs.co.
5. How we share information
We do not sell your personal information. We may share information in the following circumstances:
- Service providers: with vendors who help us run the Service (hosting, databases, analytics, communications, security). They are permitted to process data only for our instructions.
- Messaging and telecom providers: to deliver SMS/MMS or voice services (for example, Twilio and carriers), which may process message metadata and content as needed to deliver communications.
- Integrations you enable: when you connect third-party services, data may be exchanged with those services per your authorization.
- Legal and safety: if required by law, subpoena, court order, or to protect rights, safety, and security of users and the Service.
- Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction.
When you connect Google, information received from Google APIs is processed on our behalf by:
- Fly.io: application hosting.
- Supabase: database.
- LLM providers: the model that generates a response for that individual request. Those calls are routed through OpenRouter; OpenAI, Groq, and Anthropic are used directly when OpenRouter is unavailable. Which model answers a given request can change.
They are permitted to process that information only on our instructions, to provide the user-facing feature you asked for in that request.
6. Cookies and similar technologies
Steele sets two first-party cookies, one to keep you signed in and one to count how many visitors become users, and loads no third-party analytics, advertising or tracking script at all. Each one, what it holds and how long it lasts is in the Cookie Notice. You can also block cookies in your browser, though blocking the sign-in cookie will keep you signed out.
7. Data retention
We retain information for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary depending on the type of data and how it is used. You can disconnect Google at any time from your dashboard, which revokes Steele's access, and you (or your parent or legal guardian) can request deletion of your account and Google-derived data by contacting us; we delete it within 30 days except where retention is required by law. Apple Health is held differently and briefly: we keep only the most recent daily summary, each one replaces the last, Steele stops using a summary once it is more than 36 hours old, and disconnecting deletes it immediately.
Deletion happens in two stages, in this order. We delete from the live Service first, on the timeline above. Deleting there does not instantly remove the record from our encrypted backups, which are held on a rotating schedule, so it is purged from those within 30 days after the live deletion. That second window runs from the live deletion rather than from your request. Nothing is restored from a backup into the live Service after a deletion request except to recover from an incident, and we re-apply the deletion if it is.
8. Security
We use reasonable administrative, technical, and physical safeguards designed to protect information. However, no method of transmission or storage is 100% secure.
9. Your choices & rights
- Opt out of SMS: reply STOP.
- Access/updates: you may request access to or correction of certain information.
- Deletion: you may request deletion of certain information, subject to legal requirements.
To make a request, email support@steelelabs.co.
10. Children's privacy
Steele is built for parents, and the account holder is always the parent or legal guardian. A child does not create an account, does not sign in, and is not contacted by the Service. The parent is the account owner and may review, change, or request deletion of everything on the account, including anything they have recorded about a child, at any time by contacting us. The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we have collected personal information from a child under 13 without the consent required by law, we will delete it.
11. International users
If you access the Service from outside the United States, you understand that information may be processed in the United States and other countries where our providers operate.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date will reflect the most recent changes. Where a change is material, we will say so in the product or by email or text before it takes effect.
13. Who to contact
The controller of this information, and the company behind Steele, is:
Steele Labs LLC, a Wyoming limited liability company
EIN 42-3465149
Mailing address: 32 West Way, Old Greenwich, CT 06870
support@steelelabs.co