Outside Chair Privacy Policy

Version 2026-10-08-2 · Effective date 8 October 2026 · Last updated 8 October 2026

1. Who we are

Outside Chair is operated by StewAI AG, Rainstrasse 82a, 8143 Stallikon, Switzerland, registered in the commercial register of the Canton of Zurich under CHE-257.898.357. In this policy "StewAI", "we" and "us" mean StewAI AG.

Privacy contact: privacy@stewai.com. Legal notices: legal@stewai.com. Postal requests go to the address above.

2. What this policy covers

This policy explains how we process personal data when you:

  • visit outsidechair.com;
  • sign in to app.outsidechair.com;
  • connect an AI assistant to Outside Chair through our MCP endpoint or a plugin;
  • use a workspace, invite people or accept an invitation;
  • take part in the Analysis Exchange;
  • write to us.

It also covers people who do not use Outside Chair but whose data a member enters into a workspace, for example a person named as the owner of an action, and people named in their public or business roles in Exchange analyses.

Together, the website, the web application, the MCP endpoint at app.outsidechair.com/mcp, the Outside Chair plugins for Claude, ChatGPT, Codex and other MCP clients, and the Analysis Exchange are the "Service".

3. Roles

StewAI is the controller for your account, sign-in and connection data, audit and security data, the Analysis Exchange and the website.

For the content of a workspace, the workspace owner is the controller and StewAI is the processor. The workspace owner, or the organisation on whose behalf they act, decides what goes into the workspace. We store and serve that content on their documented instructions, which are set out in section 13 of the Outside Chair Terms of Service. If you want to exercise rights over personal data that another member put into a workspace, contact that workspace's owner. We will help them respond.

Your AI assistant's provider processes data under its own terms, as a separate controller or, if your organisation has a business agreement with it, as your organisation's processor. See section 6.

4. How Outside Chair works

You use Outside Chair through an AI assistant you choose: Claude, ChatGPT, Codex or any other MCP-compatible client. Your assistant reads from and writes to your workspace through our MCP endpoint, using a connection you authorise.

Outside Chair runs no AI model, fetches no documents and verifies no source. It stores what you and your assistant send to it. Everything your assistant reads from Outside Chair passes through your assistant's provider.

5. The data we process

5.1 Account data

When you first sign in we create an account holding:

  • your email address and whether Auth0 verified it;
  • a display name, taken from your Auth0 profile or, if there is none, your email address;
  • the stable identifier Auth0 assigns to your email identity;
  • the time of creation and of later updates.

Source: you, through Auth0. Purpose: identify you, give you access to your workspaces and keep the same account when you reconnect.

We also record your explicit Terms acceptance and acknowledgment of this policy: your account identifier, the document versions and cryptographic hashes, the source and the time. When an operator records a separately evidenced agreement, we retain the reporter, agreement date, statement and evidence reference. Acknowledging this policy is not consent to marketing. Purpose: document the agreement governing your account and the notice you acknowledged.

5.2 Sign-in data

Sign-in uses Auth0 passwordless email. You enter your email address, Auth0 sends a one-time code, you enter the code. Auth0 processes your email address, the code, your IP address and browser data on its own domain, as our processor under our data processing agreement with Okta.

The web application keeps you signed in with an encrypted, HTTP-only session cookie that holds your Auth0 session. It expires after 1 day without activity and after 3 days at most.

5.3 Connection data

When you connect an AI assistant, Outside Chair acts as the OAuth authorisation server. We store:

  • the registration details of the AI client you connected, for example ChatGPT or Claude;
  • the scopes your AI client requested and you authorised by completing sign-in (read, or read and write);
  • authorisation requests and codes, used once and expiring within 10 minutes;
  • refresh tokens, stored only as hashes, rotating and valid for 30 days after each use;
  • your email, verified status and display name as carried in those tokens.

Access tokens are valid for 15 minutes and are not stored. We do not store Auth0's own tokens for connector sessions.

If you still need to accept the current documents, a necessary encrypted, HTTP-only cookie temporarily holds the verified identity and its pending connection-request identifier. It expires after 10 minutes and is deleted when that acceptance completes. No connection is granted by merely displaying the acceptance page.

A connection stays active for as long as your assistant keeps using it. Outside Chair has no screen to list or revoke connections. Your assistant can revoke its token through our revocation endpoint. To force a disconnection, write to support@stewai.com.

5.4 Billing data

If you start or manage a paid subscription, we store your plan, subscription status, billing-period end date and the Stripe customer, subscription and price identifiers linked to your account. Stripe collects your billing name, address, tax details and payment method on its hosted pages. We do not receive or store your full card or bank-account details. Purpose: take payment, provide paid features, issue invoices, prevent duplicate subscriptions and handle cancellation or failed payment. Source: you and Stripe.

5.5 Workspace content

A workspace stores what you and your fellow members enter through your assistants or the web application:

  • strategy records: priorities, initiatives, assumptions, signposts, measures, observations, decisions, actions and outcomes, each with its full version history and the member who submitted each version;
  • evidence cards: a public claim summary, your private interpretation, excerpts, strength and relationship;
  • sources: titles, links, file names, publishers and technical identifiers such as a file hash. Local files are stored as path references only, never uploaded; a path can include your computer's user name. We strip fragments and common token parameters from web links before storing them;
  • approved reviews, frozen with the evidence they relied on;
  • deliberation questions, attributed viewpoints and resolutions;
  • the workspace name and kind.

Free-text fields can contain personal data about you or other people, for example the name of the person who owns an action. The workspace owner decides what is entered. Do not enter sensitive personal data as defined in Art. 5 let. c FADP or Art. 9 GDPR.

Data from the retired Signals feature, where any exists, stays in the workspace record and its export.

5.6 Team data

For each member we store their display name as recorded when they joined, their role, join date and, if removed, the removal date. For each invitation we store the invitee's email address, the role offered, who invited them, a hash of the single-use invitation link, its status and its expiry 14 days after creation.

All members see the names and roles of current members. Only owners and admins see member and invitee email addresses. A display name that falls back to an email address is visible to all members. Anyone who opens an invitation link and signs in sees the workspace name, the inviter's name, the role offered and a masked form of the invited email address.

5.7 Integrity and audit data

To keep the record trustworthy we store:

  • audit events: which member did what, when, by identifier. No IP address, no browser data;
  • hashes of confirmation proposals. The proposal content itself is cleared when the proposal is committed, and deleted 24 hours after it expires;
  • idempotency records that hold the stored response of a write, so that a repeated request returns the same result.

5.8 Analysis Exchange data

The Analysis Exchange is off unless the workspace owner opts in. If they do, we process:

  • the owner's acceptance of the Exchange terms, by account and time;
  • the analyses the workspace publishes, as immutable versions, with the submitting member;
  • a random contributor label such as "Contributor 3f9a1c" shown to other participants instead of any name, account or workspace;
  • feedback and ratings you give or receive, with a per-analysis reviewer label. Every revision of a feedback item is kept; only the latest counts;
  • delivery receipts: which account retrieved which analysis, when. Opening a delivered analysis can deliver its latest version and record a new receipt;
  • private reputation statistics per account, shown only to you, and only when you act in a workspace you own;
  • the list of organisation names you asked us to block in preflight;
  • for searches with no result, a keyed pseudonym of your account and the search cell, kept for 30 days and reported to us only when at least 3 distinct accounts hit the same cell.

Analyses are shared with other participating workspaces under the recipient restrictions in the Terms. Analyses may name people only in their public or business roles, as taken from public sources. Preflight is a structural check. It does not detect personal data. We reject a submission whose content is identical to an analysis already published from any account.

5.9 Technical data

Our reverse proxy logs the IP address, the requested URL, the time, the response status and the browser identifier of each request. Invitation links, sign-in redirects, OAuth routes and authentication callbacks are excluded from these logs. We use these logs to keep the Service secure and to diagnose faults.

We use no analytics, no tracking pixels and no third-party scripts. The fonts are served from our own servers.

5.10 Correspondence

If you write to support@stewai.com, privacy@stewai.com or legal@stewai.com we keep the correspondence for as long as needed to handle the matter and for 24 months after.

5.11 Newsletter preferences

The Outside Chair newsletter is optional and off by default, including for existing accounts. If you choose to opt in under Email preferences, we record your account identifier, verified email address, choice, the wording and version shown, the portal source and the time. We retain the history of opt-ins and withdrawals so we can demonstrate your choices. Consent is specific to that email address and does not transfer automatically if it changes.

If an operator records an agreement given outside the portal, we also retain the reported agreement date, statement, reporter and evidence reference. We distinguish direct agreement from agreement reported by another person; neither is recorded as a portal checkbox action.

We are collecting preferences; newsletter sending is not enabled yet. No newsletter contacts are currently transferred to an email-marketing platform. This choice is separate from accepting the Terms, acknowledging this policy, receiving necessary service emails and enabling the Analysis Exchange. You can withdraw at any time by unchecking the newsletter option and saving in Email preferences, or by contacting privacy@stewai.com. Withdrawing does not affect your access to the Service.

6. AI assistants

Your AI assistant is provided by a third party, for example Anthropic (Claude), OpenAI (ChatGPT, Codex) or the provider of another MCP client. When your assistant calls Outside Chair:

  • everything the tool returns goes to your assistant's provider: your email and name, workspace names, strategy records, evidence including private interpretations, member names, deliberation content, Exchange analyses and feedback, and, for owners and admins, member and invitee email addresses and invitation links;
  • everything your assistant writes to Outside Chair was generated in your conversation with that provider.

The provider processes that data under its own terms and privacy policy, in the locations it chooses. We have no contract with the provider about your data and do not control what it retains or whether it trains on your conversations. Check your provider's settings.

We send data to an AI provider only in response to a tool call from your assistant under a connection you authorised. We never initiate the transfer. We do not train models on your data.

We process personal data to:

Purpose Legal basis where the GDPR applies
Provide the Service, including sign-in, workspaces, teams, export and the Exchange Performance of a contract, Art. 6(1)(b)
Process subscription payments and provide paid-plan entitlements Performance of a contract, Art. 6(1)(b); our legitimate interest in preventing billing errors and fraud, Art. 6(1)(f)
Keep the record accurate, versioned and auditable Contract, Art. 6(1)(b); our legitimate interest in the integrity of the record, Art. 6(1)(f)
Secure the Service, prevent abuse, diagnose faults Our legitimate interest in a secure and reliable Service, Art. 6(1)(f)
Operate the Exchange, including pseudonymous labels, ratings, limiting and takedown Contract, Art. 6(1)(b); our legitimate interest in running a trustworthy marketplace and preventing manipulation, Art. 6(1)(f)
Publish reference analyses and host Exchange analyses that name people in their public or business roles Our legitimate interest in providing business analysis built from public sources, Art. 6(1)(f)
Contact you about the Service, security, changes to terms Contract, Art. 6(1)(b); our legitimate interest in informing you about security and legal changes, Art. 6(1)(f)
Record your optional newsletter preference Your consent; you can withdraw at any time
Comply with law, respond to lawful requests, establish or defend claims Legal obligation, Art. 6(1)(c); our legitimate interest in defending our rights, Art. 6(1)(f)

Under the Swiss FADP we rely on the principles of Art. 6 FADP. We do not need your consent for the processing described here, except where we ask for it.

We do not use your data for advertising and make no automated decision with legal or similarly significant effect on you. We compute per-account Exchange statistics automatically (section 5.8); they affect how analyses are ranked and limited, not your access to the Service. There is no fixed daily publication allowance. We do not sell personal data.

8. Who receives data

8.1 Processors

Processor Role Location
Okta, Inc. (Auth0) Identity verification and session issuance; Auth0 delivers the one-time code Tenant hosted in Auth0's EU region; Okta, Inc. is certified under the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Data Privacy Framework
Hostinger International Ltd. Virtual server hosting the application, database and proxy Frankfurt, Germany
Stripe group companies Hosted subscription checkout, payment processing, invoicing, tax-ID collection and the customer billing portal EEA and United States; Stripe applies its published international-transfer safeguards

We also share our domain name with a certificate authority to obtain TLS certificates. No personal data is involved.

8.2 Other recipients

  • Workspace members, according to their role, as described in section 5.
  • Exchange participants, who receive published analyses and feedback under a contributor or reviewer label, never your name, account or workspace.
  • Your AI assistant's provider, as described in section 6, on your instruction.
  • StewAI operators: the founder can read workspace data, run Exchange takedowns and maintenance and read production logs, only for support you asked for, security, legal compliance and Exchange operation, as set out in section 6 of the Terms.
  • Advisers and authorities: lawyers, auditors, courts or authorities where the law requires it or where we need to establish, exercise or defend a legal claim.
  • A successor if StewAI AG or the Outside Chair business is sold or merged, under this policy.

9. International transfers

Our servers are in Germany. Switzerland and the EU/EEA recognise each other's level of data protection.

Data goes to the United States when Okta processes identity data. Okta, Inc. is certified under the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Data Privacy Framework. The Swiss Federal Council and the European Commission recognise these frameworks as adequate. Where a transfer is not covered by a certification, we use the standard contractual clauses recognised by the European Commission with the Swiss amendments required by the Federal Data Protection and Information Commissioner and, for UK data, the UK Addendum.

Stripe may process billing and payment data in the EEA, the United States and other locations needed to provide its payment services. Stripe publishes the transfer mechanisms it uses, including adequacy decisions, the EU standard contractual clauses and applicable data-privacy frameworks.

Your AI assistant's provider receives data in the country where it operates, usually the United States. The transfer is necessary to perform our contract with you and happens on your instruction (Art. 17(1)(b) FADP, Art. 49(1)(b) GDPR). Providers process data under the terms you agreed with them. We do not control what a provider does with the data.

10. How long we keep data

Data Retention
Account data Until you ask us to delete your account or we terminate it. We delete or anonymise it within 30 days of a verified request or of termination, except as stated below
Session cookie 1 day without activity, 3 days at most
Authorisation requests and codes Deleted after expiry
Refresh tokens 30 days after last use, or until revoked. Revoked and expired token hashes are deleted within 30 days
Billing identifiers and subscription status For the subscription term and afterwards for as long as required for accounting, tax, dispute and fraud-prevention records; ordinarily 10 years for records subject to Swiss commercial retention law
Workspace content, members, audit events For as long as the workspace exists. Archiving keeps the content and makes it read-only. The owner can request deletion; we delete the workspace within 30 days. If we terminate the owner's account, we delete the workspace 30 days after termination
Invitations Pending invitations expire after 14 days. Invitee email addresses are deleted 90 days after acceptance, revocation or expiry, except as recorded in audit events
Confirmation proposals Content cleared on commit; expired proposals deleted after 24 hours
Idempotency records 90 days after the write
Exchange analyses, feedback, delivery receipts For as long as the Exchange exists. Versions are immutable. Withdrawal stops future distribution but does not delete the version or copies already delivered. Your name is never shown to other participants. We store which account submitted each version; when you delete your account we remove that link
Exchange demand pseudonyms 30 days
Proxy access logs 30 days
Correspondence 24 months after the matter is closed
Newsletter choices and consent history Until account deletion; withdrawal immediately changes your current preference to opted out
Terms acceptance and Privacy acknowledgment history Until account deletion, unless retention is necessary for an identified legal obligation or dispute

We keep data longer where the law requires it, for example commercial records under Art. 958f CO, or where we need it for a legal claim.

If you leave a workspace or are removed, the versions you submitted stay in that workspace's record. Your display name stays on them. This is what the workspace owner has instructed us to do in the Terms, so that the record stays complete.

11. Security

  • All traffic between you and the Service is encrypted in transit with TLS.
  • The database is on a private network and not reachable from the internet.
  • Session cookies are encrypted and HTTP-only. Invitation links, authorisation codes and refresh tokens are stored as hashes only.
  • Every request is authorised against the workspace it names. A token for one account cannot read another account's workspaces.
  • Approved reviews and Exchange versions are designed to be immutable: the Service has no function to change them, Exchange versions are additionally protected by database rules that reject updates and deletions, and we correct them only by adding a new version or a note.
  • Access to production systems is limited to the founder and protected by SSH keys and two-factor authentication on the hosting account.

No system is completely secure. If you believe your account or data is compromised, write to support@stewai.com.

12. Your rights

You can ask us to:

  • tell you whether we process your personal data and give you a copy (Art. 25 FADP, Art. 15 GDPR);
  • correct it (Art. 32 FADP, Art. 16 GDPR); immutable versions are corrected by a new version or a correction note, not by changing the old one;
  • delete it (Art. 32 FADP, Art. 17 GDPR), subject to the retention rules in section 10;
  • restrict or object to processing based on legitimate interests (Art. 30 FADP, Art. 18 and 21 GDPR);
  • give you your data in a machine-readable format (Art. 28 FADP, Art. 20 GDPR). Independently of this right, any member can export a complete workspace as JSON at any time from the workspace settings or with the export_workspace tool.

Write to privacy@stewai.com from the email address of your account, with "Privacy request" in the subject. We answer within 30 days. We may extend this by up to two months for complex requests and will tell you. We may ask you to confirm your identity. Requests are free; for manifestly unfounded or excessive requests we may charge a reasonable fee where the law allows.

Rights over personal data inside another member's workspace content are exercised against the workspace owner, who is the controller. We will pass your request on and help them respond.

You can complain to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland, www.edoeb.admin.ch, or, if you are in the EU or UK, to your local data protection authority.

13. Cookies

We set only the cookies needed to sign you in: an encrypted session cookie and short-lived transaction cookies during sign-in. They are strictly necessary and need no consent. We set no analytics, advertising or cross-site cookies. If you block cookies for app.outsidechair.com you cannot sign in to the web application. Connecting an AI assistant sets no cookies on our domain, but Auth0's sign-in page needs cookies on its own domain.

14. Children

The Service is for business use by people aged 18 or over. We do not knowingly collect data from children. If you think a child has given us data, write to privacy@stewai.com and we will delete it.

15. Changes

We will update this policy when the Service changes. The effective date at the top shows the current version. We will tell you about material changes by email or in the Service at least 30 days before they take effect.

16. Contact

StewAI AG Rainstrasse 82a 8143 Stallikon Switzerland UID CHE-257.898.357

Privacy requests: privacy@stewai.com Legal notices: legal@stewai.com Support: support@stewai.com