steepdbeta

Privacy

Steepd holds your reading, so it holds as little else as it can. Nothing you read is shown to anyone unless you turn on newsletter organization, which is off until you do.

What we hold

You sign up with an email address. It is used to send you sign-in links and, when you ask for it, to relay one temporary forwarding-verification email. It is not used for a newsletter or product mail, and it is not passed on.

When you forward an email or send a public webpage URL to your Steepd address, we convert it and store the result as an EPUB in your library. That file belongs to your account and is reachable only with your session or your device password.

What publishers can see

Public webpage HTML and newsletter or webpage images are fetched once, at the moment we convert the item, and stored inside the EPUB. A publisher can therefore learn that a message was converted, but not when or whether you read it. Tracking pixels are dropped and tracking parameters are stripped out of links before the file is built.

What we do not do

There is no analytics, no advertising, no third-party script and no tracking cookie. One cookie is set, and it exists only to keep you signed in.

How long we keep it

On the free plan an item is deleted automatically 60 days after it arrives, and the stored file goes with the record of it. Deleting an item yourself deletes it straight away. Deleting your account deletes your library and your stored files, and your inbox address is held back so nobody else can ever be sent your mail.

If you turn on newsletter organization

This is off unless you turn it on, and it applies to newsletters only — never to books or saved webpages. When it is on, each newsletter's readable text, its title, byline and language, and the website its own view-online link points to, are sent to OpenRouter and the model provider it routes to, so that the publication can be identified. Your publications go with it: their names, any earlier names from renaming or combining, any identification note you wrote, and the title, byline and website of up to three issues you assigned by hand. The request is routed to providers that agree not to retain or train on it, and prompt logging is off on the key we use. Temporary processing and caching inside a provider are still possible, so this is not a promise that no copy exists anywhere for any length of time.

Before the text is sent, email addresses are removed and links are reduced to the site name, dropping the per-reader tracking identifiers in their paths. The article itself is sent as it is. Newsletter text can contain personal information, and removing addresses does not make it anonymous. A very long issue may be sent as its opening and its ending, marked as shortened; the copy in your library is never shortened. Your reader password, your account credentials, your email address and your account identifiers are never sent, and the model is given no way to act on your account.

What is kept afterwards is small: the publication names you end up with, any note you write to help identify one, and a record of which issue belongs to which publication. A handful of your own corrections are read from the issues themselves to guide later decisions, so they disappear when those issues do. Turning the setting off stops all further analysis immediately; your existing publications stay browsable and you can still correct them. Deleting your account deletes all of it.

Who else is involved

Steepd runs on Railway, in the United States, and the email it sends you is delivered by Resend. Each sees only what its job needs: Railway holds the machine and its disk, Resend handles the messages we send. If you turn on newsletter organization, OpenRouter and the model provider it routes your request to see the newsletter text and publication details described above. Our logs record that a request happened, never what was in it — no message content, no sign-in links, and nothing sent to or returned by a model.

Questions

Write to hello@steepd.app and a person will answer.