Stafett is pre-alpha. This policy describes current practice, including where that practice still has gaps, rather than promising more than the system does today.
For payload content you send through Stafett, you are the controller and Stafett is your processor (GDPR Art 28). For account data (your email, login sessions, billing status), Stafett is the controller.
One cookie: a __Host--prefixed session cookie, strictly necessary to keep you logged into the control plane. No analytics, advertising, or third-party tracking cookies. This cookie is exempt from consent under ekomloven ยง 2-7b; we disclose it here rather than asking you to opt in.
Fly.io (hosting, Postgres) and Resend (transactional email for login links). Our subprocessor register and each provider's data protection terms are still being finalised; do not treat this list as complete.
Cancelling a job stops delivery but does not yet hard-delete it, and there is no self-serve tenant purge today. We will update this section the day that changes.
You can request access to or deletion of your account data by writing to abuse [at] stafett.dev. Deletion requests are currently handled manually.
Our hosting region and its transfer mechanism status are still being confirmed. We will publish specifics here once verified rather than claim a mechanism ahead of that review.