Legal

Privacy Policy

Effective date: June 1, 2026  ·  Last updated: May 12, 2026

Table of Contents

  1. Information We Collect
  2. How We Use Your Information
  3. Information Sharing
  4. Data Retention
  5. Security
  6. Your Rights (GDPR & CCPA)
  7. Cookies
  8. International Transfers
  9. Children's Privacy
  10. Contact & DPO

CutoverStream is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights regarding your personal information.

1. Information We Collect

We collect the following categories of information:

CategoryExamplesSource
Account DataName, email, username, password (hashed)You provide at registration
Profile DataJob title, team, phone, timezone, avatarYou provide optionally
Plan & Project DataCutover plans, tasks, issues, comments, audit logsYou create within the Service
Billing DataSubscription tier, billing history (card details handled by Stripe)You provide at checkout
Usage DataPages visited, features used, API calls, session durationAutomatically collected
Technical DataIP address, browser type, device type, error logsAutomatically collected

We do not collect sensitive personal data such as health information, racial or ethnic origin, or financial account numbers.

2. How We Use Your Information

We use your information to:

We do not sell your personal data to third parties. We do not use your Customer Data to train AI models without your explicit consent.

3. Information Sharing & Sub-processors

We share your data only with trusted service providers who help us operate the platform ("sub-processors"):

ProviderPurposeLocation
CloudflareInfrastructure, CDN, database (D1), storage (R2), edge computeGlobal
ClerkUser authentication and identity managementUnited States
StripePayment processing and subscription billingUnited States
ResendTransactional email deliveryUnited States
SentryError monitoring and performance trackingUnited States
AnthropicAI narrative generation (optional feature)United States

Each sub-processor is bound by data processing agreements and required to protect your data in accordance with applicable law.

We may also disclose your information when required by law, court order, or to protect the rights and safety of CutoverStream, our users, or the public.

4. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

You may request early deletion of your data by contacting privacy@cutoverstream.com.

5. Security

We implement industry-standard security measures to protect your data, including:

No security system is impenetrable. In the event of a data breach that affects your personal data, we will notify you within 72 hours as required by GDPR Article 33.

6. Your Rights (GDPR & CCPA)

Depending on your location, you may have the following rights regarding your personal data:

RightDescription
AccessRequest a copy of your personal data
RectificationCorrect inaccurate or incomplete data
ErasureRequest deletion of your personal data ("right to be forgotten")
PortabilityReceive your data in a machine-readable format
RestrictionRestrict processing of your data in certain circumstances
ObjectionObject to processing based on legitimate interests
Opt-out (CCPA)California residents may opt out of the sale of personal information (we do not sell data)

To exercise any of these rights, contact privacy@cutoverstream.com. We will respond within 30 days.

7. Cookies

CutoverStream uses essential cookies and session tokens necessary to operate the Service. We do not use advertising or tracking cookies. Specifically:

You may clear cookies and local storage at any time through your browser settings. This will require you to sign in again.

8. International Data Transfers

CutoverStream is based in the United States. If you access the Service from the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, your data may be transferred to and processed in the United States.

For EEA users, we rely on Standard Contractual Clauses (SCCs) as the legal basis for data transfers. Enterprise customers may request our Data Processing Agreement (DPA) at cutoverstream.com/dpa.

9. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child under 16 has provided personal data, we will delete it promptly.

10. Contact & Data Protection Officer

For privacy questions, data subject requests, or to reach our Data Protection Officer:

If you are in the EU and believe we have not addressed your privacy concern adequately, you have the right to lodge a complaint with your local data protection authority.

Privacy questions?

Contact privacy@cutoverstream.com — we respond within 30 days.