1. Who we are
Stedra is run by Butikkdrift Johansen, org. no. 931 440 802, based in Tromsø, Norway. If you have a question about this page, or a request about your own data, write to privacy@stedra.no. That address forwards to a real inbox we read, not an unmonitored alias.
2. What we collect
This is split by what you actually do, not one long list — most of it only applies to one or two things you might do on Stedra.
If you join the waitlist
Just your email address.
If you claim a business
This requires an account. We store the business name, address, category, description, website, and a contact email and phone number for the business — this is contact information for a real, identifiable person, not just the business. If you give us an address, we look up its coordinates so the business can appear on a map.
If you create an account
During this closed pilot, creating an account means an email address, a password, and an invitation code — the only sign-in method turned on right now. (Google sign-in exists in the app but is switched off for this phase, so nobody can currently use it.)
- Preferences. Anything you tell us about your travel preferences — pace, budget, interests, things you'd rather avoid — used only to shape your own trip recommendations.
- What you ask Stedra to plan. The exact text you type into the search field is stored, along with the itinerary we generate for you, and it is sent — as you typed it — to the AI provider that writes the plan. See section 4 for exactly where that goes.
- Saved trips and favorites. Trips, favorite places, and notes you choose to save.
- Photos you upload. For a Local Voices contribution or a Trip Memory. Every photo has its embedded location and device metadata (EXIF) removed automatically before it is stored.
- Location. Only ever sent to us for a specific “near me” search, and only after you explicitly allow it in your browser. We remember that choice for your current browser session so we don't ask again and again — we don't track your location in the background.
- Payment information. Handled entirely by our payment processor. See section 4 — we never see your card details.
What we log without you doing anything extra
Every request to Stedra passes through our authentication system, which keeps its own logs — these include your IP address and the page that referred the request. That logging happens on the same hosting provider described in section 4, which means it's part of the transfer discussed there. We also log which AI model calls and which map/place lookups happened for a given account, for cost tracking — those logs record which model was used, how many tokens, and the cost, but not the text of your request itself.
3. Why, and on what basis
We collect this to run the service you asked for: to build your itinerary, to let a business owner claim and manage their listing, to process a payment, to keep the platform working and safe from abuse, and to notify you if you asked to be. That is our basis for processing it — performing the service you asked us for, or a step you took towards it (like joining a waitlist). We don't use your data for anything beyond that, and we don't sell it or hand it to advertisers.
5. How long we keep it
We keep it until you ask us to delete it. There is currently no automatic expiry on any of it — trips, waitlist entries, business claims, or logs. You can delete a saved trip, a favorite, or a Local Voices contribution yourself, at any time, from your account. For anything else, see section 7.
6. Your rights
You can ask us, at any time, to let you see what we hold about you, correct it if it's wrong, delete it, give you a copy in a portable format, or stop processing it. Write to privacy@stedra.no and we'll act on it. If you're not satisfied with our answer, you can complain to Datatilsynet (the Norwegian Data Protection Authority).
7. Deleting your account
There isn't a self-service “delete my account” button in the app yet. Email privacy@stedra.no and ask us to close your account — we'll do it by hand. That removes your account and everything tied directly to it: your trips, favorites, saved notes, usage records, and subscription record.
8. Children's privacy
Stedra is not directed at children, and we do not knowingly collect information from anyone under 16.
9. Changes to this policy
If we make a material change to this policy, we'll update the date at the top of this page and, where required, let you know directly.
This page describes what our systems actually do, checked directly against the code and the database as of the date above. It is not legal advice, and we have not had it reviewed by a lawyer for compliance with GDPR or Norwegian law — that review is still open.