Legal

Privacy Policy

Last updated: 2 September 2026

1. Who we are

Stedra is run by Butikkdrift Johansen, org. no. 931 440 802, based in Tromsø, Norway. If you have a question about this page, or a request about your own data, write to privacy@stedra.no. That address forwards to a real inbox we read, not an unmonitored alias.

2. What we collect

This is split by what you actually do, not one long list — most of it only applies to one or two things you might do on Stedra.

If you join the waitlist

Just your email address.

If you claim a business

This requires an account. We store the business name, address, category, description, website, and a contact email and phone number for the business — this is contact information for a real, identifiable person, not just the business. If you give us an address, we look up its coordinates so the business can appear on a map.

If you create an account

During this closed pilot, creating an account means an email address, a password, and an invitation code — the only sign-in method turned on right now. (Google sign-in exists in the app but is switched off for this phase, so nobody can currently use it.)

  • Preferences. Anything you tell us about your travel preferences — pace, budget, interests, things you'd rather avoid — used only to shape your own trip recommendations.
  • What you ask Stedra to plan. The exact text you type into the search field is stored, along with the itinerary we generate for you, and it is sent — as you typed it — to the AI provider that writes the plan. See section 4 for exactly where that goes.
  • Saved trips and favorites. Trips, favorite places, and notes you choose to save.
  • Photos you upload. For a Local Voices contribution or a Trip Memory. Every photo has its embedded location and device metadata (EXIF) removed automatically before it is stored.
  • Location. Only ever sent to us for a specific “near me” search, and only after you explicitly allow it in your browser. We remember that choice for your current browser session so we don't ask again and again — we don't track your location in the background.
  • Payment information. Handled entirely by our payment processor. See section 4 — we never see your card details.

What we log without you doing anything extra

Every request to Stedra passes through our authentication system, which keeps its own logs — these include your IP address and the page that referred the request. That logging happens on the same hosting provider described in section 4, which means it's part of the transfer discussed there. We also log which AI model calls and which map/place lookups happened for a given account, for cost tracking — those logs record which model was used, how many tokens, and the cost, but not the text of your request itself.

3. Why, and on what basis

We collect this to run the service you asked for: to build your itinerary, to let a business owner claim and manage their listing, to process a payment, to keep the platform working and safe from abuse, and to notify you if you asked to be. That is our basis for processing it — performing the service you asked us for, or a step you took towards it (like joining a waitlist). We don't use your data for anything beyond that, and we don't sell it or hand it to advertisers.

4. Who we share it with, and where

We use outside services to run Stedra. Each one only gets what it needs for its specific job. We describe them here by category, not by company name — what matters to you is what kind of thing happens to your data, not which companies are involved. A complete, company-by-company register exists and can be provided on request — see the note at the end of this section.

  • An AI provider generates your itinerary, from the exact text of your request, as you typed it — this is the single piece of information most worth knowing about. We do not currently know which region it processes it in, which means we can't yet say whether this counts as a transfer outside the EEA, or what the legal basis for that would be. That's an open gap we're working to close, not a hidden fact.
  • A places service finds real locations for your trip. It receives place names, destination names, and coordinates — never the text you typed. For a “near me” search, those coordinates are the ones you allowed us to use.
  • An events service finds real event listings, given only a destination/city and a date range.
  • A weather service provides forecasts for the place you're planning around, given only coordinates — for a “near me” search, that means the coordinates you allowed us to use. It is operated within the EEA (Germany) and receives no name, account, or identifier.
  • A payment processor handles your payment on its own page, not ours — we only ever send it your email address and an internal account reference, never your card details. Its account is registered in Norway.
  • An email provider sends our emails (password resets, waitlist confirmations, a trip postcard you choose to share). Its sending region for our domain is in the EEA (Ireland). Its own documentation states that stored message data sits in the United States; we have not separately confirmed what that means for our messages.
  • A hosting provider runs the app itself. It operates in the United States (Oregon), outside the EEA, and its logs include your IP address and the page that referred your request — this is the same logging described in section 2.
  • A security and performance layer sits in front of the site and sees the same traffic the hosting provider does. It runs on a global network with no single region.
  • A database, authentication, and file storage provider operates within the EEA (Ireland).
  • Images and maps are fetched directly by your own browser, not through our servers. When you view a trip, your browser makes its own requests to the image and map services behind the page — so those services see your IP address directly, the same way any website you visit can see it, not filtered through us the way the categories above are. Our settings limit what else they learn: they see only that the request came from stedra.no, not which trip you were looking at.
  • A booking partner's panel on our front page loads from their servers, and sees you before you click anything. The front page carries two such panels, each embedded from its own booking partner: Viator under the bookable experiences, and GetYourGuide further down. Each runs its own script in your browser as the page loads, which means both of them see your IP address, your browser, and the fact that you were on Stedra's front page — whether or not you ever click a tour. If you do click through, the one you clicked knows you came from us, which is how we are paid a commission. We name them here rather than describing them by category, as we do above, because their names are visible on the page anyway; describing them vaguely would tell you less than your own screen does. We do not send them your name, your email, or anything you typed into Stedra, and we do not receive anything about you back from them. We have not yet built a consent step in front of this, and until we do, both panels load for everyone who opens the front page. That is an open gap we are stating plainly, not one we are hiding.

Transfers outside the EEA. The hosting provider above processes data in the United States — a transfer outside the EEA that requires a legal basis, typically standard contractual clauses. We rely on that provider's own standard terms for this; we have not yet finished our own documented review confirming it covers our specific use, and that review stays open until we have. The AI provider's region is still unknown to us, as noted above — until we confirm it, we can't say whether it adds a second such transfer. Where the email provider's stored message data ends up is a similar open question, for the reason given above.

We share information beyond this list only if the law requires it, or to protect someone's safety.

A complete register — which company sits behind each category above, what specifically it receives, and its confirmed region where we have one — is kept internally and can be provided on request. Write to privacy@stedra.no.

5. How long we keep it

We keep it until you ask us to delete it. There is currently no automatic expiry on any of it — trips, waitlist entries, business claims, or logs. You can delete a saved trip, a favorite, or a Local Voices contribution yourself, at any time, from your account. For anything else, see section 7.

6. Your rights

You can ask us, at any time, to let you see what we hold about you, correct it if it's wrong, delete it, give you a copy in a portable format, or stop processing it. Write to privacy@stedra.no and we'll act on it. If you're not satisfied with our answer, you can complain to Datatilsynet (the Norwegian Data Protection Authority).

7. Deleting your account

There isn't a self-service “delete my account” button in the app yet. Email privacy@stedra.no and ask us to close your account — we'll do it by hand. That removes your account and everything tied directly to it: your trips, favorites, saved notes, usage records, and subscription record.

8. Children's privacy

Stedra is not directed at children, and we do not knowingly collect information from anyone under 16.

9. Changes to this policy

If we make a material change to this policy, we'll update the date at the top of this page and, where required, let you know directly.

This page describes what our systems actually do, checked directly against the code and the database as of the date above. It is not legal advice, and we have not had it reviewed by a lawyer for compliance with GDPR or Norwegian law — that review is still open.

Terms of service