Skip to content
Stewards Stewards
  • Home
  • Privacy Policy
  • Terms of Use
  • How Processing Works
  • Security & Risk Disclosure
  • Sign in

Stewards

Privacy Policy

The same text Stewards shows under Settings › About. Revised 16 September 2026.

Stewards is built to keep your work private.

On your device

Your Matters, Notebook notes, files, conversations, messages, and writing styles are stored locally. Chat contents, note bodies, file contents, extracted text, your glossary, writing samples, style notes, and the party a Matter says it represents are encrypted at rest with a device-bound key held in your device Keychain; the key never syncs and never moves to another device, so carrying your Matters to a new device means exporting a Stewards backup. Titles, file names and types, writing-style names, and activity-record names and destinations are also encrypted. Structural IDs, timestamps, counts, sizes, and policy flags remain readable. Eligible titles and file names are included in AI requests when their Matter is used.

When you ask for AI help

Only the context needed for your request — the current conversation and the Matter context you have included; a writing style you applied to the Matter, as passages chosen on this device from your own writing samples, scrubbed here as they were added, with measurements and your notes; and for a request made from the discovery drafter (drafting a set, suggesting topics, or drafting responses) the party you represent — is sent transiently to the Stewards Gateway for processing. Stewards does not keep readable chat history on its servers. The gateway relays each request to Tinfoil, a confidential-inference provider whose hardware enclaves run the model. The app verifies the enclave hardware, encryption key, and signed software build on your device and encrypts the request to it before sending, so the gateway forwards ciphertext it cannot read; the AI path cell above every chat says how far that is proven, and opens that evidence in full beneath itself. The model is an open-weight model chosen by Stewards, which may change it; Settings › Security & Privacy › Protections names the one in use. Before each request, that verification proves the request can be opened only inside a genuine AMD SEV-SNP enclave, whose memory the hardware keeps sealed from the machine's own operator, running a build that Tinfoil's public release workflow signed into a public transparency log. The Stewards Gateway cannot read it, and neither can Tinfoil's staff as far as that enclave's firmware carries AMD's published security fixes; where it does not, the AI path reading names the missing fixes, and against whoever controls Tinfoil's servers the seal rests on trust rather than proof until they are installed. What remains Tinfoil's word is narrower: that its published enclave code does what its public source says, since Stewards checks the signature and the log entry rather than rebuilding it; that the GPU's own attestation checks out, which the enclave verifies at boot and Stewards does not repeat; and what Tinfoil keeps about a request — token counts, the model, and the time.

Your account and allowance

When account sign-in is enabled, sign-in itself happens on a page run by Auth0, an identity service Stewards uses for every sign-in method, including Apple and Google. Auth0 receives your email address or the account you sign in with, your network address, and your browser details, and keeps its own sign-in records under its terms. The invitation email, and the one-time code Auth0 emails when you sign in that way, are delivered by Resend, an email delivery service that receives the address and the message for that delivery and keeps its own delivery records under its terms. The Stewards gateway then keeps an opaque account identifier and the sign-in subject Auth0 assigns, sign-in sessions, invitation and access dates, daily and monthly request counts, and aggregate input and output token counts by model and allowance period. It stores no password, payment-card details, or work content, and no email address: an invitation keeps a keyed fingerprint of the address it was sent to, which lets the service match the invitation to you and lets the operator confirm a specific address, but cannot be turned back into the address. An invitation may ask for a card on file before AI access begins. The card is entered on a page run by Stripe, a payment processor, which keeps the card and whatever you enter there under its terms; the gateway keeps only Stripe's reference for your account and the date the card was added, and nothing is charged to the card until you choose a plan. If you add a passkey — an optional second way in, offered on the account page, that signs you in with Touch ID or your phone instead of an emailed code — the gateway keeps a record of that too: its public key, an identifier for it, the name you gave it, and the dates it was added and last used. The private key never leaves your device, and the gateway checks a passkey sign-in itself, without Auth0. A passkey is an addition rather than a replacement: an emailed code always still works, so losing one cannot lock you out of your account. The operator can associate your account with its sign-in identity through Auth0; to anyone else the account is opaque. Sign-in sessions expire on their own; usage counts are kept for the current allowance period and the three before it; the other records are kept while the account exists. You can delete the account yourself, from Settings › Usage & Account or from the account page at accounts.askstewards.com: one step removes the account, its sign-ins on every device, its passkeys, its download access, its allowance and the usage counts kept for it, and closes the invitation it claimed, and asks Stripe to delete its record of you when a card was on file; daily totals survive only as figures tied to no account. The login record Auth0 holds, with your email address, is removed in the same step when the service is authorized to do so, and the confirmation says whether it was. Backups are kept for a limited time, so an account you delete is gone from every backup within 60 days. When you sign in with an emailed code, the address you typed is kept on this device in its Keychain, beside the session, so Settings can say whose account the device is signed in to; it leaves with the session when you sign out or delete the account. When the provider's token counts for a request are missing, the service counts an estimate instead; only in the rare case it has nothing to estimate from does AI use pause until the request is accounted for. There are no automatic overage charges.

Requests Stewards makes on its own

On the Mac, Stewards checks accounts.askstewards.com for updates, and downloads them, unless you turn that off in Settings › Software Updates. Those requests carry your network address, the app version, and your system language — never your work — and a download presents your update credential. At launch, Stewards asks the gateway once whether it requires an account. Opening a Matter or Protections checks the AI path when no current reading is available; every AI query checks it again before sending, and every web search and page fetch checks Tinfoil's search enclave the same way; while Live monitoring is on in Settings › Protections, it is checked every 15 minutes while Stewards is open; opening Usage & Account in Settings asks for your allowance. None of these carry your work, and none are recorded in Data Activity, which records the requests that do.

Where the service runs

The Stewards Gateway runs on a virtual server rented from Aleph Cloud, a hosting network whose machines are run by independent operators. The gateway is built for that: sealed requests reach it as ciphertext it cannot open, it keeps no copy of any request, and the account records above are the whole of what it holds. Auth0's tenant for Stewards is in the United States, and Tinfoil, Exa, Resend, and Stripe are United States companies whose own published terms govern where they process. Stewards does not offer to keep your data within any particular country.

Web research

In Standard and Guarded Matters, the assistant may suggest a web search. A search query you approve, or the address of a page you choose to read, is sealed on your device to Tinfoil's search enclave once that enclave's hardware, encryption key, and signed software build pass the checks the AI's enclave passes, so the gateway relays it without being able to read it. Inside the enclave, Tinfoil's search service runs the search, or reads the page, through Exa, a search engine that receives the query or address but never your network address or the gateway's. Tinfoil states that it uses Exa under a zero-data-retention agreement, and its service may also screen queries and results with a model running in Tinfoil's enclaves. Before you see a query, glossary terms, the party you represent, and structured identifiers are removed from it on this device, unless a Standard Matter has turned that off; under Guarded, a search is blocked while any of them remain. Local-Only Matters never reach the web. Your notes, files, and messages are never sent to search. Web content is treated as source material, never as instructions.

No advertising, no training

Stewards does not sell your data, use it for advertising, or use it to train AI models.

askstewards.com · Built for the Mac · Privacy Policy · Terms of Use · How Processing Works · Security & Risk Disclosure