Back to Steer

Data & Privacy Policy

Last updated: 18 June 2026

Your information is yours. Steer is built on a simple promise: no ads, no selling your data, and your data is never used to train third-party AI models. This policy explains what personal data we process, why, on what legal basis, how long we keep it, where it resides, and the rights you have under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and Greek Law 4624/2019.

1. Who we are (data controller)

The data controller is APEX LABS Ε.Ε. (distinctive title “Apex Labs”), a limited partnership (Ετερόρρυθμη Εταιρεία / Ε.Ε.) with its registered seat at Pl. Ippodameias 8, 18531 Piraeus, Greece, VAT no. EL802389881 (Attica KEFODE Tax Office (Κ.Ε.ΦΟ.Δ.Ε. Αττικής)), operating Steer at steercopilot.com.

For any privacy matter you can contact our data protection team at [email protected].

2. What personal data we process

  • Account data — your email address, password (stored only as a secure one-way hash), display name, and account settings (language, currency, timezone).
  • Your content — the goals, habits, and manually-entered personal-finance information (accounts, income, expenses, loans, investments, transactions) you create, and the briefs, forecasts and simulations generated from them.
  • Connected-app data — where you connect a service, the access tokens for it (encrypted at rest) and the data we sync for that feature (see section 6).
  • Billing data — your plan and subscription status. Payments are handled by our payment provider; we do not store your full card details.
  • Support & feedback data — messages, feedback and ratings you send us.
  • Technical data — limited information needed to operate the service securely (such as your session and basic device/usage information).

Steer does not require special-category data. Please do not enter sensitive personal data (for example about health or beliefs) into free-text fields unless necessary.

3. How and why we use your data (legal bases)

  • To provide the service — performance of a contract (Art. 6(1)(b) GDPR): creating and securing your account, storing your goals/habits/finances, generating your brief and projections, processing your subscription.
  • To keep the service secure and improve it — legitimate interests (Art. 6(1)(f) GDPR): protecting against fraud and abuse, diagnosing problems, and improving features using aggregated/anonymised insights. You can object to this processing (section 9).
  • Optional integrations and communications — consent (Art. 6(1)(a) GDPR): connecting a third-party app, or sending you optional product updates. You can withdraw consent at any time.
  • To meet legal obligations (Art. 6(1)(c) GDPR): issuing invoices and retaining records, and responding to lawful requests from authorities.

4. How the AI brief uses your data

Steer’s brief and suggestions are generated from your own data (your goals, habits and finances) to help you plan. We use this data only to produce your output, with meaningful human oversight over the service.

  • Your personal data is never used to train third-party (or our own) AI models.
  • The AI brief does not make decisions with legal or similarly significant effects about you; it provides suggestions you choose whether to act on.
  • We use a third-party AI provider to generate the brief. That provider acts as our processor under contract, may process the request outside the EU (for example in the United States) under Standard Contractual Clauses (section 8), and is contractually prohibited from using your data to train its models.

5. Where your data is stored

Your account and content are hosted on infrastructure located in the European Union, and our databases and backups reside in the EU. The only routine exception is the AI brief, where the request to generate your summary may be processed by our AI provider outside the EU under the safeguards described in section 8. We never store your data on infrastructure that lacks an adequate legal basis for the transfer.

6. Connected apps and what we sync

Connecting a third-party service is always your choice and is based on your consent. You can disconnect at any time from Settings → Connections, and we use secure, official sign-in (OAuth) — we never see or store your password for those services, and the access tokens that keep a connection working are encrypted at rest.

  • Google Calendar (currently available) — when connected, we read events from the calendars you choose, to detect your habits and keep your brief current, and (only if you enable it) write reminders back to your calendar. You control which calendars sync and can revoke access at any time. Google’s use of your data is governed by Google’s own policy.

As we add more connections (for example fitness trackers), we will update this section to describe what each one reads and writes. In this version, finance is manual-entry only — Steer does not connect to your bank. If we introduce bank connections in the future, we will update this policy first to explain exactly what is accessed and on what legal basis, and we will never store your bank login credentials.

7. Who we share your data with

We never sell or rent your personal data. We share it only with service providers (processors) who act on our instructions and under contract, strictly to run Steer:

  • Hosting & database — our cloud infrastructure provider (EU region).
  • Payments — our billing provider (Chargebee) and the payment networks, to process subscriptions.
  • Email — our email provider, to send service and support messages.
  • AI — our AI provider, to generate your brief (section 4), under contract and barred from training on your data.

We may also disclose data where required by law or to protect our rights, and in the context of a corporate reorganisation (with appropriate safeguards). A current list of processors is available on request.

8. International transfers

Where a processor processes data outside the European Economic Area (for example our AI provider in the United States), we ensure an appropriate safeguard under Chapter V GDPR — an adequacy decision of the European Commission, the European Commission’s Standard Contractual Clauses, or another valid mechanism under Art. 46 GDPR, together with supplementary measures where needed. A copy of the relevant safeguards is available on request.

9. How long we keep your data

  • Account and content — kept while your account is active. When you delete your account, your data is permanently deleted and the deletion cascades to the goals, habits, finances, connections and history we hold for you (backups are purged on their normal rotation).
  • On request — you can delete your account, or ask us to erase your data, at any time (section 10), subject only to data we must keep by law.
  • Billing records — retained for the period required by Greek tax law (generally at least 5 years).
  • Support & legal records — retained for as long as needed to handle the matter and for the applicable limitation period for legal claims.

10. How we protect your data

We apply technical and organisational measures appropriate to the risk, and continuously work to protect your data against threats:

  • encryption of data in transit and at rest;
  • passwords stored only as a secure one-way hash; access tokens for connected apps encrypted before storage;
  • strict, least-privilege access controls, with every request scoped to the signed-in user;
  • monitoring, backups and safeguards against unauthorised access, loss or misuse.

No system is perfectly secure, but we take protecting your information seriously and review our measures over time.

11. Your rights

Under the GDPR you have the right to:

  • access your data and obtain a copy;
  • rectify inaccurate or incomplete data;
  • erase your data (“right to be forgotten”);
  • restrict or object to certain processing;
  • data portability — receive your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting prior processing.

You can exercise the main rights directly in Steer: export all of your data or delete your account from Settings → Data & Privacy. For any other request, contact our data protection team at [email protected]. We respond within the time limits set by the GDPR (normally one month).

12. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. The AI brief and habit predictions are suggestions, generated with human oversight of the service, that you decide whether to act on.

13. Cookies

Steer uses only the strictly necessary cookies required to sign you in and keep the app working securely. We do not use advertising or third-party tracking cookies.

14. Children

Steer is intended for adults aged 18 and over. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact us and we will delete it.

15. Supervisory authority

You have the right to lodge a complaint with a supervisory authority. In Greece this is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) — Kifisias 1-3, 115 23 Athens; tel. +30 210 6475600; www.dpa.gr. We would appreciate the chance to address your concern first.

16. Changes to this policy

We may update this policy to reflect new features or legal requirements. We will post the updated version with a new “last updated” date and, for material changes, notify you on a durable medium.

17. Contact

For any question about your data or this policy, contact our data protection team at [email protected], or write to APEX LABS Ε.Ε., Pl. Ippodameias 8, 18531 Piraeus, Greece.

This document is provided for transparency and is tailored to Steer. It should be reviewed by qualified legal counsel before being relied upon.