Stillbound · Trust
Where your data lives, what touches it, and what we will not claim. Written so your IT reviewer can answer “is this safe?” without booking a call.
Your distillery data — cask records, uploads, and the engine that works on them — is hosted and processed in the EU. The processing engine runs on EU compute in Amsterdam; your data is stored in managed EU Postgres. Account-level services (transactional email, error monitoring) run in EU regions too.
Web delivery uses a global edge network that defaults to the EU and can route via the EEA or US under EU Standard Contractual Clauses. It carries no cask records. EU-resident processing is a deliberate choice for European distilleries, not a default we inherited, and the specific provider behind each function is named in your Data Processing Agreement.
The Research list. If you ask to stay in the know on /research, we store your email address, the page you signed up from, the exact consent wording you saw, when you confirmed it, and a hashed IP for abuse control, in our managed Postgres on Supabase (eu-west-1); the list itself never leaves the EU and is never joined to enquiry or customer data. The confirmation and edition emails are delivered by Resend from its EU region, and every edition carries a one-click leave link that takes you off the list immediately, with no survey and no third-party list in between.
Stillbound is built using AI coding tools. That is a fact about how we work, not about where your data goes.
The product runs on deterministic services on our infrastructure. Your cask records are processed to provide the service. In normal operation they are not sent to a third-party large language model, and no customer data is used to train third-party AI models.
AI-assisted features that operate on your data are available as a separate tier. They run under a commercial provider contract with no-training terms, are listed on your DPA subprocessor schedule, and can be switched off for your account on request without renegotiating anything.
What we will not tell you: that the same records always produce a byte-identical answer. An engine that improves, gains rules, or corrects a calculation will sometimes return a better answer than it did last quarter — that is the product working. We would rather say that plainly than make a determinism claim we cannot stand behind. Every insight shows the inputs it used, so you can check the working rather than trust the label.
Your data is scoped to your account. Every request is authorised against your tenant, and a request carrying another tenant’s credentials is rejected.
That is enforced by the database, not only by our application code. Row-level security policies sit underneath every tenant-scoped table, so a bug in our own query layer that forgot a filter would still return nothing. We verify it directly rather than assuming it: a session authenticated as one distillery, explicitly asking for another distillery’s casks by name, returns zero rows. A session carrying no tenant claim at all returns zero rows across every table we checked. The check is scripted and re-runnable, so it is a standing test rather than a one-off assurance.
| Function | Region |
|---|---|
| Supabase — managed Postgres, authentication & object storage | EU |
| Fly.io — processing engine compute | EU (Amsterdam) |
| Vercel — web hosting & edge delivery | EEA / US (defaults EU) |
| Resend — transactional email | EU region |
| Sentry — error monitoring (personal data scrubbed) | EU region (Germany) |
| Optional AI providers — contracted tiers only | Commercial, no-training terms |
The authoritative subprocessor schedule is in your Data Processing Agreement. We give at least 30 days’ notice before adding a new subprocessor and you may object on reasonable data-protection grounds. Any transfer outside the EEA is governed by the EU Standard Contractual Clauses, relied on with the EU–US Data Privacy Framework where a US provider is certified.
We would rather tell you what we have than imply more.
Demo on synthetic data first. NDA before real data. DPA and statement of work before any production processing. We are happy to complete your vendor security questionnaire — email hello@stillbound.ai.
This page describes current operation and is maintained alongside the product. The binding commitments are in your Data Processing Agreement and Terms: DPA · Terms · Privacy. Reviewed August 2026.