Privacy Policy
Last updated 30 August 2026
Steno is an OCR and annotation service for archives, libraries, and research teams. Almost everything we hold is material you uploaded in order to work on it, and we treat it as yours.
This policy covers steno-ocr.com and the Steno application. It is written to be read, not to be survived.
What we collect
- Account details
- Your email address, display name, and username. If you sign up with a password we store a cryptographic hash of it, never the password itself.
- Your content
- The files and pages you upload, the images derived from them, and the bounding boxes, recognised text, translations, notes, and review decisions your team records, along with the revision history of those annotations.
- Session records
- For each sign-in we store a session token, the IP address, and the browser user agent. This is what lets a session expire and what lets a password reset end the others.
- Demo requests
- If you use the demo form on the public site, the name, organisation, email address, message, page language, and IP address you submit. These are kept apart from accounts, because whoever writes to us may never hold one.
We run no analytics, advertising, or tracking software of any kind. There is no third-party script on this site watching what you do.
Signing in with Google
Google sign-in is optional; an email address and a password work just as well. If you do use it, we ask Google only for the standard sign-in scopes: your email address, your basic profile (name and profile picture), and your Google account identifier. We request no access to Gmail, Drive, Contacts, Calendar, or any other Google service, and we could not read them if we wanted to.
We use what Google returns for exactly one purpose: creating your Steno account and signing you in. We do not sell it, pass it to anyone, use it for advertising, or train any model on it. If a Steno account already exists under the same verified address, Google sign-in attaches to that account rather than making a second one.
Because Google never shows you our sign-up form, we ask for a display name and a username the first time you arrive. Both are yours to change later in your settings.
What we use it for
- Running the service
- Storing your pages, running OCR over them, and showing your team its own work and nobody else's.
- Transactional email
- Address verification, password resets, email-change confirmations, team invitations, and a notice to you if someone tries to sign up with your address. We send no marketing email.
- Keeping the service standing
- Rate limiting, abuse prevention, diagnosing faults, and enforcing the page and storage limits of a plan.
OCR, translation, and model training
OCR runs on hardware we operate ourselves in Hong Kong. Your pages go to a vision-language model we host; they are not sent to OpenAI, Google, Anthropic, or any other model provider.
Translation is on by default. A team's owner or manager can turn it off in that team's settings. While it is on, the recognised text of the pages that team asks to translate, never the page images, is sent to Google Cloud Translation, a Google service that runs outside Hong Kong, and the translations it returns are stored in the team's workspace. Turning translation off stops any further text from being sent; it does not delete translations already stored.
Pages your team reviews to a gold standard can be used to fine-tune a model for that team, and that model serves that team. We do not train a shared or general model on your content, and one team's material never improves another team's results.
Cookies and browser storage
We set one cookie: the session cookie that keeps you signed in. It is httpOnly, so no script can read it, it expires after seven days, and it carries a five-minute cached copy of your session so that every page load need not query the database. There is no advertising or analytics cookie.
Your light or dark theme preference is kept in your browser's local storage and is never sent to us.
Cloudflare, which carries traffic to the site, may set its own cookie to tell automated traffic from people.
Where your data is stored
Steno runs on our own servers in Hong Kong, and the database is ours. Uploaded files are held in our own object storage by default; teams on a paid plan may instead have theirs in Google Cloud Storage in the asia-east2 (Hong Kong) region. A team's files always live in exactly one of the two, never split between them.
Who else handles your data
- Sign-in only, and only if you choose it. Google learns that you signed in to Steno.
- Resend
- Delivers our transactional email, and so handles the recipient address and the message.
- Cloudflare
- Carries traffic to the site and routes mail sent to our contact address, and so sees request metadata such as IP addresses.
- Google Cloud Storage
- Stores uploaded files for teams on a paid plan, in Hong Kong.
- Google Cloud Translation
- Translates recognised text for teams that turn translation on; outside Hong Kong.
That is the complete list. We do not sell personal data and we do not share it with advertisers or data brokers.
How long we keep it
- Your account and content
- Until you ask us to delete them.
- Sessions
- Seven days, or sooner if you sign out or reset your password.
- Verification and reset links
- Short-lived, and spent the moment they are used.
- Finished OCR jobs
- Pruned automatically once they are no longer needed.
- Demo requests
- Kept as our record of who asked to speak with us, until you ask us to remove yours.
Deleting your account
There is no self-service delete button yet. Write to [email protected] from the address on the account and we will do it.
Deleting an account removes its sessions, its sign-in methods, its team memberships, its notes, and its personal workspace with every project, file, and image in it, stored objects included. Work you contributed to someone else's team stays with that team; where a record must survive, your name is detached from it rather than the record being destroyed.
Your choices
Your name, username, email address, and password are yours to change in your settings at any time.
Ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it, by writing to [email protected]. Your content itself needs no request: everything you produce in Steno exports in open formats from the app.
We are based in Hong Kong and handle personal data under the Personal Data (Privacy) Ordinance. If you are somewhere that grants you further rights over your data, write to us and we will honour them.
Security
Passwords are stored hashed. Uploaded objects are private and reachable only through an authenticated proxy, never from a public bucket URL. Access to a team's material is re-checked on the server on every request rather than merely hidden in the interface.
No system is faultless. If you find a security problem, write to [email protected] and we will answer.
Children
Steno is a tool for professional and research work and is not directed at children.
Changes to this policy
If we change this policy we will change the date at the top. If a change materially affects how we handle your data, we will tell account holders by email rather than leaving them to notice.
Contact
Questions about this policy, or a request about your data: [email protected].