Privacy Policy
This page explains what happens to data when you use this website or start a Roz trial. We keep the surface small on purpose — the less we collect, the less we have to protect.
Who we are
Roz is a product of StitchAI Pty Ltd, a company registered in New South Wales, Australia. For any privacy question, email hello@stitchai.com.au.
What we collect when you start a trial
When you submit your email through any sign-up form on this site, we store the following in a managed Postgres database hosted in Sydney by Neon:
- The email address you entered (lowercased, trimmed).
- A status indicating where you are in the sign-up flow (pending, verified, converted, unsubscribed, bounced).
- Timestamps for first seen, last seen, verified, converted and (if applicable) unsubscribed.
- A source tag (which form on the site you used) and any UTM parameters on your URL, so we can understand which marketing channels brought you in.
- The referring URL, if your browser sent one (up to 500 characters).
- Your country, as derived by Cloudflare.
- Your browser user-agent string (up to 200 characters).
- A one-way hash of your IP address — SHA-256 with a per-environment salt, so we never store the raw IP.
- A random unsubscribe token we generate, so future emails can include a one-click unsubscribe link.
- If you complete the sign-up, the identifier of your Clerk user account and workspace, so we can match lead activity to your trial.
We use this to send you the magic-link that completes sign-up, to follow up if you don't finish signing up, and to understand which marketing channels are working. We don't sell it, share it, or use it for advertising.
Resubmitting the same email updates the row's last-seen timestamp; we keep the first-touch source and UTM values so attribution stays stable.
We also send a user.signed_up event to PostHog, our product-analytics platform, when your sign-up form submission is a new lead. That event carries your email address, the source form, any UTM parameters, and whether the submission came from production or a non-production environment. This lets us measure how many people who start a trial go on to become customers, before you have an account or have signed in to anything.
What we collect when you use Roz
Once you're a customer, we hold the operational data your workspace runs on: rosters, shifts, availability, leave requests, and staff names and contact details entered by you or your employer, plus messages you send in team chat and to Roz, our AI assistant. This is collected when you or your workspace's managers enter it. It's stored in the same Neon Postgres database in Sydney as your trial data. We use it to run your workspace's rostering — building and publishing rosters, notifying staff of shifts, and powering Roz's answers.
Product analytics in the app (PostHog)
We use PostHog to understand how the app is used — which pages and features get used, and where people run into errors. This runs for every signed-in session; there's currently no separate opt-out for it.
PostHog automatically records page views and clicks (autocapture) in your browser, plus specific actions we send explicitly — for example publishing a roster or confirming a shift. Each event carries your Clerk user account id, so we can see usage per person, and your workspace id, so we can see usage per business. Once you're signed in, we also send PostHog your name and email address once, so events can be labelled with a person rather than a raw id, and we attach your workspace's name, plan, and subscription status to your account's workspace profile in PostHog.
PostHog also runs session replay — recordings of on-screen activity, used to see how the app is actually used and to debug problems. Every input value and every piece of page text is masked before a replay is captured, so replays show layout, clicks, and navigation, never the words on the screen or in an input. Request and response bodies are stripped from any network activity a replay captures. Uncaught errors in your browser are reported to PostHog for error tracking; error messages we send from the server are scrubbed first — any id-shaped value (a UUID, or a long number) is replaced with a placeholder — so an error report can't reveal which specific draft, staff member, or site it relates to.
Microsoft Teams
If your organisation uses the Roz bot in Microsoft Teams, then when you message Roz there, Microsoft passes us your message text, your Teams (Azure AD) user id, and the conversation id — the minimum needed to route Roz's reply back to you. We store that conversation reference so we can respond, and once you've connected via your invite link we link your Teams identity to your staff record in Roz. We don't receive your wider Teams data — only the messages you send Roz. Message content you send Roz is processed by Anthropic as described below.
What Clerk holds for authentication
Sign-in itself is handled by Clerk, a third-party auth provider. When you start a trial we ask Clerk to create a user account on your behalf; Clerk holds your email address, your verification status, and the session tokens that prove you're signed in. Clerk processes data in the United States.
AI processing by Anthropic
Roz's conversational features are powered by Claude, an AI model from Anthropic, a US company.
When you chat with Roz — in the app or on the web — we send Anthropic: your messages, any photos you attach, and the roster data needed to answer. That's shift dates, times, sites, and roles, staff names, and availability.
Anthropic uses this only to generate Roz's responses. Under our commercial agreement, Anthropic does not use it to train AI models, and retains it only briefly for abuse monitoring.
In the iOS app, we ask your permission before the first time Roz sends anything, and you can withdraw consent at any time in Settings → Data & Privacy. If you don't consent, Roz is disabled and no data is sent; the rest of the app works normally.
What we collect when you browse the site
We use Google Analytics 4 (measurement ID G-PTXGBE5DQJ) to understand aggregate traffic patterns — which pages people visit, which sources refer them, and how long they stay. IP addresses are anonymised before Google receives them (anonymize_ip: true). Google sets cookies to support this; they can be blocked in your browser or by an ad-blocker without affecting the site.
Cloudflare, which serves the site, collects standard request logs (IP, user-agent, URL) for security and performance reasons. See Cloudflare's privacy policy.
Where your data lives
Sign-up entries are stored in a Neon Postgres database in the Sydney (ap-southeast-2) region. Neon is operated from the United States; the database resides in their Australian region. Authentication state lives with Clerk in the United States. Google Analytics data is processed by Google on its global infrastructure. Data you send to Roz is processed by Anthropic in the United States. PostHog analytics events — both the trial-signup event and in-app product analytics — are processed on PostHog's US Cloud infrastructure.
How long we keep it
Sign-up entries are kept while you're an active Roz customer or trial user, and for a reasonable period afterwards so we can answer billing or audit questions. If you ask us to delete your account, we anonymise the row (your email is replaced with a placeholder) so funnel analytics stay intact without retaining your contact details. You can ask for full deletion of the anonymised row too.
To delete your Roz account and the personal data linked to it, follow the steps on Delete your Roz account.
Your rights
You can email hello@stitchai.com.au at any time to:
- Ask what we hold about you.
- Have your sign-up entry deleted or anonymised.
- Delete your Roz account. See Delete your Roz account for the steps.
- Correct an email address you submitted by mistake.
Australian residents: the Australian Privacy Principles under the Privacy Act 1988 apply to handling of your personal information. EU/UK residents: we honour GDPR data-subject requests on the same contact address.
Changes to this policy
If we change what we collect or how we use it, we'll update the "Last updated" date at the top of this page. Material changes will be flagged to active customers by email before they take effect.