Strova
StrovaPI
Features Pricing Contact
Sign in Start a project free →

Privacy Policy

Version 1.0 Effective 14 August 2026 Australian Privacy Principles
DRAFT — pending legal review. This policy describes how Strova actually handles data today and is published so customers can assess us. It has not yet been reviewed by a qualified Australian privacy lawyer. If you are evaluating Strova and need a reviewed and executed policy, or a Data Processing Agreement, contact support@strovapi.com.

On this page

1. Who we are 2. Controller and processor 3. What we collect 4. Why we collect it 5. Sensitive information 6. Who we share it with 7. AI processing 8. Overseas disclosure 9. Security 10. Retention and deletion 11. Your rights 12. Cookies 13. Data breaches 14. Changes 15. Contact and complaints

1. Who we are

Strova ("Strova", "we", "us") provides a project intelligence and document control platform for construction and infrastructure projects, available at strovapi.com and app.strovapi.com (the "Platform").

This policy explains how we handle personal information, and is written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").

2. Who controls the data — an important distinction

Strova holds two different kinds of personal information, and your rights differ between them.

CategoryWhat it isOur role
Account data Information about the people who sign up for and administer a Strova account — name, work email, company, role, billing contact. We are the controller. We decide how it is used.
Project data Everything a customer puts into the Platform — defects, RFIs, drawings, photographs, site diaries, inductions, worker competency records, correspondence. We are the processor. The customer (your employer or principal contractor) is the controller and decides what goes in, who sees it, and how long it is kept.

If you are a worker or subcontractor whose details appear in a project because a head contractor put them there, your first point of contact is that organisation, not Strova. We will help them respond, and we will act on their instructions, but we cannot delete or change their project records on your say-so alone. See §11.

3. What we collect

3.1 Information you give us

  • Account and profile: name, email address, company, job title, project role, and a password (stored only as a hash by Firebase Authentication — we never see it).
  • Project content: whatever is entered or uploaded — documents, drawings, photographs, mail, meeting minutes, defect and NCR records, site diaries, plant and equipment registers.
  • Site and workforce records: site sign-in and sign-out times, inductions completed, licences, tickets and competency evidence (including images of those documents), emergency contacts where a customer chooses to collect them.
  • Correspondence: email sent to or from a project address passes through the Platform and is stored as part of the project record.
  • Support requests, including any screenshot you attach.

3.2 Information collected automatically

  • Usage events — which module was opened, which records were created or closed. Used to understand what customers use and to bill metered features. It is not sold, and it is not used for advertising.
  • Error reports — when the app crashes we record the error, the page, the browser, and which workspace and project you were in. Email addresses and access tokens are stripped in your browser before the report is sent.
  • Server logs — standard request logs kept by Google Cloud.

We do not use third-party analytics, advertising trackers, or behavioural profiling tools.

4. Why we collect it

  • To provide the Platform and the features a customer has enabled.
  • To authenticate users and enforce who can see what.
  • To send transactional email — invitations, notifications, delivery failures. We do not send marketing email to project participants.
  • To meter and bill usage.
  • To diagnose faults and improve reliability.
  • To meet legal obligations and respond to lawful requests.

5. Sensitive information

Construction site records can contain sensitive information as defined by the Privacy Act — for example an incident report describing an injury, or a medical restriction recorded against a worker's induction.

Strova does not require this information and does not ask for it. Where a customer chooses to record it, they are responsible for obtaining the consent the Privacy Act requires. We process it only to provide the Platform, and it inherits the same access controls as the rest of that project's data.

If you are a customer configuring an induction or incident form, only collect what you actually need. Every field you add is a field you become responsible for.

6. Who we share it with

We do not sell personal information. We never have and we will not.

We disclose it to the following categories of recipient, and to no others:

RecipientPurposeLocation
Other users on the same projectThe Platform's core function. Visibility is controlled by the customer through project roles and company scoping.As configured
Google Cloud / FirebaseHosting, database, file storage, authentication.Australia (australia-southeast1/2)
SendGrid (Twilio)Transactional email delivery and inbound mail routing.United States
AnthropicAI features — see §7.United States
xAISecondary verification on some AI answers — see §7.United States
CloudConvertDocument format conversion where required.Germany
Professional advisers, or a lawful authorityWhere required by law, or to establish or defend a legal claim.—

If Strova is ever acquired or merged, personal information would transfer as part of that transaction. We would tell customers before it took effect.

7. AI processing

The Platform includes an AI assistant ("Stella") and several AI-assisted features such as document review and drafting help. You should understand precisely what this means for your data.

  • When you use an AI feature, the relevant project context is sent to Anthropic to generate the response. That can include record summaries, document text, and any file you explicitly attach.
  • Some answers are additionally checked against xAI.
  • Content is sent only when an AI feature is used. We do not feed your project data to a model in the background. The one exception is automatic SWMS review, which a customer can disable.
  • Strova does not use your project data to train any AI model, and our agreements with these providers prohibit them from doing so with data submitted through our API.
  • AI output is general information to assist your team. It is not legal, safety, engineering or professional advice, and it must be verified by a competent person before it is relied on.

If your organisation cannot send project data to a US-based AI provider, tell us — AI features can be disabled at the workspace level.

8. Overseas disclosure (APP 8)

Your project data is stored in Australia. Firestore, Cloud Storage and our Cloud Functions all run in Google Cloud's Australian regions.

Some processing necessarily happens overseas: email delivery (United States), AI features when you use them (United States), and document conversion (Germany). We take reasonable steps to ensure these recipients handle the information consistently with the APPs, but you should be aware that overseas providers are subject to their own local laws.

9. How we protect it

  • Encrypted in transit (TLS, HSTS enforced) and at rest (Google Cloud managed encryption).
  • Access controlled by server-enforced security rules, not merely hidden in the interface. Project membership, role, and company scoping are all evaluated on the server for every read and write.
  • Passwords are handled by Firebase Authentication and are never visible to Strova staff.
  • Credentials for third-party services are held in Google Secret Manager.
  • Nightly database backups, retained 90 days.
  • Error reports are scrubbed of email addresses and tokens in the browser, before transmission.

No system is perfectly secure, and we would rather say so than imply otherwise. Our current security posture, including known limitations, is described at /security.html.

10. How long we keep it

DataRetention
Project dataFor as long as the customer's account is active. Construction records often must be retained for years after practical completion; the customer decides.
After cancellationRetained for 90 days so the account can be reinstated or the data exported, then eligible for deletion.
Account dataWhile the account exists, plus any period required for tax and corporate records.
Backups90 days, then automatically deleted.
Error reportsRetained while diagnostically useful.

11. Your rights

Under APP 12 and APP 13 you may ask to access the personal information we hold about you, and to have it corrected.

If you are an account holder

Email support@strovapi.com. We will respond within 30 days. There is no charge for a reasonable request.

If your details appear in someone else's project

Contact that organisation first — they control the record and they are the ones who can change or remove it. If you cannot identify or reach them, write to us and we will pass the request on and tell you who we passed it to. We will not alter a customer's project records without their instruction, because those records are frequently contractual or safety documents where unilateral alteration would cause real harm.

12. Cookies and local storage

We use only what the Platform needs to work:

  • Authentication — keeps you signed in. Set by Firebase.
  • Preferences — your dashboard layout, saved filters and column choices, stored in your browser's local storage.

There are no advertising cookies and no third-party trackers. Blocking the authentication cookie will prevent sign-in.

13. Data breaches

We maintain a data breach response plan. If a breach is likely to result in serious harm, we will notify the affected customers and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where Strova is the processor, we will notify the customer promptly so they can meet their own obligations.

14. Changes to this policy

We will post any change here and update the version and effective date. For a change that materially reduces your privacy protections, we will give account holders reasonable notice by email before it takes effect.

15. Contact and complaints

Privacy enquiries and complaints: support@strovapi.com.

We will acknowledge a complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.

Strova
StrovaPI

Project intelligence for infrastructure and engineering-led projects.

Product

FeaturesPricingChangelogSecurity

Company

AboutContactCareers

Legal

Terms of ServicePrivacy PolicyCookies
© 2026 StrovaPIstrovapi.com