Legal
Privacy Policy
Last updated September 26, 2026
This page describes the information Struct collects when you use the website, dashboard, and device gateway, and how that information is used.
Information we collect
- Account. Email address, authentication credentials, and (if you use GitHub or Google sign-in) the identifier those providers send us.
- Organization. Workspace name, members, and roles (owner, admin, viewer).
- Devices and schemas. Device names, MAC addresses, tags, API keys, schema field definitions, optional encryption keys, and queued downlink commands.
- Telemetry. Authenticated uplink frames and the parsed JSON we store and show in the dashboard.
- Destinations. HTTPS webhook URLs you configure so we can forward parsed telemetry to your systems.
- Billing. Plan, device quantity, and Stripe customer identifiers needed to charge and show invoices. Card details are handled by Stripe, not stored in Struct.
How we use it
We use this information to run the service: authenticate you, accept and parse device frames, store telemetry for your plan’s retention window, send webhooks you configure, bill paid plans, and keep organization roles working.
Who processes it
- Supabase — account auth, database, and realtime dashboard updates.
- Stripe — paid-plan checkout, invoices, and the customer portal.
- GitHub and Google — optional sign-in, if you choose those buttons.
If you add a destination, we send parsed telemetry to the URL you provide. That system is under your control, not ours.
Retention
Telemetry retention follows the plan shown on Pricing: 24 hours on Free, 7 days on Flexible, and 30 days on Pro and Scale. This window also applies to delivery payload copies and packet traces. Replay nonces are removed after their security window; minimal event identities are kept for device deduplication. Account, organization, device, schema, billing, and audit records have separate lifecycles and may remain until you delete the workspace or a longer operational or legal retention period ends. Custom retention requires a separate agreement.
Cookies and local storage
We store a session so you stay signed in. The dashboard also keeps a few UI preferences in the browser, such as whether the sidebar is collapsed and which color mode you chose. We do not use advertising cookies.
Your choices
You can update account and organization settings in the dashboard, delete devices and workspaces you own, and sign out. For access or deletion of remaining account data, email sales@struct.dev.
Also see the Terms of Use.