Privacy policy
Last updated: 11 September 2026
1. Who is responsible
The controller for data processing on this website and in the Stratos app is:
Michael SezerMS Strategies (Einzelunternehmen)
Rämelgässli 96
3067 Boll
Switzerland
Email: kontakt@msstrategies.ch
Stratos is an offering of MS Strategies (Einzelunternehmen, sole proprietorship), owner Michael Sezer. For any privacy question, email us at the address above.
2. Summary
- We use no analytics, no tracking, no advertising pixels, and no third-party embeds.
- The public pages set no cookies and store nothing in your browser.
- When you start a free analysis, we fetch public pages of the website you enter and send their text to Google's Gemini API. The results are stored in a database in the EU (Frankfurt).
- During early access, project dashboards are not protected by a login. Do not enter confidential information (section 4).
3. Hosting and server logs
Stratos runs on our own server, rented from Hostinger International Ltd., Larnaca, Cyprus, in the data center in Frankfurt am Main, Germany. Until the ongoing move is complete, Vercel Inc., San Francisco, USA, also delivers the website and runs the app's server functions in its US data center region (Washington, D.C. area); after the move, Vercel only redirects requests to the former address (stratos-cmo.vercel.app).
When you open a page, the server and, where applicable, Vercel process technical data: your IP address, date and time, the URL requested, the referring page (if your browser sends it), and the browser identifier (user agent). Purpose: delivering the website and app, stability, and protection against abuse. Legal basis: our legitimate interest in a secure and working service (Art. 6(1)(f) GDPR; in Switzerland Art. 31(1) FADP). We do not analyze these logs, build no profiles, and do not combine them with other data. They are kept only as long as needed for operation and security.
4. Free analysis, strategy docs, and agents
What you enter: the website address and the target language (English or German). No name or email address is needed.
What happens: our server fetches the home page and up to four further pages of that website and extracts their visible text. This text is sent to Google's Gemini API (section 5), which writes five strategy documents. When you run an agent (SEO, Writer, Reddit, GEO, X, LinkedIn), the strategy documents and, where relevant, the keyword you picked are sent to the Gemini API again. The Reddit agent sends search terms derived from your strategy to reddit.com (Reddit, Inc., USA) from our server; your IP address is not passed on.
What we store: the website address, the brand name detected, the language, the strategy documents, the agent results, and generated articles, in a Supabase database in the EU region Frankfurt, Germany (Supabase, Inc. as processor). The website text itself is not stored, only what the AI generated from it. If sign-in is enabled and you are signed in, the project is also linked to your user ID.
Who can see it: during early access, a project dashboard is not protected by a login. Its address is derived from the analyzed domain (for example /dashboard/example-com), so anyone who knows or guesses it can view the project and run agents on it. Analyzing the same domain again replaces the stored project. Only submit public information about websites you are allowed to analyze.
Legal basis and retention: performance of the service you requested (Art. 6(1)(b) GDPR) and our legitimate interest in providing it (Art. 6(1)(f) GDPR). We keep a project until you ask us to delete it; send the domain to our email address and we delete the project with all agent results and articles.
5. Google Gemini API
To generate strategy documents, articles, posts, and GEO checks, we send the texts described in section 4 to the Gemini API of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google processes the content to generate the response and, under its Gemini API terms, may retain it for a limited time to detect abuse. Google LLC is certified under the EU-US and Swiss-US Data Privacy Framework.
6. Sign-in with a magic link (only when enabled)
Sign-in is not enabled on this deployment at the moment. When it is, you can enter your email address to receive a one-time sign-in link. Your email address and a user ID are stored by Supabase Auth in the EU region Frankfurt, and Supabase sends the sign-in email. After sign-in, Supabase sets strictly necessary session cookies (names starting with "sb-") that keep you signed in until you sign out or the session expires. Legal basis: Art. 6(1)(b) GDPR. We keep the account until you ask us to delete it.
7. Payments (only when paid plans are open)
Paid plans are not open for purchase yet. Once they are, payments are processed by Stripe (Stripe Payments Europe, Ltd., Ireland, together with Stripe, Inc., USA). Stripe collects your payment details directly on its checkout page; we receive your name, email address, plan, and payment status, never your full card number. Legal basis: Art. 6(1)(b) GDPR, and for invoices our legal duty to keep business records for 10 years (Art. 958f Swiss Code of Obligations). Stripe, Inc. is certified under the EU-US and Swiss-US Data Privacy Framework.
8. Cookies and local storage
The public pages and the free analysis set no cookies and write nothing to your browser's local storage. The only cookies Stratos can set are the strictly necessary sign-in cookies described in section 6, and only after you sign in. That is why there is no cookie banner. Copy and download buttons in the dashboard work locally in your browser.
9. Email
If you email us, we use your address and message only to answer you (Art. 6(1)(b) or (f) GDPR) and delete the message once the request is settled, at the latest after 12 months, unless we must keep it by law.
10. Transfers outside Switzerland and the EU
Vercel (until the move is complete, then only for redirects), Google, Reddit, and (once payments are open) Stripe may process data in the USA. For Vercel, Google, and Stripe, the transfer is based on their certification under the EU-US and Swiss-US Data Privacy Framework and on the European Commission's standard contractual clauses. The request to Reddit contains no personal data about you.
11. Your rights
You have the right to access your data, to correct it, to have it deleted, to restrict or object to its processing, and to receive it in a portable format (Art. 15 to 21 GDPR, Art. 25 and 28 FADP). Email us to use these rights.
You can also complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch), in the EU a data protection authority, in particular in the member state where you live.
12. Changes
We update this policy when the app or the services we use change. The version published here applies. See also our Terms of service.