Privacy and security
Stenz assistant connections use OAuth. You sign in on Stenz and approve named permissions; you never give ChatGPT or Claude your Stenz password, API key, or client secret.
Data boundaries
Section titled “Data boundaries”- Every request is tied to one artist workspace and checked again on the server.
- OAuth scopes, subscription, connection policy, and ownership all apply independently.
- Client contact details, media, messages, and financial actions have narrower permissions than general workspace access.
- Search and list operations are bounded and paginated; they do not provide a cross-studio directory.
- Stenz records security-relevant actions so the studio can review what a connection attempted and completed.
The provider receives only the data returned for the tool call you asked it to make. Its own retention and model-training settings are governed by your provider account and agreement, so review those settings before connecting client data.
Untrusted client content
Section titled “Untrusted client content”Form answers, messages, filenames, and images may contain instructions written by a client or embedded by another system. They are treated as data. An assistant must not let that content override your request, grant permissions, select a new payment destination, or approve an action.
Keep access narrow
Section titled “Keep access narrow”Start with read-only permissions. Add write, client-detail, media, message, deposit, or invoice scopes only for a concrete workflow. Use allowlists and quiet hours when available. Pause a connection you are not using and revoke it when a provider account, device, or team member changes.
To revoke safely, follow the order in Permissions and approvals. For legal and privacy contacts, see Privacy and legal.