Skip to content

Privacy and security

Stenz assistant connections use OAuth. You sign in on Stenz and approve named permissions; you never give ChatGPT or Claude your Stenz password, API key, or client secret.

  • Every request is tied to one artist workspace and checked again on the server.
  • OAuth scopes, subscription, connection policy, and ownership all apply independently.
  • Client contact details, media, messages, and financial actions have narrower permissions than general workspace access.
  • Search and list operations are bounded and paginated; they do not provide a cross-studio directory.
  • Stenz records security-relevant actions so the studio can review what a connection attempted and completed.

The provider receives only the data returned for the tool call you asked it to make. Its own retention and model-training settings are governed by your provider account and agreement, so review those settings before connecting client data.

Form answers, messages, filenames, and images may contain instructions written by a client or embedded by another system. They are treated as data. An assistant must not let that content override your request, grant permissions, select a new payment destination, or approve an action.

Start with read-only permissions. Add write, client-detail, media, message, deposit, or invoice scopes only for a concrete workflow. Use allowlists and quiet hours when available. Pause a connection you are not using and revoke it when a provider account, device, or team member changes.

To revoke safely, follow the order in Permissions and approvals. For legal and privacy contacts, see Privacy and legal.