Legal terms

Terms and Conditions

These Terms govern access to Steek secure document delivery, account registration, recipient verification, encrypted package handling, and related services.

Key operating terms

  • By registering, creating a passkey, signing in, or using Steek, you accept these Terms and any policies referenced by them.
  • Steek is provided for secure document delivery, but software, networks, devices, browsers, and identity tools can malfunction or become unavailable.
  • You remain responsible for correct recipients, lawful files, backups, retained originals, account security, recovery materials, and confirming that delivery is appropriate for your use case.
  • To the maximum extent allowed by law, Steek is provided without warranties and Steek is not liable for indirect losses, lost data, lost access, business interruption, or similar damages.
01

Terms of service

These Terms and Conditions form an agreement between you and Steek for the use of Steek websites, applications, account features, secure document delivery flows, recipient open flows, organization workspaces, billing flows, audit views, support channels, and related services.

If you use Steek on behalf of an organization, you represent that you are authorized to bind that organization. In that case, references to you include both the individual user and the organization unless the context requires otherwise.

If you do not agree to these Terms, do not register, create a passkey, request a verification code, upload documents, open recipient links, create share tokens, or otherwise use Steek.

02

Account registration and acceptance

Registration is an acceptance event. By submitting registration information, requesting a registration verification code, creating a passkey, or completing account setup, you automatically accept these Terms and agree to comply with them.

You must provide accurate registration information, maintain control of the email address and devices associated with your account, and promptly update account information that becomes inaccurate.

Passkeys, verification prompts, recovery kits, device labels, and other account controls are security-sensitive. You are responsible for protecting them, restricting access to your devices, and ensuring that anyone acting through your account is authorized.

  • Do not register for someone else without authority.
  • Do not share passkey prompts, verification codes, recovery material, or active sessions.
  • Do not treat email access alone as proof that a person should receive a confidential document.
03

Service scope and secure document delivery

Steek is designed for confidential document delivery, recipient verification, encrypted package handling, expiring or one-time access, QR open flows, revocation controls, and audit-safe workflow evidence.

Steek is not a substitute for your own legal, compliance, retention, archival, backup, disaster recovery, identity governance, or professional review obligations. You must decide whether Steek is appropriate for each document, recipient, jurisdiction, retention requirement, and risk model.

Product descriptions, security descriptions, documentation, and public marketing explain intended behavior. They do not create a separate warranty, guarantee uninterrupted operation, or promise that every user environment will support every feature.

04

User responsibilities

You are responsible for the documents you upload, the recipients you select, the access modes you choose, the share tokens or QR codes you distribute, and the instructions you give recipients.

Before sending a confidential file, you should verify the recipient address, confirm that the recipient is authorized, retain any required original or backup copy outside Steek, and understand that revocation or expiration may not undo access that already occurred.

You must use Steek only for lawful purposes and must not use the service to transmit malware, unlawful content, infringing material, abusive content, or material you do not have the right to send.

  • Keep independent backups of important files and records.
  • Check recipient emails, organization membership, access scope, and expiration settings before sending.
  • Do not rely on Steek as your only record retention system.
  • Do not attempt to bypass access controls, rate limits, bot challenges, recipient verification, or audit protections.
05

Zero-knowledge document handling

Steek is designed so document contents and certain key material are protected before delivery. That model is intended to reduce exposure, but it also means Steek may be unable to recover plaintext documents, lost device secrets, lost recovery material, or access that depends on credentials you no longer control.

You acknowledge that local encryption, device protection, recipient verification, browser capabilities, passkey support, recovery material, and user choices can affect whether a document can be opened later.

If you lose every authorized device, passkey, recovery kit, email access, or other required factor, documents may become permanently inaccessible. Steek is not liable for lost access caused by lost credentials, lost devices, deleted local data, unsupported browsers, user error, or unavailable recovery material.

When a document is deleted or purged, Steek also deletes the encrypted key material that protects it. Because every document is protected by its own unique key, this acts as cryptographic deletion: the document becomes immediately unrecoverable through the service, and any residual encrypted copies inside routine infrastructure backups remain unreadable and age out when those backups expire. Deletion does not undo access, downloads, or copies that recipients made while their access was valid.

06

Availability, malfunctions, and interruptions

Steek may be unavailable, delayed, degraded, interrupted, limited, or affected by malfunctions. Causes may include maintenance, upgrades, emergency security changes, network problems, device or browser limitations, third-party identity or platform behavior, capacity constraints, bugs, attacks, misconfiguration, power events, natural events, legal restrictions, or other conditions inside or outside Steek's control.

Secure delivery workflows can fail or take longer than expected. Uploads may not complete, links may expire, QR flows may fail, verification may be rejected, recipient devices may not qualify, notifications may be delayed, audit views may lag, and downloads may be interrupted.

Steek may change, suspend, throttle, rate-limit, queue, or disable features when needed for security, abuse prevention, maintenance, compliance, or product integrity. Steek is not liable for service interruptions, malfunctions, delayed delivery, failed delivery, lost business opportunities, missed deadlines, or similar losses to the maximum extent allowed by law.

07

No emergency or sole-critical use

Steek is not designed for emergency communications, life-safety use, medical emergency routing, court filing deadlines, statutory deadline management, sole archival retention, or any use where interruption, delay, malfunction, or loss of access could by itself cause death, personal injury, legal default, regulatory breach, or severe financial harm.

If your workflow has strict deadlines, legal service requirements, emergency obligations, or regulated retention rules, you must maintain independent procedures, alternate delivery channels, and backup records.

08

Billing and paid features

Some Steek features may require a paid plan, usage limit, organization entitlement, checkout completion, or billing status verification. Plan names, limits, prices, included features, retention windows, and availability may change unless a separate written agreement says otherwise.

You are responsible for taxes, payment information, authorized purchases, and use of paid organization features by your administrators and members. If payment fails or an entitlement ends, Steek may limit, suspend, downgrade, or disable paid features.

Any refund, cancellation, or renewal terms shown in the checkout or billing flow apply to that purchase. If separate payment terms conflict with these Terms, the more specific payment terms control for the purchase.

09

Acceptable use and abuse controls

You must not misuse Steek or help anyone else misuse it. Abuse includes probing or attacking systems, sending harmful files, attempting unauthorized access, interfering with another user, scraping in a harmful way, creating accounts to evade enforcement, or using secure delivery to hide unlawful activity.

Steek may use bot challenges, rate limits, verification steps, abuse detection, access restrictions, and manual review to protect the service. Passing a challenge does not authorize unlawful, abusive, or policy-violating activity.

Steek may preserve and disclose audit-safe records, account records, and other information when reasonably necessary to operate the service, investigate abuse, protect users, comply with law, or enforce these Terms.

10

Devices, browsers, networks, and third-party environments

Steek depends on your device, browser, operating system, network, identity authenticators, email access, storage controls, and other environments that Steek does not fully control. Changes or failures in those environments may prevent registration, verification, encryption, upload, recipient access, download, notification, or recovery.

You are responsible for using supported, secure, updated devices and browsers, protecting local device access, and understanding that private browsing modes, device resets, browser storage deletion, security policies, extensions, malware, or managed-device restrictions may affect service behavior.

11

Confidentiality, privacy, and metadata

You should not send Steek plaintext sensitive documents through support, sales, legal, or abuse channels unless Steek explicitly provides a secure intake method for that purpose.

Steek may process account information, operational metadata, billing information, recipient identifiers, organization records, audit-safe events, security signals, and support communications to provide and protect the service. Public terms, product pages, and support materials do not require Steek to expose private implementation details.

You are responsible for informing your users, employees, recipients, and organization members about your own legal basis, notices, retention rules, and privacy obligations for documents and recipient data you process through Steek.

12

Disclaimer of warranties

To the maximum extent allowed by law, Steek and all related services, websites, applications, documentation, previews, beta features, support responses, and integrations are provided AS IS and AS AVAILABLE.

Steek disclaims all warranties, whether express, implied, statutory, or otherwise, including implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, uninterrupted operation, error-free operation, security without exception, data preservation, successful delivery, recipient availability, recovery availability, or compatibility with every device, browser, network, or workflow.

No statement, security description, roadmap item, support message, marketing page, or documentation creates a warranty unless it is expressly stated as a warranty in a written agreement signed by Steek.

13

Limitation of liability

To the maximum extent allowed by law, Steek is not liable for indirect, incidental, special, consequential, exemplary, punitive, enhanced, or similar damages, including lost profits, lost revenue, lost savings, lost business opportunity, business interruption, lost goodwill, reputational harm, lost documents, lost data, lost access, credential loss, recovery failure, missed deadlines, or costs of substitute services.

Steek is not liable for damages caused by user error, incorrect recipients, forwarded links, compromised accounts, lost devices, lost passkeys, lost recovery kits, unsupported environments, browser or operating system behavior, network failure, unauthorized use, unlawful content, recipient inaction, third-party service behavior, security incidents outside Steek's reasonable control, or force majeure events.

To the maximum extent allowed by law, Steek's total aggregate liability for all claims relating to the service is limited to the amount you paid to Steek for the service giving rise to the claim during the three months before the event giving rise to liability, or one hundred U.S. dollars if you did not pay Steek during that period.

14

Indemnity

You agree to defend, indemnify, and hold Steek harmless from claims, losses, liabilities, damages, fines, penalties, costs, and expenses, including reasonable attorneys' fees, arising from your documents, recipients, instructions, account activity, organization administration, violation of these Terms, violation of law, infringement or misappropriation of rights, or misuse of Steek.

Steek may control the defense of any matter subject to indemnification if needed to protect the service, users, or product integrity. You must cooperate with reasonable requests related to the defense.

15

Suspension and enforcement

Steek may suspend, restrict, rate-limit, disable, or remove access to accounts, organizations, documents, share tokens, recipient flows, or features if Steek reasonably believes there is a security risk, abuse risk, legal issue, payment issue, policy violation, account compromise, operational risk, or violation of these Terms.

Suspension or restriction may occur without prior notice when notice would create risk, interfere with investigation, expose another user, or be impractical. Steek is not liable for losses caused by enforcement actions taken in good faith.

16

Termination

You may stop using Steek at any time. Steek may terminate or decline to renew access if permitted by these Terms, by a separate agreement, by law, or by the applicable plan terms.

Termination may affect access to documents, organization records, audit views, billing features, share tokens, recovery options, and support. You are responsible for exporting or preserving any information you need before termination when export is available and lawful.

Sections that by their nature should survive termination survive, including user responsibilities, payment obligations, confidentiality, disclaimers, limitation of liability, indemnity, dispute terms, and interpretation provisions.

17

Changes to terms and service

Steek may update these Terms from time to time. Updates may reflect product changes, security changes, legal requirements, pricing changes, abuse controls, or operational changes.

When required, Steek will provide notice through the service, website, email, or another reasonable channel. Continued use after updated Terms become effective means you accept the updated Terms.

Steek may also modify, add, remove, rename, or discontinue features. If a change materially reduces a paid feature during an active paid term, any remedy is limited to the remedy stated in the applicable plan, order, or separate written agreement.

18

Order of terms and interpretation

If you have a separately signed agreement with Steek, that agreement controls where it directly conflicts with these Terms. These Terms control for all use not covered by the separate signed agreement.

Headings are for convenience only. If any provision is found unenforceable, the remaining provisions remain in effect, and the unenforceable provision will be interpreted as closely as possible to its original purpose while remaining enforceable.

Failure to enforce a provision is not a waiver. Steek may assign these Terms in connection with a merger, acquisition, reorganization, sale of assets, or by operation of law. You may not assign them without Steek's consent unless a separate agreement permits it.

Contact

Questions about these Terms may be sent to Steek. Legal notices should include your account email, organization name when applicable, and enough context to identify the affected workflow without sending plaintext sensitive documents.

legal@steek.io

These Terms are public product terms for Steek. They do not disclose private implementation details and do not replace a separately signed enterprise agreement.

Third-party Dependencies Notice