1. Scope
This Policy applies to personal information we process when you visit stelrai.com, sign up for, or use the Service, or otherwise interact with us. It does not apply to third-party services, such as AWS, which have their own privacy policies.
2. Information We Collect
Account & billing
- Contact details (name, email, company, role).
- Subscription and plan information, including AWS Marketplace subscription status.
Service & technical
- API identifiers, AWS Marketplace customer identifiers, and usage events (for example, signing and verification requests).
- Log data: timestamps, request IDs, IP addresses, user agent, and device information.
- Operational metadata: content hashes, signatures, and provenance records generated by the Service.
Content you provide
- Text, documents, and associated metadata submitted for signing or verification. We process this content to provide the Service and retain signed artifacts and provenance records based on your configuration.
Cookies
Our website uses cookies for essential functions, such as session management, and anonymized analytics. You can manage preferences through your browser settings.
3. Sources of Information
- Directly from you, through forms, uploads, or API calls.
- From authorized administrators on your account.
- Automatically, through Service usage such as logs and metrics.
- From AWS Marketplace, such as your customer identifier and subscription status.
- From third-party authentication providers, such as AWS IAM.
4. How We Use Information
- Provide, operate, and improve the Service, including signing and verifying content and agent actions.
- Generate and maintain provenance records and evidence.
- Authenticate and secure accounts, prevent misuse, and detect fraud.
- Meter usage and facilitate billing, including through AWS Marketplace.
- Communicate product updates, support responses, and security notices.
- Comply with legal obligations and enforce our Terms of Service.
Confirm before publishing: this draft does not include a model-training clause, since STELR does not currently use customer content to train models. If that changes, this section needs an explicit clause and an opt-out mechanism before publishing.
5. How We Share Information
- Infrastructure providers: Amazon Web Services (including KMS, DynamoDB, Lambda, SQS, Cognito, and CloudWatch) for hosting and processing.
- AWS Marketplace: metering records and registration tokens to resolve your customer identifier and manage subscriptions.
- Service providers: sub-processors for monitoring, logging, or support, under data processing agreements.
- Legal: to comply with law, respond to legal requests, or protect rights, safety, and security.
- We do not sell personal information or share it for marketing purposes.
6. Data Retention
Confirm before publishing: the retention periods below are placeholders and must match your actual practice once a retention schedule is finalized. As drafted: account data is retained for the duration of your contract plus 90 days, and log data for 12 months, unless a longer period is required by law. Content is retained according to your configuration. To request deletion, contact privacy@stelrai.com.
7. Security
Signing operations use AWS KMS-backed cryptographic keys. Confirm before publishing: claims about encryption at rest, encryption in transit, and specific protocol versions must match your actual implementation exactly, these become legal representations once published, not aspirational statements. No system is completely secure. You are responsible for safeguarding your API keys and should report suspected breaches to security@stelrai.com promptly.
8. Your Choices & Rights
Depending on applicable law, such as the GDPR or CCPA, you may have rights to access, correct, delete, port, or restrict processing of your personal information. Contact privacy@stelrai.com. If you're an individual user under an enterprise account, please contact your account administrator first.
9. International Transfers
We process data in the United States. Confirm before publishing: if you have or expect customers or users in the EU/UK, this section needs a real transfer mechanism, such as Standard Contractual Clauses, reviewed by counsel, not boilerplate carried over from a template.
10. Children's Privacy
The Service is not directed to children under 13. If we learn we've collected personal information from a child, we will delete it. Contact privacy@stelrai.com with concerns.
11. Changes to This Policy
We may update this Policy. We'll post the new effective date, and provide notice by email or on our website for material changes. Continued use after changes take effect constitutes acceptance.
12. Contact Us
STELR, Inc.
[insert registered business address]
Email: privacy@stelrai.com
Confirm before publishing: the previous version listed a "Data Protection Officer" and address that both looked like placeholder content. Naming a formal DPO is a specific legal designation, generally only required for certain companies under GDPR, don't include it unless you've actually designated one. I've removed it here rather than guess.