1. Scope
This Policy applies to personal information we process when you visit stelrai.com, sign up for, or use the Service, or otherwise interact with us. It does not apply to third-party services, such as AWS, which have their own privacy policies.
2. Information We Collect
Account & billing
- Contact details (name, email, company, role).
- Subscription and plan information, including AWS Marketplace subscription status.
Service & technical
- API identifiers, AWS Marketplace customer identifiers, and usage events (for example, signing and verification requests).
- Log data: timestamps, request IDs, IP addresses, user agent, and device information.
- Operational metadata: content hashes, signatures, and provenance records generated by the Service.
Content you provide
- Text, documents, and associated metadata submitted for signing or verification. STELR's architecture is designed so that this content is processed and stored entirely within your own AWS account, using infrastructure our software deploys there. Your content and the signed artifacts and provenance records generated from it never leave your AWS account or reach STELR's own infrastructure.
Cookies
Our website uses cookies for essential functions, such as session management, and anonymized analytics. You can manage preferences through your browser settings.
3. Sources of Information
- Directly from you, through forms, uploads, or API calls.
- From authorized administrators on your account.
- Automatically, through Service usage such as logs and metrics.
- From AWS Marketplace, such as your customer identifier and subscription status.
- From third-party authentication providers, such as AWS IAM.
4. How We Use Information
- Provide, operate, and improve the Service, including signing and verifying content and agent actions.
- Generate and maintain provenance records and evidence.
- Authenticate and secure accounts, prevent misuse, and detect fraud.
- Meter usage and facilitate billing, including through AWS Marketplace.
- Communicate product updates, support responses, and security notices.
- Comply with legal obligations and enforce our Terms of Service.
5. How We Share Information
Your content, and the AWS services that sign and store it (including KMS, DynamoDB, Lambda, and S3), run entirely inside your own AWS account, deployed there by our software. We do not receive, process, or store your content. What STELR's own infrastructure does receive is limited to:
- Verification metadata: a public key and key identifier, published to STELR's public key registry so third parties can independently verify a signature without access to your AWS account. This is cryptographic metadata only, never content.
- Billing and usage metering: reported through AWS Marketplace's own metering service, which does not route through STELR's infrastructure either.
- Opt-in diagnostics: if you enable it, a fixed set of error-telemetry fields (error type, HTTP status, latency, model ID) with no content, prompt text, or output ever included.
- Account and subscription information: contact details and AWS Marketplace subscription status, handled through our own account infrastructure.
- Service providers: sub-processors for the above (monitoring, logging, support), under data processing agreements.
- Legal: to comply with law, respond to legal requests, or protect rights, safety, and security.
- We do not sell personal information or share it for marketing purposes.
6. Data Retention
Account data is retained for the duration of your contract plus 90 days, and log data for 12 months, unless a longer period is required by law. Your content and the signed artifacts generated from it are retained in your own AWS account, governed by your own configuration, we do not hold a copy to delete. To request deletion of account or billing data we do hold, contact privacy@stelrai.com.
7. Security
Signing operations use AWS KMS-backed cryptographic keys. No system is completely secure. You are responsible for safeguarding your API keys and should report suspected breaches to security@stelrai.com promptly.
8. Your Choices & Rights
Depending on applicable law, such as the GDPR or CCPA, you may have rights to access, correct, delete, port, or restrict processing of your personal information. Contact privacy@stelrai.com. If you're an individual user under an enterprise account, please contact your account administrator first.
9. International Transfers
We process data in the United States. If you are located in the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, we will ensure appropriate safeguards for international transfers, such as standard contractual clauses or other lawful mechanisms.
10. Children's Privacy
The Service is not directed to children under 13. If we learn we've collected personal information from a child, we will delete it. Contact privacy@stelrai.com with concerns.
11. Changes to This Policy
We may update this Policy. We'll post the new effective date, and provide notice by email or on our website for material changes. Continued use after changes take effect constitutes acceptance.
12. Contact Us
STELR, Inc.
Atlanta, GA
Email: privacy@stelrai.com