Privacy Policy

Effective date: 23 August 2026

This Privacy Policy explains how Stem-Notes, operated by Individual Entrepreneur Resh Krist Alexander ("we", "us", or "our"), collects, uses, retains, and shares information when you use our website and app (the "Service"). We are the controller of personal data processed for the Service.

1. Information we collect

  • Account and profile data: name, email, username, avatar, phone number (if provided), and organization membership details.
  • Content you create: documents, notes, titles, icons, cover images, and other content you add to the Service.
  • Files and attachments: images, PDFs, text files, and other files you upload.
  • Collaboration data: shared documents, access permissions, and real-time edits.
  • AI assistant data: prompts, messages, and outputs if you use AI features.
  • Calls and meetings: identifiers, timestamps, and audio/video streams when you use video calls; recordings if you enable them.
  • Payment and subscription data: plan, amount, currency, order and transaction identifiers, payment status, and payment credentials or tokens returned by LiqPay while needed to manage an active subscription. LiqPay collects card details through its hosted payment flow.
  • Optional integration data: access credentials and selected content for services such as Google Calendar or Trello when you connect them.
  • Usage and technical data: device and browser information, IP address, logs, and diagnostics.

2. How we use information

  • Provide and operate the Service.
  • Authenticate users and secure accounts.
  • Store and sync your documents and files.
  • Enable collaboration, sharing, and publishing.
  • Provide AI features and improve responses.
  • Facilitate video calls and meetings.
  • Maintain safety, prevent abuse, and debug issues.
  • Comply with legal obligations.

We process information as necessary to perform our contract with you, comply with legal obligations such as accounting requirements, and pursue legitimate interests such as securing and troubleshooting the Service. We rely on consent only for genuinely optional processing where consent is requested and may be withdrawn.

3. Sharing and disclosure

We share information only as needed to provide the Service:

  • Clerk for authentication and account profiles.
  • Our PostgreSQL and Qdrant infrastructure for application data and AI-memory vectors.
  • EdgeStore and its content delivery infrastructure for uploaded files.
  • Stream for chat and video features.
  • Google Gemini for AI processing and Google services for optional calendar/workspace integrations.
  • LiqPay for payment and subscription processing.
  • Trello when you choose to connect a Trello account.
  • Legal and safety purposes when required by law or to protect rights and security.

We do not sell your personal data.

4. Public and shared content

If you publish a document, it becomes accessible to anyone with the link. Shared documents may be visible to collaborators or organization members depending on your settings.

When a publicly accessible uploaded file is deleted, we remove it from active origin storage. A copy already delivered through a content delivery network (CDN) may remain temporarily accessible at its existing URL until the provider cache expires.

5. AI features

If you use the AI assistant, your prompts, messages, and attached files may be processed by Google Gemini to generate responses. Embeddings used for AI memory are stored in our Qdrant infrastructure. Avoid submitting sensitive data that you do not want processed by automated systems.

6. Cookies and similar technologies

We use essential cookies and local storage to keep you signed in, remember preferences, and operate the Service. You can control cookies in your browser settings.

7. Data retention

We retain account data and personal Service content while your account is active and the information is needed to provide the Service. Account deletion removes the account and personal content from active systems through a provider-by-provider erasure workflow. Organization-owned documents remain available to the organization, but the deleted user's author identifier is replaced with a deleted-user marker.

After deletion, we may retain minimized payment and accounting evidence for the period required by applicable Ukrainian tax or accounting law, or longer when an audit, dispute, or legal hold requires it. We remove direct account identifiers and stored payment credentials from those records where they are not legally necessary.

Operational logs and rolling backups may persist until their scheduled rotation and are restricted from ordinary use. If a backup is restored, completed erasures must be reapplied before normal processing resumes. Transient CDN copies expire under the provider's cache controls.

8. Security

We use reasonable technical and organizational measures to protect your data. No system is completely secure, and we cannot guarantee absolute security.

9. Your rights

Depending on your location, you may have rights to access, correct, erase, restrict, or export your data, object to certain processing, withdraw consent where processing relies on consent, and complain to a competent data-protection authority.

You may request account erasure while signed in at /account/delete or contact us using the address below. We may request information needed to verify your identity. We respond without undue delay and, for requests governed by the GDPR, normally within one month of receipt.

The right to erasure is not absolute. We may retain specific information where processing is required by law or necessary to establish, exercise, or defend legal claims. If we refuse all or part of a request, we will explain the applicable reason and available complaint rights.

10. International transfers

Our service providers may process data outside your country. Where a cross-border transfer requires safeguards, we use the provider's applicable contractual or other lawful transfer mechanism. You may contact us for information about safeguards relevant to your data.

11. Changes to this policy

We may update this policy from time to time. The effective date will be updated when changes are posted.

12. Contact

If you have questions or requests, contact us at [email protected].