Privacy Policy
Last updated: September 19, 2026
1. Introduction
Stompy ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI memory service.
2. Information We Collect
Account Information
When you create an account, we collect your email address and authentication credentials through our identity provider (Auth0).
Usage Data
We collect information about how you interact with our service, including:
- Contexts and memories you store
- Session metadata (timestamps, access patterns)
- API usage statistics
Technical Data
We automatically collect certain technical information, including IP addresses, browser type, and device information for security and analytics purposes.
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain the Stompy service
- Process and store your AI memory contexts
- Improve and optimize our service
- Communicate with you about updates and changes
- Detect and prevent fraud or abuse
4. Data Storage and Security
Your data is stored with the providers listed in section 6, in a database provisioned for your account. We use industry-standard encryption for data in transit (TLS) and at rest. Your contexts are isolated by project and only accessible to your authenticated account.
5. Data Retention
We retain your data for as long as your account is active. You can delete your projects and contexts at any time through the dashboard. Upon account deletion, all associated data is permanently removed within 30 days, except for records that a provider listed in section 6 must retain to meet legal obligations that apply to it.
Billing is the one such exception today. When you delete your account we ask Stripe to cancel your subscription, and the billing details we hold — your Stripe customer and subscription identifiers and your subscription status — are removed within the same 30 days. Stripe keeps its own record of the invoices and payments on your account in order to meet legal obligations that apply to it as a payment processor. Those records are held by Stripe rather than by us; we cannot delete them, and how long they are kept is determined by those obligations and by Stripe's own policy.
6. Third-Party Services (Subprocessors)
We rely on the following providers to operate the Service. Each receives only the data described, and only to provide its function:
- Neon - Managed PostgreSQL. Your projects, contexts, tickets and documents are stored here, in a database provisioned for your account.
- DigitalOcean - Application servers, caching and object storage for uploaded files.
- Auth0 - Authentication and identity management. Receives your email address and sign-in metadata.
- Cloudflare - DNS, CDN and DDoS protection. Receives request metadata such as IP address.
- Voyage AI - Generates the embeddings that make semantic search work. Receives the text of the content you store.
- OpenRouter, which routes to model providers includingOpenAI - Used for conflict detection, summarisation and related analysis. Receives the text of the content being analysed. See section 6a.
- Stripe - Subscription billing and payments. Receives your email address, your display name, an identifier for your account, and the plan you choose. Card and other payment details are entered on Stripe's own payment pages and are held by Stripe; they never reach our servers and we do not store them. Stripe returns your subscription and payment status so that we can apply your plan, and we ask Stripe to cancel your subscription when you delete your account. Stripe also creates its own record of the invoices and payments on your subscription; section 5 explains what happens to that record when you delete your account.
- Resend - Transactional email (invitations, reminders, account notices). Receives your email address.
- Plausible - Privacy-focused website analytics on our public pages. Does not use cookies and does not receive your stored content.
6a. Processing by Language Models
Some features send the text of content you store to third-party language model providers, listed above, so that they can be analysed. This is how conflict detection identifies contradictions between the things you have saved, and how related analysis features work. Only the content relevant to the request is sent. It is processed to return a result to you, and is not used by us to train models.
6b. Where Your Data Is Stored
Customer data is stored in the region assigned to your account at the time it is provisioned. Because providers and regions change as the Service grows, the current list of providers and processing locations is maintained on this page rather than fixed in a separate document; material changes are notified as described in section 9.
7. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data
- Export your data
- Opt out of marketing communications
8. Contact Us
If you have questions about this Privacy Policy, please contact us at hello@stompy.ai.