Privacy Policy

Last updated August 21, 2026

Stele is operated by Akash T, a sole proprietor based in India, who is the controller of the personal data described here. This policy covers the Stele website, web app and browser extension. Privacy questions go to privacy@stele.so.

What we collect

  • Account data: your email address, the sign-in method you used, and a username and avatar if you set them.
  • Content you save: the elements, regions, recordings, bookmarks, notes and files you capture or upload, along with the source page URL and title and the metadata we derive from them, such as colours and generated code.
  • Billing data: Paddle collects and holds your payment details as merchant of record. We receive only your subscription status, plan, renewal dates and a customer identifier. We never see or store your full card number.
  • Product analytics: page views and a fixed allowlist of product events, such as a capture being saved. Autocapture is off and we do not use session replay, so nothing outside that list is recorded.
  • Technical data: our hosting and infrastructure providers log request data, including IP address, browser user agent and timestamps, so that the Service can run securely and errors can be diagnosed. Our host also measures aggregate traffic and page load speed without cookies and without an identifier that persists across visits.

Why we use it, and on what basis

  • To run your account, sync your library and provide the features you use, because we need to in order to perform our contract with you.
  • To take payment, issue receipts and meet tax and accounting duties, on the basis of that contract and our legal obligations.
  • To keep the Service secure, prevent abuse and understand which features are used, on the basis of our legitimate interest in a working, sustainable product, or your consent where local law requires it.
  • To email you about your account, your subscription and material changes to the Service. Marketing email is sent only if you opt in, and every such email can be unsubscribed.

We do not sell personal data and we do not use it for advertising.

Cookies and local storage

We use a small number of cookies that are strictly necessary to sign you in and keep your session valid. There are no advertising or cross-site tracking cookies. Your browser also holds data locally so the app works offline: your library is cached in IndexedDB, and an anonymous analytics identifier is kept in local storage until you sign in, at which point events are attributed to your account instead. Analytics requests from the web app are sent through our own domain rather than to a third-party host. Clearing your browser storage signs you out and removes the local copy of your library; nothing on the server is affected.

The browser extension

The extension reads a page only when you start a capture, and it sends the result to your library. It does not collect your browsing history. It reads the Stele session cookie on our own site so that signing in on the web signs you in in the extension; it reads no other site’s cookies. It reports a small number of usage events, such as that a capture was started, and those events contain counters and identifiers only, never page content. Those events are sent only while you are signed in, and go directly to our analytics provider.

On x.com, twitter.com and instagram.com the extension additionally watches the responses those sites load for themselves, because a video there is playable but not downloadable from the page. It keeps only an item identifier, a media address, and optionally a thumbnail address and an aspect ratio, in that tab’s memory. That list is capped, is discarded when the tab navigates away, is never written to storage, and is never sent to us or to anyone else. It is used only if you then choose to capture that specific item. You can turn this off in the extension’s options, under Site access, and nothing on those sites is watched afterwards.

On x.com and twitter.com, capturing a video may repeat the page’s own request for that one item, in your own logged-in session, when the response we needed has not already gone by. It happens only on a capture you started, never in the background. The same applies when you start an X or Pinterest import from Settings: the extension reads your own bookmarks or pins from your own logged-in session on that site. In both cases the credentials involved are your browser’s, are held only for the length of that one action, and are never stored, logged, or sent to us.

If an image cannot be fetched from the page you captured it from, the extension asks the Internet Archive whether an archived copy of that address exists. The page address is the only thing sent, and only in that case.

AI features

AI features are optional and can be switched on or off per feature in Settings. When one is on, the content it needs is sent to Google's Gemini API for processing and the result is returned to your library. We do not use your content to train models. If you would rather nothing leave our own infrastructure, leave these features off.

Who processes data for us

  • Supabase, for authentication and the primary database
  • Cloudflare, for asset storage and delivery
  • Vercel, for application hosting, request logs and cookieless traffic and page speed measurement
  • Paddle, for payments, as merchant of record
  • Resend, for transactional email
  • PostHog, for product analytics
  • The Internet Archive, for the archived-copy lookup described above
  • Google, for the AI features described above

Each processes data only to provide its part of the Service. We may also disclose data if we are legally required to, or to a successor if the business is ever transferred, in which case this policy continues to apply to the data transferred.

International transfers

We operate from India and the providers above process data in regions including the European Union and the United States. Where personal data leaves its region of origin, we rely on the transfer safeguards those providers offer, such as the European Commission's standard contractual clauses.

Keeping and deleting data

We keep your data for as long as your account is active. Content you delete is removed from your library immediately and cleared from backing storage during routine cleanup; copies can persist briefly in backups. When you ask us to delete your account we remove your library, your stored assets and your profile, and keep only what we must for tax and accounting. Payment records are held by Paddle under its own retention rules.

Security

Traffic is encrypted in transit. Each account's content is isolated from every other account, assets are served only to the origins that need them, and access to production systems is limited to those who require it. No service can promise perfect security, so we also recommend keeping your own export of anything you cannot lose.

Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict certain processing, and withdraw consent you have given. You can export your entire library as a .zip at any time from Settings, then Storage. For anything else, write to privacy@stele.so and we will respond within 30 days. If you are in the EEA or the UK you can also complain to your local data protection authority.

Children

Stele is not intended for anyone under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.

Changes

If we update this policy, the revised version is posted here with a new date, and material changes are announced by email or in the app before they take effect.

Contact

Privacy questions and requests: privacy@stele.so. Anything else: hello@stele.so.