Trust and data use

Privacy Policy

Last updated: August 4, 2026

YourStasis handles the content you ask it to capture, enrich, review, and export. This page explains the hosted, BYOK, local, account, and Google boundaries.

Short version

Provider keys remain local-only. Account snapshots are sanitized. Google export happens only after you connect Google and choose an export action.

Information the product handles

Optional screenshot fallback

Screenshot fallback is off by default. After an explicit current-tab capture, the Chrome extension may create one low-detail image only when selected text, visible snippets, headings, and metadata do not provide enough context. The image is bounded to reduce data and model cost, sent once to the configured model provider, and then discarded.

No screenshot history: the image is not saved to extension storage, pending actions, rows, logs, canonical memory, or account snapshots. If visual capture is unavailable, enrichment continues with text context.

Google export history

After a successful New Sheet or New Doc action, YourStasis keeps up to 20 recent created-file links. Signed-in users can include this non-secret history in their account settings snapshot so the same destinations are available on another surface.

Links, not contents: export history does not contain OAuth tokens, spreadsheet values, document contents, provider keys, or source-page excerpts. You can clear the list in Settings.

Optional Google Workspace reading

Google Workspace reading is off by default. When you enable it and explicitly capture an open Google Doc or Google Sheet, the Chrome extension asks Google for a bounded excerpt from that exact file: at most 1,200 characters from the Doc, or the first 20 rows and 26 columns from the Sheet. Existing Google file permissions still apply.

No background Drive scan: the extension does not browse arbitrary Drive content. OAuth tokens remain in memory, and source excerpts are not written to extension storage, rows, logs, pending actions, canonical memory, or account snapshots.

Internal platform analytics

The hosted service may calculate day-level aggregate adoption, usage, and reliability metrics from existing server records. These metrics help the product Owner understand whether enrichment works, which model routes are used, and where errors occur. They are not a customer-facing analytics product and are not available to normal, Support, or Admin accounts.

Content is excluded: platform analytics do not select or return resource URLs, titles, page content, Prompt text, model input or output, credentials, emails, or account identifiers. Buckets with fewer than five accounts are suppressed.

How data moves

Hosted and hosted BYOK

Captured content can be sent to the YourStasis API and to the active provider configured for enrichment, such as OpenRouter or OpenAI. Hosted BYOK uses the hosted API but keeps your provider key local to the surface where you entered it.

Local / Ollama

When you choose local mode, the client calls the API and provider endpoints on your machine, such as localhost:8787 and localhost:11434. Do not point hosted mode at a localhost provider.

Outbound delivery to your endpoints

Push to API, managed webhooks, and the ApplyOS connector send the enriched rows you choose to the exact endpoint you configure and nowhere else. These outbound paths are opt-in and default-off.

Signed and sealed: managed webhooks are HMAC-signed, and the hosted ledger stores only a payload hash and metadata, never the row body. Endpoint credentials are excluded from account snapshots and sync only inside the encrypted secrets bundle.

Account sync

Account snapshots are designed for cross-surface continuity. They can include sanitized settings, prompt presets, workspace rows, usage, logs, copy/export state, and provider-key status.

On by default: syncing across your own devices is enabled unless you turn it off, so a record captured in the browser extension, the desktop app, or the mobile app appears on the others. This covers your own signed-in devices only — nothing is shared with another person unless you publish a list and invite them by email. Turn it off under Account › Sync across my devices, and this device keeps its records local.
Keys are not synced: snapshots reject raw API keys, sessions, passwords, direct keys, and privileged Supabase credentials. If you share an account snapshot or debug log, remove any locally stored secrets first.

Loading a snapshot can merge account history into local history, replace local history, or be canceled when both surfaces already contain rows. An invite code may also be retained in local browser storage long enough to carry onboarding into account signup.

Google APIs and Drive export

Google Sheets export, Google Doc creation, and Google Workspace reading are user initiated. Export runs after you choose to append to a Sheet, create a Sheet, or create a Doc from the selected rows. Workspace reading runs only after you enable it and explicitly capture the open Doc or Sheet. Neither workflow bypasses file permissions or scans arbitrary Drive content. Google API information is used only to provide the requested workflow and is handled under the Chrome Web Store User Data Policy, including Limited Use requirements.

Storage, retention, and deletion

What we do not do

Who is responsible, and how to reach us

The data controller for personal data processed through the Service is GrowthNodes ApS (Denmark), operating as YourStasis. For all privacy matters — questions, rights requests, or complaints — contact info@yourstasis.com. We respond to verified requests within the timelines described below.

Enrichment samples and service improvement

To improve enrichment quality, the hosted service retains bounded enrichment signals and the rows you accept or edit at copy/export time, linked to your account tenant. These samples exclude provider keys, passwords, sessions, and encrypted secrets. They are used solely to tune enrichment behavior — for example, learning which model routes produce rows you keep versus rows you correct — and never for advertising.

Your control: deleting your account removes account-scoped hosted data, and you can ask us to remove retained samples at any time via info@yourstasis.com.

Legal bases for processing (GDPR)

We process personal data under the EU GDPR on these bases:

Your rights and how to exercise them

Depending on your location, you may have rights to access, correct, delete, restrict, or receive a portable copy of your personal data, to object to processing based on legitimate interests, to withdraw consent, and to lodge a complaint with a supervisory authority — in Denmark, Datatilsynet, or the authority of your place of residence.

Use the built-in tools first — they are faster than a formal request:

For anything the built-in tools do not cover, email info@yourstasis.com. So that we never disclose personal data to the wrong person, the following applies to formal requests:

California privacy rights (CCPA/CPRA)

Storage, transfers, and subprocessors

Retention

Security and breach notification

Data in transit is protected with TLS. Provider keys stay in local storage by design, and optional key sync is end-to-end encrypted on your device with a passphrase we never receive. Access tokens are scoped, and hosted observability excludes content and identifiers. No system is perfectly secure; if a breach affects your personal data, we will notify you and the competent authorities as applicable law requires.

Cookies and site data

This website sets no advertising or analytics cookies and loads no third-party trackers. The only site storage used is a short-lived local record of a referral code you arrived with, which is validated, carried into signup on this origin only, and cleared after account creation.

Children

The Service is not directed to children under 13 (or the higher local age of digital consent), and we do not knowingly collect their data. If you believe a child has provided us personal data, contact info@yourstasis.com and we will delete it.

Changes to this policy

We will update this page as the Service evolves and give reasonable notice of material changes on this site or by email. The “Last updated” date above always reflects the current version. Liability for the Service is governed by the Terms of Service.