Private beta
Privacy Policy
This is the private-beta version of our Privacy Policy. Stockmeta is in a private beta run by Mariusz Ostoja-Świerczyński, Pabianice, Poland. Until Stockmeta sp. z o.o. is registered, he is the controller of your personal data. During the beta no real payment is taken (see 3.5). Before Stockmeta launches, a new version of this policy will apply, and we will email you before it takes effect.
This policy explains what personal data we collect when you use Stockmeta, why we collect it, who we share it with, and what rights you have.
The controller of your personal data is Mariusz Ostoja-Świerczyński, Pabianice, Poland, who runs Stockmeta during the private beta ("we", "us"). You can reach us about anything in this policy at support@stockmeta.ai.
We have not appointed a Data Protection Officer, because we are not required to. Privacy questions go to the address above.
1. What this policy covers
1.1 This policy covers the Stockmeta online service (the account portal and metadata generation), the Stockmeta desktop application, and our website at stockmeta.ai.
1.2 The desktop application can be used without an account. In that mode it works entirely on your own computer and we receive no personal data from it, other than as described in clause 3.7.
2. The short version
- We ask for as little as possible: an email address, and a name if you give one.
- We do not store your photographs. They pass through our systems to be analysed and are not retained by us; our AI model provider keeps them only for a limited period (see 3.3).
- We do not use your photographs to train AI models, and we do not sell your data.
- Your account data is held in the European Union.
- Marketing email is opt-in only and never a condition of using the Service.
- During the beta, payments are simulated: no real money changes hands.
The rest of this policy sets out the detail.
3. What we collect and why
3.1 Account data
Your email address, a canonicalised form of it, your name if you provide one, how you signed up, your plan, your account status, and whether you have opted in to marketing.
We need this to create and run your account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
The canonicalised email — the same address with formatting variations removed — exists to stop one person creating many accounts to collect the signup bonus repeatedly. Legal basis for that use: our legitimate interest in preventing abuse (Art. 6(1)(f)).
3.2 Sign-in data
Stockmeta has no passwords. You sign in either with Google or with a code or link we email you.
- Google sign-in. Your browser sends us a token from Google which we verify. We store the identifier Google assigns to your account and your email address. We do not receive your Google password and Google does not receive your Stockmeta activity.
- Email sign-in. We create a short-lived record holding a hashed sign-in code and link, valid for about ten minutes, single-use, with a limit on failed attempts.
We also keep a session record while you are signed in, referenced by a cookie, expiring after about 30 days of inactivity.
Legal basis: performance of a contract, and legitimate interest in keeping accounts secure.
3.3 Photographs and generated metadata
When you use metadata generation, your image is transmitted from the desktop application through our processing infrastructure to our AI model provider, analysed, and the resulting metadata returned to you.
We do not store your images. They are not written to our databases and are not retained in our logs after processing. The generated metadata is returned to your computer and stored there, not with us.
Our AI model provider, Anthropic, does not use your images to train its models. Under its commercial terms it may keep them for a limited period for safety and abuse monitoring, as those terms set out.
Images may themselves contain personal data — faces of identifiable people, and location coordinates or other information embedded in the file by your camera. We process that data only to the extent it forms part of the image being analysed, and only for as long as the analysis takes.
Legal basis: performance of a contract. Where an image contains personal data about someone else, you are responsible for having the necessary basis to submit it, as set out in the Terms of Service.
3.4 Usage and metering data
The number of photos you have analysed, your remaining balance, which model was used, and timestamps. We need this to enforce plan limits. During the beta we also look at how much each account uses Stockmeta, to learn whether it is useful — which is what the beta is for.
Legal basis: performance of a contract, and our legitimate interest in improving the Service.
3.5 Payment data
During the beta no real payment is taken. If you try a paid plan, you do so through Stripe's checkout running in Stripe's test environment: nothing is charged and real cards are declined. We do not see or store card details. Stripe receives what you enter on its checkout page and handles it under its own privacy policy.
We receive from Stripe only what we need to run your account: which plan you chose, when, and whether the simulated payment went through.
3.6 Support, correspondence and feedback
If you contact us, we keep the message and our reply, together with your address and any information you choose to include — for example diagnostics or a log file you send us from the application. During the beta this also covers feedback you give us by email or in a call, and our notes of it.
Legal basis: performance of a contract where the query concerns your account, otherwise our legitimate interest in answering correspondence and improving the Service. Where a message is a formal complaint, we keep it to demonstrate we responded within the period the law requires — a legal obligation.
3.7 Technical and security data
Our servers record IP addresses and request metadata, used for rate limiting, abuse prevention and diagnosing faults.
The desktop application does not send us error or crash reports. Its log file stays on your computer unless you choose to send it to us (see 3.6). When it starts, the application checks a file on our download server (Google Cloud Storage, reached directly or through Cloudflare) for a newer version; like any web request this carries your IP address, but no account data.
Legal basis: legitimate interest in the security and reliability of the Service.
3.8 Marketing
If, and only if, you opt in, we send you occasional email about Stockmeta. Consent is asked for separately, is never a condition of registering, and you can withdraw it at any time using the link in every marketing message or by writing to us. Withdrawing it does not affect service messages such as sign-in codes, which are part of the Service.
Legal basis: consent (Art. 6(1)(a)).
3.9 Cookies and the website
The account portal sets one cookie: a session cookie that keeps you signed in. It holds a reference to your session rather than any personal data, and it is strictly necessary to operate the Service — without it you could not stay signed in. No consent is required for a cookie of this kind, and you cannot refuse it while continuing to use the portal. It expires when you sign out or after about 30 days of inactivity. Legal basis: performance of a contract.
Our website at stockmeta.ai does not set cookies, does not run analytics, does not track you across sites, and loads no third-party content: even its fonts are served from our own site.
If this changes — if we add analytics or any other non-essential cookie — we will ask for your consent before setting it, and we will update this policy first. We will not add tracking quietly.
4. Who we share data with
We do not sell personal data and we do not share it for anyone else's marketing.
We use the following providers. Each processes data on our instructions, under a contract meeting the requirements of Art. 28 GDPR, except where noted otherwise.
| Provider | What they do | Where |
|---|---|---|
| Google Cloud | Hosts our servers and databases, and the application's download files | European Union |
| Anthropic | Provides the AI model that analyses images | United States |
| Brevo | Sends sign-in and service email, and marketing email if you opt in | European Union |
| Verifies your identity if you use Google sign-in | See clause 3.2 | |
| Stripe | Runs the simulated checkout during the beta, under its own privacy policy | See clause 3.5 |
| Cloudflare | Serves our website and our download address, and carries traffic to the account portal | Global network (see clause 5) |
We may also disclose data where the law requires it, or to establish or defend legal claims.
5. Sending data outside the EEA
Your account data stays in the European Union. It is held in data centres located within the EU.
One transfer leaves the EEA by design: images are sent to Anthropic in the United States for analysis, and the generated metadata comes back. This transfer is covered by the European Commission's Standard Contractual Clauses, which are part of Anthropic's Data Processing Addendum and its commercial terms. The images are not retained by us, and our agreement with the provider governs what they may do with them.
Cloudflare's network may carry requests to our website, download address and portal through servers outside the EEA. Those transfers are covered by Cloudflare's certification under the EU–US Data Privacy Framework, with the Standard Contractual Clauses in its Data Processing Addendum as a second basis.
If you never use metadata generation, none of your images leaves the EEA through us.
6. How long we keep things
We keep personal data only as long as we need it for the purpose we collected it for.
- While your account is open, we keep your account, sign-in and usage data. When you ask us to close your account, we delete it within 30 days, except for data listed below that we must keep longer.
- Short-lived technical data — sign-in codes, sessions and security logs — is deleted automatically: sign-in codes within minutes, everything else within 30 days.
- Data we must keep by law — correspondence about complaints — is kept for the period the law requires, or until claims relating to it can no longer be brought.
- Notes of beta feedback are kept while they help us improve Stockmeta, and no longer than 180 days, unless you ask us to delete them sooner.
- Marketing consent is kept until you withdraw it. After that we keep only a record that you withdrew, so we don't contact you again.
- Images are not retained by us at all.
7. Your rights
You have the right to:
- access your data and get a copy;
- correct it if it is wrong;
- have it deleted, where we have no overriding reason to keep it;
- restrict what we do with it while a dispute is resolved;
- portability — receive data you gave us in a machine-readable form;
- object to processing based on our legitimate interests;
- withdraw consent to marketing at any time, without affecting anything done before you withdrew it.
To use any of these, write to support@stockmeta.ai. We will respond within one month. If your request is complex we may extend that, and will tell you if we do.
To close your account and have your data deleted, write to the same address; we delete it as described in clause 6.
Complaints. If you think we have handled your data wrongly, please tell us first — we would rather fix it. You also have the right to complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, or to the supervisory authority in the EU country where you live.
8. Security
We keep account data in a database that is not reachable from the public internet. Sign-in codes are stored hashed rather than in readable form. The credential the desktop application uses to reach our service is encrypted before storage. Access to production systems is limited to those who need it.
No system is perfectly secure, and we do not claim otherwise. If a breach occurs that is likely to put your rights at risk, we will tell you and the supervisory authority as the law requires.
9. Automated decision-making
The Service uses AI to generate metadata suggestions. That is a description of the product, not a decision about you: it produces no legal or similarly significant effect on you within the meaning of Art. 22 GDPR.
We apply automated checks at signup to prevent abuse — rate limits, and blocking of disposable email domains. These may prevent an account being created. If that happens and you think it is wrong, write to us and a person will look at it.
10. Children
Stockmeta is not for people under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
11. Changes to this policy
We may update this policy. If a change materially affects how we handle your data — including when Stockmeta sp. z o.o. takes over as controller — we will tell you by email at least 30 days before it takes effect. Older versions are available on request.
12. Contact
support@stockmeta.ai
Mariusz Ostoja-Świerczyński, Pabianice, Poland