Skip to content
StayCharted
HomePricing
Solutions ⌄

Business Use Cases

Image ClassificationVisual Inspection & TriageSupport Ticket RoutingProduct CategorizationExpense ClassificationCRM Data ClassificationRequest RoutingDocument ClassificationSupplier DataRecord MatchingScoring and PrioritizationData Mapping

For Software Companies

AI for Your ApplicationCustomer-Specific AIReplace Business Rules
View all solutions →
InsightsSign InTry AI Model Trainer ↗
← Home

STAYCHARTED LEGAL

Privacy Policy

Privacy PolicyTerms of ServiceData Processing Addendum

Effective date: 28 September 2026 Last updated: 29 September 2026

This Privacy Policy explains how StayCharted LLC ("StayCharted", "we", "us") handles personal information in connection with the StayCharted service (the "Service"). It forms part of our Terms of Service.


1. The short version

  • You upload files; we train a model on them for you and store the results.
  • We do not use your uploaded content to train base models, to train models for other customers, or to improve our general capabilities. It is processed to run the Service for you and for nothing else.
  • Your content lives in a database schema dedicated to your organisation, with workspaces separated from each other inside it — enforced at the database rather than by a query filter.
  • We do not sell or share personal information, and we do not run advertising.
  • You can export your content yourself at any time, on every plan including Free — do it before you cancel or close anything — and you can ask us to close your organisation at any time.

2. Two different roles, and which one applies

This distinction matters, because it determines who you should contact.

We are a controller for the information we hold about you as our customer: your account, your sign-in, your billing, how you use the Service, and our security and audit records. Sections 3 to 13 describe that.

We are a processor (a "service provider" under US state privacy laws) for the personal information contained inside the files and text you submit — "Customer Content". We process it only on your documented instructions, which for most purposes are the actions you take in the application and through the API.

If you are an individual whose personal information appears in a customer's uploaded file and you want it accessed, corrected or deleted, contact that customer, not us. We will refer you to them. If you do not know who they are, write to privacy@staycharted.com and we will pass your request on where we can identify the account.

Where we act as processor and the processing is subject to the GDPR, the UK GDPR, Swiss law or a US state privacy law, our Data Processing Addendum applies. It is published at https://staycharted.com/legal/dpa, is incorporated into our Terms of Service, takes effect automatically when you accept them, and needs no signature — though we will provide a countersigned copy on request to privacy@staycharted.com. It includes the EU Standard Contractual Clauses and the UK International Data Transfer Addendum for transfers out of Europe. Where it conflicts with this Policy about the processing of personal data, the Addendum prevails.


3. What we collect

3.1 Account information

What Where it comes from
Email address, and whether it is verified You, at signup
Name and organisation, if you provide them You
Password (stored only as a salted scrypt hash — never in readable form) You
Linked sign-in identities, where you sign in with a third-party identity provider or your organisation's single sign-on: the provider's identifier for you, your email address, and your name where the provider supplies it The identity provider
Preferred language, profile settings You

We do not receive your password from a third-party sign-in provider, and we do not receive your contacts, files or anything else from them.

3.2 Billing information

Subscription tier, billing cycle dates, invoices, payments, refunds, disputes and plan changes. Stripe, our payment processor, collects your billing address and, if you provide one, your tax ID to calculate applicable taxes. Payments are processed by Stripe; card numbers go directly to that processor and are never received or stored by us. We hold the processor's identifiers for your customer and subscription records, and the last four digits and card brand where the processor reports them.

3.3 Customer Content

Everything you submit through the Service, including:

  • training files you upload, and the archived copy of each upload we retain as provenance;
  • the curated dataset derived from them — your labels, corrections, merged and excluded categories, and de-duplicated rows;
  • files you submit to be filled, and the filled results;
  • text you submit to the Prediction API, and the predictions returned;
  • pictures, where you use Vision: uploaded in a ZIP file, or fetched by us from image links you supply in a spreadsheet or send to the API;
  • the trained models themselves: Classifier Models and AI Classifier Models, AI Image Classifier Models, and the adapter files produced by Dedicated AI Model and Dedicated AI Image Model training.

We do not inspect Customer Content, other than automated processing to run the Service (parsing, file-type and safety validation, sensitive-data detection, training, prediction) and except where we must to investigate a security incident, respond to a support request you make, or comply with a legal obligation.

What we do with pictures

When you supply a picture, either in a ZIP file or as a link we fetch, our image service produces from it a checksum, a resized copy no larger than 512 pixels, a small thumbnail, and a numeric vector used to train and run the Model. We remove the picture's embedded metadata in doing so — EXIF, including any GPS position, camera serial number and time taken, along with XMP and the colour profile — and the resized copy we store carries none of it. The vector, resized copy and thumbnail are used for model training and prediction. The original ZIP you upload is also retained unchanged as the model's training file until you delete the model. Pictures inside that original ZIP may still contain location, camera and other embedded metadata. Metadata removal from the model-use copies does not remove it from the original ZIP.

Checking text for personal information

Before you train a text Model, the Service automatically examines your data for values that look like personal or secret information — email addresses, payment card numbers, IBANs, US social security numbers, IP addresses, telephone numbers, access keys and credentials embedded in links. This runs on every plan.

You choose how detected values are handled. The findings appear as a data quality step showing masked hints rather than whole values, and you choose per type to mask the values, leave out the rows containing them, or keep them as they are. A decision to keep is recorded with who made it and when. The check does not refuse or change anything on its own.

Where you mask, the masking applies to what is trained and predicted on — the training data, and the text sent for prediction through the app, the API and file fills. Masking does not modify the following files:

  • the original file you uploaded, which we keep as provenance exactly as you supplied it, including any values you later masked;
  • the filled file we give back to you, which keeps your original text.

Training files can be downloaded but cannot be deleted individually in the Service. To remove an original training upload and its archived copy, delete the model it belongs to, or ask us to delete the data — see section 8.

Please do not upload special-category or highly sensitive personal data — health, biometric, genetic, precise location, government identifiers, payment card numbers, or criminal-offence data — unless we have agreed to it in writing under a data processing agreement. The Service is not designed for it, and the detection described above is a safety net for what turns up by accident in business records, not permission to send such data deliberately.

3.4 Usage and metering

Counts of predictions consumed against your monthly budget, training runs, retrains, active models, storage consumed, API calls and rate-limit state, and the timestamps of your activity. We use these to enforce plan allowances, bill correctly, and detect abuse.

3.5 Technical and security information

Server logs including IP address, timestamp, request path, status code and user agent; session records; API key identifiers and their last-used times; failed sign-in attempts and throttling state; and file-validation outcomes.

3.6 Operator audit log

Every administrative action our staff takes on an account — who did what, to whom, and when — including suspensions, plan changes, overrides, closures and erasures. Settings changes record which fields changed, never their values, because those values can contain secrets.

3.7 Communications

Emails we send you (verification, password reset, plan and billing notices, completion notices for long-running fills, inactivity warnings where that feature is in use) and support correspondence you send us.

3.8 Cookies, and how our public website differs

In the application, we use strictly necessary cookies only: a session cookie to keep you signed in, and, for our staff, a separate operator session cookie. Both are HttpOnly, SameSite=Lax and Secure over HTTPS. Customer sessions expire after 30 days; operator sessions after 12 hours.

On our public website, we use one optional, cookieless analytics measurement provided by our hosting provider. It does not run until you accept it. On your first visit you are asked to accept or decline, and nothing is sent to the measurement unless and until you accept.

We record your choice in your browser's local storage, under the name staycharted-privacy-v1, for 180 days. This is not a cookie and is not transmitted to us or to anyone else; it exists so that we can honour your choice on later visits, and storing it is strictly necessary for that purpose. A decision to decline is recorded the same way, and that record is what keeps the measurement from running. After 180 days we ask again.

To change or withdraw your choice, use "Privacy preferences" in the footer of any page. Withdrawal takes effect immediately and stops any further collection. Your choice applies to this browser on this website, so another browser or device is asked separately, and clearing your browser storage discards the record and returns you to the initial question. Declining does not affect how the website works.

If you accept, each page view sends:

  • the page address you are on, with any query string and fragment removed before it is sent, and the referring address that brought you there;
  • your browser, operating system and device type, and your approximate location, derived from your request — our provider documents this as potentially including country, region and city;
  • a short-lived identifier computed from your request, including your IP address and browser user agent, which resets every day — so a visitor cannot be recognised from one day to the next, or on any other website.

The measurement sets no cookies, though the daily identifier is personal data even though no cookie is involved. We use it to count how many people read a page and which page sent them there, and for nothing else. We do not use it to identify anyone, to single out an individual visitor, or to make any decision about a person.

Across both the application and the website, we use no advertising cookies, no tracking pixels, no cross-site trackers, and no analytics that follow you between sites or build a profile of an individual. There is no sale or sharing of personal information here, so there is nothing of that kind to opt out of.

We do not use performance or diagnostic measurement on the website. If we add further measurement, we will describe it here and ask for your consent before it runs.


4. Why we use it, and on what legal basis

For customers in the EEA, UK or Switzerland, the legal bases are noted in the third column.

Purpose Information used Legal basis (GDPR)
Create and operate your account, authenticate you §3.1, §3.5 Performance of a contract
Provide the Service — train models, produce predictions, store results §3.3 Performance of a contract (and, for the personal data inside Customer Content, processing on your instructions as processor)
Bill you and take payment §3.1, §3.2, §3.4 Performance of a contract
Enforce plan allowances and rate limits §3.4 Performance of a contract
Send service and transactional emails §3.1, §3.7 Performance of a contract
Keep the Service secure; detect and investigate abuse and incidents §3.5, §3.6 Legitimate interests (securing our service and our customers' data)
Maintain an audit trail of administrative actions §3.6 Legitimate interests; legal obligation
Keep financial and tax records §3.2 Legal obligation
Diagnose faults and improve reliability §3.4, §3.5 Legitimate interests
Respond to legal claims and requests from authorities As relevant Legal obligation; legitimate interests
Measure use of our public website §3.8 Consent, given on the website and withdrawable at any time through Privacy preferences
Remember your analytics choice for that website §3.8 Legitimate interests (recording and honouring the choice you made; the browser storage is strictly necessary for that)
Send product marketing, if we do §3.1 Consent, or legitimate interests where permitted — with an unsubscribe link in every message

We do not carry out automated decision-making with legal or similarly significant effects about our own customers. The Service produces automated classifications for you; how you use them, and any obligation that creates for you under Article 22 GDPR or equivalent, is your responsibility as controller.


5. What we do not do with your data

  • We do not use Customer Content to train base models.
  • We do not use one customer's content to train, tune or evaluate anything for another customer.
  • We do not use Customer Content to improve the Service's general capabilities.
  • We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA and comparable state laws. We have not done so in the preceding 12 months. Passing information to a service provider so it can do a job for us, or disclosing it because the law requires us to, is not a sale and not a share.
  • We do not send Customer Content to any third-party AI provider. Training and prediction run on infrastructure we control within our own cloud account.

6. Who we share it with

We share personal information only with the following categories of recipient, and only as needed.

Service providers and subprocessors. We use a small number of established third-party providers to operate the Service. They act on our instructions, under written contracts that restrict them to providing their service to us, and they may not use your information for their own purposes. The categories are:

  • Cloud infrastructure — application hosting, the database, object storage, and the compute that runs model training and prediction.
  • Payment processing — taking payment, managing subscriptions and issuing invoices.
  • Outbound email — delivering verification, billing, notification and other transactional messages.
  • Identity providers — only where you choose to sign in with one, or where your organisation has configured single sign-on.
  • File safety scanning — checking uploaded files for malware.
  • Website hosting — serving our public website, and the cookieless aggregate visitor analytics described in section 3.8.
  • Professional tooling — error reporting, support ticketing and similar operational services, where used.

We will identify the specific providers on request to privacy@staycharted.com, and where a data processing agreement is in place we will give notice before adding a new subprocessor, as that agreement provides.

Professional advisers — lawyers, accountants and auditors, under confidentiality obligations.

Authorities — where we are legally required to disclose. We will notify you of a request for your data unless legally prohibited, and we will challenge requests we consider overbroad or unlawful.

A successor — in a merger, acquisition or sale of assets, subject to this Policy continuing to apply, with notice to you.

We do not otherwise disclose your information to third parties.


7. Where it is stored, and international transfers

Where it is hosted today. Customer Content is currently stored and processed in data centres in the United States. We may add or change hosting locations as the Service grows. Where we do, we will update this Policy, and we will give account holders at least 30 days' notice before a change that moves Customer Content to a different country.

International transfers. Some of our providers, and our own staff, are located in the United States. If you are in the EEA, the UK or Switzerland, this means your information is transferred outside your region. Where it is, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), or on an adequacy decision or another lawful transfer mechanism, together with the technical measures described in section 9. A copy of the relevant clauses is available from privacy@staycharted.com.


8. How long we keep it

Most of what we hold is kept for as long as your organisation exists and is removed when it closes. Where a period is fixed, it is stated; where it depends on circumstances, the criteria we use are stated instead.

Data Retained
Customer Content in a live workspace While the organisation is open, until you delete it, or until a retention period you or an operator has configured expires
Customer Content after cancellation or an unsuccessful payment Cancelling a paid subscription moves the workspace to Free at the end of its paid period. Paid access continues during payment retries; if those retries are exhausted and the subscription ends, the workspace moves to Free. The workspace remains visible and its content is retained, subject to the retention rules above. Cancellation or unsuccessful payment does not start an automatic 30-day deletion period. See sections 4.6 and 11.2 of our Terms
Organisation record, while open For the life of the organisation
Organisation record, after closure Retained, marked closed, with commercial history attached — so we can answer later questions about whether and what you paid
Organisation record, after erasure on a lawful request Deleted
Financial and tax records For the period our tax, accounting and audit obligations require. After an erasure we remove the identity from these records where the law permits; where a record must carry a name to serve its legal purpose — an invoice, for example — it keeps it
Dispute and chargeback records Until the dispute is resolved and any period for challenging that resolution has passed
Operator audit log For as long as we need it to answer questions about an account's history and to meet our legal and accountability obligations. Retained after account closure. Where an erasure is a lawful demand, the identifying label on that account's entries can be removed on request — the action, date, operator and an unlinked identifier remain
Server and security logs A limited period, set for security investigation and fault diagnosis, and shorter than the retention of anything they describe
Your website analytics choice 180 days, held in your own browser's local storage and not by us. Cleared sooner if you clear browser storage; changed at any time through Privacy preferences in the website footer
Session records Until expiry — 30 days for customer sessions, 12 hours for operator sessions — or until sign-out, whichever comes first
Backups No more than 35 days, and in practice a much shorter rolling window. Backups exist for disaster recovery only and are never used for ordinary business purposes. Deleted content persists in a backup until the window rolls past it, is not restored to the live Service, and remains protected while it persists. Ask us for the current figure
Support correspondence For as long as needed to handle the matter and any follow-up, and to keep a record of what we told you

If you want the current figure for any period stated as criteria above, ask at privacy@staycharted.com and we will tell you what it is today.

On closure of an organisation, we drop the database schema holding its content, delete its API keys and sessions, and remove its stored files from object storage, including any left behind by a failed deletion. Signing up again on the same email address creates a new organisation, not the old one reopened — so retrieve what you need before closing.

Logins are handled separately from the organisation they belonged to, because a person may be a member of more than one. Closing an organisation deletes the login of anyone whose only connection to StayCharted was that organisation. A person who owns an organisation of their own, or who is a member of another one, keeps their login and that other access, and simply loses their membership of the closed organisation.

Removing one person from an organisation is different again: it ends their membership and their roles in that organisation's workspaces, and reaches nothing else. Their login survives, as does their own organisation and any other membership they hold. The organisation keeps everything they created. Section 11.3 of our Terms sets out when a login is deleted and when it is not.

Inactivity. Where an inactivity policy is in operation, we email a warning to the owner with a grace period of at least 7 days before closing anything, we never close an organisation holding a paid subscription — including one whose payment has failed — or one that is suspended, and we never close an organisation we could not successfully warn. Activity is measured across sign-ins, API key use and work done in the Service, so an organisation used exclusively through the Prediction API is not treated as dormant.


9. How we protect it

  • Isolation at the database. Each organisation's content is held in its own database schema, and workspaces are separated from each other inside that schema by row-level security, which is enabled and forced at the database level rather than relying on application queries alone. A request is bound to one organisation and one workspace for its lifetime, and an unbound connection sees nothing at all rather than everything. Isolation is tested adversarially in our test suite, from two different database roles.
  • Encryption. TLS in transit, with HSTS. Encryption at rest is enabled on the database and on every storage bucket holding your content, and public access to those buckets is blocked. Stored secrets — worker keys, payment provider keys — are separately encrypted and are never returned to a browser. Passwords are hashed with scrypt and verified in constant time.
  • Our staff do not sign in to your account. The Service provides no way for us to sign in as you, act on your behalf inside the application, or use your API keys. There is no impersonation or support-login mechanism. If one of your API keys is compromised, you delete it; we cannot do it for you.
  • Access control. Staff access is role-separated, and every administrative route names the role it requires. The most destructive actions — erasure, closure, plan pricing and the account-lifecycle policy — are restricted to a single owner role and require typing the account's name to confirm. Every administrative action is recorded in an audit log.
  • Multi-factor authentication for staff. Accounts with administrative access to the deployment require a second factor in addition to a password.
  • Authentication. Sign-in returns identical responses for an unknown address and a wrong password, so addresses cannot be enumerated, and credential routes are rate-limited.
  • Uploads are treated as hostile. File types are verified against their actual contents rather than their extension, and spreadsheet formulas are neutralised on export. For data files, macro-bearing formats and archives other than workbooks are refused. For picture ZIP files, a separate reader accepts only image files — anything else in the archive is skipped and reported back to you — with limits on the size of each file, the total uncompressed size and the number of entries. In both cases decompression is measured against a budget rather than trusted.
  • Uploads are scanned for malware, and an upload is refused if the scanner cannot be reached.

If a breach affects your personal information, we will notify you and any required regulator without undue delay and, where the law specifies a deadline, within it.


10. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you;
  • Correct it if it is inaccurate;
  • Delete it;
  • Export it in a portable format;
  • Object to or restrict certain processing, including processing based on legitimate interests;
  • Withdraw consent where we relied on it, without affecting prior processing;
  • Not be discriminated against for exercising a right (CCPA/CPRA). We do not offer financial incentives for personal information;
  • Appeal a refusal, where your state's law provides for it;
  • Complain to a supervisory authority. In the EEA this is the authority where you live or work; in the UK it is the Information Commissioner's Office. We would appreciate the chance to address it first.

How to exercise them. Write to privacy@staycharted.com. We will verify your identity by reference to the account, and an authorised agent may act for you with written permission we can verify.

How long we take, depending on which law gives you the right:

We respond within Extension
GDPR / UK GDPR One month of receiving the request Two further months where the request is complex or there are several; we will tell you within the first month, and why
Texas (TDPSA) and comparable US state laws 45 days One further 45 days where reasonably necessary, with notice to you within the first period
California (CCPA/CPRA) 45 days One further 45 days, with notice

If we decline a request we will tell you why and how to appeal. We will decide an appeal within 60 days under the TDPSA, or within the period the applicable law sets, and if we refuse it we will tell you how to complain to your regulator.

Texas residents. We are established in Texas, and Texas residents have rights under the Texas Data Privacy and Security Act, including the rights to access, correct, delete and obtain a portable copy of their personal data, to opt out of targeted advertising, sale of personal data and certain profiling, and to appeal a decision we make on a request. We do not sell personal data, do not process it for targeted advertising, and do not profile individuals for decisions producing legal or similarly significant effects. If an appeal is refused you may complain to the Texas Attorney General at texasattorneygeneral.gov.

Product features are not the same as these rights. Some of what is listed above you can also do yourself in the Service — edit your profile, change your email address, retrieve content, ask for your organisation to be closed. Those features are a convenience, and what they cover depends on your plan and your role. The rights in this section do not. They apply whatever plan you are on, including Free, and whether or not your account is in good standing, and we will act on them by hand where the Service cannot.

Two different requests, which we handle differently:

  • "Give me my personal data." This is the access and portability right above, and it belongs to you as an individual whatever role you hold. It produces the personal data we hold about you — your account and profile, your sign-in and activity records, and personal data about you that we hold as controller. It does not produce your employer's business records, your colleagues' data, or the contents of a workspace.
  • "Give me the contents of this workspace." That is business content belonging to the organisation, not personal data belonging to a person, and it is not something we do for you: the owner exports it from within the Service, on any plan. Our staff do not sign in to customer accounts, so there is no route by which we could produce it even if asked. A member who needs an export asks their owner. See section 11.4 of our Terms of Service.

If personal data about you sits inside a workspace's business content — because your employer or a customer of ours uploaded it — see section 2: we are the processor for it, and the request goes to them.

If you are not our customer — see section 2. Direct your request to the customer whose account holds your information.


11. Categories at a glance

The following table summarises the information described above.

Category Why we process it Who may receive it
Identifiers — name, email address, organisation, sign-in identifiers Creating and operating your account, authenticating you, support, service emails Cloud infrastructure, email delivery, and identity providers where you use them
Commercial information — plan, billing cycle, invoices, payments, refunds, disputes Taking payment, managing your subscription, tax and accounting records Payment processing and cloud infrastructure providers
Customer Content — your uploaded files, labels, datasets, models and predictions Providing the Service you asked for, and nothing else Cloud infrastructure and file safety scanning. Never an AI provider outside our own cloud account
Usage and metering — predictions consumed, training runs, storage, API calls Enforcing plan allowances, billing correctly, detecting abuse Cloud infrastructure providers
Internet and technical activity — IP address, browser and device type, request logs, security events Operating and securing the Service, diagnosing faults Cloud infrastructure and operational tooling providers
Public website activity, collected only with your consent — page and referring addresses, browser, operating system, device type, approximate location, and a daily-rotating identifier derived from IP address and user agent Understanding which pages are read Our website hosting provider
Operator audit records — administrative actions taken on accounts Accountability, answering later questions about an account, legal obligations No one outside StayCharted, except professional advisers or where the law requires

We do not sell or share any of these categories. We do not use or disclose sensitive personal information for any purpose that would give you a right to limit it under state law, and we ask you not to send us sensitive personal information in the first place — see section 3.3.


12. If you have a separate agreement with us

Our Data Processing Addendum already applies to every account, automatically, wherever we act as processor under a law that requires one — see section 2. If your organisation has in addition signed a separate written agreement with us — an order form, a negotiated addendum, or similar — that agreement controls wherever it directly conflicts with this Policy. Everything not covered by it still applies.


13. Changes to this Policy

We may update this Policy. If a change materially affects how we handle your information, we will give at least 30 days' notice to the email address on your account before it takes effect. Otherwise we will post the updated Policy with a new date. Previous versions are available on request.


14. Contact

StayCharted LLC, Texas, United States Privacy: privacy@staycharted.com Security: security@staycharted.com

StayCharted
AboutContact usPrivacy PolicyTerms of ServiceDPA
© 2026 STAYCHARTED. ALL RIGHTS RESERVED.