Draft. This document is pending legal review and is not yet binding. Final wording will replace this draft before public launch.
Privacy Policy
Last updated: 2026-05-12
This policy explains what Stello collects, why, and what we won't do with it. The product is built to make money clarity possible without surveillance — the policy reflects that.
What we collect
- Account. Name, email, and provider ID from Google or Apple sign-in.
- Financial data you enter. Accounts, transactions, budgets, goals, investments, and split-bill data. All of this is user-entered. Stello does not connect to your bank or scrape statements in v1.
- Subscription state. Tier, expiry, and store identifier received from RevenueCat when you subscribe to PLUS.
- Usage analytics. Page-level traffic via Plausible. No cookies, no device IDs, no cross-site tracking.
- AI chat content. When you use the AI chat assistant (free or PLUS), your message and a small ledger-context snapshot are sent to our AI provider for the duration of the request. The provider name and retention terms are listed below.
What we don't collect
Bank credentials. Contacts. Location. Advertising identifiers. Third-party tracking signals.
AI chat handling
- Provider: TBD — confirmed before publish
- What's sent: your message text plus the deterministic ledger snapshot used to give the answer context.
- Retention by the provider: TBD — link to provider policy
- Opt-out: chat is opt-in. You can use Stello without ever opening the chat surface. Manual entry remains unlimited for everyone.
Where data is stored
PostgreSQL hosted in TBD — region. Backups are encrypted at rest.
Deleting your account
Send a request to privacy@app-stello.com. Account deletion removes your ledger, goals, investments, and subscription state. Anonymized usage counts may remain in our analytics for product planning.
Children
Stello is not intended for users under 18, or the applicable minimum age in your jurisdiction.
Your rights by region
- Australia (Privacy Act 1988 / APPs): You can access, correct, and delete the personal information we hold.
- EU / UK (GDPR): You can request access, rectification, erasure, restriction, portability, and object to processing.
- California (CCPA / CPRA): You can request to know, delete, and opt out of sale or sharing of personal information.
Requests via privacy@app-stello.com.
Changes
Material changes will be announced in-app and on this page at least 14 days before they take effect.