Skip to content
Starterdough
Menu

Legal Updated

Privacy policy

How this deployment of Starterdough handles personal data.

Template: review with counsel. This text is a starting point for the operator of a Starterdough deployment. Replace every [placeholder], remove the rows and paragraphs that do not apply to how you configured it, and have it reviewed by a lawyer in your jurisdiction before publishing. The date shown above this page comes from the updated field in this file’s frontmatter. Change it when you change the text.

This policy describes how [Company name] (“we”) handles personal data when you use the Starterdough service at [Service URL] (the “Service”). Questions go to [Contact email].

Data we process

Account data. When you sign up we store your email address, your name, a hashed password (if you use one), and whether your email address is verified. If you sign in with GitHub or Google, we store the identifier the provider gives us and the profile fields you agree to share.

Security settings. If you enable two-factor authentication we store the shared secret and your hashed backup codes. If you register a passkey we store its public key and identifiers. We keep a list of your active sessions (creation time, expiry, IP address and user agent) so you can review and revoke them.

Organizations and workspaces. Organizations, teams and workspaces you create, your membership and role in them, invitations you send or receive (recipient email, role, expiry), and the content you store in workspaces.

Documents you upload, and what we derive from them. The file itself, its name, type and size, and, when you run text extraction, a summary or indexing on it, the extracted text, the summary, and numeric embeddings of the text used for search. We also record each processing job: what was asked for, when, by whom, whether it succeeded, and what it cost in plan credits. Deleting a document deletes the stored file and the text and embeddings derived from it.

Audit log. For each organization we record who performed which action and when (for example creating a workspace or changing a member’s role) so owners and administrators can review changes.

Billing. If your organization subscribes to a paid plan, payment is processed by Stripe. We store the Stripe customer and subscription identifiers, the plan, its status and period, and the seat count. We never see or store full card numbers.

Technical data. Server logs include IP addresses and request metadata for security and rate limiting.

Why we process it

To provide the Service you asked for (account, organizations, documents and the processing you request, billing), to keep it secure (verification, two-factor, sessions, rate limits, audit log), to communicate about your account, to comply with legal obligations, and, with your consent, to understand how the Service is used.

Sharing: our sub-processors

We share data with the processors needed to run the Service, and with no one else. We do not sell personal data. Delete the rows that do not apply to this deployment, and name the actual providers. Several of them are optional and are only reached when the operator has configured them.

Processor What it receives Applies when
[Hosting provider] Everything above: the application, its database and its server logs Always
[Object storage provider, e.g. Cloudflare R2 / AWS S3] The files you upload and their names When documents are stored in a bucket rather than on the server’s own disk
[AI provider, e.g. OpenAI] The text of your documents (and the images themselves, when text is read out of an image), plus your search queries Only when the Service is configured to use an external model. Configured with its built-in local processing instead, document contents never leave the Service
Stripe Your billing contact details, payment details you enter, and organization identifiers When your organization is on a paid plan. Card details go to Stripe directly and never through us
[Email provider, e.g. Resend] The recipient address and the contents of account emails (verification, password reset, email change, account deletion, invitations, billing notices) When an email provider is configured
[Error tracking, e.g. Sentry] Error reports: the failing request’s metadata and your user identifier When error tracking is enabled
[Analytics, e.g. PostHog] Pages visited and product events When analytics is enabled and you accept the consent banner; nothing is sent before that

Retention

Account data is kept while your account exists. You can delete your account from the settings page; deletion is confirmed by email and removes your account data. The sole owner of an organization with an active subscription must cancel it or transfer ownership first. Deleting a document removes the stored file and the text and embeddings derived from it. Audit log entries and invoices may be retained as required by law.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. Contact [Contact email] to exercise them.

Changes

We will post changes to this page and update the date above. Material changes will be announced to account holders by email.