Privacy Policy

Last updated: August 9, 2026

1. Introduction

This Privacy Policy explains how STAC INFRAESTRUTURA DE TECNOLOGIA LTDA, CNPJ 68.403.514/0001-21, with address at Av. Anita Garibaldi, 850, Conj 312, Andar 03, Cond Infinity Prime Office, Bloco Torre 02 B, Cabral, Curitiba - PR, CEP 80.540-400 ("Stac", "we", "us") collects, uses, stores, shares, and protects personal data in connection with the Stac platform, API, and website (the "Service").

We process personal data in accordance with the Brazilian General Data Protection Law — LGPD, Law 13.709/2018 — and other applicable law.

This Policy covers two distinct categories of information, and the difference matters: personal data relating to you as a customer or visitor, and API content you send to the Service for processing. API content receives the specific treatment described in Section 4.

2. Data we collect

Data you provide. Name, email address, telephone number, password (stored only as a cryptographic hash), company details, billing address, and tax identification where required to issue an invoice. Payment card data is collected and stored by our payment processor, not by us — we receive only a token and limited metadata such as the last four digits, card brand, and transaction status.

API content. Prompts, messages, documents, files, and other data you or your end users submit to the Service for inference or retrieval, together with the output returned. See Section 4.

Account and usage data. Stacks and configurations you create, API keys (stored hashed), volume and timing of requests, models used, errors, and the actions you take in the dashboard.

Data collected automatically. IP address, browser and device type, operating system, language, pages visited, referrer, access timestamps, and server logs. We also use cookies and similar technologies as described in Section 9.

Support communications. Messages you send us and their content, so that we can respond and keep a record of the request.

We do not intentionally collect sensitive personal data or data relating to children and adolescents. Do not submit such data to the Service unless a specific written agreement between us covers it.

  • Providing the Service — creating and administering your account, processing API requests: performance of a contract (art. 7, V);
  • Billing, invoicing, and collections: performance of a contract; compliance with a legal obligation (art. 7, II and V);
  • Support and service notices — responding to you, communicating incidents and changes: performance of a contract; legitimate interests (art. 7, V and IX);
  • Security and fraud prevention — abuse detection and integrity of the Service: legitimate interests; compliance with a legal obligation (art. 7, IX and II);
  • Improving the platform — diagnosing errors and capacity planning, using account and usage data, not API content: legitimate interests (art. 7, IX);
  • Marketing communications about Stac: consent, revocable at any time (art. 7, I);
  • Legal, regulatory, tax, and accounting compliance: compliance with a legal obligation (art. 7, II);
  • Exercising rights in judicial, administrative, or arbitral proceedings: art. 7, VI.

Where we rely on legitimate interests, we assess whether the processing is necessary and proportionate and whether it respects your reasonable expectations.

4. API content: isolation and no training

This is a core commitment of the Service, not a formality.

Isolation per account. API content is processed within your account's isolated context. It is not mixed with, or made accessible to, other customers.

We do not train on your content. API content is not used to train, fine-tune, adjust, evaluate, or otherwise improve any AI model — neither our own models nor those of any third party.

This is the default, not an opt-out. Not using your content for training is how the Service works by design. It is not a setting you have to find, a preference you have to request, or a right you have to exercise. There is no configuration in which your API content becomes training data without you actively asking for it.

The one exception is fine-tuning you contract explicitly. On the Max and Enterprise plans you may choose to fine-tune a model on your own data. In that case, and only for the data you designate for that purpose, your content is used to train that model. The resulting model is for the exclusive use of your account — it is never shared with other customers, never merged into a general-purpose model, and never used to serve anyone else.

Retention. API content is retained only for as long as operationally necessary to deliver the Service — to return your result, to maintain the context of a conversation or document set you are actively using, and for short-lived operational logs used to diagnose failures. After that it is discarded. Where you have configured a knowledge base or fine-tuned model, the content you supplied for it persists until you delete it or close your account. We may retain data beyond these periods only where a legal obligation or the defence of rights in a proceeding requires it, and then only for that purpose.

Human access. Our personnel do not read API content as a matter of course. Access is limited to named administrators, restricted to what is necessary to investigate a security incident, a technical failure, or a suspected serious violation of the Terms of Use, or where required by law — and it is logged.

5. Infrastructure outside Brazil, and international transfers

You should know where your data runs.

The Service currently operates on infrastructure located outside Brazil, in the United States — today through RunPod for model inference and Railway for application hosting. This means your personal data and API content may be transferred to, stored in, and processed in other countries, whose data protection laws may differ from Brazilian law.

We rely on the international transfer mechanisms permitted by the LGPD (arts. 33 to 36), including contractual clauses with our providers that impose confidentiality and security obligations, combined with the per-account isolation described in Section 4.

A data centre in Brazil is on our roadmap as a future option for customers with a data residency requirement. It is not available today. If data residency in Brazil is a requirement for you now, contact us before subscribing so we can tell you honestly whether we can meet it.

6. Sharing data

We share personal data only as described here:

  • Infrastructure and hosting providers — RunPod (model inference, United States) and Railway (application hosting, United States), acting as operators on our instructions;
  • Payment processorChargefy, which processes recurring charges in Brazilian reais (BRL) via Pix, bank slip (boleto bancário), and credit card, and which processes card data and transactions under its own privacy policy;
  • Operational service providers — email delivery, authentication, error monitoring, and analytics, limited to the data each needs to perform its function;
  • Professional advisers — accountants and lawyers, bound by confidentiality, where necessary;
  • Authorities — where required by law, regulation, or a valid order from a competent authority. Where legally permitted, we will notify you before disclosing;
  • Successors — in a merger, acquisition, corporate reorganization, or sale of assets, in which case the acquirer remains bound by this Policy for the data transferred, and you will be notified of any material change.

We do not sell personal data. We do not share it with third parties for their own independent marketing.

Payment data. Charges for the Service are processed by Chargefy, which acts as a third-party payment provider and processes recurring charges in Brazilian reais (BRL) via Pix, bank slip (boleto bancário), and credit card.

Your payment method data — in particular the full card number, expiry date, and security code — is collected and stored directly by Chargefy, not by Stac. That data passes to Chargefy without Stac retaining it in its systems.

Chargefy is responsible for the tokenization and security of card data, holding it to the security standards applicable to the payment industry. Stac receives and stores only a payment token and limited transaction metadata — such as the last four digits of the card, the card brand, the date, and the status of the charge — which is enough to identify the subscription, process renewals, and provide support, but not enough to reconstruct the card details.

Chargefy's processing of payment data is governed by its own privacy policy, which applies alongside this Policy with respect to that data.

7. Data retention

We retain personal data for as long as your account is active. After you close your account or terminate your subscription, we delete or anonymize personal data within 60 (sixty) days, except where a longer period is required to: comply with tax, accounting, or other legal obligations; exercise or defend rights in judicial, administrative, or arbitral proceedings; or maintain security and fraud-prevention records.

Retention of API content follows Section 4, which is shorter and independent of this Section.

Backups are cycled on their own schedule, so data may persist in encrypted backups for a limited period after deletion from production systems.

8. Security

We apply technical and administrative measures appropriate to the risk, including: encryption in transit (TLS) and at rest, hashing of passwords and API keys, isolation of customer environments, access control on a least-privilege basis with logging, and monitoring for anomalous activity.

No system is completely secure. If a security incident occurs that presents a relevant risk or harm to data subjects, we will notify the National Data Protection Authority (ANPD) and the affected data subjects in accordance with article 48 of the LGPD.

Your side matters too: protect your credentials, do not embed API keys in client-side code or public repositories, and rotate keys you believe may be exposed.

9. Cookies and similar technologies

We use cookies that are necessary for the Service to function — authentication, session integrity, security, and remembering your language and theme preferences. We also use a limited set of analytics cookies to understand how the site and dashboard are used, in aggregate.

You can block or delete cookies in your browser settings. Blocking necessary cookies will prevent you from logging in or using parts of the Service.

10. Your rights

Under article 18 of the LGPD, you may request:

  • Confirmation that we process your personal data;
  • Access to that data;
  • Correction of incomplete, inaccurate, or out-of-date data;
  • Anonymization, blocking, or deletion of data that is unnecessary, excessive, or processed in breach of the LGPD;
  • Portability to another provider, subject to regulatory requirements and preserving trade secrets;
  • Deletion of data processed on the basis of your consent, subject to the retention exceptions in Section 7;
  • Information about the public and private entities with which we have shared your data;
  • Information about the possibility of refusing consent and the consequences of refusal;
  • Revocation of consent at any time, where consent is the legal basis;
  • Review of decisions taken solely by automated means that affect your interests;
  • To object to processing carried out on a basis other than consent, where you believe the processing does not comply with the law.

To exercise any of these rights, write to stac@trystac.com. We will respond within the periods set by the LGPD and may need to verify your identity before acting on a request. Some of these actions — such as deleting your account data — are also available directly in your dashboard settings.

You may also lodge a complaint with the National Data Protection Authority (ANPD).

11. Data Protection Officer

Our Data Protection Officer ("Encarregado pelo Tratamento de Dados Pessoais", art. 41 of the LGPD) can be reached at:

stac@trystac.com

Use the same address for any question about this Policy or about how we handle your data.

12. Changes to this Policy

We may update this Policy. Where a change is material — for example a new purpose of processing, a new category of recipient, or a change to the commitments in Section 4 — we will notify you by email or through the Service before it takes effect. The "last updated" date at the top of this page always reflects the current version.

13. Contact

stac@trystac.com