Privacy Policy
Effective August 9, 2026
This is a standard SaaS privacy policy template describing how this product actually handles data today. It has not been reviewed by a lawyer for any specific jurisdiction (GDPR, CCPA, or otherwise) — before relying on it for a real enterprise or regulated customer, have counsel review it against your actual entity, region, and data flows.
1. What this policy covers
This Privacy Policy explains what information StreamIndexAI collects, how we use it, and the choices you have. It applies to your organization's account data and to "Customer Data" — the documents and content your organization uploads or connects to the Service.
2. Information we collect
- Account information: name, email address, and organization details you provide at signup.
- Customer Data: documents you upload directly, and content synced from data sources you connect (Amazon S3, SharePoint, or a database) using credentials you supply.
- Usage data: search queries, ingestion activity, and admin actions, used to power your organization's own dashboards and audit trail — not shared outside your organization.
- Payment information: handled directly by Stripe, our payment processor. We do not receive or store your full card number.
- Session and cookie data: authentication cookies needed to keep you signed in securely.
3. How we use information
- To provide the Service: indexing, search, access control, and admin tooling.
- To operate your subscription: billing, trial tracking, and renewal via Stripe.
- To communicate with you: onboarding, security alerts, and service updates.
- To maintain security: detecting abuse, enforcing access controls, and audit logging.
We do not sell your data, and we do not use your Customer Data to train models or for any purpose outside operating the Service for your organization.
4. Sub-processors
We rely on the following infrastructure providers to operate the Service:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Stripe — payment processing and subscription billing.
- Resend — transactional email delivery (invites, verification, notifications).
When you connect an external data source (S3, SharePoint, or a database), that infrastructure remains under your control — we access it only to sync content into your index, using credentials you provide and that we store encrypted at rest.
5. Data retention and deletion
Customer Data is retained for as long as your account is active, or per the retention policy your organization's admin configures (Admin → Compliance lets you set an automatic deletion window). You can delete individual documents at any time, and you can request full account and data deletion by contacting us — we'll delete your organization's data within a reasonable period, except where retention is required by law.
6. Security
Access to data is scoped per organization using row-level security at the database layer — one organization's data is never queryable by another. Data-source connector credentials (cloud storage keys, database passwords) are encrypted at rest using AES-256-GCM and are never exposed back through the application after they're saved. All traffic to the Service is encrypted in transit via TLS.
7. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Organization admins can self-serve most of these (viewing, exporting, and deleting documents; managing team members) directly in the product. For anything else, contact us using the details below.
8. International data transfers
Our infrastructure providers may process data in regions other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border data transfers.
9. Children's privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we'll notify you by email or through the Service before the changes take effect.
11. Contact
Questions about this policy or requests regarding your data can be sent to privacy@streamindexai.com.