Privacy Policy
NordStella ("we", "our") is an AI work assistant that helps you manage email, meetings, and follow-ups. This policy explains what data we handle, why, and the rules we hold ourselves to. The short version: your data is used only to provide the service to you — never sold, never used to train AI models, and never sent anywhere without your action.
Information we collect
- Account information — your name, email address, and password (stored as a salted scrypt hash; we cannot read it).
- Email content — when you connect an email account (Microsoft, Google, or IMAP), we sync messages from your inbox to summarize, prioritize, and draft replies. Focused/primary inbox only; spam and promotional folders are excluded.
- Calendar & meeting content — meeting titles, attendees, and transcripts (from Microsoft Teams, Google Meet, or files you upload) used to produce minutes and action items.
- Connection credentials — OAuth tokens for accounts you connect, and IMAP/SMTP passwords you provide, stored encrypted at rest (AES-256-GCM).
- Usage records — counts of AI operations and their processing cost, used for the Usage dashboard and billing.
How we use it
- To provide NordStella's features: email triage and summaries, meeting minutes, action tracking, drafts, daily briefs, and workspace search/chat.
- Email and meeting content is processed by enterprise AI providers (Anthropic; OpenAI for optional audio transcription) under agreements that prohibit using your data to train their models.
- Drafted emails are sent only when you (or a teammate who owns them) explicitly approve and send them.
Who we share data with (subprocessors)
- Anthropic — AI processing (summaries, minutes, drafts). No model training on your data.
- OpenAI — optional audio transcription (Whisper). API data is not used for training.
- Render — cloud hosting and storage (encrypted disks).
- Resend — delivery of NordStella's own notification emails (daily brief, password reset).
- Microsoft & Google — when you connect accounts, we access their APIs on your behalf with the permissions you approve.
We do not sell personal data, and we do not share it with advertisers. Ever.
Retention & deletion
- Your data stays in your workspace until you delete it — individual items (emails, chats, drafts) can be deleted in the app.
- Disconnecting an account stops syncing and deletes its stored credentials immediately.
- Deleting a user removes all of that user's data — emails, meetings, drafts, conversations, credentials, and usage records.
- To request full deletion of your account and data, email us at the address below.
Security
- All traffic is encrypted in transit (TLS/HTTPS, enforced).
- Connection credentials are encrypted at rest with AES-256-GCM; passwords are hashed with scrypt.
- Each user's workspace is isolated; workspace admins see usage totals, never content.
- Nothing is ever emailed on your behalf without your explicit approval.
Your rights
You may access, correct, export, or delete your personal data at any time — most of it directly in the app, or by contacting us. If you are in a jurisdiction with specific data-protection rights (such as the GDPR), we honor requests consistent with those laws.
Changes
If we make material changes to this policy, we'll update the date above and notify active users by email before the changes take effect.
Contact
Questions or requests: brief@nordstella.app