StemX

Privacy Policy

Effective 1 September 2026

This explains what StemX collects, why, how long we keep it, and who else touches it. It covers stemx.app and the API.

The data controller is Shruti Jadhav, an individual trading as StemX, of 1st A Cross Rd, Nagavarapalya, C V Raman Nagar, Bengaluru, Karnataka 560093, India. For anything in this policy, including a request to access or delete your data, write to support@stemx.app.

What we collect

Your account. Your email address and whether it has been verified. If you signed up with a password, we store an argon2 hash of it — never the password itself. If you signed in with Google, we store the identifier Google gives us, not your Google password.

The audio you upload, the filename you uploaded it under, and the separated tracks we produce from it.

Job and usage records: when a separation ran, how long the audio was, whether it succeeded, and how many minutes it consumed against your allowance. We need these to enforce plan limits and to bill correctly.

IP addresses, for abuse control only. We record the address a sign-up, a sign-in attempt and an anonymous preview came from, so that a single source cannot exhaust the free tier or brute force a password. We do not use these to profile you or to build an advertising audience, and we do not sell them.

A session cookie when you are signed in. It is strictly necessary to keep you signed in, which is why there is no cookie banner: we run no advertising, analytics or tracking cookies at all.

If you subscribe, a Paddle subscription identifier. We never see or store your card details — those go to Paddle directly.

How long we keep things

Audio is deleted automatically by a scheduled sweep, not by request:

  • Previews from anonymous visitors: 1 hour.
  • Previews once you are signed in: 24 hours.
  • Completed full separations: 3 days on Free, 7 days on Pro, 30 days on Scale, from when the job finished.

Account records and usage history are kept while your account exists, and billing records for as long as tax law requires after that. Abuse control records are short-lived and pruned on a rolling window.

Who else sees your data

We use these services, and no others touch your data:

  • Google Cloud Platform — hosting, and the object storage your audio sits in while it exists.
  • Paddle — payments. Paddle is our Merchant of Record and handles your payment details; we never receive them.
  • Resend — the transactional email we send you (verification, account notices). We send no marketing email.
  • Google — only if you choose to sign in with Google.

We do not sell your data, and we do not share it with anyone for their own purposes. We would disclose it if the law compelled us to, and we would tell you unless legally prevented.

What we do not do

We do not train models on your audio. The separation models are third-party pretrained weights; nothing you upload is added to them or used to improve them. Your audio is processed to produce your result and then deleted on the schedule above.

Your rights

You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account and everything attached to it. Write to support@stemx.app and we will act within 30 days.

Deleting your account removes your identity records, your job history and any audio still inside its retention window. Billing records we are required to keep are retained for that period and nothing more.

Depending on where you live you may also have the right to object to processing, to data portability, or to complain to your local data protection authority.

Security

Traffic is encrypted in transit. Passwords are stored as argon2 hashes. Download links are time-limited signed URLs rather than public addresses. Access to production data is limited to the people who operate the service.

No system is perfect. If we ever discover a breach affecting your data, we will tell you and the relevant authority as the law requires.

Changes

If this policy changes materially we will update the effective date above and email account holders before it takes effect. Questions: support@stemx.app.