StageMind Privacy Policy
Version 1.0 · Effective date [not yet set]
This document is published at version 1.0; its effective date is set at publication and has not been set yet.
- Operator
- Beautify Insights LLC, a Florida limited liability company, doing business as StageMind (Florida fictitious name reg. no. G26000083231), 6751 Forum Drive, Suite 240, Orlando, FL 32821, USA.
- Contact
- privacy@stagemind.app
- Applies to
- the StageMind desktop application (the "App"), the StageMind account and cloud services, including Managed AI (the "Cloud Services"), the stagemind.app website, and the transactional email we send.
In plain English
- StageMind is local-first. Your scripts, your script library, your recordings' transcripts, your ingested YouTube research, and your settings live in files and a local database on your computer — not on our servers. We have no copy of them and no way to read them.
- Your microphone audio never leaves your machine. Voice recognition (speech-to-text) runs entirely on your device. We don't record, upload, or store your audio.
- We collect what a paid account needs: your email address, a securely hashed password, and your plan and billing status. Payments run through Stripe — we never see or store your card number. One thing worth knowing up front: for fraud prevention and its own legal compliance, Stripe acts on its own account rather than on our instructions, so for that part of the processing your rights run to Stripe directly (§6.2, §8).
- The honest caveat: Managed AI. If you use StageMind's cloud AI features (instead of your own API key or a local model), the text you submit — and, for content analysis, short excerpts of the YouTube material you're analyzing — is sent through our cloud gateway to the AI provider (Google Vertex AI, OpenAI, or Anthropic) to generate the response. We keep metering records (token counts, model, feature tag) for billing. For interactive requests we do not store the content of what you sent.
- No telemetry in the App. The App contains no analytics, tracking, crash reporting, or advertising SDKs. We don't sell your data. We don't use it for ads.
- The website is a separate thing, and today it measures nothing. stagemind.app runs no analytics and sets no analytics cookies. We have written down in advance what we may run there and what would need your consent first (§12, §13) — so if that changes, what you see is a consent notice, not a rewritten policy.
- YouTube research happens from your device. When you point StageMind at public YouTube content, your computer fetches it directly from YouTube; results are stored locally. Signing in to YouTube inside StageMind is optional, and your session cookies stay on your machine.
- You're in control. Deleting the App's data folders removes your local data — note that uninstalling the App on its own does not. Ask us to delete your account and we close it immediately; §7 says exactly what we keep afterwards and why.
- StageMind is for adults. You must be 18 or over (§10).
The sections below say the same thing precisely, and disclose the narrow exceptions — for example an asynchronous "batch" AI lane that is switched off today and that would store request content on our servers if we ever enabled it.
1. Who we are
StageMind is operated by Beautify Insights LLC, a Florida limited liability company doing business as StageMind ("StageMind," "we," "us"). For privacy questions or requests, contact privacy@stagemind.app or write to the address above. For legal notices, use legal@stagemind.app; for everything else, support@stagemind.app.
For the personal data described in this Policy, Beautify Insights LLC is the controller — except where §6.2 says a third party decides for itself.
2. Scope
This Policy covers personal data processed when you use the App, the Cloud Services, and the stagemind.app website, and when we send you transactional email. It is incorporated by reference into our Terms of Service and our End User License Agreement, and it is the authoritative description of how we handle data; where either of those documents summarises data handling, this Policy governs.
"Cloud Services" is a defined term and has the meaning given in Terms of Service §1 — the StageMind account and cloud services, including Managed AI. The website is not part of the Cloud Services. The providers that host or measure the website (§12, §13) are not Cloud Services providers, they are not part of Managed AI, and they never receive your account content, your local data, or your Managed-AI request content.
This Policy does not cover third-party services you choose to connect or use through StageMind (for example YouTube, Notion, Google Drive, Stripe's checkout pages, or an AI provider you bring your own key for) — those are governed by their own policies. Where we send data to a third party that acts on our instructions, §6.1 lists it. Where a third party decides for itself what to do with your data, §6.2 says so and §8 tells you where your rights run.
3. Local-first: what stays on your device
The following data is created and stored only on your computer. It is not transmitted to StageMind, and we cannot access it. You control it: it lives in your user folders and is removed if you delete those folders (or, for scripts, wherever you chose to keep them).
| Data | Where it lives (Windows default) |
|---|---|
| Scripts and script library (incl. projects, backups) | Documents\Prompter Scripts\ |
| App settings and presets | %APPDATA%\StageMind\settings.json |
| Assistant conversation history (your messages and AI replies) | local app storage + %APPDATA%\StageMind\cold_archive\ |
| Context/memory database — indexed documents, knowledge graph, pinned turns | %APPDATA%\StageMind\context.db |
| Content research (YouTube video metadata, transcripts, comments, embeddings, clusters, insights) | %APPDATA%\StageMind\context.db |
| Optional YouTube sign-in session cookies | %APPDATA%\StageMind\auth\ |
| Connector tokens you authorize (Notion, Google Drive) | %APPDATA%\StageMind\ |
| Your own AI provider API keys (BYOK) | %LOCALAPPDATA%\StageMind\config\ |
| License state and a local device identifier (see §4.4) | %LOCALAPPDATA%\StageMind\ |
| Downloaded AI models (speech recognition, embeddings) | %LOCALAPPDATA%\StageMind\models\ |
Notes, stated plainly:
- Microphone audio is processed in memory for on-device speech recognition and is not written to disk, with two user-controlled exceptions: audio files you explicitly import for transcription are stored temporarily during processing and deleted when it completes, and voice-rehearsal audio and transcripts are kept only if you turn those retention settings on (both default to off).
- Transcribed text of what you say to the assistant becomes part of your conversation history, which is stored locally as described above.
- The App keeps no log files on disk, and does not upload logs.
- No automatic cloud backup or sync. The App never uploads your local data as a backup. Exports are manual, user-initiated files saved where you choose. (If your organization uses Windows roaming profiles, your operating system — not StageMind — may copy the App's roaming data folder between your own machines.)
4. What we collect, and why
4.1. Account data
When you create a StageMind account we collect your email address, a password (stored only as a bcrypt hash — we never store it in plain text), and an optional display name. We associate your account with your plan and subscription status.
Two-factor authentication is implemented on our servers: where it is enabled on an account, the TOTP secret is stored encrypted at rest and one-time recovery codes are stored as hashes. There is no enrolment screen in the App today, so this is a description of how the secret is protected, not an invitation to turn it on.
We use account data to authenticate you, provision your plan and AI allowance, send the transactional emails described in §4.8, and provide support. On your device, your session is kept as: an access token in memory only, a refresh token encrypted with your operating system's credential protection, and a small plain-text cache of your email and plan name so the App can show who is signed in.
4.2. Payments (Stripe)
Payments are processed by Stripe, LLC. Checkout happens on Stripe-hosted pages: your card number never touches StageMind's systems, and we store no card data. To set up checkout we send Stripe your email address, display name, and internal account ID; Stripe returns us non-sensitive references (a Stripe customer ID and subscription IDs), which we store to manage your plan. We do not store invoices, payment amounts, or payment methods on our servers.
Depending on your country, either StageMind is the seller of record (US — Stripe Tax calculates tax) or Stripe acts as merchant of record for the transaction (supported international countries). In both cases Stripe processes your payment data under its own privacy policy, and for the purposes listed in §6.2 it does so as an independent controller rather than on our instructions.
4.3. Managed AI: content we process, and metering we keep
StageMind's AI features can run three ways: on-device models (nothing leaves your machine), your own API key ("BYOK" — your device calls your chosen provider directly; StageMind's servers are not involved and see nothing), or Managed AI (included cloud AI on eligible plans, routed through StageMind's cloud gateway).
When you use Managed AI, the text needed to answer your request is sent to our gateway and on to an AI provider (Google Vertex AI, OpenAI, or Anthropic). Depending on the feature, that text is:
- your co-scripting and assistant messages (and the script context the feature includes);
- for the memory-recall classifier, the message you typed, to decide whether you're asking the assistant to recall something;
- for content analysis of YouTube material you ingested: video titles and short description excerpts (relationship typing), video titles (cluster labeling, insights, personas), key sentences extracted from a transcript — not the full transcript — (transcript intelligence), and short viewer-comment excerpts (comment intelligence).
Our gateway processes this content in memory to route, meter, and forward it. For interactive (real-time) requests, prompt and response content is not stored on our servers. What we do store, per call, is metering metadata: token counts, an internal cost estimate used for billing, the provider and model, a feature tag (for example "transcript_intel"), the routing mode, a request ID, and timestamps — tied to your account for billing, quota, and abuse prevention. Metering records contain no prompt or response content.
Batch processing — built, but switched off. Our gateway contains an asynchronous "batch" lane for large analysis jobs. It is not enabled in the current deployment: no batch storage bucket is configured, no batch job runs, and no request or response content is stored under it. If we enable it, request content and the AI's response would be stored on our infrastructure (our database and a Google Cloud Storage bucket) while the job is queued, runs, and its results are delivered. We will adopt a deletion schedule for batch payloads, and state it in this Policy, before the lane is ever enabled — no such schedule exists in our code today, and we will not turn the lane on without one.
AI providers. Managed-AI requests are processed by the provider our gateway selects — Google (Vertex AI), OpenAI, or Anthropic — under the API terms that apply to our accounts. We send the provider the request content and receive the response. We do not send your name or your email address with an AI request: requests are authenticated at our gateway and forwarded to the provider without your account identity.
On training and provider-side retention, stating only what we have verified against the providers' own published terms: OpenAI does not use API content to train or improve its models unless the customer expressly opts in, and retains content for a limited abuse-monitoring window (currently 30 days). Anthropic is contractually prohibited from training on customer content submitted through its API, with a comparable abuse-monitoring window that can be longer where content is flagged for a policy violation. Google's terms for Vertex AI — the Google service our gateway uses — restrict training on customer data, with an abuse-monitoring window of up to 90 days. These are the providers' terms and not our promises: each provider can change them, and the current version of each provider's terms governs. If you use BYOK instead, the terms of your own account with that provider apply, and they may differ.
4.4. Licensing and device identifier
The App computes a device identifier on your machine: a one-way SHA-256 hash derived from hardware details (motherboard, CPU, disk serials, network adapter). Today it is stored locally and used locally — to detect licence tampering and to show you a "Device ID" for support. The current version of the App does not transmit this identifier to us.
The server side of device activation is built: our licence service can activate a device against your licence, list the devices activated on it, and deactivate one to free a slot, and it stores the hashed identifier against your licence in order to count activations. Because the App does not send the identifier, that server side receives nothing from you today and your plan's device limit does not bind. There is no self-service device screen in the App today either; if you need a device released, contact support@stagemind.app.
When a version of the App that transmits the identifier ships, activation will send the hash to our gateway and we will store it against your licence to enforce your plan's device limit. It is a hash of hardware details, not your name. This disclosure is written now so that this Policy stays accurate either way.
Hardware capability detection (GPU and RAM probing, to pick the right on-device AI models) runs entirely on your device; the result is not transmitted.
4.5. Software updates
The App checks GitHub (which hosts our releases) for updates: at startup in production builds, and when you click "Check for updates." GitHub receives the network request (your IP address, as with any web request) and serves version metadata; updates download only when you choose. No device identifier and no usage data is attached.
4.6. YouTube ingestion (Content Universe)
When you ask StageMind to analyze YouTube content, your device fetches public data directly from YouTube (video metadata, subtitles and auto-captions, top comments) using open-source components bundled with the App, including a helper that obtains anonymous access tokens from YouTube so that no sign-in is needed. Everything fetched is stored locally (§3). It is not uploaded to StageMind — only the short excerpts listed in §4.3 are sent if you run Managed-AI analysis.
Optional YouTube sign-in. If YouTube requires it, or you choose to, you can sign in to YouTube inside StageMind. Your YouTube session cookies are stored on your device only, are used only to fetch content you direct, are never sent to StageMind's servers, and are deleted when you sign out. During ingestion your device may also fetch a small open-source component from GitHub in order to complete YouTube's technical checks.
The open-source components bundled with the App, and their licences, are listed in the notice bundle that ships with the App and on the App's About screen. This Policy does not restate that list, so that the list you read is always the one generated from the build you are running.
You are responsible for using ingestion in line with YouTube's terms and applicable law (see the Terms of Service).
4.7. Connectors you authorize
- Notion: to connect Notion, the App sends the one-time OAuth authorization code to our gateway, which exchanges it with Notion (this keeps the app secret off your device) and returns the token to your device. Our gateway does not store the code or the token.
- Google Drive: the App talks to Google's OAuth service directly; StageMind's servers are not involved. Tokens are stored on your device.
4.8. Transactional email
We send account emails — verification, password reset, password-changed notice — through AC PM LLC (the provider behind Postmark), which receives your email address and the message content, including tokenized links.
We do not send you marketing email because you have a StageMind account. If we ever offer a newsletter or other marketing email, joining it will be a separate, explicit opt-in, and every message will carry an unsubscribe link. Email addresses you give us on the website — for example to join a launch or waiting list — are covered by §12.2.
4.9. Server infrastructure logs
Our gateway runs on Google Cloud Run. Like any web service, its access logs record the IP address, request path, status, and timestamp of API requests — not request bodies, and not message content. These logs are operational (debugging, abuse prevention) and live in our cloud logging infrastructure; retention is described in §7. Our application database does not store your IP address. In-memory rate limiting uses the request IP for about a minute and is never written to disk.
4.10. What we do NOT collect
This section is about the App and the Cloud Services. What the website does — which today is close to nothing — is set out separately in §12 and §13. Verified against the App's code:
- No analytics, telemetry, tracking, or crash-reporting SDKs in the App. No usage events, feature counters, screen views, or session tracking are transmitted. All internal "telemetry" tables are local diagnostics on your device.
- No advertising, no ad identifiers, no cross-site tracking, and no cookies in the App.
- No audio upload. No recording of your microphone reaches our servers, ever.
- No sale of personal data, and no sharing for cross-context behavioural advertising, as "sell" and "share" are defined in the CCPA. We have never done either. If that were ever to change we would say so here and provide the opt-out the law requires before it happened, not afterwards.
5. How we use personal data
- Provide the service — authenticate you, run Managed AI requests, enforce plan quotas and (once the App transmits the identifier) device limits, deliver purchases (contract).
- Billing — meter AI usage, manage subscriptions through Stripe (contract).
- Communicate — transactional email (contract); support replies (legitimate interests).
- Protect the service — rate limiting, abuse and fraud prevention, security (legitimate interests, and legal obligation where one applies).
- Comply with law — tax, accounting, lawful requests (legal obligation).
- Understand whether the website works — cookieless, non-identifying aggregate measurement, where it runs, on the basis of our legitimate interest in knowing which pages are used (§12.4); and, for anything that stores or reads information on your device, your consent (§13).
We do not use your content or your personal data to train AI models. We do not make automated decisions about you that produce legal or similarly significant effects.
6. Who we share data with
Some of the parties below act on our instructions as processors. One of them, for part of what it does, acts on its own account — and that difference decides where your rights run, so we set it out separately rather than folding it into one list.
6.1. Processors acting on our instructions
These providers process personal data only on our documented instructions, only as needed to run StageMind, and never for their own advertising.
| Provider (legal entity) | Role | What they receive |
|---|---|---|
| Google (Google Cloud) | Hosting: Cloud Run, Cloud SQL, Secret Manager, Cloud Storage | The account and metering data we store; infrastructure logs; batch AI payloads only if the §4.3 batch lane is ever enabled |
| Google (Vertex AI), OpenAI, Anthropic | Managed-AI model providers | The AI request content described in §4.3, with no account identity attached |
| AC PM LLC (Postmark) | Transactional email | Your email address and the message content |
| Stripe, LLC — for the processor half of its role only | Customer and subscription records, checkout, billing operations we instruct | Your email address, display name, and internal account ID; see §6.2 for the half it controls itself |
| Vercel | Website hosting, and — where enabled — the cookieless aggregate website measurement described in §12.4 | Technical request information sent by your browser when it loads a page (IP address, request path, user agent, timestamp) |
| Neon | The database behind website forms | An email address you submit through a website form, if you submit one |
| PostHog (EU Cloud region) | Product analytics — only if we enable it, and only with your consent where consent is required (§12.5). We do not use it today. | Website and account-page usage events, if and when it runs |
6.2. Parties that decide for themselves (independent controllers)
Stripe, LLC. Stripe is our payment processor, and for part of what it does it is not acting on our instructions. Under the data processing agreement that forms part of our Stripe Services Agreement, Stripe has sole and exclusive authority over the purposes and means of processing for:
- fraud detection and prevention;
- mitigating financial loss and security risk; and
- meeting its own legal and regulatory compliance obligations.
For that processing Stripe is an independent controller. It decides for itself, we cannot instruct it, and we cannot exercise your rights against it on your behalf — §8 explains where your rights run instead. For the rest of what Stripe does for us — creating a customer record, running checkout, managing your subscription — it acts as our processor and is listed in §6.1. Where Stripe is merchant of record it is additionally the seller of your purchase and processes your data as a controller for that sale. Stripe's own privacy policy governs its independent processing, and its card data never passes through our systems in any case.
6.3. Other recipients
- GitHub (update hosting, and the component fetch described in §4.6) receives a standard web request from your device when the App checks for or downloads a release. We do not send GitHub your data; your device makes the request, and GitHub sees it as it would see any web request.
- We may disclose personal data if required by law, to protect our rights or the safety of users, or as part of a merger, acquisition or asset sale — with notice where notice is possible.
- We have no data-broker relationships and we do not disclose personal data for anyone's advertising.
7. Retention
- Local data: yours, on your device, until you delete it. Uninstalling the App does not remove your data folders — that is deliberate, so an uninstall or a reinstall cannot lose your scripts. §3 lists the locations if you want to remove them yourself.
- Account data: kept while your account is active. After a subscription is cancelled, plan data enters a 90-day read-only grace period during which you can reactivate.
- Deletion requests: when you ask us to delete your account, we deactivate it immediately — it is closed, excluded from the service, and can no longer be used to sign in or to reach the Cloud Services. We then retain the account record itself for audit, billing and legal-compliance purposes, and we use it for nothing else. Where the law gives you an erasure right we will honour it to the extent we are not required to keep a record, and where we do keep one we keep the minimum. Nothing here stops us from erasing more, sooner: if we move to full erasure or irreversible de-identification of the account record, we will do that without needing to change this Policy, and this paragraph remains the outer limit of what we keep.
- AI metering records (§4.3): retained for as long as we need them for billing, quota and audit, including after an account closes — they are the record of what you were charged for. We do not operate an automatic deletion schedule for them today, and we will not print a retention period here until our code enforces one. These records contain no prompt or response content.
- Batch AI payloads (§4.3): none exist today — the batch lane is switched off and stores nothing. A deletion schedule will be adopted, and stated in this Policy, before the lane is ever enabled.
- Audit logs: administrative audit entries are configured with a 365-day retention setting, and a cleanup routine exists in our code. That routine is not currently scheduled to run, so the 365 days is the configured intent rather than something enforced automatically today. We would rather say that than imply a schedule we do not operate.
- Infrastructure logs: Google Cloud logging defaults, unmodified. The default log bucket retains entries for 30 days. Google's
_Requiredbucket, which holds admin-activity logs and which cannot be reconfigured, retains for 400 days.
8. Your rights
Email privacy@stagemind.app to exercise any of these. We verify requests against your account email and respond within the time the applicable law requires (for example 30 days under the GDPR, 45 days under the CCPA).
Everyone: access a copy of the personal data we hold about you; correct it; delete it (see §7 for exactly what deletion means today); object to or restrict processing; and withdraw consent where processing is consent-based. Remember that most of your content is local — you can access, export, and delete it directly on your device, without asking us.
Withdrawing analytics consent. Where you have consented to a cookie or similar technology, you can change or withdraw that consent at any time by the mechanism described in §13.6.
Where your rights run for payment data. For the parts of Stripe's processing where Stripe is an independent controller (§6.2) — fraud detection and prevention, mitigating financial loss and security risk, and Stripe's own compliance — your rights run to Stripe directly, not through us. We cannot access, correct or delete that data on your behalf, and we cannot instruct Stripe to. Use the contact route in Stripe's privacy policy. If you come to us first we will point you there, and we will help with everything we do control.
EEA/UK (GDPR and UK GDPR): the legal bases in §5 apply. You also have the right to data portability and the right to lodge a complaint with your supervisory authority. Our processing happens in the United States (§9). Stated plainly, because it is the kind of thing a policy should not bury: we have not appointed an EU or UK representative under Article 27, and we have not appointed a Data Protection Officer. We honour GDPR-style rights regardless, and privacy@stagemind.app is the route to us.
California (CCPA/CPRA): you have the rights to know, delete, correct, and to opt out of the sale or sharing of personal data — we do not sell or share personal data (§4.10), so there is nothing to opt out of. We do not use or disclose sensitive personal information beyond providing the service you asked for. We will not discriminate against you for exercising a right. Authorized agents may submit requests with proof of authorization.
Other US states: residents of states with comparable privacy laws — including Virginia, Colorado, Connecticut, Texas and Utah — have equivalent rights, exercised the same way.
9. International data transfers
StageMind is operated from the United States, and the Cloud Services run on US infrastructure (Google Cloud, us-central1). If you use StageMind from outside the United States, your account data and your Managed-AI request content are processed in the US.
Payments are a US transfer, and we say so specifically. Stripe's contracting entity follows the location of the merchant account. Beautify Insights LLC is a US company, so our counterparty is Stripe, LLC in the United States rather than Stripe's European entity. For data subjects in the EEA, the UK and Switzerland, that makes payment processing an outbound international transfer to the United States, and the transfer mechanism for it is the one contained in Stripe's data processing agreement, which forms part of our Stripe Services Agreement (version on file: 2025-11-18).
Our other providers. Google Cloud's data processing terms are incorporated into our Google Cloud agreement (current published version), and AC PM LLC's are incorporated into the Postmark terms of service (version on file: 2025-11-17). Each contains the international transfer terms that apply to that provider.
The basis for our own transfer. For EEA and UK users, our transfer of your account data and Managed-AI request content to the United States currently rests on the transfer being necessary for the performance of the contract between you and us (GDPR Article 49(1)(b)). It does not currently rest on standard contractual clauses of our own. We state that rather than imply an apparatus we have not put in place.
The website. Website hosting is global by design, so a page request may be served from infrastructure near you. The product-analytics option named in §12.5 is PostHog's EU Cloud region, chosen so that, if it is ever enabled, that data stays in the EU.
10. Children
StageMind is for adults. Our services are not directed to anyone under 18 and we do not knowingly collect personal data from anyone under 18. You must be at least 18 years old to create a StageMind account or to use the App. If you believe someone under 18 has given us personal data, contact privacy@stagemind.app and we will delete it.
11. Security
We protect data in transit with TLS. Account passwords are stored as bcrypt hashes. Where two-factor authentication is enabled, the secret is encrypted at rest and recovery codes are stored as hashes. Our cloud secrets live in a managed secret store. On your device, your access token is held in memory and never written to disk, and your refresh token is encrypted using your operating system's credential protection.
One thing we will not overstate. The operating-system encryption above covers the refresh token. It does not cover your own AI provider API keys: if you save BYOK keys in the App, they are written to a configuration file on your machine in plain text. They never leave your device and are never sent to us, but anyone who can read files under your user account on that machine can read them. Encrypting them is a known hardening item; until it ships, this is the accurate description, and we would rather state it here than hide it in a caveat.
No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you as required by law.
12. The stagemind.app website
12.1 What the website collects today. The stagemind.app website is a marketing and information site, separate from the App and outside the defined term "Cloud Services" (§2). As published, it runs no analytics and it sets no analytics cookies. No analytics package is installed in the site's code, and no measurement component is mounted on its pages. Enabling an analytics product in a hosting dashboard does not by itself instrument a site — the installed package and the component on the page are what collect — and neither is present.
12.2 Information you give the website. If you submit your email address through a form on the site — for example to join a launch or waiting list — we store that address in our website database so that we can reply and send you what you asked for. You can ask us to remove it at any time at privacy@stagemind.app, and any list email we send carries an unsubscribe link. We do not sell it, and we do not pass it to advertisers.
12.3 Hosting. The website is hosted by Vercel, which, like any host, processes the technical information your browser sends when it requests a page — IP address, request path, user agent, timestamp — in order to serve the site and keep it secure. That is ordinary server-side operation, not analytics, and it happens whether or not §12.4 is running.
12.4 Cookieless aggregate measurement (permitted, and it may run without further notice). We may use our hosting provider's privacy-preserving aggregate measurement — Vercel Web Analytics — to count page views and see which pages people visit. It is cookieless: it stores nothing on your device and reads nothing from it. Visits are counted from a hash of request attributes that is discarded within 24 hours; it sets no third-party cookies, it does not follow you across other websites, and it does not identify you. Because nothing is stored on or read from your device, it does not require a consent notice. We disclose it here in advance so that it can be switched on without amending this Policy; where it is not switched on, nothing is collected by it at all.
12.5 Product analytics (only if we enable it, and only with consent where consent is required). We may use a product-analytics service to understand how the website and, in future, the account pages are used, so that we can improve them. The service we have selected for that purpose is PostHog, in its EU Cloud region. We do not use it today. If we do enable it, it will store or read information on your device, so — unlike §12.4 — it is consent-gated: for visitors in the EEA, the UK and Switzerland it will run only where you have consented, on the terms in §13. The consent notice and the instrumentation ship together, as one change: the notice never appears before there is something to consent to, and the instrumentation never runs before the notice exists.
12.6 What the website never receives. The website and the providers named in this section are not part of the Cloud Services. They never receive your scripts or other local data, your Managed-AI request content, your AI metering records, or your password or payment details.
13. Cookies and similar technologies
13.1 What we mean. "Cookies and similar technologies" means cookies, local storage and session storage, pixels and tags, embedded SDKs, and any other technology that stores information on your device or reads information already stored there. This section applies to the website. It does not apply to the App, which uses none of them (§4.10).
13.2 What is in use today. No analytics cookie, no advertising cookie, and no cross-site tracking technology is set on the website today. Anything the site does set is strictly necessary to serve the page and keep it secure. If we add signed-in account pages on the web, those will additionally use a strictly necessary session cookie to keep you signed in.
13.3 The categories we may use, and the basis for each. Writing these down in advance is deliberate: it means adding one later is a change you are asked to consent to, not a policy you are asked to re-accept.
| Category | What it would be for | Legal basis | Runs without asking you? |
|---|---|---|---|
| Strictly necessary | Serving pages, security and abuse prevention, keeping you signed in, and remembering the privacy choice you made | Necessary to provide a service you asked for; no consent required | Yes |
| Cookieless aggregate measurement | Counting page views without storing or reading anything on your device (§12.4) | Our legitimate interest in knowing whether the site works; nothing is stored on or read from your device, so no consent is required | Yes |
| Analytics / product analytics | Understanding how pages and features are used, so that we can improve them (§12.5) | Your consent, for visitors in the EEA, the UK and Switzerland | No — off until you allow it |
| Advertising and advertising measurement | Not used today. It would cover storing an advertising identifier, personalising advertising, measuring advertising, and passing your data to an advertising provider for those purposes | Your consent | No — off until you allow it |
13.4 How consent works, and how granular it is. Where consent is required, we ask for it with a consent notice before anything in a consent-gated category runs. Consent is asked for each category separately, so you can allow one and refuse another. Within the advertising category, consent is signalled separately for advertising storage, for analytics storage, for the use of your data by an advertising provider, and for advertising personalisation — four independent choices, each defaulting to denied, so that a provider requiring them can be accommodated without changing what you were asked. Every consent-gated category is off by default until you choose, and refusing costs you nothing: the website works the same either way.
13.5 Who is asked. The consent notice is shown to visitors in the EEA, the UK and Switzerland, where consent is legally required for these technologies. That we are a US company does not change that — the obligation follows the visitor, not us. We do not show it elsewhere, because nothing that would require it is running.
13.6 Changing or withdrawing your consent. Where a consent notice is running, you can change or withdraw your choice at any time from the same place you gave it: a persistent "Privacy choices" control in the website footer, which reopens the notice with your current choices. That control ships as part of the same change as the notice and the instrumentation — until then there is nothing to withdraw, because nothing consent-gated is running. You can also refuse or delete cookies in your browser at any time (strictly necessary ones cannot be refused without breaking the site), and you can write to privacy@stagemind.app. Withdrawal takes effect immediately going forward; it does not undo processing that was lawful while your consent was in place.
13.7 What we will not do here. We do not use cookies or similar technologies in the App. We do not use them to build advertising profiles of you. We do not sell what they collect, and we do not share it for cross-context behavioural advertising (§4.10).
14. Changes to this Policy
We will post updates on this page and update the effective date. For material changes we will notify you — an in-app notice or an email — before they take effect. Adding something this Policy already permits, such as the measurement described in §12.4 or a category in §13.3 that you are then asked to consent to, is not a material change to this Policy; enabling the §4.3 batch lane, or changing what §7 says we keep, would be.
15. Contact
Beautify Insights LLC d/b/a StageMind
6751 Forum Drive, Suite 240, Orlando, FL 32821, USA
privacy@stagemind.app — data protection and privacy requests
legal@stagemind.app — legal notices
support@stagemind.app — everything else
https://stagemind.app/legal/privacy
Permanent address of this version: /legal/privacy/v/1.0
← All legal documents