Components, templates, design and tools for agentic work Private alpha · free for now
Legal

Privacy Policy.

We collect what running the products requires, we use it to run the products, and we do not sell it. The details below are that sentence, expanded.

Version
3.0
Effective
Applies to
The products, stacklumen.com and baselumen.com
Contents
  1. The short version
  2. What we collect
  3. How we use it, and the legal basis
  4. What we do not do
  5. Who else processes it
  6. Your clients and your visitors
  7. How long we keep it
  8. Where it is stored, and how it is protected
  9. Your rights
  10. Children
  11. Cookies
  12. Changes

The short version

  • We measure how the products are used. We do not read what you write in them.
  • We do not sell personal data, share it for advertising, or train models on your content.
  • Data your workspace collects about your clients and visitors is yours; we process it for you.
  • You can access, correct, export or delete your data.

A summary for convenience, not part of the document. The numbered sections below govern.

The short version #

We measure how the products are used. We do not read what you write in them. That distinction is enforced in the database by an explicit allowlist of the columns telemetry may touch, so customer text is not merely something we choose not to look at; it is something the measuring code cannot reach.

Stacklumen LLC is the controller of the personal data described here. For data your workspace collects about your own clients and visitors, you are the controller and we are your processor, under the Data Processing Terms.

What we collect #

WhatWhyWhere it comes from
Name, email, profile photoTo identify your account and to contact youYou, and your sign-in provider
Workspace name, industry, sizeTo set up the workspace and shape what we show youYou, during onboarding
Subscription and payment statusTo know what you are entitled to use, and to billStripe; we never see card numbers
Your content: sites, files, records, messagesTo provide the products to youYou and your members
Usage events: runs, views, feature countsTo know what is used and what is brokenThe products, as you use them
Page views on our own sitesTo understand what is read, under your consent choicesOur sites, as the Cookie Policy describes
Support submissionsTo answer youThe support forms and email
Records of agreementTo show which terms you agreed to, and whenBilling and checkout

The public support form additionally records the page you were on, the error the app reported, your browser version and a hashed form of your IP address. The hash exists only to limit abuse of a form that requires no sign-in; the address itself is never stored by that form. Our hosting provider processes IP addresses and browser details to serve every request.

How we use it, and the legal basis #

  • To provide the products you signed up for, and to bill for them: performance of our contract with you.
  • To secure the service, prevent fraud and abuse, enforce our terms and defend legal claims: our legitimate interests, and legal obligation where it applies.
  • To understand and improve the products from usage counts: our legitimate interests.
  • To send operational messages (invitations, receipts, security and policy notices): contract and legitimate interests. These are not optional while your account is open.
  • To send marketing, and to measure our own sites beyond what is essential: your consent, which you can withdraw at any time.
  • To comply with the law, including tax and accounting records: legal obligation.

What we do not do #

  • We do not sell your data, or share it for anyone else's advertising.
  • We do not use your content to train machine-learning models.
  • We do not read your projects, files, messages or client material in the course of running the service.
  • We do not run third-party advertising or tracking pixels in the products.

Support is the exception, and only with your involvement: if you send us a screenshot or ask us to look at a specific record, we look at that record. We do not browse. Staff may also open a workspace to support it, to review content reported to us, or to enforce our terms or comply with the law; staff access is limited by role, and every change made that way is logged.

Who else processes it #

We use a small number of providers to run the service. Each processes data only on our instructions and only for the purpose named. The full list, with what each one handles, is on the Subprocessors page.

Services you connect yourself (your own AI provider key for the in-app agent, apps and connectors from the Marketplace, GitHub, an agent you connect over MCP) receive the data you direct to them, under their own terms. They are your providers, not ours.

We also disclose data where the law requires it or a valid legal process demands it, to protect the rights, property or safety of Stacklumen, our customers or the public, to professional advisers bound by confidentiality, and to a successor in a merger, acquisition or sale of assets, who would be bound by this policy.

Your clients and your visitors #

Data your workspace collects (client records, portal guests, form submissions, CMS entries and the pages you publish) belongs to you, and we process it on your instructions. You are responsible for telling your clients and visitors what you collect and why.

If you arrived here as a visitor of a site published through Stacklumen, or as a guest in somebody's client portal, the site or workspace owner is who to contact about your data. Requests that reach us by mistake are forwarded to them.

How long we keep it #

  • Account and workspace data: while your account exists. A deleted workspace can be restored for 14 days, and is then purged.
  • Usage events: retained in aggregate for product analysis.
  • Support submissions: kept while the matter is open and for a reasonable period afterwards for context.
  • Billing records and records of agreement: kept as long as tax and accounting law requires, and as long as we need them to resolve a dispute, which is longer than the account itself.
  • Records connected to a breach of our terms or a legal matter: kept for as long as the matter requires.

Where it is stored, and how it is protected #

The service is hosted in the United States, and your data is stored and processed there. If you use the products from elsewhere, your data is transferred to the United States, and we rely on the safeguards the law provides for that transfer. We protect data with encryption in transit, access controls and least-privilege access for staff, but no system is perfectly secure, and we cannot guarantee that data will never be accessed without authorisation. If a breach affects your personal data, we will tell you as the law requires.

Your rights #

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, to withdraw consent, and to complain to a regulator. California residents have the right to know, delete and correct, and not to be discriminated against for exercising them; we do not sell or share personal information as California law defines it. Write to support@stacklumen.com and we will act on it within 30 days, after confirming it is you.

Much of it you can do yourself: the Profile tab edits your details, the Agency tab edits the workspace, and deleting a workspace removes it and its contents. To delete your account, write to us; deleting it deletes your data, subject to what the law and the retention above require us to keep.

Children #

The products are for people aged 18 and over. We do not knowingly collect personal data from children, and we delete it if we learn we have.

Cookies #

We set cookies that are necessary for the service to work, principally your sign-in session and your interface preferences such as theme and rail state. We do not set advertising cookies, and we do not use cross-site tracking. The Cookie Policy lists what our public sites store and how your consent choices work.

Changes #

We will update this policy as the products change. Each version carries its effective date, and material changes are announced in the products or by email before they take effect.

These are the binding terms Stacklumen operates Baselumen by. The short version at the top of each document is a summary and does not change it. Nothing here is legal advice to you; if a decision depends on these terms, ask your own counsel. Earlier versions are available on request, and anything that looks wrong or unclear can be raised at support@stacklumen.com.