Stetful
LegalTrustLegal contact

Privacy

Privacy Policy

How Stetful collects, uses, shares, retains, and protects information for the initial U.S. launch.

Documents

Legal

  • Terms
  • Privacy
  • Acceptable Use
  • AI Notice
  • Security
  • Changelog

Trust

  • Trust Principles

Document version

Effective
July 15, 2026
Updated
July 22, 2026
Service scope
U.S. business use

Contact routing

Use the right inbox.

  • Legal notices and terms questionslegal@stetful.com
  • Privacy, data protection, and data-rights requestsprivacy@stetful.com
  • Security reports and vulnerability disclosuressecurity@stetful.com

Effective date: July 15, 2026

Last updated: July 22, 2026

Short version

  • Every standard customer organization starts with Stetful’s standard legal-instrument profile; eligible final instruments contribute by default unless the customer expressly opts out or has a separate enterprise restriction.
  • Uploaded evidence and company legal records remain confidential service data. Stetful does not disclose the contributing customer, artifact, source text, filename, storage location, tenant interpretation, accepted state, or operational conclusion through party-scoped use.
  • A named contractual party may receive eligible, source-redacted normalized mechanics for review. An unrelated third party may not.
  • Structured data describes field support and confidence, effective-version posture, amendment coverage, and analysis coverage; it does not reproduce source passages.
  • We do not sell Customer Legal Content or use it to train foundation models or third-party models.
  • Voice dictation is optional. When you use it, Stetful sends the recording transiently to OpenAI for transcription; Stetful does not persist the raw audio or maintain a separate dictation transcript history.
  • Artifact deletion, future-contribution opt-out, party-use opt-out, retroactive suppression, account closure, and separately negotiated processor-only treatment are different operations.
  • Source-redacted structured observations may remain after artifact deletion or account closure only where a lawful, contractually permitted, current retained basis remains.
  • Stetful is initially for U.S. organizations and U.S. users.

1. Scope

This Privacy Policy explains how Stetful, Inc. (“Stetful,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use Stetful’s websites, landing page, first-question intake, product application, evidence upload features, AI-assisted legal-state analysis, and related services (the “Service”).

Read this Policy together with the Terms of Use, Acceptable Use Policy, AI Output and Legal-State Notice, and Subprocessors and Security Disclosure.

2. Information we collect

Account and contact information

We may collect your name, email address, organization, role, authentication information, account settings, support requests, legal/privacy/security requests, and related communications.

Organization and authority information

We may collect organization names, company identifiers, user roles, authority confirmations, review/acceptance receipts, and information needed to connect users to company records.

First-question intake

Before account creation, Stetful may collect a first question and optional legal-state attachments. This intake is short-lived unless you continue into an account or company context.

Optional voice dictation

If you activate voice dictation, your browser requests microphone access and keeps the recording in browser memory while it is sent through Stetful to OpenAI for transcription. OpenAI returns dictated text. If you choose Insert, Stetful places the text in the composer for review and editing; if you choose Send, Stetful appends the text and immediately submits the resulting question or prompt. Stetful does not persist the raw recording or maintain a separate history of dictation transcripts. If transcription fails, the browser may keep the recording only in memory so you can retry; it is cleared after a successful transcription, when you dismiss it, or when you navigate away. Text that you choose to send is then handled as your question or prompt under the other sections of this Policy.

Customer legal records and uploaded evidence

We collect legal-state material you submit, including questions, prompts, legal documents, contracts, governance records, cap table-related records, IP assignments, privacy/security records, commercial contracts, evidence files, company context, and review rationales (“Customer Legal Content”).

Derived legal-state and observation information

We may create derived information from Customer Legal Content, including extracted facts, evidence classifications, coverage checks, field-level support and confidence, evidence-basis records, source-redacted provenance summaries, observed legal instruments and parties, instrument-version graphs, effective-term resolutions, amendment and analysis coverage, normalized terms, instrument-level effects, party-entitlement decisions, customer reconciliations, tenant interpretations, evidence requests, proposed representations, findings, action cards, review receipts, audit events, and legal-state snapshots (“Legal-State Data”).

An evidence-basis record describes why Stetful is permitted to rely on evidence for a statement and what policy conditions apply. A source-redacted provenance summary describes source class, lineage, timing, and related limits without identifying a contributing customer or disclosing source content. Normalized terms and instrument-level effects preserve supported mechanics and field-level uncertainty without reproducing source passages. Version and analysis coverage state which versions and supported term families Stetful evaluated and where coverage is partial, unresolved, or insufficient.

Customer reconciliations and tenant interpretations are organization-specific review or reasoning layers. A platform-maintained instrument effect is not accepted state and does not become accepted state unless an authorized review and acceptance flow records that decision.

3. How we use information

We use information to:

  • provide, operate, maintain, and improve the Service;
  • create and maintain accounts, organizations, roles, and sessions;
  • answer legal-state questions from available state and evidence;
  • transcribe speech when you choose to use voice dictation;
  • process uploaded evidence and create Legal-State Data;
  • identify confidence-building evidence requests;
  • support proposed legal-state changes and company review/acceptance receipts;
  • secure the Service, detect abuse, troubleshoot errors, and prevent unauthorized access;
  • provide support and respond to legal, privacy, and security requests;
  • communicate about the Service and legal/policy updates;
  • comply with law and enforce our Terms; and
  • use aggregated, de-identified, or non-content operational metrics to improve Stetful.

4. AI processing and model training

Stetful may use AI providers to process bounded information needed to provide the Service, such as transcribing an optional voice recording, extracting facts, classifying evidence, drafting answers, or identifying coverage and confidence posture.

Stetful does not sell Customer Legal Content. Stetful does not use Customer Legal Content to train foundation models or third-party models, and it selects business or API provider services whose standard terms do not use business inputs and outputs for model training by default.

AI providers may process and, under their applicable service settings, retain limited Customer Legal Content to provide the Service, monitor for abuse or security threats, comply with law, and enforce their terms. Provider personnel may review content in limited abuse, security, support, or legal circumstances under provider controls. Not every provider request is necessarily subject to zero data retention or an “eyes off” configuration.

Stetful may use aggregated, de-identified, non-content telemetry and operational metrics to improve the Service. Stetful will not use raw Customer Legal Content for benchmarking, evaluation datasets, fine-tuning, or model training unless you explicitly authorize that use.

5. How we share information

We may share information with:

Service providers and subprocessors

We use providers for hosting, authentication, database, object storage, AI processing, security, code/operations tooling, and support communications. The Subprocessors and Security Disclosure identifies the current categories and providers.

Authorized users in your organization

We may make Customer Legal Content and Legal-State Data available to authorized users in the relevant organization according to their roles and permissions.

Legal, safety, and compliance recipients

We may disclose information if we believe disclosure is required by law, legal process, regulation, or a government request, or if needed to protect rights, security, confidentiality, safety, or the integrity of the Service.

Business transfers

If Stetful is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate confidentiality protections.

With your direction or consent

We may share information when you direct us to do so or when you consent.

6. Multi-party legal instruments, platform observations, and tenant isolation

Every organization using the Service under the standard Terms is automatically provisioned with Stetful’s standard legal-instrument profile. Eligible final or executed Customer Evidence may contribute source-redacted evidence-basis records, observed instrument and party structure, amendment and version relationships, normalized terms, analysis coverage, and instrument-level effects by default. A customer may expressly opt out of future contribution or party-scoped use. A separately negotiated enterprise agreement may narrow the profile for that customer.

A legal instrument may involve more than one organization. If Stetful currently identifies an organization as a named party to an instrument, Stetful may make eligible source-redacted structured mechanics available to that organization’s authorized users for reconciliation or orientation. A provisional identity match may be presented for review but does not establish accepted identity or accepted state. An unrelated third party is not an eligible recipient.

Stetful does not disclose the contributing customer, uploaded artifact, source passage or excerpt, filename, storage key or location, raw or deterministic extraction, privileged material, tenant-specific interpretation, accepted state, or operational conclusion to another organization through party-scoped use.

Party-scoped mechanics remain visibly unreviewed and include available field-level support and confidence, effective-version posture, amendment coverage, and analysis coverage. They may describe instrument-level effects, but they do not decide a customer’s company-specific transaction or become accepted state without the relevant facts and authorized review.

7. Retention

We keep information for as long as needed to provide the Service, maintain accepted state, comply with law, resolve disputes, enforce agreements, maintain security, and preserve audit and review history.

Current retention categories:

  • Pre-account first-question intake: short-lived unless converted into an account or company context.
  • Voice dictation: Stetful does not persist raw dictation audio or maintain a separate dictation transcript history. A failed recording may remain temporarily in browser memory for retry. OpenAI may retain request content under the applicable provider settings described in Section 4 and the Subprocessors and Security Disclosure.
  • Account and organization data: retained while the account or organization is active and for a reasonable period afterward for legal, security, and operational purposes.
  • Customer Legal Content and evidence objects: retained while needed for the customer’s legal-state record unless deleted, discarded, or subject to another retention rule.
  • Evidence-basis and source-redacted provenance records: may remain after source-artifact deletion or account closure only where lawful, contractually permitted, minimized, non-disclosing, not suppressed, and supported by a current retained basis.
  • Observed instruments, version relationships, normalized terms, analysis coverage, and instrument effects: may be independently maintained under the same restrictions. If the last permitted basis is removed or suppressed, dependent party-scoped use is blocked.
  • Customer reconciliations, tenant interpretations, tenant projections, and accepted state: remain tenant-specific and are retained while needed for review history, auditability, and answer revision, then deleted or de-identified with the tenant unless a lawful exception applies.
  • Worker jobs, operational metadata, and security logs: retained as needed to process, troubleshoot, audit, and secure the Service without intentionally placing customer legal content or raw extracted legal text in broad logs.
  • Backups: retained for limited backup and recovery periods and deleted on ordinary backup cycles.

Retention depends on source class, policy, dispute and suppression status, applicable law, and customer agreement. Stetful does not promise a deletion SLA, fixed retention period, residency, or processor-only treatment unless separately agreed and operationally supported.

8. Deletion, correction, and privacy requests

Contact privacy@stetful.com for privacy, data protection, and data-rights requests. We may ask you to verify identity, organizational authority, and the instrument or record at issue.

Tell us which operation you request because these controls are distinct:

  • future-contribution opt-out for eligible new Customer Evidence;
  • party-use opt-out for observations surfaced to your organization;
  • artifact deletion for a specific uploaded source artifact;
  • retroactive suppression review for existing structured observations or uses;
  • account closure for your tenant context; or
  • processor-only treatment, which requires a separate agreement and supported configuration.

If you believe an observed instrument, party match, normalized mechanic, version resolution, or analysis-coverage statement is inaccurate, incomplete, outdated, disputed, or does not belong to your organization, provide enough source-safe detail for Stetful to evaluate correction, identity review, dispute, or suppression without revealing another customer or source artifact.

We may decline or limit a request where allowed by law, including when retention is needed for security, legal compliance, dispute resolution, auditability, fraud or abuse prevention, or a lawful current retained basis. Artifact deletion or account closure does not automatically require retroactive suppression of every independently maintained observation. If no permitted basis remains, dependent use is blocked under the applicable policy.

9. Cookies and similar technologies

The marketing site does not use analytics cookies, pixels, external scripts, or third-party SDKs. The product app may use essential cookies or similar technologies for authentication, session management, security, and product operation.

If Stetful adds analytics, advertising, or non-essential cookies, this Policy and the product notices will be updated before those features launch.

10. Security

Stetful uses administrative, technical, and organizational measures designed to protect information, including tenant-scoped data handling, role/capability checks, object storage controls, worker/logging rules designed to avoid customer legal content in logs, and provider-based infrastructure security.

No system is perfectly secure. If you believe you found a vulnerability, contact security@stetful.com. Please do not include unnecessary Customer Legal Content in vulnerability reports.

11. U.S.-only launch posture

Stetful is operated from the United States and is initially for U.S. organizations and U.S. users. If you use Stetful from outside the United States or submit information about people outside the United States, you understand that information may be processed in the United States.

Stetful may add GDPR, UK, EU, international transfer, or data processing addendum terms later if needed for broader launch or enterprise contracting.

12. Children and minors

Stetful is not directed to children or minors. Do not use Stetful to store minors’ records or information unless that information is incidental to an authorized company legal record and you are legally permitted to provide it.

13. Changes to this Policy

We may update this Privacy Policy over time. We will post the updated version with a new effective date. Material updates may also be listed in the Legal Changelog or communicated through the Service or by email.

14. Contact

Stetful, Inc.
7775 Walton Parkway, Unit #192
New Albany, OH 43054

  • Legal notices and terms questions: legal@stetful.com
  • Privacy, data protection, and data-rights requests: privacy@stetful.com
  • Security reports and vulnerability disclosures: security@stetful.com

© 2026 Stetful, Inc.

Legal
  • Terms
  • Privacy
  • Acceptable Use
  • AI Notice
  • Security
  • Changelog
Trust
  • Trust Principles

Contact

  • legal@stetful.com
  • privacy@stetful.com
  • security@stetful.com