Legal
Data Processing Addendum
Effective date: June 23, 2026
1. Roles
When you use the hosted Service, you are the controller of personal data you submit (account profiles, organization membership, and the contents of memory you store). stored is the processor of that data. Polar is the merchant of record for paid plans and is an independent controller of payment data.
This addendum is a standard processor commitment. It does not grant a service-level agreement, uptime credit, or indemnity beyond the Terms of Service. Have counsel review it against your own compliance program before relying on it for enterprise procurement.
2. Processing instructions
We process personal data only to provide, secure, and bill the Service, and as otherwise required by law. We do not sell personal data and we do not use the contents of your memory to train our own or third parties’ models.
You may give further documented instructions through the dashboard (export, deletion, membership changes) or by emailing privacy@stored.to. We will notify you if an instruction appears to violate applicable law.
3. Security
We apply technical and organizational measures appropriate to the risk: TLS in transit, encryption of BYO provider keys and integration tokens at rest (AES-256-GCM), hashed API keys and invite tokens, tenant isolation of memory on the data plane, and access limited to operators who need it to run the Service.
These measures are described honestly. They are not a certified ISO, SOC, or similar attestation unless we publish one separately.
4. Subprocessors
We use the infrastructure providers listed at /legal/subprocessors. We remain responsible for their performance as processors. Material additions will be reflected on that page before they process production data.
5. International transfers
The Service is hosted in the United States by default. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on the transfer mechanisms our subprocessors publish (typically Standard Contractual Clauses) plus the safeguards in this addendum.
6. Assistance and deletion
We will assist you, at your cost if the request is excessive, with data-subject requests, DPIAs, and regulator inquiries that relate to our processing. After an account is closed we delete or anonymize associated personal data within 90 days, except where longer retention is required by law or to resolve disputes.
7. Contact
Privacy questions: privacy@stored.to. Security reports: security@stored.to.
Questions about this document? Email privacy@stored.to.
