Privacy Notes

Last updated: 2026-07-19

S-tello Trace is a tool that “sees” how you work. We believe the privacy notes for such a tool shouldn't read like lawyers writing to lawyers — you should be able to understand, in five minutes, exactly what is recorded, where it lives, what leaves your machine, and how to undo everything. Here are the full answers.

1. What gets recorded

2. Where it lives

Screen pixels are used in memory on-device for OCR and key-frame selection by default; selected frames are written to local files only if you enable local replay. OCR, window titles, URLs, raw timeline rows, and personal work memory are stored in a local SQLite database on your machine. Signing in does not automatically copy them to the Stello cloud. The app shows the location and provides export and deletion controls.

Accounts and S-tello-hosted AI are in invite-only beta. If you sign in, acknowledge the current processing disclosure, and redeem an invite, account, allowance, and usage metadata enter a separate cloud control plane; the versioned consent receipt stays on this device. Signing in does not copy local work history. Local capture, Today, Week, Briefs, search, export, and local deletion continue to work when cloud services are unavailable.

3. What leaves your machine

Accounts and hosted AI are enabled only for the invite beta; organization/FDE sync is still not a public capability. Signing in, redeeming an invite, changing models, or submitting ordinary feedback does not enable organization sync.

4. Hosted-AI providers, regions, and retention

This hosted-AI path may involve cross-region or cross-border processing across Cloudflare's global network, Mumbai, India, and Beijing, China. Before using it, exclude sensitive apps and sites such as password managers and medical, financial, legal, or customer-confidential systems. Do not intentionally submit passwords, API keys, identity credentials, or other highly sensitive content to hosted AI. If this path is not acceptable, switch to loopback Ollama or choose and assess your own BYOK provider.

5. API keys and account sessions

The model key for S-tello-hosted mode stays server-side and is never sent to the client. API keys you provide are stored in the macOS Keychain; local configuration retains only non-secret provider, endpoint, and model metadata. A BYOK key is used only between your machine and that provider and is never attached to product feedback or organization data. The cloud-account refresh token uses a separate Keychain item; the access token is memory-only and does not enter the WebView, localStorage, logs, or exports.

6. How to undo

7. About Stello and organizations

Personal and organization spaces are separate isolation boundaries: joining an organization does not move personal history into it. Organization views should receive only separately consented derived facts and default to role, team, and workflow aggregates; cohorts smaller than three are not shown as team aggregates. FDE access will be purpose-, resource-, and time-bounded rather than tenant-wide or raw-evidence access by default. Cross-organization training and the data flywheel are currently disabled; organization consent does not grant cross-customer learning rights.

8. Questions

If anything above is unclear — or you find behavior that contradicts this document — reach us via s-tello.com/contact. “Behavior doesn't match the docs” is treated as a highest-priority bug here.