Privacy Policy
Version
v1.1.0
This Privacy Policy explains how Stirling PDF, Inc. ("Stirling," "we," "us," or "our") collects, uses, shares, and protects personal information when you visit our websites, use our products and services, or otherwise interact with us.
We design our Services to minimize personal data. We do not sell personal information and do not share it for cross-context behavioral advertising. In our own activities as a controller (Section 1) we do not use automated decision-making that produces legal or similarly significant effects; document processing you configure through the product runs at your direction, and you are responsible for how you use its outputs.
If you do not agree with this Policy, please do not use the Services. You can contact us anytime at [email protected] with questions or requests.
1. Our two roles
Stirling acts in two roles, and this Policy is precise about which applies:
Your account, authentication, billing, metering, security, fraud prevention, product analytics, support, marketing, recruiting — Our primary role: Controller · Whose policy governs: This Policy
The content of files you process through the Services (including any personal data inside them) — Our primary role: Processor / service provider, acting on your instructions · Whose policy governs: Your organization's privacy notices, and our data processing terms
Some activities involve both roles for different purposes — for example, we may process the same account data as a processor where we act solely on an organization's documented instructions, and as a controller for our own security, billing, and legal obligations. Where this Policy says "we do not," it speaks to our controller activities unless it says otherwise.
2. What information do we collect?
2.1 Information you provide to us
Account & contact data. Name, email address, organization, and similar information when you create an account, sign up for communications, request support, or otherwise contact us.
Billing. If you purchase a paid offering, payment details are processed by our payment processor (e.g., Stripe). We do not store full payment card numbers.
Content you choose to send us. When you voluntarily share files or information with our support team (e.g., for troubleshooting), we process that content solely to address your request.
Recruiting or event data. Information you submit when applying for a role or signing up for events or surveys.
2.2 Information collected automatically
Usage & device data. IP address (stored and/or logged in a truncated or full form), browser and device type, pages visited, referring/exit pages, timestamps, and similar diagnostic data to operate, secure, and improve the Services.
Approximate location. We infer a general location from IP address. We do not collect precise (GPS-level) location.
Cookies & similar technologies. See Section 6.
2.3 Information from third parties and integrations
Authentication providers. If you log in with a provider (e.g., GitHub or Google), we receive basic profile details permitted by that provider (usually name, email, avatar) for authentication and account linking (see Section 7).
Payments & fraud prevention. Payment processors supply limited data to confirm transactions and prevent fraud.
Google APIs (if you connect them). Where applicable, we access Google user data only to provide requested functionality and handle it in line with the Google API Services User Data Policy (Limited Use).
2.4 Customer file content; self-hosted deployments; sensitive data
Customer file content (hosted). Documents you process through our hosted Services are your files, processed at your direction (see Terms §7.1). We process them as a processor/service provider on your behalf: your policies, pipelines, and retention settings decide what happens to them and how long they are stored.
Self-hosted. If you deploy self-hosted Stirling PDF, your organization controls that environment. We do not access your self-hosted files or logs unless you choose to share them with us (e.g., support). Paid self-hosted deployments transmit license-validation and usage-metering data to us: process counts, file sizes, file hashes (for billing integrity), and diagnostic data — never file content or file names.
Sensitive data. Do not submit "special categories of personal data" under the GDPR (such as health, biometric, racial/ethnic origin, political opinions, or religious beliefs) to us directly — for example in account fields, support tickets, or survey responses; if you do, we will take commercially reasonable steps to delete it once identified. This restriction does not apply to the customer file content you process through the Services: customers may lawfully process documents containing such data (for example, health records) as the controller of that content, and we process it solely as your processor under our data processing terms. You are responsible for having a lawful basis for the content you process.
3. How do we use personal information?
We use personal information to:
Provide and maintain the Services (including account creation, authentication, core functionality, and customer support).
Secure and monitor the Services (fraud, abuse, incident detection, and service reliability).
Improve and develop features (analytics, quality assurance, research, and de-identified reporting).
Communicate with you (service notifications, transactional emails, and — if you opt in — product updates or marketing that you can unsubscribe from at any time).
Comply with law and enforce our terms.
Protect vital interests where required (e.g., to prevent harm).
In our controller activities, we do not use personal information for cross-context behavioral advertising or for automated decisions with legal or similarly significant effects.
4. What legal bases do we rely on (EEA/UK)?
Where GDPR applies, we process personal data on these bases: contract (to provide the Services you request); legitimate interests, balanced against your rights — specifically: securing the Services and preventing fraud and abuse; measuring and improving product performance; enforcing our terms and protecting legal rights; and communicating service information to business contacts; consent (e.g., for certain cookies/marketing where required; you may withdraw at any time); and legal obligation and vital interests where applicable.
Account identifiers and billing details are required to provide an account or a paid plan — without them we cannot provide those Services; other data (for example, optional profile fields or analytics) is not required, and declining it does not affect the Services.
When we process customer data on behalf of an organization (e.g., customer file content, self-hosted environments, or enterprise arrangements), that organization is the controller and we act as a processor under a separate agreement.
5. When and with whom do we share information?
We share personal information only with:
Service providers that help us operate the Services (e.g., hosting, security, analytics, email, customer support, and payments). They access data under contract and only to perform work for us. Our current subprocessors are listed at /legal/subprocessors.
AI model providers, for AI features only. The classification, extraction, redaction-assist, and Stirling Assistant features use models from Anthropic (which receives prompts and queries) and Voyage AI (which receives extracted text excerpts solely to generate embeddings, only where you enable retrieval features). No complete customer files are transmitted to any AI provider; prompts, queries, and excerpts are derived from your content and may contain personal data. Neither provider uses your data to train models (contractually confirmed).
Organizational admins (if your account is provided by your employer or team).
Corporate events (merger, acquisition, or asset transfer) subject to continuity of protections.
Legal/safety reasons (to comply with law, enforce terms, or protect rights and safety).
We do not sell personal information and do not share it for cross-context behavioral advertising. We also do not permit our service providers to use your data for their own marketing. Pseudonymous identifiers, telemetry events, and file hashes can be personal data, and we treat them under this Policy where they are.
6. Cookies and similar technologies
We use essential cookies to run our site and Services and optional analytics cookies to understand usage and improve the product. Product analytics run on EU-hosted infrastructure (PostHog) and collect pseudonymous usage events — never file content. Website measurement uses Google Analytics, delivered through Google Tag Manager, which involves a transfer of pseudonymous usage data to Google in the United States under Standard Contractual Clauses; it never receives file content. Analytics cookies are set only with your consent where consent is required. You can manage or withdraw your choices at any time through the cookie banner ("Consent Preferences" in the site footer) or your browser.
7. How we handle social logins
If you choose to register or log in using a social account (e.g., GitHub or Google), we receive basic profile information permitted by that provider solely to create or link your account. You can disconnect through the provider's settings and, where applicable, in your account with us.
8. International data transfer
We are a U.S. company and may process information in the United States and other countries. Where required, we use appropriate safeguards (such as the EU Standard Contractual Clauses and the UK Addendum) for transfers from the EEA/UK/Switzerland. You may request a copy of the relevant safeguards via Section 17.
9. How long we keep information
We retain personal information only as long as necessary to provide the Services, comply with law, resolve disputes, and enforce agreements.
Customer file content (hosted): stored per the retention settings you configure; on account or workspace termination, deleted from live systems within thirty (30) days and from backups within ninety (90) days, consistent with our data processing terms.
Billing and transaction records: 7 years (tax/legal compliance).
Account information: until your account is deleted, then for up to 12 months in backups/logs.
Support tickets and correspondence: 2 years.
Retention may be extended where required by law, legal hold, or an active security investigation.
10. How we protect information
We use a combination of organizational and technical measures (access controls, encryption in transit, logging, and other safeguards) designed to protect personal information. No system is 100% secure; you are responsible for maintaining the security of your credentials and devices.
11. Children's Privacy
The Services are not intended for individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
12. Your privacy rights (global)
Depending on your location, you may have rights to: access the personal information we hold about you; correct inaccurate data; delete your data; port a copy of your data; restrict or object to certain processing (including where we rely on legitimate interests); withdraw consent (where processing is based on consent); and lodge a complaint with your local data protection authority.
In the EEA, UK, and Switzerland, you also have the right to lodge a complaint with your local data protection authority. A list of EU authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK, you can complain to the Information Commissioner's Office (ICO): https://ico.org.uk.
To exercise rights, see Section 17.
13. Do-Not-Track signals
We distinguish two kinds of browser signals. Opt-out preference signals (such as the Global Privacy Control) are legally recognized in some U.S. states as a request to opt out of sale, sharing, and targeted advertising; because we do not sell or share personal information or engage in targeted advertising, honoring the signal confirms that practice, and we treat GPC accordingly. Do-Not-Track (DNT) has no industry standard, and we do not respond to it. You can control cookies and analytics as described in Section 6.
14. US state privacy disclosures (including California)
Some U.S. state laws (e.g., California, Colorado, Connecticut, Utah, Virginia, and others) give residents specific rights. We provide the following disclosures:
Disclosures for the preceding 12 months.
Identifiers (name, email, IP, account IDs) — Collected: Yes · Sources: You; your devices; auth providers · Purposes: Provide, secure, support, bill · Disclosed for business purposes to: Hosting, security, analytics, email, payments providers
Commercial information (subscription status, transactions) — Collected: Yes · Sources: You; payment processor · Purposes: Billing, support · Disclosed for business purposes to: Payment processor; hosting
Internet/network activity (usage logs, device/browser) — Collected: Yes · Sources: Your devices · Purposes: Secure, improve, support · Disclosed for business purposes to: Hosting, security, analytics providers
Geolocation (general, from IP) — Collected: Yes · Sources: Your devices · Purposes: Security, localization · Disclosed for business purposes to: Hosting, security providers
Professional information (organization, role) — Collected: Yes · Sources: You · Purposes: Provide, support · Disclosed for business purposes to: Hosting, support providers
Customer-records information (Cal. Civ. §1798.80: name, contact, billing) — Collected: Yes · Sources: You; payment processor · Purposes: Provide, bill, support · Disclosed for business purposes to: Payment processor; hosting
Support-message contents — Collected: Yes · Sources: You · Purposes: Support · Disclosed for business purposes to: Hosting, support providers
Inferences — Collected: Limited product-usage analytics only; not used for profiling with legal or similarly significant effects · Sources: Your devices · Purposes: Improve · Disclosed for business purposes to: Analytics provider
Sensitive personal information — Collected: Account log-in credentials only, used solely for authentication and account security (a permitted purpose; we do not use them to infer characteristics). See Section 1 for file content. · Sources: You · Purposes: Authentication, security · Disclosed for business purposes to: Hosting, security providers
Biometric, precise geolocation, minors' data, audio/visual — Collected: No
Sold or shared: none — we have not sold personal information and do not share it for cross-context behavioral advertising.
We do not collect sensitive personal information about you as an account holder, biometric data, precise geolocation, or information about minors as minors. Customer file content processed through the Services may contain sensitive information; we process that content only as a service provider at the customer's direction, as described in Section 2.4.
Your state rights may include the ability to: access/know, correct, delete, obtain a portable copy, and opt out of sale, sharing, targeted advertising, and certain profiling. Because we do not sell or share personal information and do not engage in targeted advertising or significant profiling, our opt-out is currently a confirmation of that practice. You will not be discriminated against for exercising your rights.
Submitting requests; verification; appeals. Submit requests per Section 17. We verify requests by matching the information you provide against our records (for example, confirming control of the account email); we may request additional verification where the request is sensitive. An authorized agent may submit a request on your behalf with signed permission; we may still verify your identity directly. We respond within the time your state law requires (generally 45 days, extendable once with notice). If we decline a request, we will explain why, and — where your state provides an appeal right — you may appeal by replying to our decision with the subject line "Privacy Appeal"; we will respond to appeals within the statutory period, and you may also contact your state attorney general.
15. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date reflects the latest version. Material changes will be posted on this page (and, where appropriate, notified to you).
16. How to contact us; representatives
Email: [email protected]
Mail: Stirling PDF, Inc., 548 Market Street PMB 887643, San Francisco, CA 94104, United States.
Stirling PDF, Inc. is the data controller of your personal information (except customer file content, where your organization is the controller and we are the processor).
EU/UK representative (GDPR / UK GDPR Art. 27): Anthony Stirling — contact via [email protected] with the subject line "GDPR".
17. How to access, update, or delete your information
You can submit a privacy request to access, correct, delete, or export your personal information by emailing [email protected] with the subject line "Privacy Request." We will verify your request and respond as required by applicable law.
---