StoneSky

The fine print

Privacy.

Stonesky.ai Privacy Policy
Effective Date: August 10, 2026

 

1. Introduction and Scope

 

This Privacy Policy describes how StoneSky.AI, LLC, an Illinois limited liability company (“StoneSky,” “we,” “us,” or “our“), collects, uses, and discloses personal information in connection with our websites, including stonesky.ai (the “Site“), our AI-native data custody and preservation platform and related services, including SkyKeep (collectively, the “Services“), and our marketing and sales activities.

This Policy covers personal information we handle as a “controller” (or “business”) — that is, information about:

  • Site visitors — people who browse the Site or interact with our content and forms;
  • Prospects and business contacts — people who request demos, sign up for communications, or interact with our sales and marketing;
  • Account users — individuals who register for or administer accounts on the Services on behalf of a customer.

This Policy does not cover Customer Content. Our business customers use the Services to store, preserve, and manage their own data (“Customer Content“), which may contain personal information about their employees, customers, or other individuals. For Customer Content, StoneSky acts as a “processor” or “service provider” on behalf of the customer, who is the controller of that data. We process Customer Content only per our customer’s instructions, our Terms of Use, and any applicable data processing addendum. If your personal information is contained in Customer Content, please direct privacy questions and rights requests to the organization that placed the data in our Services — we will refer any request we receive to the relevant customer and support their response as required by law. Section 5 (AI and Your Information) describes commitments that apply to Customer Content as well.

2. Information We Collect

2.1 Information you provide directly

  • Contact and business information — name, email address, company, job title, phone number, and message contents when you fill out contact, demo-request, or newsletter forms, register for events or webinars, or communicate with us.
  • Account information — name, business email, credentials (hashed), role, and preferences when an account is created for you on the Services.
  • Commercial information — records of subscriptions, order details, and billing contacts (payment card processing, where applicable, is handled by payment processors; we do not store full card numbers).
  • Support and feedback — the contents of support requests, feedback, and survey responses.

2.2 Information collected automatically

When you use the Site or Services, we and our service providers automatically collect:

  • Device and browsing data — IP address, browser type, operating system, device identifiers, referring URLs, pages viewed, links clicked, and timestamps.
  • Usage data — feature usage, session activity, and performance and diagnostic logs from the Services.
  • Cookies and similar technologies — see Section 6 (Cookies and Tracking Technologies).

2.3 Information from other sources

We may receive information from business partners, event co-sponsors, publicly available professional sources (e.g., company websites, LinkedIn), our CRM and marketing platforms, and lead-enrichment providers, and combine it with information we have. We may also receive contact information about you from a colleague (for example, when they add you as an account user or refer you).

2.4 Sensitive information

The Site and our marketing are not designed to collect sensitive personal information (such as government identifiers, precise geolocation, health data, or biometric identifiers), and we ask that you not submit it through our forms. See Section 10 for our Illinois biometric-data statement.

3. How We Use Personal Information

We use personal information to:

  • Provide and operate the Site and Services — create and administer accounts, authenticate users, deliver features, and provide support;
  • Communicate with you — respond to inquiries, send service and administrative messages, and provide requested information;
  • Market our Services — send newsletters and marketing communications (with opt-out in every message), personalize content, run and measure advertising campaigns, and understand our audience;
  • Improve and secure the Services — analyze usage, debug, develop new features, monitor for and prevent fraud, abuse, and security incidents;
  • Comply with law — meet legal, regulatory, tax, and audit obligations, enforce our agreements, and protect our rights and the rights of others.

We do not use personal information for automated decision-making that produces legal or similarly significant effects about individuals without human involvement.

4. How We Use AI — and How AI Uses Your Information

StoneSky is an AI-native company: machine learning is integral to how the Services classify, organize, enrich, and preserve data. Because of that, we hold ourselves to specific commitments about how AI intersects with your information:

  • No training on Customer Content. We do not use Customer Content — the data our customers place in our custody — to train, fine-tune, or improve generalized AI or machine learning models, whether ours or any third party’s. We contractually require our third-party AI model providers to honor the same restriction.
  • Third-party model providers, disclosed. Some AI features are powered by third-party foundation-model providers acting as our subprocessors under written data protection agreements. We will identify our material AI subprocessors upon request at hello@stonesky.ai. 
  • Zero retention with AI providers. Our agreements with third-party AI providers are configured so that Customer Content submitted for processing is not retained by the provider after processing is complete and is not used for the provider’s own purposes. 
  • Limited human access. StoneSky personnel do not access Customer Content in the ordinary course of operations. Access is limited to narrow circumstances: (a) with the customer’s permission, to provide requested support; (b) as necessary to secure and maintain the Services (e.g., incident response); or (c) as required by law. Such access is role-restricted, logged, and audited.
  • De-identified data. We may use aggregated, de-identified usage data (which cannot reasonably identify any person or customer) to operate, benchmark, and improve the Services. We commit to maintaining such data in de-identified form and not attempting to re-identify it.
  • AI in our own operations. We may use AI tools to help with internal operations (e.g., drafting support responses, summarizing inquiries). Where such tools process personal information, they are subject to the same vendor diligence and contractual protections as our other service providers.

5. How We Disclose Personal Information

We disclose personal information to:

  • Service providers / processors — hosting and infrastructure providers, AI model providers (per Section 4), analytics providers, CRM and marketing platforms, email delivery services, payment processors, and support tooling — each bound by contract to use the information only to provide services to us;
  • Advertising partners — as described in Section 6, advertising and social media platforms whose tags on our Site collect identifiers for ad measurement and retargeting (this may constitute a “sale” or “sharing” under some state laws — see Section 7);
  • Professional advisors — lawyers, accountants, auditors, and insurers as reasonably necessary;
  • In business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case this Policy will continue to apply to previously collected information unless you are notified otherwise;
  • For legal reasons — to comply with law, respond to lawful requests from public authorities, enforce our agreements, or protect the rights, safety, and property of StoneSky, our customers, or others. Where a legal demand seeks Customer Content, our practice is to redirect the requester to the customer and to notify the customer before disclosure unless legally prohibited;
  • With your direction or consent — when you ask us to share information or consent to a disclosure.

We do not sell personal information for money.

6. Cookies and Tracking Technologies

The Site uses cookies, pixels, and similar technologies:

  • Essential — required for the Site to function (e.g., security, load balancing, SEO / AEO tools). These cannot be disabled.
  • Analytics — services such as Google Analytics that help us understand Site traffic and usage. Google’s practices are described at https://policies.google.com/privacy; you can opt out of Google Analytics at https://tools.google.com/dlpage/gaoptout.
  • Marketing and advertising — tags and pixels from advertising and social platforms (such as Google Ads, Meta, LinkedIn) that collect device identifiers and browsing activity to measure campaigns and show you relevant ads on other sites (retargeting).

Your choices: You can manage cookies through your browser settings, and the opt-out mechanisms in Section 7. Industry opt-outs are also available at optout.aboutads.info and optout.networkadvertising.org. We honor Global Privacy Control (GPC) signals as an opt-out of targeted advertising where required by law. Because there is no consistent industry standard, we do not otherwise respond to “Do Not Track” browser signals.

7. Your US State Privacy Rights

Depending on your state of residence (including California, Colorado, Connecticut, Texas, Virginia, and other states with comprehensive privacy laws), you may have the right to:

  • Know / access — confirm whether we process your personal information and obtain a copy;
  • Correct — fix inaccurate personal information;
  • Delete — request deletion of personal information we hold about you;
  • Portability — receive your information in a portable format;
  • Opt out — opt out of (a) targeted advertising (“sharing” for cross-context behavioral advertising under California law), (b) “sales” of personal information, and (c) profiling in furtherance of decisions producing legal or similarly significant effects (which we do not do);
  • Non-discrimination — not receive discriminatory treatment for exercising your rights;
  • Appeal — appeal a refusal of your request (see below).

Categories disclosure (California). In the preceding 12 months we have collected the categories of personal information described in Section 2 (identifiers; commercial information; internet/network activity; professional information; inferences drawn from the foregoing), from the sources in Section 2, for the purposes in Section 3, and disclosed them as described in Section 5. Our use of advertising cookies and pixels may constitute “sharing” (and in some interpretations, a “sale”) of identifiers and internet activity to advertising partners. We do not knowingly sell or share the personal information of consumers under 16, and we do not collect or process sensitive personal information for purposes requiring a right to limit under California law.

How to exercise your rights:

  • Email hello@stonesky.ai with the subject “Privacy Rights Request”; or
  • Use the “Your Privacy Choices” link on the Site, or
  • Enable Global Privacy Control in your browser (treated as an opt-out of targeted advertising for that browser).

We will verify your request using the email address associated with you and, if needed, additional information (used only for verification). Authorized agents may submit requests with proof of authorization. We respond within the time required by applicable law (generally 45 days, extendable once). If we decline a request, you may appeal by replying to our decision with “Appeal” in the subject line; if the appeal is denied, we will provide a method to contact your state attorney general.

If your data is in Customer Content: rights requests must go to the customer (the controller); we will forward requests we receive and assist the customer as their processor.

8. Data Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, and then delete or de-identify it. Retention periods vary by category: prospect and marketing data is retained while relevant to the relationship and purged on a periodic schedule; account data is retained for the life of the customer relationship plus a limited wind-down period; billing records are retained as required by tax law; Site analytics are retained per the configured retention period of the analytics service. Customer Content is retained per the customer’s configuration and the export-and-deletion terms of the customer’s agreement (generally exported by the customer within 30 days after termination and deleted thereafter, subject to backup cycles and legal requirements).

9. Security

We maintain an information security program with administrative, technical, and physical safeguards designed to protect personal information — including encryption in transit and at rest, role-based access controls, logging and monitoring, and personnel training. No method of transmission or storage is completely secure; if we learn of a breach affecting your personal information, we will notify you and regulators as required by applicable law.

10. Illinois Biometric Information (BIPA)

StoneSky does not collect, capture, purchase, or otherwise obtain biometric identifiers or biometric information (such as fingerprints, voiceprints, or facial geometry scans) from Site visitors, prospects, or account users, and our AI features are not used to derive biometric identifiers from Customer Content on our own behalf. If this ever changes, we will first provide the written notice and obtain the consent required by the Illinois Biometric Information Privacy Act.

11. Children

The Site and Services are designed for business use and are not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 for the purposes of “sales”/”sharing”). If you believe a child has provided us personal information, contact hello@stonesky.ai and we will delete it.

12. United States Operations

The Services are operated from the United States and this Policy is designed for a US audience. If you access the Site or Services from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those of your jurisdiction. If StoneSky begins offering the Services to customers subject to the GDPR, UK GDPR, or similar regimes, we will update this Policy and our contracts (including a data processing addendum with appropriate transfer mechanisms) accordingly.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new effective date, and for material changes we will provide additional notice (such as email to account contacts or a prominent Site notice) before the changes take effect. Your continued use of the Site or Services after the effective date constitutes acceptance of the updated Policy.

14. Contact Us

StoneSky.AI, LLC Email: hello@stonesky.ai Website: https://stonesky.ai

For privacy rights requests, use the subject line “Privacy Rights Request.”

STONESKY™ and SKYKEEP™ are trademarks of StoneSky.AI, LLC.

Scroll to Top