1. Scope and who we are
Stemera provides ScheduleFlow, an AI-assisted business operations product. This Privacy Policy describes the information ScheduleFlow accesses, how it is used, what may be stored, and the choices available to customers and authorized users.
Questions or requests can be sent to rob@stemerahq.com.
2. Google user data ScheduleFlow accesses
When a customer authorizes a Google account, ScheduleFlow may access the following data and capabilities only as needed to provide requested product functionality:
Gmail read access
Read relevant messages, threads, sender and recipient information, timestamps, labels, and attachments or metadata needed to understand incoming work and conversation context.
Gmail send access
Send an email only after the owner reviews and approves its content and then separately, explicitly authorizes execution.
Calendar read access
Read calendars, events, availability, attendees, and related metadata to interpret scheduling requests and suggest suitable times.
Calendar event creation
Create an event only after the owner reviews and approves its details and then separately, explicitly authorizes execution.
ScheduleFlow does not autonomously send external email or create calendar events. Preparation, approval, and execution are separate steps.
3. How we use information
Google user data and other customer-provided information are used only to provide and support ScheduleFlow functionality, including to:
- Summarize relevant email conversations and identify incoming work;
- Organize tasks, commitments, follow-ups, and open loops;
- Prepare draft email responses for owner review;
- Review scheduling requests and calendar availability;
- Suggest meeting times and prepare proposed calendar events;
- Execute approved Gmail and Calendar actions after separate explicit authorization;
- Produce a structured Morning Brief;
- Maintain operational continuity, audit history, security, and customer support.
Stemera does not sell Google user data or use it for advertising. Google user data is accessed, used, and transferred only as necessary to provide or improve user-facing ScheduleFlow functionality, maintain security, comply with applicable law, or when otherwise authorized by the customer.
When relevant content must be processed by a service provider to provide ScheduleFlow functionality, including the OpenAI processing described below, that processing is limited to purposes consistent with this Privacy Policy. Human access is limited to circumstances necessary to provide or improve user-facing functionality with permission, address security or abuse, comply with applicable law, or as otherwise permitted under Google’s policies.
4. AI processing and service providers
Relevant content may be transmitted to OpenAI through its API for AI processing such as summarization, classification, extraction, or draft generation. Stemera has disabled OpenAI API data sharing and model-training opt-ins and uses store=false for applicable API calls.
These settings do not mean that provider-side retention is always zero. Standard API provider retention may still apply for security, abuse prevention, legal, or service-operational purposes under the provider’s applicable terms and policies.
Stemera may also use infrastructure, backup, and operational service providers that process limited data on our behalf and under appropriate obligations.
5. Local data, storage, and retention
Operational data
While service is active, ScheduleFlow retains operational data as needed to provide the service. Raw inbound Gmail message bodies are not retained locally by default. Derived operational data may be retained, including summaries, tasks, drafts, approvals, audit history, meeting proposals, provider identifiers, and customer-specific configuration.
Backups
During active service, local backups use a 14-day rolling retention period. Encrypted off-device backups may also be used and follow a 14-day rolling retention period.
After termination
After service termination, customer data may be retained for up to 30 days to support recovery or export and is then deleted, subject to legal requirements. A customer may request earlier deletion. Deletion scope includes the customer workspace and database, backups as they roll out of the retention window, logs, OAuth tokens, and customer-specific configuration. Google access is disconnected or revoked during offboarding.
We may retain limited records when required by law or reasonably necessary to establish, exercise, or defend legal claims.
6. Google API Services Limited Use
ScheduleFlow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Your choices and requests
Customers may:
- Revoke ScheduleFlow’s access through their Google Account security settings;
- Request a manual export of customer data during active service or the post-termination retention window;
- Request deletion, including earlier deletion after termination, subject to legal requirements;
- Ask questions about data handling or correct relevant account information.
Send requests to rob@stemerahq.com. We may need to verify the requester’s identity and authority before completing a request.
8. Security
Stemera uses reasonable technical and organizational safeguards appropriate to the pilot-stage service, including access controls, scoped Google authorization, and encrypted off-device backups where used. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Changes to this policy
We may update this policy as ScheduleFlow develops or legal and operational requirements change. We will post the revised policy here with a new effective date and provide additional notice when appropriate.
10. Contact Stemera
For privacy questions, access revocation help, export requests, or deletion requests, contact:
Stemera
rob@stemerahq.com