Your privacy matters. Here is exactly how we handle your data — in plain English.
Last updated: July 2, 2026
Introduction
STOA Tools ("we," "our," or "us") is operated by STOA Digital Solutions (stoa.agency). This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our website at tools.stoa.agency and related services (collectively, the "Service").
We are committed to being transparent about your data. We wrote this policy in simple language so you can actually understand it. If you have questions, email us at hello@stoa.agency.
What We Collect
We collect information in a few different ways:
Information You Give Us
Account information: When you sign up, we collect your email address, name, and password. If you sign in with Google, we receive your name and email from Google.
Business profile: During onboarding, we collect your company name, industry, number of employees, annual revenue range, your role in the company, whether you make software purchasing decisions, how many team members use software daily, and your biggest technology frustration.
Business processes: We ask which business processes you manage (such as sales, marketing, HR, or operations), how each process is currently handled, your top priorities, your monthly software budget range, and when you plan to make changes.
Current software stack: We collect which software tools you currently use, how satisfied you are with each one (love it, it's fine, frustrating, or want to replace it), why you are dissatisfied if applicable, and which business processes each tool supports.
Primary goal: We ask what you most want to accomplish with better software so we can tailor your recommendations.
AI conversations: When you chat with our AI Tech Advisor, we store the conversation history. To personalize responses, we also include a summary of your business profile (industry, company size, current tools) as context for the AI.
Assessment responses: When you use our Tech Stack Assessment, we collect your answers so we can generate personalized recommendations.
Newsletter subscription: If you subscribe to our weekly digest, we collect your email address. We also mirror subscriber data to our marketing platform (Mautic) for lifecycle emails and preference management.
ROI Calculator leads: If you use our ROI Calculator and submit your email, we collect your email address, the inputs you entered in the wizard, and the computed savings estimate so we can send your results and follow up.
Payment information: If you subscribe to a paid plan (monthly, yearly, or lifetime), your payment details are processed securely by Stripe. We never see or store your full credit card number.
Feedback and ratings: If you rate an AI response or leave a comment, we store that feedback to improve our recommendations.
Consultant client data: If you use our Consultant plan, you may enter information about your clients, including their company name, contact name, contact email, industry, company size, revenue range, pain points, notes, and their current software stack with satisfaction ratings. You are responsible for having permission to share this data with us.
Information We Collect Automatically
Usage data: We track which pages you visit, which tools you view, searches you perform, and how you interact with the platform. This helps us improve the experience.
Device information: We collect basic information about your browser, operating system, and device type.
IP address: We collect your IP address for security purposes and to understand where our users are located (at a country/region level).
AI usage metrics: When you use AI-powered features, we log which AI model was used, the number of tokens processed, response time, and estimated cost. This helps us manage service quality and enforce plan-based usage limits.
Affiliate click tracking: When you click an outbound partner or affiliate link, we may log the tool, an optional account ID if you are signed in, and the page you came from. This helps us understand which recommendations drive interest.
Session replay and frontend diagnostics: With your consent, Better Stack may record session replays, web vitals, frontend errors, and console logs to help us debug issues and improve performance.
Email engagement: If you receive marketing or digest emails through Mautic, we may receive open and click events via webhooks to measure engagement and honor unsubscribe requests.
Information We Store Temporarily
Session storage: While you are completing onboarding, your form progress is saved in your browser's session storage so you do not lose your work if you navigate away. This data is cleared when you close the browser tab and is never sent to our servers until you complete onboarding.
Cookies and Tracking
We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how you use our site. Here is a breakdown:
Essential cookies: Our authentication provider (Supabase) sets a session cookie to keep you signed in. These are required for the site to work properly. You cannot opt out of these.
Preference storage: We store your theme choice (light/dark) in your browser's local storage. This is not shared with third parties.
Analytics cookies (consent required): We use Google Analytics 4 to understand how people use STOA Tools and Better Stack for real-user monitoring (web vitals, session replays, and frontend errors). When you are signed in, analytics events may be linked to your account ID so we can understand feature usage across subscription tiers.
Marketing cookies (consent required): Mautic sets tracking cookies (such as mtc_*) to attribute visits and link signed-in users to lifecycle email campaigns. When you are signed in, we may also send a one-pixel tracking request that includes your email address so Mautic can link your visit to your contact record.
Survey cookies (consent required): We use Formbricks for in-app surveys and feedback. Formbricks may set cookies on feedback.stoa.agency to track which surveys you have seen or completed.
Search widget (consent required): If enabled, our Cloudflare AI Search widget sends your search queries to Cloudflare to return results from our site content.
Non-essential cookies are blocked until you choose Accept all, Reject non-essential, or customize your preferences. You can change your choices anytime via in the site footer.
We do not use advertising cookies or sell your identifiable data to ad networks.
Third-Party Services
We use trusted third-party services to run STOA Tools. Here is who has access to what, organized by function:
Data Storage and Authentication
Supabase (database and authentication): Stores your account data, business profile, tool ratings, AI conversations, and assessment results. Supabase provides our authentication system and database hosting.
Upstash Redis (caching): Temporarily caches your profile data and tracks monthly usage counts for rate-limited features (like AI chat limits). Cached data expires automatically, typically within 24 hours.
AI and Recommendations
OpenRouter (AI model routing): Routes AI requests to language models from providers including Anthropic (Claude), Google (Gemini), and OpenAI (GPT). Your conversation messages and a summary of your business profile (industry, company size, current tools) are sent to generate personalized recommendations. OpenRouter does not store your data beyond processing the request. Each provider's own data policies apply to their processing of your messages.
Qdrant Cloud (search): Stores vector embeddings (mathematical representations) of tool descriptions, integrations, and use cases to power our semantic search. Your search queries are converted to vectors for matching but are not stored permanently in Qdrant.
Cloudflare AI Search (site search widget): When enabled and you have granted functional consent, search queries you enter in the site search widget are processed by Cloudflare to return results from our published content.
Payments
Stripe (payment processing): Processes subscription payments securely. Stripe stores your payment method details (card number, billing address) on their servers. We only receive a token — we never see your full card number.
Communications
Resend (email delivery): Sends transactional emails (confirmation emails, password resets) and our weekly digest newsletter. Resend processes your email address to deliver these messages.
Mautic (marketing automation, self-hosted at mautic.stoa.agency): Manages lifecycle email, lead scoring, and campaign attribution. On the client, Mautic's tracking script records visits, may fire a tracking pixel containing your email when you are signed in, and may link anonymous cookies to your account. On our servers, we sync contact data on signup, onboarding, subscription changes, newsletter signups, ROI calculator submissions, and AI advisor usage. Mautic webhooks notify us of email opens, clicks, and unsubscribes. Lead scores may sync back to your STOA Tools profile.
Analytics and Feedback
Google Analytics 4 (analytics): Tracks usage patterns to help us improve the product. When you are signed in, events may be associated with your account ID to understand feature usage per subscription tier. Data is processed by Google LLC.
Formbricks (surveys and feedback): Powers in-app surveys and feedback collection. We share your email, name, and subscription plan with Formbricks to target relevant surveys. Formbricks is self-hosted on our infrastructure.
Infrastructure and Monitoring
Vercel (hosting): Hosts our website. Vercel may process server logs that include IP addresses and request data.
Better Stack (monitoring): We use two layers. Client-side real-user monitoring (betterstack.net) collects web vitals, session replays, frontend errors, and console logs when you grant analytics consent. Server-side OpenTelemetry exports HTTP traces, server logs, and AI telemetry to Better Stack — this does not use browser cookies.
How We Use Your Data
We use your information to:
Provide and improve the STOA Tools platform
Personalize your tool recommendations based on your business profile, processes, current stack, and goals
Power AI-powered recommendations by including your business context in AI conversations
Track AI feature usage (model used, token counts, response times) to manage costs and improve quality
Enforce usage limits based on your subscription plan
Send you the weekly digest newsletter (only if you opted in)
Process subscription payments
Respond to your questions and support requests
Generate Tech Stack Assessment reports and Team Training guides
Enable consultants to manage client software assessments (Consultant plan only)
Prevent fraud and protect the security of our platform
Understand usage patterns so we can build better features
Run lifecycle email marketing and lead scoring (with your consent where required)
Show in-app product surveys and measure email engagement
Diagnose frontend issues using session replay and error monitoring (with analytics consent)
We do not sell your personal information to anyone. Period.
Data Retention
We keep different types of data for different periods:
Account and profile data: Retained while your account is active. If you delete your account, we will remove your personal data within 30 days, except where we are legally required to retain it.
AI conversations: Retained while your account is active. You can delete individual conversations from your dashboard at any time.
AI usage logs: Retained for 12 months for billing and quality improvement purposes, then aggregated and anonymized.
Cached data: Automatically expires within 24 hours.
Payment records: Retained as required by tax law, typically 7 years.
Newsletter subscriber data: Retained until you unsubscribe. After unsubscribing, we keep your email address in a suppression list to make sure we do not accidentally email you again.
Mautic contact data: Retained while you remain subscribed or have an active account, unless you unsubscribe or request deletion.
Anonymous analytics data: May be retained indefinitely in aggregate form.
Anonymized Knowledge & Aggregated Insights
We extract anonymized, aggregated insights from user interactions to improve our recommendation engine and produce market intelligence. This process is designed to protect your privacy:
No personal information is retained: All identifying information (names, email addresses, company names, specific financial details) is stripped before any insight is created.
Minimum group sizes enforced: No insight can represent fewer than 10 distinct users. This ensures that individual behavior cannot be inferred from aggregate data.
Only structured insights, never raw conversations: We extract patterns like tool preferences, common pain points, and workflow trends — never verbatim conversation text.
Insights may be shared in aggregate form: Anonymized, aggregated insights may be used to improve our services and may be shared with or sold to third parties (such as software vendors or market researchers) in aggregate form only. No individual-level data is ever shared.
You can opt out: You can disable this in your dashboard settings at any time. Opting out means your future conversations will not be included in knowledge extraction. Already-extracted insights cannot be traced back to you and are retained in their anonymized form.
Legal basis: We process this data under legitimate interest (GDPR Article 6(1)(f)), as the fully anonymized and aggregated nature of the insights means no personal data is retained in the knowledge pool.
Your Rights
You have the right to:
Access your data: You can view your profile, assessment history, and conversation logs in your dashboard at any time.
Update your data: You can edit your profile and preferences from your account settings.
Delete your data: You can request account deletion through your account settings or by contacting us. We will process your request within 30 days.
Export your data: You can request a copy of your personal data by contacting us.
Opt out of marketing: You can unsubscribe from our newsletter at any time using the link in every email.
Manage cookie preferences: Use in the site footer to accept, reject, or customize non-essential cookies at any time.
If you are in the European Economic Area or United Kingdom, we process personal data under these legal bases:
Contract: To provide your account, AI features, assessments, and paid subscriptions.
Consent: For non-essential cookies, newsletter emails, and in-app surveys where required.
Legitimate interest: For security, fraud prevention, product improvement, and anonymized knowledge extraction (with opt-out available in dashboard settings).
International Data Transfers
STOA Tools is operated from the United States. Your data may be processed in the U.S. and other countries where our service providers operate, including Supabase, Vercel, Stripe, Google, Cloudflare, OpenRouter, Qdrant, Resend, and Better Stack. These providers may use standard contractual safeguards where required by law. If you are outside the U.S., you may have additional rights under local privacy laws.
California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Right to know: You can request details about the categories of personal information we collect, the purposes for collecting it, and the third parties we share it with.
Right to delete: You can request that we delete the personal information we have collected about you, subject to certain exceptions.
Right to opt out of sale or sharing: We do not sell or share your personal information for cross-context behavioral advertising. Anonymized aggregate market insights (with no individual-level data) may be licensed to third parties — this does not constitute a sale of personal information under CCPA. Use to manage optional tracking cookies.
Right to non-discrimination: We will not treat you differently for exercising your privacy rights.
Right to limit use of sensitive data: We collect business financial information (such as revenue range and software budget) that may be considered sensitive under California law. This data is used solely to personalize your software recommendations and is never shared for unrelated purposes.
To exercise any of these rights, email us at hello@stoa.agency. We will respond within 45 days as required by law.
Data Security
We take reasonable measures to protect your personal information, including:
Encrypted data transmission (HTTPS) for all connections
Row-level security policies on our database to prevent unauthorized access
Secure password hashing (handled by Supabase Auth)
PCI-compliant payment processing through Stripe
Regular security reviews of our codebase and dependencies
No system is 100% secure. If we ever discover a data breach that affects your personal information, we will notify you as required by applicable law.
Children's Privacy
STOA Tools is designed for business owners and professionals. We do not knowingly collect personal information from anyone under 16 years of age. If you believe we have collected data from a minor, please contact us and we will delete it promptly.
Changes to This Policy
We may update this privacy policy from time to time. When we make significant changes, we will notify you by email (if you have an account) or by posting a notice on our website. The date at the top of this page always shows when the policy was last updated.
Contact Us
If you have any questions about this privacy policy or how we handle your data, please reach out: