← Back to Stella

Privacy Policy

Stella — FromYou LLC
Last updated: August 22, 2026

This Privacy Policy describes how FromYou LLC ("FromYou," "we," "us," or "our") handles information when you use Stella, including the desktop application, mobile companion app, backend services, and related websites or APIs (collectively, the "Service").

Stella uses a local-first desktop architecture: its normal desktop chat database, local workspace files, settings, and runtime state are stored on your device. The Service also includes cloud and third-party features. When you use managed AI, media generation, web search, mobile access, connected services, cloud backups, publishing, or other hosted features, the information needed to provide them may be transmitted to, processed by, and in some cases retained by FromYou and our service providers.


1. Local-First Desktop Storage

Stella runs primarily on your local machine:

• Your normal desktop chat history, agent state, tool outputs, settings, and local workspace files are stored on your device.
• Some core functionality can be used without a registered account, although anonymous device and usage data may still be processed for rate limiting and security.
• Local storage does not mean that every request remains on-device. Content is transmitted when a feature requires a cloud service or third-party provider.


2. Data Commonly Kept Local

FromYou does not routinely upload a general-purpose copy of the following local data merely because it exists on your device:

• Your normal desktop chat database as a whole
• Files on your computer or files created, modified, or deleted by Stella's AI agents
• Screenshots, screen captures, or on-screen content read by the agent
• Websites visited, forms filled, or actions taken by Stella's browser-use capabilities
• Browser history, bookmarks, or browsing data (yours or the agent's)
• Contents of your messages, notes, or calendar
• Shell commands executed by the agent or their output
• Voice recordings or transcripts
• Any data discovered during onboarding personalization
• Your locally stored API keys
• Your locally stored Stella settings and runtime files

Any of these categories may nevertheless be included in a request when you or an agent uses managed AI, media generation, search, mobile access, a connected service, publishing, backup, or another cloud feature. For example, a screenshot, file excerpt, web content, tool output, or prior message may be sent as model context. This section is not a promise that listed data never leaves your device.


3. Information Stored Locally on Your Device

The following data is ordinarily created and stored on your device. Items may be transmitted when needed for a feature you invoke or authorize:

• Conversations and chat history — your interactions with Stella
• Agent state and event transcripts — runtime operation of the AI agent system
• Tool execution results — output from shell commands, file operations, web searches, browser actions
• Computer-use activity logs — records of agent actions (browsing, file edits, commands)
• Discovery signals — optional onboarding personalization data (browser bookmarks, apps, dev environment, etc.)
• Pseudonymized identity map — de-identification of personal names/contacts found during discovery
• Voice transcripts — records of voice interactions
• LLM API keys (encrypted) — your own provider credentials for BYOK use
• Local preferences and settings — theme, model preferences, configuration
• Local app projects and skills — projects and extensions stored in your Stella workspace
• Device identity keypair — cryptographic identity for your device
• Local SQLite database — persistent storage for all of the above

You can delete local data by removing the Stella data directory from your device or using available in-app reset controls. Deleting local data does not automatically delete data already sent to a third party or stored for a cloud feature.


4. Information Processed by Our Services

Depending on the features you use, our backend may process or store:

Stella Provider (Managed LLM Inference) — When you use managed AI, your prompt, attachments, relevant conversation context, tool definitions or results, and model output pass through our infrastructure to the provider selected for the request. Depending on the model and routing path, providers may include OpenAI, Anthropic, Google, xAI, OpenRouter, or Fireworks. We record usage and operational metadata such as owner or anonymous identifier, model, agent type, token counts, duration, estimated cost, plan, timestamp, and success or failure. We do not intentionally retain provider request content as a model-training product. We may temporarily buffer plaintext response text, reasoning, and tool arguments for stream recovery; current relay access expires after brief inactivity and has a hard ten-minute lifetime, while cleanup and security records may persist longer. When a BYOK call goes directly from your device to your selected provider, FromYou's managed model relay is not involved, but the provider still processes the request under its own terms.

Mobile and Connector Delivery — When you interact through the mobile app or a connected messaging service, our backend may store request text or references, delivery and routing metadata, request state, stream state, and response delivery data so a desktop or service can claim, cancel, complete, and deliver the work. Records are deleted or expire according to operational cleanup rules, which vary by record type.

Media, Search, and Connected Services — Media prompts, uploaded files, generated outputs, search queries, search results, and connected-service content may pass through our infrastructure. Stella may temporarily store encrypted media submission payloads and may store generated media, references, job state, or connected-service records as needed to deliver and manage those features.

Optional Cloud Content — Cloud backups, publishing, social or collaboration features, and other hosted features store the content and metadata needed to provide them.


5. Computer Use and Agent Activity Data

Stella's AI agents can perform actions on your computer, including browsing the web, executing commands, reading and writing files, and interacting with applications. Much of this activity occurs locally, with the following cloud-processing exceptions:

• Websites the agent visits, forms it fills, and data it reads from web pages may remain local, but relevant content can be included in model, search, connector, or connected-service requests.
• Files the agent creates, reads, modifies, or deletes remain on your local filesystem.
• Shell commands and their output are executed and stored locally.
• Screenshots and screen content captured by the agent remain local unless included as context for a model call or another feature.
• The desktop action history is recorded in your local conversation log; relevant portions may be submitted as context for a cloud-backed feature.

When an action requires managed AI or another cloud-backed feature, the submitted context is processed as described in this policy. BYOK requests may bypass FromYou's managed model relay, but they are still processed by the provider you choose.


6. Information We Collect When You Create an Account

Account creation is optional. If you choose to sign in, we collect: your email address (for authentication and account identification), your name if provided (for display purposes), and your account creation timestamp (for account management).

We use Better Auth for authentication, with magic-link email sign-in and optional Google sign-in. We do not collect passwords.


7. Billing Information

If you subscribe to a paid Stella Provider plan, payment is processed by Stripe. We store: Stripe customer ID (linking your account to Stripe), subscription status and plan (determining your access level), payment method brand and last 4 digits (displaying payment info in settings), billing period dates (usage window tracking), and usage totals in micro-cents (enforcing plan limits).

We do not store your full credit card number, CVV, or banking details. All payment processing is handled by Stripe under their privacy policy.


8. Device Information

When your desktop registers with our backend (for mobile bridge or connector functionality), we store: device ID (identifying your desktop for message routing), device public key (verifying device identity via cryptographic signatures), online status (determining whether to route to your device or the offline responder), platform — Windows/macOS (display purposes), and mobile bridge base URLs (allowing your phone to connect to your desktop).


9. Anonymous Device Usage

If you use Stella without an account, we track: an anonymous device identifier (for rate limiting) and request count and timestamps (for enforcing fair-use limits). This data is not linked to any personal identity.


10. Website Advertising Measurement

If you arrive at the Stella website through a Google Ads click, we use the Google tag to measure whether that advertising visit leads to a Stella download. For those advertising referrals, Google may receive the ad click identifier (such as GCLID, GBRAID, or WBRAID), page and device information ordinarily sent by your browser, and a download conversion event. We retain a first-party attribution flag in your browser for up to 30 days so a later download can be associated with the advertising visit. The tag is not loaded for visitors who did not arrive through a Google Ads referral.

We use this information only for aggregate advertising measurement and campaign optimization. We do not use enhanced conversions, do not send customer-provided data such as email addresses to Google for this purpose, and do not use this measurement for remarketing or targeted advertising. Google processes this information under its own privacy policy and data-processing terms. You can prevent or clear this measurement by blocking advertising cookies or clearing this site's local storage and cookies.


11. Social Features

If you use Stella's social features (friend system, chat rooms, collaborative sessions), the following is stored on our backend: social profile (username), friend relationships, chat room membership and messages, and collaborative session metadata and file operations. Social features are opt-in and require a signed-in account.


12. Third-Party Services and Provider Retention

Stella uses third-party services including AI gateways and model providers (which may include OpenAI, Anthropic, Google, xAI, OpenRouter, and Fireworks), fal.ai and other media providers, Exa and other search providers, Convex for backend infrastructure, Stripe for billing, authentication and connected-service vendors, and Google Ads for advertising-referred download measurement.

These providers process data under their own terms, privacy policies, and account configurations. Depending on the provider and feature, they may retain prompts, outputs, uploaded files, generated media, search requests, or metadata for safety, abuse prevention, service operation, or other stated purposes. Some providers offer optional or account-specific zero-data-retention controls, but availability and coverage vary. FromYou does not make a blanket zero-data-retention promise for third-party processing. When using BYOK, a model request may go directly from your device to the provider, but that does not change the provider's own practices.


13. Google Workspace Connector and Google API Services User Data

Stella includes a first-party Google Workspace connector that you can optionally enable to let Stella work with your Google account across Gmail, Google Calendar, Google Drive, Google Docs, Google Sheets, and Google Tasks. This section describes how that connector handles data received from Google APIs and applies in addition to the rest of this policy.

How You Connect — The connector is off until you choose to connect it, and connecting is always optional. Connecting starts a Google OAuth consent flow in which you sign in to Google and approve the access. You can connect Google services granularly — enabling one service at a time (for example, just Gmail or just Calendar), which incrementally expands a single shared Google grant to add each service's scopes — or use the one-tap Google Workspace bundle to enable all of the services listed above at once. A single consent screen does not necessarily cover every service; a granular connection requests only the scopes for the service you are enabling, and you review and approve the requested scopes on Google's consent screen before access is granted.

Data and Scopes We Access — When connected, only for the services you have connected and only as needed to carry out tasks you ask Stella to perform, the connector can access:

• Basic account identity — your Google account email address, basic profile, and an OpenID identifier, used to identify the connected account (scopes: openid, userinfo.email, userinfo.profile)
• Gmail — read, compose, send, and organize your messages, drafts, and labels; this does not include permanently deleting mail (scope: gmail.modify)
• Google Calendar — view and manage your calendars and events (scope: calendar)
• Google Drive — view and manage files in your Drive (scope: drive)
• Google Docs — create, read, and edit your documents (scope: documents)
• Google Sheets — create, read, and edit your spreadsheets (scope: spreadsheets)
• Google Tasks — view and manage your task lists (scope: tasks)

User-Directed Use — Stella accesses and acts on your Google data only after you connect the account and direct Stella (or a Stella agent acting on your instruction) to perform a task, such as reading an email, scheduling an event, or editing a document. Stella does not access your Google data for purposes you have not requested.

Where Your Credentials Live — Depending on how you run the connector, your Google OAuth tokens are stored in one of two ways. For on-device (local) execution, the OAuth access and refresh tokens Google issues are stored on your own device in Stella's protected credential store, encrypted at rest using your operating system's secure storage (the OS keychain or credential vault, via the desktop framework's safeStorage). For cloud or Store-based execution — where Stella carries out connector actions on your behalf from our backend — the tokens are persisted in FromYou's server-side credential vault, encrypted at rest using AES-256-GCM with a versioned master key. In both cases the confidential OAuth client secret is held only by FromYou's backend and is never shipped inside the app.

How Google Data Is Processed — When the connector runs on your device, Google API calls are made from your device using the locally stored token, and content returned from Google (for example, an email, event, file, or spreadsheet) is handled like Stella's other local tool output: it stays on your device unless a task you invoke requires a cloud feature. When you use cloud or Store-based execution, Stella's backend decrypts the token from the server-side vault to call Google APIs on your behalf and processes the returned content to carry out the task you requested. In either mode, when you direct Stella to reason over your Google data, the relevant content may be sent to the AI model provider handling your request, and to service providers strictly to operate the feature you invoked, as described elsewhere in this policy. We do not use Google Workspace data to develop, train, or improve generalized artificial-intelligence or machine-learning models.

No Sale, Advertising, or Credit Use — We do not sell or rent data received from Google APIs, and we do not transfer or use it to serve advertising or to determine creditworthiness or for lending purposes.

Restricted Human Access — FromYou personnel do not read data obtained through the Google connector, except where you give explicit consent to view specific data (for example, for support you request), where necessary for security purposes such as investigating abuse, where required to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.

Retention, Deletion, and Revocation — For on-device execution, your Google tokens and the content returned from Google reside on your device; FromYou does not keep a separate server-side copy of that content, and it reaches our servers only when a cloud feature you use requires it. Disconnecting the Google connector in Stella deletes the on-device tokens, and deleting Stella's local data also removes them. For cloud or Store-based execution, the encrypted tokens are kept in FromYou's server-side vault only while the connection remains active; disconnecting the service in Stella (or removing the integration) deletes those tokens from the vault, and content returned from Google APIs is processed to perform the tasks you request and retained only as needed for that purpose and the operational records described elsewhere in this policy, not as a standalone copy of your Workspace content. You can revoke Stella's access at any time from your Google Account under Security → Third-party access (https://myaccount.google.com/permissions), which invalidates the tokens held both on your device and in the vault; you can also disconnect individual services within Stella to remove just those services' access.

Limited Use — Stella's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.


14. Data Retention

• Local device data — until you delete it; we have no access to it
• Account information — until you delete your account
• Billing records — as required by law and for dispute resolution (typically 7 years for financial records)
• Usage and operational metadata — retained as needed for billing reconciliation, rate limiting, security, and service operation
• Temporary relay buffers — brief operational windows for stream recovery, subject to cleanup and hard lifetime limits
• Mobile and connector delivery records — retained according to operational delivery, deduplication, and cleanup periods that vary by record type
• Media inputs, outputs, and job records — retained as needed to submit, deliver, manage, and clean up media jobs; third-party copies follow provider policies
• Anonymous device usage — retained for rate-limiting purposes; periodically pruned
• Google Ads attribution flag — stored in your browser for up to 30 days
• Social data — until you delete your account or the relevant content


15. Data Security

We implement reasonable security measures to protect data that does reach our infrastructure: encryption in transit (all communication uses TLS/HTTPS), secret encryption (user-provided secrets stored on our backend are encrypted using AES-256-GCM with a versioned master key system), local encryption (API keys stored on your device are encrypted locally), device identity (devices authenticate using Ed25519 cryptographic keypairs), rate limiting (multi-layer rate limiting protects against abuse), and provider redaction (AI responses are scrubbed of upstream provider details before being returned to you).


16. Your Rights and Choices

Access and Control — You can view, export, or delete local data by accessing Stella's data directory or using available in-app reset controls, revoke connected integrations, and request deletion of eligible account and hosted data. Some records may be retained where required for legal, security, fraud-prevention, billing, or dispute-resolution purposes. Deleting data from Stella does not necessarily delete copies retained by third-party providers under their policies.

Discovery Opt-Out — During onboarding, each discovery category is individually selectable. The most sensitive category (Messages & Notes) is disabled by default and requires explicit opt-in. You can skip discovery entirely.

Anonymous Use — You can use Stella's core features without creating an account or providing any personal information.

BYOK — You can provide your own AI provider API keys to avoid routing prompts through our infrastructure entirely.


17. Children's Privacy

Stella is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will promptly delete it.


18. International Users

Our backend infrastructure is hosted in the United States. If you access the Service from outside the United States, your information (to the extent it reaches our servers, as described in this policy) may be transferred to and processed in the United States.


19. California Privacy Rights

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). Personal information we process may include account, billing, device, usage, delivery, connected-service, and optional cloud-feature data. You may exercise your rights to know, delete, or opt out by contacting us. We do not sell your personal information. We do not use your data for targeted advertising.


20. European Privacy Rights

If you are in the European Economic Area (EEA) or United Kingdom, you may have rights under the GDPR including the right to access, rectify, erase, restrict processing, data portability, and objection. These rights apply to personal data we process, which may include account, billing, device, usage, delivery, connected-service, and optional cloud-feature data. Contact us to exercise these rights. Where we process personal data, we rely as applicable on: (a) contractual necessity; (b) legitimate interests such as security and abuse prevention; and (c) consent for optional features.


21. Changes to This Policy

We may update this Privacy Policy from time to time. We will indicate the date of the most recent revision at the top. For material changes, we will make reasonable efforts to notify you. Your continued use of the Service after changes constitutes acceptance of the updated policy.


22. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of your rights, contact us at:

FromYou LLC
131 Continental Drive, Suite 305
Newark, DE 19713

Email: contact@fromyou.ai