Legal
Privacy Policy
Effective September 25, 2026
Steletta reviews K–12 educational materials. This policy explains what data reaches Steletta, why we use it, who receives it, how long it remains, and the choices available to you.
The short version
Scope
This policy applies to Steletta’s website, personal review workspace, organization workspace, assessment API, ChatGPT, Codex, and Muse connectors, related tools, and service emails (together, the “Services”). It does not govern information that OpenAI keeps in ChatGPT or Codex, or that Meta keeps in Muse, under those companies’ own terms and privacy policies.
Steletta operates the Services from 2222 Ponce De Leon Blvd, Miami, Florida 33134, United States.
For personal accounts, Steletta determines how account and service data is handled. For an organization using the API or workspace, the organization may control the submitted material and associated personal data, while Steletta processes it on the organization’s instructions. Contact the organization first if it provided your data to us.
ChatGPT, Codex, and Muse connectors
When you review material through Steletta in an AI assistant
What reaches Steletta through a connector
When you ask Steletta to review a file or text in ChatGPT, Codex, or Muse, the platform reads the source and retains the conversation and original attachment according to your account settings. Steletta does not receive the original PDF, Word file, ZIP archive, file-download link, complete extracted document, or full chat history.
Steletta receives only the information needed to perform and display the review:
- basic material metadata, such as title, subject, grade, purpose, page count, and question count
- a compact inventory of questions or tasks and the unabridged original printed stem or instruction for every learner task, including shared directions when needed to understand it
- structured item checks, such as item identifiers, answerability, independently solved and supplied answer positions, option counts, skills, and risk flags
- answer choices, keys, explanations, visual details, or additional source excerpts when needed to support a finding, source check, or targeted verification step
- item-level conclusions, findings, evidence, recommendations, coverage assessments, strengths, confidence information, and score inputs
- for ChatGPT and Codex, a pseudonymous identifier supplied by OpenAI, which we immediately hash and use for rate limits, job ownership, abuse prevention, and continuity during the review
- for Muse, connector authentication and technical request information used to authenticate the connector, apply rate limits, prevent abuse, and keep the review together; the current connector does not send your Meta profile name, email address, or profile identifier to Steletta
For documents with 101–250 learner tasks, the connector may first send only the task count so Steletta can ask whether you want to continue. Steletta does not use connector identifiers to obtain your name, email address, platform profile, contacts, or other conversations.
We cannot delete a conversation or attachment held by OpenAI or Meta; use the controls in ChatGPT, Codex, or Muse for that data. See OpenAI’s privacy policy and Muse’s privacy policy.
Connector retention and controls
Connector review state remains for up to 6 hours after the last update while a review is active and up to 2 hours after completion. Short-lived duplicate-request records expire after about 10 minutes.
Connector state is tied to a hashed or technical connector identifier rather than your email address. We normally cannot connect an email request to that short-lived state. It expires automatically under the schedule above; you can manage the original conversation and attachment through OpenAI or Muse.
Steletta’s connector servers do not place analytics or advertising cookies in your ChatGPT, Codex, or Muse conversation.
Website, dashboard and API
When you upload a file, paste material or manage reviews directly with Steletta
Uploaded copies and pasted source text are temporary. Your original material stays yours. Report retention depends on whether you use a personal workspace, an organization workspace or temporary API results.
File deletion and report retentionData collected through the website and API
Depending on the feature you use, we collect:
- Account data: name, email address, profile image, authentication provider, workspace membership, and session information
- User content: files, pasted text, document metadata, instructions, learning goals, and other material submitted for review
- Review data: processing status, verdict, scores, findings, quoted evidence, suggested fixes, strengths, and report history
- Organization and API data: organization name, member roles, API-key records, webhook configuration, usage, and customer-supplied identifiers used to reconcile requests
- Billing data: plan, subscription status, usage, Stripe customer and subscription references, and transaction records. Stripe receives payment-card details directly; Steletta does not store complete card numbers
- Communications: support requests, pilot inquiries, email preferences, and service messages
- Technical data: IP address, browser and device information, request time, pages viewed, security events, errors, and diagnostic records created by our hosting and security systems
You may paste text or choose a file before signing in. Until you sign in, obtain access, and submit the review, that draft remains in the memory of your browser tab and is not uploaded to Steletta.
Retention and deletion
| Data | Normal retention |
|---|---|
| Website and API source files or pasted source text | Scheduled for permanent deletion as soon as processing completes, permanently fails, or is cancelled and upload permissions expire. Unfinished sources are scheduled for deletion no later than 24 hours after upload begins. Failed deletion jobs are retried until successful. |
| Temporary API reports | Available for 24 hours after completion, then access ends and report content is scheduled for deletion. An API customer may request earlier deletion. |
| Personal reports | Kept until you delete the report or close the personal workspace. Cancelling a subscription does not delete report history. |
| Organization reports | Kept under the organization’s selected retention setting or written agreement. The organization may delete them earlier. |
| Account and workspace data | Kept while the account or workspace is active, then deleted or de-identified within 30 days after a valid closure request, except for the records below. |
| Website analytics | Google Analytics user-level and event data is kept for no more than 14 months. |
Deleting a source removes it from the active private file store rather than moving it to an account trash folder. Steletta does not offer source-file recovery, so keep your original. Deletion jobs retry after temporary failures, and provider caches may take a short time to clear.
Across all Steletta services
The following provisions apply to the connectors and the website/API
How we use data
We use data to provide requested reviews, authenticate users, keep workspaces and reports available, calculate usage, process billing, send requested service messages, provide support, secure the Services, prevent abuse, diagnose failures, comply with law, and improve reliability.
We do not use source materials, pasted assessment text, report evidence, or tutor conversations to train generative AI models. We may use content-free or de-identified measurements, such as document-size bands, processing times, score ranges, error counts, and review-route outcomes, to evaluate capacity and quality. These measurements do not include source text, filenames, report prose, account details, network data, or job identifiers.
Legal bases
Where data-protection law requires a legal basis, we process data as needed to perform our contract with you or your organization, for legitimate interests such as security and service improvement, with consent where requested, and to meet legal obligations. You may withdraw consent at any time, without affecting earlier processing.
Security
We use access controls, private storage, encryption in transit, scoped credentials, expiring upload permissions, rate limits, and deletion workflows designed to protect data. No system can guarantee absolute security. If we learn of a breach that requires notice, we will notify affected users and authorities as required by law.
Your choices and rights
You can delete personal reports in History, manage email preferences and close a personal workspace in Settings, manage billing in Usage, and control connector conversations and attachments through OpenAI or Muse.
Depending on where you live, you may ask to access, correct, export, delete, restrict, or object to our use of personal data, or appeal a decision about a request. You may also complain to your local data-protection authority. We may need to verify your identity and authority before completing a request. Authorized agents may contact us on your behalf where permitted by law.
International processing
Steletta and its providers may process data in the United States and other countries. Where required, we use contractual and organizational safeguards for international transfers.
Changes to this policy
We may update this policy as the Services or legal requirements change. We will change the effective date above and provide additional notice when a change materially affects how we use personal data.
Contact us
Steletta
2222 Ponce De Leon Blvd
Miami, FL 33134
United States
For privacy questions, requests, or product help, email info@steletta.com.