Skip to content
Steletta
For large catalogsPricing
Let’s talkStart a review
Menu
For large catalogsPricingLet’s talk

Legal

Privacy Policy

Effective September 25, 2026

Steletta reviews K–12 educational materials. This policy explains what data reaches Steletta, why we use it, who receives it, how long it remains, and the choices available to you.

ChatGPT, Codex, and Muse connectorsWebsite, dashboard and APIAcross all services

The short version

AI connectorsYour original attachment and full conversation stay with ChatGPT, Codex, or Muse. Steletta receives task-level content and structured review data, not the original file.
Website and APIFiles and pasted source text are temporary. They are scheduled for deletion after processing, and unfinished uploads are scheduled no later than 24 hours after they begin.
No training or saleWe do not train generative AI models on your materials, sell personal data, or use assessment content for advertising.
You stay in controlYou can delete reports, close a personal workspace, or ask us to access, correct, export, or delete your personal data.

Scope

This policy applies to Steletta’s website, personal review workspace, organization workspace, assessment API, ChatGPT, Codex, and Muse connectors, related tools, and service emails (together, the “Services”). It does not govern information that OpenAI keeps in ChatGPT or Codex, or that Meta keeps in Muse, under those companies’ own terms and privacy policies.

Steletta operates the Services from 2222 Ponce De Leon Blvd, Miami, Florida 33134, United States.

For personal accounts, Steletta determines how account and service data is handled. For an organization using the API or workspace, the organization may control the submitted material and associated personal data, while Steletta processes it on the organization’s instructions. Contact the organization first if it provided your data to us.

ChatGPT, Codex, and Muse connectors

When you review material through Steletta in an AI assistant

What reaches Steletta through a connector

When you ask Steletta to review a file or text in ChatGPT, Codex, or Muse, the platform reads the source and retains the conversation and original attachment according to your account settings. Steletta does not receive the original PDF, Word file, ZIP archive, file-download link, complete extracted document, or full chat history.

Steletta receives only the information needed to perform and display the review:

  • basic material metadata, such as title, subject, grade, purpose, page count, and question count
  • a compact inventory of questions or tasks and the unabridged original printed stem or instruction for every learner task, including shared directions when needed to understand it
  • structured item checks, such as item identifiers, answerability, independently solved and supplied answer positions, option counts, skills, and risk flags
  • answer choices, keys, explanations, visual details, or additional source excerpts when needed to support a finding, source check, or targeted verification step
  • item-level conclusions, findings, evidence, recommendations, coverage assessments, strengths, confidence information, and score inputs
  • for ChatGPT and Codex, a pseudonymous identifier supplied by OpenAI, which we immediately hash and use for rate limits, job ownership, abuse prevention, and continuity during the review
  • for Muse, connector authentication and technical request information used to authenticate the connector, apply rate limits, prevent abuse, and keep the review together; the current connector does not send your Meta profile name, email address, or profile identifier to Steletta

For documents with 101–250 learner tasks, the connector may first send only the task count so Steletta can ask whether you want to continue. Steletta does not use connector identifiers to obtain your name, email address, platform profile, contacts, or other conversations.

We cannot delete a conversation or attachment held by OpenAI or Meta; use the controls in ChatGPT, Codex, or Muse for that data. See OpenAI’s privacy policy and Muse’s privacy policy.

Connector retention and controls

Connector review state remains for up to 6 hours after the last update while a review is active and up to 2 hours after completion. Short-lived duplicate-request records expire after about 10 minutes.

Connector state is tied to a hashed or technical connector identifier rather than your email address. We normally cannot connect an email request to that short-lived state. It expires automatically under the schedule above; you can manage the original conversation and attachment through OpenAI or Muse.

Steletta’s connector servers do not place analytics or advertising cookies in your ChatGPT, Codex, or Muse conversation.

Website, dashboard and API

When you upload a file, paste material or manage reviews directly with Steletta

Uploaded copies and pasted source text are temporary. Your original material stays yours. Report retention depends on whether you use a personal workspace, an organization workspace or temporary API results.

File deletion and report retention

Data collected through the website and API

Depending on the feature you use, we collect:

  • Account data: name, email address, profile image, authentication provider, workspace membership, and session information
  • User content: files, pasted text, document metadata, instructions, learning goals, and other material submitted for review
  • Review data: processing status, verdict, scores, findings, quoted evidence, suggested fixes, strengths, and report history
  • Organization and API data: organization name, member roles, API-key records, webhook configuration, usage, and customer-supplied identifiers used to reconcile requests
  • Billing data: plan, subscription status, usage, Stripe customer and subscription references, and transaction records. Stripe receives payment-card details directly; Steletta does not store complete card numbers
  • Communications: support requests, pilot inquiries, email preferences, and service messages
  • Technical data: IP address, browser and device information, request time, pages viewed, security events, errors, and diagnostic records created by our hosting and security systems

You may paste text or choose a file before signing in. Until you sign in, obtain access, and submit the review, that draft remains in the memory of your browser tab and is not uploaded to Steletta.

Retention and deletion

DataNormal retention
Website and API source files or pasted source textScheduled for permanent deletion as soon as processing completes, permanently fails, or is cancelled and upload permissions expire. Unfinished sources are scheduled for deletion no later than 24 hours after upload begins. Failed deletion jobs are retried until successful.
Temporary API reportsAvailable for 24 hours after completion, then access ends and report content is scheduled for deletion. An API customer may request earlier deletion.
Personal reportsKept until you delete the report or close the personal workspace. Cancelling a subscription does not delete report history.
Organization reportsKept under the organization’s selected retention setting or written agreement. The organization may delete them earlier.
Account and workspace dataKept while the account or workspace is active, then deleted or de-identified within 30 days after a valid closure request, except for the records below.
Website analyticsGoogle Analytics user-level and event data is kept for no more than 14 months.

Deleting a source removes it from the active private file store rather than moving it to an account trash folder. Steletta does not offer source-file recovery, so keep your original. Deletion jobs retry after temporary failures, and provider caches may take a short time to clear.

Cookies and analytics

We use essential cookies to keep you signed in, protect sessions, and remember necessary service state. Google Analytics may use cookies or similar technology to measure visits and product usage. We do not use advertising cookies. You can block or delete cookies in your browser; blocking essential cookies may prevent sign-in.

Across all Steletta services

The following provisions apply to the connectors and the website/API

How we use data

We use data to provide requested reviews, authenticate users, keep workspaces and reports available, calculate usage, process billing, send requested service messages, provide support, secure the Services, prevent abuse, diagnose failures, comply with law, and improve reliability.

We do not use source materials, pasted assessment text, report evidence, or tutor conversations to train generative AI models. We may use content-free or de-identified measurements, such as document-size bands, processing times, score ranges, error counts, and review-route outcomes, to evaluate capacity and quality. These measurements do not include source text, filenames, report prose, account details, network data, or job identifiers.

Legal bases

Where data-protection law requires a legal basis, we process data as needed to perform our contract with you or your organization, for legitimate interests such as security and service improvement, with consent where requested, and to meet legal obligations. You may withdraw consent at any time, without affecting earlier processing.

Who receives data

We disclose data only as needed to operate the Services, follow your instructions, protect users, complete a business transaction, or comply with law. Our main recipient categories and providers are:

RecipientPurpose and data involved
OpenAIHosts ChatGPT and Codex interactions. For website and API reviews, an OpenAI business API may process submitted review content to produce analysis. OpenAI’s handling of your ChatGPT and Codex data is governed separately by your OpenAI account.
MetaHosts Muse interactions and processes the source in Muse before structured review data is sent to Steletta. Meta’s handling of your Muse conversation and attachment is governed separately by your Muse account.
VercelApplication hosting, network delivery, private source-file storage, and platform logs.
NeonAccount, workspace, report, subscription, usage, and operational database records.
UpstashShort-lived connector review state, rate limits, request continuity, and aggregate operational measurements.
GoogleGoogle account authentication and website analytics. Google receives information according to the feature you choose and its own privacy terms.
StripeCheckout, payment processing, invoices, subscription management, and fraud prevention.
PostmarkMagic-link, account, inquiry, waiting-list, and subscription service email delivery.

Additional model providers may be used for a defined review step when they offer appropriate business data protections. We will update this policy and provide any notice required by law before a new provider processes user content.

We do not sell personal data. We do not share source material or review content for targeted advertising. We may disclose information to professional advisers, authorities, or a successor in a merger, financing, acquisition, or sale, subject to appropriate confidentiality and legal safeguards.

Operational and legal retention

DataNormal retention
Security and operational logsNormally up to 90 days. Content-free connector operational aggregates expire after 45 days. Records connected to an active security incident may be kept until the incident is resolved.
Support communicationsUp to 24 months after the request is closed, unless a longer period is needed for an ongoing dispute.
Billing, tax, fraud, and legal recordsUp to 7 years, or longer when applicable law requires it.

Security

We use access controls, private storage, encryption in transit, scoped credentials, expiring upload permissions, rate limits, and deletion workflows designed to protect data. No system can guarantee absolute security. If we learn of a breach that requires notice, we will notify affected users and authorities as required by law.

Your choices and rights

You can delete personal reports in History, manage email preferences and close a personal workspace in Settings, manage billing in Usage, and control connector conversations and attachments through OpenAI or Muse.

Depending on where you live, you may ask to access, correct, export, delete, restrict, or object to our use of personal data, or appeal a decision about a request. You may also complain to your local data-protection authority. We may need to verify your identity and authority before completing a request. Authorized agents may contact us on your behalf where permitted by law.

International processing

Steletta and its providers may process data in the United States and other countries. Where required, we use contractual and organizational safeguards for international transfers.

Changes to this policy

We may update this policy as the Services or legal requirements change. We will change the effective date above and provide additional notice when a change materially affects how we use personal data.

Contact us

Steletta
2222 Ponce De Leon Blvd
Miami, FL 33134
United States

For privacy questions, requests, or product help, email info@steletta.com.

Steletta

K–12 assessment review

info@steletta.com
Miami, FL, USA
© 2025–2026 Steletta. All rights reserved

Product

For large catalogsDashboardPricing

Resources

API docsPrivacyTerms