Privacy Policy
Placeholder policy for the StellarFirm waitlist. A full policy will replace it before launch.
Who we are. The StellarFirm waitlist is run by Astro Code L.P., the controller of the data described here. Contact us at hey@astrocode.tech.
What we collect. Your email address. We do not ask for payment details to join. When you join we also record the time of your sign-up and the version of the waitlist wording (waitlist-consent-v2-2026-10-03). In our own logs your email appears only as a one-way hash. If you arrived through a link with a ref or utm_* parameter, that campaign label is stored with your sign-up.
Why, and on what basis. We email you about the StellarFirm waitlist, trial invites, early pricing, and product updates. Joining the waitlist is how you ask for those emails. Privacy Policy and Terms links sit in the footer, not under the form. You can unsubscribe at any time by using the unsubscribe link in any email or by writing to hey@astrocode.tech.
Who processes it for us.
- Resend stores your contact details and sends our emails (email provider and processor).
- PostHog provides product analytics (processor) for EU project 292135, on this website and in the signed-in app. It records page views, clicks (autocapture), and session recordings, and can show a short survey. All of this starts only after you accept analytics cookies in the cookie choice shown on every public page. If you reject, or have not answered yet, we do not track you: your browser sends nothing to PostHog. Our server still keeps two anonymous counts, with no cookie and nothing stored on your device: a visit that arrives from an ad link, and a waitlist sign-up. A visit carries only the campaign labels from the link (such as utm_source), whether an ad click id was present (not the id itself), the site name, and the page path. A sign-up carries the campaign labels and ad click ids from your first and latest visit, the referring site name, and the site name. Neither carries an IP address, email, name, device details, or an id that links it to you or to another event. Do Not Track turns both off. Your choice is saved in this browser. Joining the waitlist does not turn this on. Do Not Track, and turning usage events off in the desktop app, still stop capture after an accept. The data is anonymous: we do not identify you, and we do not send your email, name, account user id, or IP address. Query strings are removed from page addresses. After you accept, a page view keeps the referrer and the campaign labels and ad click ids from the link, and a waitlist sign-up sends those labels from the first visit plus the latest visit. Prices and secrets are stripped from events. Session recordings mask everything you type. In the signed-in app they also mask all text on screen, and they leave out your chats, code changes, terminal output, drafts waiting for approval, and the assistant's computer and files. PostHog also provides AI observability for your assistants' model calls, and stores the prompts you save in the prompt library. Those are tied to your account and are described under Your assistants' model calls below.
- LangSmith records your assistants' model calls so we can find and fix problems (processor, EU region). What it receives is described under Your assistants' model calls below.
- Google Analytics measures how the site is used (processor). It stays off, and its script is not loaded, until you accept analytics cookies in the cookie choice shown on every public page. Your choice is saved in this browser. Rejecting, or choosing Cookie settings and rejecting later, stops measurement and clears its cookies. Joining the waitlist does not turn it on. We keep advertising features switched off.
- TikTok provides the TikTok Pixel, which measures visits and waitlist sign-ups that come from our TikTok ads so we can improve them (processor). It stays off, and its script is not loaded, until you accept cookies in the cookie choice shown on every public page. Your choice is saved in this browser. Rejecting, or choosing Cookie settings and rejecting later, stops the pixel and clears its cookies. Joining the waitlist does not turn it on. It receives the pages you visit, clicks on the Join waitlist buttons, the fact that you joined the waitlist, and technical details such as your browser and IP address. We never send it your email, name, or account id. TikTok also uses this data under its own privacy policy, for example to measure and deliver ads. When you join the waitlist after accepting, our server also tells TikTok about the sign-up directly, with the same details, so it is counted once even if your browser blocks the pixel.
- Our website host stores this website and the requests it receives.
Your assistants' model calls. Each time an assistant asks a model for an answer, we record the call in PostHog AI observability and in LangSmith, so we can fix problems, keep answers good, and see what each call costs. Unlike the website analytics above, these records are tied to your account. Each one holds your account id and your company id (never your email or name), which assistant made the call, the model and the provider that served it, ids for the conversation and the job it belongs to, and token counts, timing, and cost. For assistants running in StellarFirm cloud it also holds the conversation text of the call: the messages, the answer, and the tool steps, with keys and passwords removed. Assistants running on your own computer send only calls made on StellarFirm credits, never their text, and nothing about calls on your own model key or a local model. PostHog keeps the conversation text for 30 days; LangSmith keeps calls for the retention period set on our account.
You can turn this off at any time in Settings, under Privacy: switch off Share model call analytics to stop all of it, or Include conversation text to keep the words out while still sharing the rest. The change applies from the next call. It does not stop the usage record your credits are counted from, which we need to bill you. Prompts you save in the prompt library are stored in PostHog under your account id, or your company's id for shared ones. When you delete one we archive it there; write to hey@astrocode.tech to have it erased.
We do not sell your data. Apart from the TikTok Pixel described above, which runs only if you accept cookies, we do not share it with advertisers. Some of these providers may process data outside the European Economic Area under standard contractual clauses or equivalent safeguards.
How long. We keep your waitlist details until you unsubscribe or ask us to delete them, and consent records for as long as needed to show that consent was given.
Your rights. You can ask to access, correct, export, or delete your data, or object to its use, by writing to hey@astrocode.tech. You can also complain to your local data protection authority, such as the Hellenic Data Protection Authority.
This site is the public page, the waitlist form, and the signed-in app. It never stores your API keys or your connected account secrets. See also our Terms of Service.
© 2026 Astro Code L.P. All Rights Reserved.