What happens to your information
Last updated: October 2026
Information we collect
3Stone AI products collect information you provide, such as account details, workspace content, files, support requests, and messages you choose to send. Our public website does not use advertising cookies. When you contact us, we receive the name, email address, company, and message you choose to provide.
We also receive ordinary technical and security information needed to operate our services, such as request timestamps, browser or device information, IP-derived security signals, and authentication events.
On 3stoneai.com, we use limited first-party analytics to understand which pages are visited. We store the page path, referring website hostname, visit time, and a pseudonymous hash derived server-side from network and browser information. We do not store the raw IP address, full referring URL, query string, or an analytics cookie. Repeat views of the same page by the same visitor on the same UTC day are counted once, and obvious automated traffic is excluded.
Connected Google services
If you connect a Google Account to 3Stone AI, we request only the permissions needed for features you choose to use. These may include viewing calendar events, sending an email you explicitly compose and submit, and accessing only the Google Drive files you select through Google Picker. We do not send email in the background or request broad access to every file in your Drive.
Google data is used only to provide or improve the user-facing feature you request, maintain security, and comply with law. 3Stone AI's use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to develop, train, or improve generalized or foundational AI or machine-learning models.
AI processing and service providers
Before you use an AI feature in the iPhone app, we ask for permission to send the message, selected attachments, and relevant conversation or workspace context to trusted third-party AI providers such as Anthropic or OpenAI. Supported media features may also use Runway or ElevenLabs. This processing is necessary to provide the AI feature you request. You can withdraw permission in the app's Settings; new AI requests will remain disabled until you consent again.
Developer Mode and the 3Stone API
Developer Mode uses the same 3Stone account, but its prepaid API balance is separate from consumer plans. API secrets are shown once and stored by 3Stone only as cryptographic hashes. Developers should keep keys in server-side secret storage and rotate or revoke a key that may have been exposed.
API inputs, selected files, and outputs are processed by 3Stone and the service providers needed for the requested capability. We retain request metadata, usage, cost, status, and financial-ledger records needed for delivery, idempotent recovery, security, support, accounting, and legal obligations. Completed responses and generated artifacts may be stored so an authenticated developer can retrieve them. Developer logs are designed around operational metadata rather than displaying prompt or file contents. We do not promise zero retention for API activity.
Google user data is sent to an AI provider only as needed to provide the feature the user invoked; it is not provided for provider advertising or generalized model training. We use commercial API services and provider controls intended to prevent API inputs and outputs from being used to train generalized models.
How information is protected
We protect sensitive data with encrypted network connections, encrypted OAuth credentials and tokens at rest, access controls, workspace and tenant isolation, private storage, and logging and monitoring intended to detect unauthorized access. Access is limited to people and systems that need the information to operate, secure, or support the service.
Retention, disconnection, and deletion
Live calendar and selected-file information is retrieved as needed for the connected feature. OAuth tokens are retained while the integration remains connected. Selected Google Drive file identifiers and other saved integration settings are retained until you remove them, disconnect the integration, delete the related workspace or account, or ask us to delete them.
Disconnecting Google revokes the connection where supported and removes the stored Google access and refresh credentials from the workspace. You may also request deletion of your account or Google-derived data by contacting us. We delete or de-identify requested data within a reasonable period, except where limited retention is required for security, fraud prevention, legal compliance, or resolving disputes.
In the 3Stone mobile app, open Account & usage, then selectDelete account. After two confirmations, this starts a permanent deletion of the account, conversations, projects, uploaded files, and associated workspace data. A saved deletion request allows unfinished cleanup to be retried if a service is unavailable or an in-flight operation must finish first. You can also request deletion by contacting us. Deleting a 3Stone account does not cancel an Apple or Google Play subscription; subscriptions can be managed separately in the applicable store account settings.
Account deletion also removes tenant-owned Developer Mode keys, request records, jobs, and generated API artifacts through the durable deletion workflow. Minimal non-content receipts may be retained where necessary for security, fraud prevention, financial accounting, disputes, or law.
Third-party services
We use service providers for hosting, databases, authentication, storage, email delivery, monitoring, payment processing, and AI processing. Depending on the product and feature, these providers may include Vercel, Neon, Supabase, Stripe, Apple, Google, Microsoft, Anthropic, OpenAI, Runway, ElevenLabs, and email-delivery vendors. They process information for the service being provided and under their applicable terms and privacy commitments.
How information is used and shared
We use information to deliver requested product features, authenticate users, provide support, prevent abuse, process payments, and improve the reliability and security of our services. We do not sell or rent personal information. We disclose information only to service providers acting for us, when you direct us to, or when required for security or legal compliance.
Questions
For privacy questions or data-deletion requests, contact us at jathan@3stoneai.com.