Last updated · 2026-09-23
Privacy policy
Stelafy measures which ads bring applications and money actually collected. This page explains what data we process, why, how long we keep it, and what — if anything — leaves the product.
Who processes what
You are the business that signs up. For the people in your data — your leads and customers — you are the controller and we are your processor: we process their data on your instructions, for the measurement you asked for, and for nothing else.
We process your own account data as a controller.
Two kinds of workspace
Clinic workspaces are read-only and internal. Ad data is read, reports are produced, and nothing is ever sent to an ad platform. The block is enforced on the server, not in the interface — a direct API call, a CSV import, a scheduled job and a retry are all refused the same way.
General lead-generation workspaces work the same way by default. An owner or admin may additionally turn on sending selected outcome events to the business's own Meta dataset. It is off until someone turns it on, and it can be turned off again at any time.
Data we process
- Account data: name, email address, password hash, workspace name, role and sign-in records.
- Ad data, read from Meta with your permission: campaign, ad set and ad names and ids, spend, dates and the lead counts the platform reports. This contains no personal data.
- Lead and application data: name, phone number, email address, the platform's lead id and form id, and the time the form was submitted. It reaches us in three ways — Meta Instant Forms, a signed notification from your own website's server, or a CSV file you upload.
- Form answers: for a lead from a Meta Instant Form, the answers to the questions you added to that form (for example budget or preferred call time), so you can see them next to the lead. Meta deletes lead data after 90 days; this is how the answers stay available to you. Contact fields are not stored a second time, and Meta's standard personal fields — date of birth, gender, marital status, identity numbers, work contact details and street address — are not stored at all.
- Outcome data from your CSV files or marked by your team in the app: qualification decisions, opportunity stages, amounts, currency and the dates those things actually happened.
- Web visit context, when your site uses our lead-touch script and your visitor has consented: an anonymous visit key, utm_* parameters, the Meta click id in fbc form, your own pixel's _fbp cookie value if one exists, the visitor's browser user agent and IP address as reported by your server, and the page address without its query string.
- Usage data: uploads, imports, sync jobs, sending records and an audit log of who changed what.
We do not process health data
Treatment names, diagnoses and health status are deliberately left out of the product. They are not imported, not stored and not reported. If your file contains such a column it is not mapped and not read.
The same applies to form answers. A question that points to health, payment cards, identity numbers or other special-category data (such as religion, ethnicity or sexual orientation) is dropped before anything is stored. In a clinic workspace no form answers are stored at all.
This check is a safety net, not a guarantee. A business using the product must not ask for such data in the forms it connects; if it does, it remains responsible for that data.
Sending outcomes to Meta
This applies only to a general lead-generation workspace where an owner or admin has turned sending on. It never applies to a clinic workspace.
Events go to your own Meta dataset using your own access token. We do not use a shared dataset and we do not build audiences, upload customer lists, create ads or change budgets — the product has no code that can do those things.
- What is sent: the event name, the real time the event happened, a stable event id, and — where the event represents money — an amount and a currency.
- How a person is identified: email address and phone number are hashed with SHA-256 before they leave the server, and so is the country the phone number belongs to (read from the number itself, never guessed). Our own internal id for the person is hashed the same way, so that events about the same person line up; it means nothing outside the product. For a lead that came from a Meta Instant Form, Meta's own lead id is sent as well. For a lead that came from your website, the browser context described above (fbc, _fbp, user agent, IP address) and the page address are sent, because Meta requires them unhashed for web events.
- What is never sent: names, CSV files, form answers, health data, free-text notes, and any raw email address or phone number.
- Eligibility is re-checked at the moment of sending: the workspace class, your declared lawful basis, whether the person still exists, whether the source record still exists, and whether the event is still inside Meta's time window. If any of these fails the event is blocked and the reason is shown to you.
What an accepted event does and does not mean
When Meta accepts an event it means the request was well formed and received. It does not mean the event was attributed to an ad, and it does not mean ad performance improved. The product reports the delivery state and nothing more.
Demo requests
When you use the Book demo form on our website, we collect your name, work email, phone number, company website and monthly ad spend range. For this data we are the controller.
We use it only to contact you and arrange the call. It is stored in our own database in the EU (Frankfurt), is not shared with anyone, is not used for advertising and is never sent to Meta. The form itself sets no cookies and runs no tracking script.
Legal basis: taking steps at your request before a possible contract, and our legitimate interest in answering your request. We delete a request when you ask us to, and in any case 12 months after it was sent.
- Data requests — to see or delete what you sent us
How long we keep it
- Account data: for as long as the account is open.
- Lead, application (including form answers), outcome and visit data: until you delete it, or within 30 days of the account being closed.
- Visit context and sending records are deleted together with the record they belong to.
- Report figures contain no personal data and are recomputed from the underlying rows on every read — they are not stored separately.
- Copies inside encrypted backups leave the rotation within 30 days.
Once an event has been sent
An event that Meta has already accepted is held by Meta under Meta's own terms; we cannot recall it. Deleting data here stops any further sending and removes our record of it. To have data removed on Meta's side, use the controls in your own Meta Business account.
Subprocessors
- Supabase — Database, authentication and file storage (EU (Frankfurt)).
- Vercel — Application hosting; the server code runs here (EU (Frankfurt)).
- GitHub — Nightly database backup: taken on GitHub's servers, encrypted there before it is stored, and kept for 30 days (US).
- Meta Platforms — Reading your ad data; and, only if your workspace turns it on, sending outcome events to your own Meta dataset (US / EU).
- Subprocessors — the full list, our commitments and 30-day notice of changes
Security
- Every workspace's rows are isolated in the database itself, not only in the application: one business cannot read or change another's data even through a direct API call.
- Access tokens for ad platforms are encrypted before they are stored, and are never returned by any endpoint.
- Access is limited to the people you invite, and an analyst role can read but cannot write or turn sending on.
Your rights as a workspace user
You can delete the data in your workspace from the settings screen at any time, and you can correct it by re-uploading a corrected file — an import fills in what was missing without overwriting what was already there.
If you are an individual whose data a business has uploaded here, contact that business first. If you contact us we will route your request to them and follow it until it is resolved.
- Data requests — how to make a request, what to include and how long it takes
Legal bases (EEA, UK and Switzerland)
- Contract: to provide the service your business signed up for — your account, your workspace and the reports.
- Legitimate interests: to keep the service secure and reliable, prevent misuse and keep an audit log of who changed what, balanced against your rights.
- Legal obligation: to keep records the law requires and to answer lawful requests.
- For the people in your data we act on your instructions; the lawful basis is yours to hold, and you declare it before sending to Meta can be turned on.
Rights in the EEA, the UK and Switzerland
We verify your identity before acting on a request and answer within one month, which the law allows us to extend where a request is complex.
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate data corrected.
- Erasure: have your data deleted where the law allows.
- Restriction and objection: limit or object to certain processing.
- Portability: receive your data in a structured, machine-readable format, on request.
- Complaint: lodge a complaint with a data protection authority — in the UK the Information Commissioner's Office, in the EU the authority where you live or work.
Rights in US states (including California)
Outcome events reach Meta only when a business turns sending on for its own Meta dataset; we send them on that business's instructions as its service provider. A request about that sending is answered by the business, and we help it do so.
You may use an authorised agent; we verify both of you. We answer within 45 days, extendable by another 45 where reasonably necessary, and we tell you if we extend.
- Know and access: what personal information we collect, use and disclose, and a copy of it.
- Delete and correct: have it deleted, subject to legal exceptions, or corrected.
- Opt out of sale or sharing: we do not sell personal information, and we do not share it for cross-context behavioural advertising for our own purposes.
- No discrimination: using these rights does not change the service you receive.
Rights in Canada
You can ask for access to and correction of your personal information, and you can complain to the Office of the Privacy Commissioner of Canada.
Where data is stored and transferred
The database and the application's server code both run in the European Union (Frankfurt). The encrypted nightly backup is stored in the United States. Where a subprocessor processes personal data outside the EEA or the UK, the transfer relies on the European Commission's Standard Contractual Clauses and, for the UK, the UK Addendum.
If a business turns sending on, the outcome events described above go to Meta Platforms, which processes them in the United States and the European Union under its own terms.
Automated decisions
We make no decisions about people by automated means that have legal or similarly significant effects on them. Matching a payment to a lead is bookkeeping for the business's reports; it decides nothing about the person.
Changes to this policy
If a change materially affects what data we process or what leaves the product, we tell workspace owners by email before it takes effect, and the date at the top of this page changes.
Children
The service is for businesses and is not directed to anyone under 18. We do not knowingly process children's data; a business must not upload it. If you believe it has happened, write to us and we will have it deleted.
Contact
Please contact the business that gave you access to this service.