We never sell your data
Your financial data is never sold or shared with advertisers, period.
Purpose-limited use
We only process your data to provide and improve the service you signed up for.
You own your data
Export or delete your data at any time from your account settings.
01Overview#
Stakari ("Stakari", "we", "us", "our") operates the Stakari financial intelligence platform. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information when you use our platform at stakari.net and our related services (collectively, the "Service").
By using the Service you consent to the data practices described in this policy. If you do not agree, please discontinue use of the Service.
02Information We Collect#
Information you provide directly
- Account information: name, work email address, password (hashed), company name, and billing address.
- Payment information: credit or debit card details are collected and processed by our PCI-DSS-compliant payment processor (Stripe). We store only the last four digits of your card number and the expiry date.
- Communications: emails, support tickets, and feedback you send to us.
Information from connected services
- Email data: when you connect a Gmail or IMAP inbox, we read only messages that our AI classifies as financial, invoices, receipts, and payment confirmations. We do not read or store personal correspondence.
- Transaction data: amounts, dates, vendors, categories, and descriptions extracted from financial emails or manually entered by you.
Information collected automatically
- Usage data: pages visited, features used, session duration, and click patterns, used to improve the product.
- Device & log data: IP address, browser type, operating system, referring URL, and timestamps.
- Cookies: session, preference, and analytics cookies. See Section 8 for details.
03How We Use Your Information#
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Process transactions and manage your subscription.
- Send you transactional emails, verification, password reset, invoices, and renewal reminders.
- Send product update emails and newsletters (you may opt out at any time).
- Detect, investigate, and prevent fraud, security incidents, and abuse.
- Comply with legal obligations and enforce our Terms of Service.
- Conduct aggregate, anonymised analytics to understand how the Service is used.
AI model training
We may use anonymised, aggregated patterns derived from transaction data to improve our AI classification models. We never train models on personally identifiable information or raw email content.
03aGoogle API Services User Data#
Google API Limited Use Disclosure
Stakari's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What Google data Stakari accesses
- Gmail read access (read-only): Stakari requests read-only permission to your Gmail inbox to identify emails that contain financial information such as receipts, invoices, order confirmations, and subscription renewal notices.
- What we read: only emails our AI classifies as financial in nature. We do not read, index, or store personal correspondence, attachments, or any email content unrelated to financial transactions.
- What we extract: transaction amounts, dates, vendor names, and categories from financial emails. Raw email content is processed in memory and is not stored on our servers.
How we use Google data
- To populate your Stakari spend dashboard with automatically categorised transactions.
- To detect anomalies and flag unusual charges in your connected inbox.
- To send you budget alerts when your spend approaches configured limits.
Limits on use of Google data
- We do not use Gmail data to serve advertisements.
- We do not share Gmail data with third parties except as necessary to provide the Service (e.g. our cloud infrastructure provider).
- We do not allow humans to read your Gmail data unless you explicitly request support and grant temporary access.
- We do not use Gmail data for any purpose beyond operating and improving the Stakari spend intelligence features you have enabled.
- You can revoke Stakari's access to your Gmail at any time from your Google Account permissions page or from Stakari workspace settings.
04Information Sharing#
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- Service providers: trusted third-party vendors who process data on our behalf, including Stripe (payments), AWS (cloud infrastructure), and Postmark (transactional email). All are contractually bound to protect your data.
- Business transfers: if Stakari is acquired or merges with another company, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
- Legal requirements: when required by law, court order, or to protect the rights, property, or safety of Stakari, our users, or the public.
- With your consent: in any other case, only with your explicit consent.
05Data Retention#
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data is retained for the life of your account plus 90 days after termination, to allow account recovery.
- Transaction and financial data is retained for 7 years to comply with accounting and regulatory obligations.
- Logs and usage data are retained for up to 90 days.
- Deleted data is purged from our primary systems within 30 days and from backups within 90 days.
You may request deletion of your personal information at any time by contacting privacy@nexbi.tech. Note that we may retain certain data where required by law or to resolve disputes.
06Security#
We take reasonable and appropriate measures to protect your data from unauthorised access, disclosure, alteration, and destruction:
- All data in transit is encrypted using TLS 1.2 or higher.
- All data at rest is encrypted using AES-256.
- Access to production systems and customer data is restricted to authorised personnel on a need-to-know basis.
- We conduct regular security audits and penetration tests.
- We maintain an incident response plan and will notify affected users within 72 hours of discovering a breach that puts your data at risk.
No method of transmission over the internet or electronic storage is 100% secure. If you discover a potential security vulnerability, please report it responsibly to security@nexbi.tech.
07Your Rights#
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your personal data ("right to be forgotten").
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing of your data for direct marketing or legitimate-interest purposes.
- Restriction: request that we limit the processing of your data under certain circumstances.
Many of these controls are available directly in your account settings under Settings → Workspace. To exercise any right not available in the UI, contact privacy@nexbi.tech. We will respond within 30 days.
08Cookies & Tracking#
We use cookies and similar tracking technologies to operate and improve the Service:
| Type | Purpose | Duration |
|---|---|---|
| Strictly necessary | Authentication, security, and session management. The Service cannot function without these. | Session |
| Preference | Remember your theme (dark/light) and UI preferences. | 1 year |
| Analytics | Understand how users interact with the Service. Data is anonymised and aggregated. | 90 days |
You can control cookies through your browser settings. Disabling strictly-necessary cookies will prevent you from signing in to the Service.
09Children's Privacy#
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@nexbi.tech and we will delete it promptly.
10International Transfers#
Stakari is based in the United States. If you are accessing the Service from outside the US, your information will be transferred to and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from those of your country.
Where required, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses (SCCs) to ensure your data receives an adequate level of protection when transferred internationally.
11Changes to This Policy#
We may update this Privacy Policy from time to time. When we make material changes we will notify you via email or a prominent notice within the Service at least 14 days before the new policy takes effect. The "Last updated" date at the top of this page will always reflect the most recent version.
We encourage you to review this policy periodically. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
12Contact Us#
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please reach out:
Stakari, Inc., Data Privacy
Privacy enquiries: privacy@nexbi.tech
Data deletion requests: privacy@nexbi.tech
Security disclosures: security@nexbi.tech
Last updated July 23, 2026