StokaTerminal ("StokaTerminal", "we", "us") is a personal life-organization and
coaching application that helps you manage your calendar, tasks, finances, health,
career, files, and notes in one place. This policy explains what data we collect,
how we use it, how we protect it, and the choices you have. It applies to
stokaterminal.com and the StokaTerminal application and connectors.
1. Data we collect
Account data
- Your name, email address, and the authentication credentials associated with your StokaTerminal account.
- Subscription and billing status. Payments are processed by Stripe; we do not store your full card details.
Content you create
- Information you enter into StokaTerminal — events, tasks, journal entries, notes, contacts, projects, domain trackers, files you upload, and notes an AI agent you have connected saves on your behalf.
Data from services you connect
- If you connect Google services, we access data only as described in Section 2.
- Optional integrations you enable (for example, calendar, messaging reminders) only access what is needed to provide that feature.
Technical data
- Basic logs needed to operate and secure the service (for example, request metadata and error logs). We do not log the contents of your Google files or your OAuth tokens.
2. Google user data & Limited Use
What we access
- Google Drive (
drive.file scope): StokaTerminal can only access the
specific files you explicitly choose through Google's own file picker, plus files StokaTerminal
itself creates. We cannot see, list, or browse the rest of your Google Drive. We use this
access to import the files you select into your StokaTerminal workspace and to preview them.
- Sign-in (
openid, email): to identify your account.
How we use Google data
- Solely to provide and improve user-facing features for you — importing, previewing, organizing, searching, and linking the files you choose, and using their content to power features you ask for (such as search and retrieval) within your own account.
What we never do with Google data
- We do not sell or rent it, and do not use it for advertising.
- We do not transfer it to others except as needed to provide the service to you, to comply with law, or as part of a merger/acquisition with notice.
- We do not allow humans to read it, except (a) with your consent, (b) for security or to comply with law, or (c) where the data has been aggregated and anonymized.
- We do not use it to develop, improve, or train generalized AI/ML models.
AI processing
StokaTerminal's search and retrieval features are powered by models running on
StokaTerminal's own infrastructure; your content is not sent to a third-party AI provider to
deliver them. Where a third-party AI provider is used to deliver a feature, that provider is
bound by API terms that prohibit using your content to train their models, and your Google file
content is never used to train any generalized model.
Separately, you may connect your own AI agent (for example Claude or ChatGPT) to your account
over our MCP connector. That agent is your relationship with your provider: when
you ask it to read or change something in your account, the content it retrieves flows to that
provider under the terms you have with them, not ours. You choose which permissions to grant,
every call is recorded in an audit log you can review, and you can revoke a connection at any
time from Settings.
3. How we use your data
- To provide, maintain, and secure the service and its features.
- To process your subscription and prevent abuse.
- To communicate with you about your account and reminders you set up.
4. How we store and protect data
- Your data is stored on infrastructure operated by StokaTerminal.
- OAuth refresh tokens for connected services are encrypted at rest and are never exposed to the browser or to other users.
- Access is scoped per user; one account cannot access another's data.
- Connections are made over encrypted (HTTPS/TLS) transport.
5. Sharing & subprocessors
We do not sell your data. We share data only with service providers that help us operate StokaTerminal, each acting under contract:
- Google — sign-in and the file picker / Drive APIs you connect.
- Stripe — payment processing.
- Cloudflare — network delivery and security.
- Infrastructure and AI providers used to deliver features, bound by terms that prohibit training on your content.
6. Data retention & deletion
- Disconnecting a Google account revokes the connection and deletes the stored tokens for it.
- Deleting content removes it from your workspace.
- Deleting your account removes your account data. You may request deletion at any time using the contact below.
- You can also revoke StokaTerminal's access to your Google account at any time at myaccount.google.com/permissions.
7. Your choices
- Choose exactly which Drive files StokaTerminal can access (via the picker) — and revoke that access anytime.
- Manage connected app/MCP connections in StokaTerminal settings.
- Request a copy or deletion of your data.
8. Children
StokaTerminal is not directed to children under 13 (or the age required by your jurisdiction) and we do not knowingly collect their data.
9. Changes to this policy
We may update this policy; material changes will be reflected by the "Last updated" date above and, where appropriate, by notice in the app.
10. Contact
Questions or data requests: [email protected].