Privacy Policy
Effective Date: January 5, 2026 | Last Updated: April 26, 2026
stellarclose.com | money.stellarclose.com | stellarclosetc.com | privacy@stellarclose.com
This Privacy Policy covers all products and services operated by StellarClose LLC, including StellarClose Money (autonomous bookkeeping), StellarClose Transaction Coordination (AI transaction coordination for real estate), StellaRose (our AI assistant character on voice and chat), and StellarClose.com. One policy. Everything we do. No exceptions.
We are not a law firm and this document does not constitute legal advice. If you have specific compliance requirements, please consult qualified legal counsel.
1. Who We Are
StellarClose LLC is a Michigan limited liability company that develops and operates AI-powered software tools for real estate professionals. Our products include:
- StellarClose Money — autonomous bookkeeping for service businesses (money.stellarclose.com)
- StellarClose Transaction Coordination — AI transaction coordination for real estate (stellarclosetc.com)
- StellaRose — our AI assistant character on voice and chat surfaces
- StellarClose.com — business hub and internal operations
When this policy refers to "we," "us," or "our," it means StellarClose LLC. When it refers to "you," it means any person or business that uses our products or visits our websites.
2. Information We Collect
A. Information You Provide Directly
- Name, email address, phone number
- Billing and payment information (processed by third-party payment processor — we do not store full card numbers)
- Real estate license information
- Business name and address
- Transaction, customer, expense, and journal data you enter into our products
- Account credentials you create
B. Bank Account Data (StellarClose Money via Plaid)
When you choose to connect a bank account to StellarClose Money, you authorize Plaid Inc. to retrieve account data from your financial institution and pass it to us. You initiate this connection yourself via Plaid Link. We never see your online banking password — Plaid handles that. We receive:
- Account metadata (institution name, account name, account type, last four digits, currency)
- Transaction history (date, amount, merchant, description, category, pending status) for the period the institution makes available, typically the last 24 months
- Account balance at the time of each sync, where the institution provides it
- The account holder's name as it appears on the account, where Plaid surfaces that field
We use your bank data only to operate StellarClose Money for you — auto-categorizing transactions, matching deposits to invoices, and producing your financial reports. We do not sell, share, license, or analyze your bank data for any other purpose. You can disconnect at any time from your settings page; disconnect halts new data fetches immediately. Plaid's own End User Privacy Policy is at plaid.com/legal/#end-user-privacy-policy.
D. Automatically Collected Information
- Device information (browser type, operating system)
- IP address and approximate location
- Usage data and analytics
- Cookies and similar tracking technologies
E. Voice and Call Data (StellaRose)
- Phone calls may be recorded for quality assurance — callers are notified before recording begins
- Voice data is processed for AI transcription
- Call logs and transcripts are stored securely
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain our services
- Process transactions and send related confirmations
- Auto-categorize bank transactions, match deposits to invoices, and produce financial reports (Profit & Loss, Balance Sheet, year-end tax package) for StellarClose Money
- Coordinate real estate transactions, track deadlines, and communicate with parties (StellarClose Transaction Coordination)
- Track usage for billing purposes
- Send service notifications, updates, and administrative information
- Respond to your inquiries and provide customer support
- Improve our products and develop new features
- Monitor system health and detect fraud or abuse
- Comply with legal obligations
We do not sell your personal information. We do not mine, analyze, or monetize your data. We do not use your bank transaction data to profile you, score you for credit, or build any non-bookkeeping derivative. We do not train external AI models on your data.
4. Bank-Account Connection via Plaid
Because the Plaid integration carries direct read access to your financial institution data, we treat it with extra care.
How the Connection Works
- You initiate every connection. We never connect a bank on your behalf.
- Plaid Link presents the consent screen and handles the credentials. We do not see your online banking password.
- Plaid passes us only the categories of data listed in Section 2.B above — nothing more.
How You Can End the Connection
- You can disconnect any connected account at any time from your StellarClose Money settings page.
- When you disconnect, we instruct Plaid to remove the connection and we stop fetching new transactions immediately.
- Existing journal entries derived from your bank transactions remain in your books for accounting integrity. You can delete those entries individually, or request full account deletion to remove them entirely.
Plaid's Role
- Plaid Inc. is a separate company that provides the secure connection layer between your bank and StellarClose. Plaid's own End User Privacy Policy and End User Services Agreement govern Plaid's collection and use of your data while it is in their system. Both are available at plaid.com/legal/.
- We do not share your bank data with any party outside the subprocessor list in Section 6.
5. AI Processing of Your Data
Several of our products use AI to process your data on your behalf. We are explicit about how AI is used and what it sees.
StellarClose Money — Transaction Categorization
- When we ask Anthropic Claude to suggest a chart-of-accounts category for a bank transaction, we send only the merchant name, transaction description, amount, and Plaid category — never your account number, your name, or any other identifying field.
- Suggestions below a confidence threshold are routed to a human-review queue rather than auto-applied. You can override any AI suggestion at any time.
- We do not train external AI models on your data. The Anthropic API calls run with the setting that disables training on submitted content.
StellaRose — Voice and Chat
- StellaRose identifies as an AI on every channel. We will never configure the system to deceive any party into believing they are speaking with a human.
- Calls handled by StellaRose may be recorded for quality assurance, with caller notification before recording begins.
6. Information Sharing
We do not sell your personal information. We share information only in the following limited circumstances:
Service Providers
We work with third-party vendors who help us operate our infrastructure, including:
- DigitalOcean — hosting (compute, managed PostgreSQL, networking)
- Backblaze B2 — encrypted off-site backup of database snapshots
- Plaid Inc. — secure bank-account connection and transaction retrieval (StellarClose Money)
- Anthropic — AI categorization and document parsing (Claude API; transaction text only, no PII)
- PayPal — invoice payment processing (we do not store full payment card data)
- SignalWire — inbound and outbound voice (StellaRose phone)
- Namecheap — domain registration and DNS
All service providers are contractually required to use your data only to perform services for us and to protect it appropriately.
Legal Requirements
We may disclose information when required by law, court order, or government request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a materially different privacy policy.
What We Never Do
- We never sell your personal information to data brokers or advertisers
- We never sell or share your bank transaction data, your bookkeeping records, or any other personal information
- We never use your email content or contact data to target advertising
7. Data Security
We implement strong security measures, including:
- TLS 1.2 or higher for all data in transit; HSTS enforced with one-year max-age
- Encryption at rest for the production database (DigitalOcean managed PostgreSQL); encrypted off-site backups to Backblaze B2
- Passwordless email magic-link authentication; no customer passwords stored
- Per-tenant data isolation enforced at the SQL layer
- Per-tenant rate limiting on authentication and AI endpoints
- Application secrets in a 0600-permissioned environment file readable only by the application service account
- Daily automated security sweep that probes the live posture against documented controls and alerts on drift
- Vulnerability management with documented patching SLAs (Critical 72h, High 14d, Medium 30d)
In the event of a data breach affecting your personal information, we will notify you within 24 hours of discovery. This is a commitment in our Constitution and it is non-negotiable.
8. Data Retention
We retain your information only as long as necessary:
- Account information: retained while your account is active; deleted upon account cancellation
- Transaction and bookkeeping records: retained for 7 years per accounting and real-estate industry standards and tax-record requirements
- Bank-connection access tokens: retained while the connection is active; revoked at Plaid the moment you disconnect
- Bank transactions imported via Plaid: retained as part of your bookkeeping for as long as you keep your account, on the same 7-year cycle as other accounting records
- Call recordings and transcripts: retained for 90 days unless you request earlier deletion
- Billing records: retained for 7 years per accounting requirements
- Usage logs (aggregate counts): retained for 24 months
When we delete data, we delete it from all systems including backups, within the timeframe specified above.
9. Your Rights
You have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your information (subject to legal retention requirements)
- Portability: Receive your data in a structured, machine-readable format
- Opt-out: Unsubscribe from marketing communications at any time
- Disconnect: Disconnect any connected bank account at any time from your settings page. We act on the disconnect immediately.
- Withdraw consent: Where we rely on consent to process your data, you may withdraw it at any time
To exercise any of these rights, contact us at privacy@stellarclose.com or 833-794-5488. We will respond within 30 days. We will confirm receipt of your opt-out request with a visible confirmation — not just a silent action.
10. California Privacy Rights (CCPA/CPRA)
California residents have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), as updated effective January 1, 2026:
- Right to know what personal information we collect, use, share, or sell (we do not sell)
- Right to delete your personal information, subject to certain exceptions
- Right to correct inaccurate personal information
- Right to opt-out of the sale or sharing of personal information (we do not sell or share)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your CCPA rights
- Right to access personal information going back to January 1, 2022, to the extent we retain it
To submit a CCPA request, contact us at privacy@stellarclose.com. We will verify your identity before processing the request. We will respond within 45 days. We will provide written confirmation when an opt-out request has been honored.
We use automated systems in our services, including AI-powered verification and transaction coordination. Where these systems make significant decisions, we are prepared to provide information about the logic involved upon request.
11. GDPR Compliance (EU/UK Users)
If you are located in the European Union or United Kingdom, the following applies:
Legal Bases for Processing
- Contract performance: We process your data to fulfill the services you've contracted with us
- Legitimate interests: We process data to operate, secure, and improve our services where this does not override your rights
- Legal obligation: We process data as required by law
- Consent: Where we rely on consent, you may withdraw it at any time
Your GDPR Rights
- Access, rectification, erasure, restriction of processing, data portability, and objection
- Right to lodge a complaint with your local data protection authority
- Response to requests within 30 days
Data Transfers
We are based in the United States. If you are in the EU or UK, your data may be transferred to and processed in the US. We take appropriate measures to protect transferred data in accordance with applicable law.
Data Protection contact: privacy@stellarclose.com
12. Automated Decision-Making
Several of our services use automated systems:
- StellarClose Money uses AI to suggest chart-of-accounts categories for bank transactions; suggestions below a confidence threshold are routed to human review rather than auto-applied, and you can override any suggestion
- StellarClose Transaction Coordination uses AI to coordinate real estate transactions, track deadlines, and communicate with parties — subject to your oversight and control as the agent
- StellaRose uses AI for voice and chat interactions; she identifies as an AI on every channel and never claims to be human
Where automated processing produces significant outcomes (such as blocking a send or flagging an account), you will be notified with an explanation and given the opportunity to seek human review. Contact us at privacy@stellarclose.com to request review of any automated decision.
13. Cookies and Tracking
We use cookies and similar technologies to:
- Keep you logged in to your account
- Remember your preferences
- Understand how our products are used so we can improve them
- Protect against fraud and abuse
We do not use cookies to serve advertising or to track you across third-party websites. You can control cookie settings in your browser. Disabling cookies may affect the functionality of some features.
14. Children's Privacy
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately at privacy@stellarclose.com and we will delete it.
15. Third-Party Links
Our websites and products may contain links to third-party websites and services. We are not responsible for the privacy practices of those sites. We encourage you to review the privacy policies of any third-party sites you visit.
16. Changes to This Policy
We review this Privacy Policy at least annually and update it whenever our data practices change materially. When we make significant changes, we will:
- Post the updated policy on our websites with the new effective date
- Notify registered users by email before the change takes effect
- For material changes affecting how we use your data, we will obtain fresh consent where required
17. Contact Us
For questions, requests, or concerns about this Privacy Policy or our data practices:
- Email: privacy@stellarclose.com
- Phone: 833-794-5488
- Mail: StellarClose LLC, 3588 Plymouth Road 233, Ann Arbor, MI 48105
- Website: stellarclose.com
We respond to all privacy inquiries within 30 days.
StellarClose LLC
The right tools can change lives.
We never sell your data | One-click cancel, always
stellarclose.com | money.stellarclose.com | stellarclosetc.com