Privacy Policy

Effective: 2026-10-01

Who this policy covers

Staffmor.com (Staffmor, we, us) provides the Staffmor website and workspace product. This policy explains information processed by our website and Staffmor-operated services, and distinguishes that information from records kept in your local office and information handled by your chosen AI providers. Contact staffmor@gmail.com about this policy or a privacy request.

Staffmor is independent of OpenAI and Anthropic. Their services, and other tools you choose to connect, have their own privacy policies. This policy does not replace those policies or promise that those providers never retain or use your information.

The short version

Your installed office keeps its working records on your own computer. Staffmor does not host a general archive or backup of that local office. That does not mean no information leaves your computer or that Staffmor collects no personal information.

Our hosted services can process saved setup choices, account and licensing identifiers, transaction records, device connection information and support messages. If a remote connection feature is enabled and you use it, selected office content and commands can pass through and be stored by our relay. Your chosen AI providers receive the prompts, files and other context you or your assistants send to them.

What stays in your local office

Organization records, agent profiles, office conversations, work history, preferences, drafts and local files are stored in the office folder on the computer you control. Staffmor's hosted service does not automatically collect that entire folder. Your own assistants, connected tools, cloud-backup software or people you authorize may read or transmit those records independently.

You control local backups and local deletion. Canceling a Staffmor subscription does not itself delete your local records. A privacy request to us cannot delete copies held only on your computer or independently by a provider you selected.

Information our hosted services can collect

Website and session information: a session identifier, visited entry page, referral/source category, audience category, timestamps, selected plan and, when enabled, assignment to a price, copy or presentation experiment and related interaction events. Hosting infrastructure also processes requests, which can include IP address, browser/device headers and diagnostic information. Our rate-limit system derives a security identifier from an IP address rather than storing the raw address in its rate-limit table; that does not mean the hosting provider has no request logs.

Saved setup: if you use an enabled online Save or resume feature, we store the answers you submit, such as work type, organization name, chosen roles/providers and an optional note, together with the selected plan and a resume/session relationship. Please do not put passwords, API keys or unnecessary confidential information in a setup note. A static preview without an enabled Save action does not save setup to our backend; saved setup is available only where the actual Save feature is enabled and confirms success.

Contact and support: an email address and chosen plan if you submit an enabled interest form, plus the message and attachments you voluntarily send to support. A purchase or transactional message is not permission for unrelated marketing; marketing preferences are handled separately.

Billing and licensing: transaction, checkout and subscription identifiers, selected plan/price, currency or paid amount where applicable, payment/refund/cancellation/activation status and timestamps, and office/workspace/license/account identifiers needed to verify your access. We can access transaction and customer information made available to us in the payment provider's dashboard; we do not claim that only the provider knows you purchased Staffmor.

Device activation and connections: office/workspace and owner identifiers, device names and public keys, software version, activation and connection status, connection timestamps, and protected or hashed session/device credentials. Your local desktop connection token remains in the local office's protected device file; hosted services retain the verification information required for the connection.

Remote relay content, if enabled: selected office state, messages or results sent for a connected device, commands and replies, member/device identifiers and action status. The current v1 relay uses HTTPS transport but is not end-to-end encrypted. Staffmor's service and infrastructure can process the relayed content. Do not interpret a local-first claim as saying our relay can never read it. Remote connection features not yet released are not available just because this policy describes their data flow. Relayed content can include conversation or thread text and images you request from your office. Requested image pieces are transmitted through our infrastructure and stored as action replies; displaying the assembled image in browser memory does not mean our hosted service never processes or stores that image.

How information is used

We use operational information to provide the feature you requested, retain and resume your setup, connect the correct office, verify entitlements, process and reconcile purchases and refunds, support you, prevent abuse and duplicate actions, measure website and offer performance, and meet applicable legal or accounting obligations.

Staffmor does not use your local office records or relayed content to train its own AI models, and does not sell your personal information or share it for cross-context behavioral advertising. This is a commitment about Staffmor's practices, not an assurance about your independently chosen AI providers. We do not need your provider passwords or API keys for the standard bring-your-own-provider workflow; do not send them to our setup or support forms.

Who receives information

Netlify and the infrastructure supporting our hosted site and database process website and operational service information to run those services. Stripe and Link process payment, transaction and subscription information; when a purchase is sold through Link using Stripe Managed Payments, Link is the transaction's merchant of record. Staffmor handles product support, while the payment channel provides its own transaction support.

The people/devices you authorize receive the office information you share with them. AI providers and other tools receive the context you or your assistants send through your own accounts, subject to their terms and settings. Staffmor does not centrally route your entire local office to every provider.

Service providers engaged to operate or support Staffmor may process information for those purposes. We may disclose information when reasonably necessary to comply with law, respond to valid legal process, protect rights or address fraud and security incidents, or in a business transfer with applicable protections and notice. These exceptions do not authorize sale of your data for advertising.

Relevant policies: https://www.netlify.com/privacy/ ; https://stripe.com/privacy ; https://link.com/privacy ; https://openai.com/policies/privacy-policy/ ; https://www.anthropic.com/legal/privacy . Follow the policy applicable to the particular account and feature you use.

Cookies, experiments and choices

An enabled hosted setup flow uses a first-party session cookie to recognize the same flow; that cookie can last up to 30 days. A resume link can expire after seven days. Expiration of a cookie or link does not by itself erase the underlying database record.

When website experiments are enabled, we record the assigned offer/presentation and associated events. Different new visitors may be offered different monthly prices; your agreed price is shown before purchase. We do not use those assignments to automatically reprice an existing subscription.

A connected browser uses local storage on that device to keep its connection credential and identity, drafts, navigation and pending command/request bodies, which may contain office text. This helps preserve unsent work and reconcile pending actions after reopening. The client does not intentionally save its fetched office snapshots, conversation history or image bytes in localStorage as an offline archive. It is designed to clear the relevant connection and pending/client records after a confirmed disconnect or when it observes revocation. Clearing browser storage can remove your local connection and unsent work; it does not itself delete hosted records. If a browser is offline, remote revocation does not guarantee that its local records have already been erased. Be careful when connecting on a shared device.

You can control cookies through your browser. Blocking a required session cookie can prevent setup, resume or activation from working. We obtain any consent legally required for nonessential cookies or measurement before activating that processing. No third-party advertising tracker is part of the reviewed first-look page; if this changes, the policy and applicable choices must change first. We do not track you across unrelated websites for behavioral advertising. Our reviewed application does not implement a special response to a browser Do Not Track signal; this does not override any privacy signal we are legally required to honor.

Retention and deletion

Local office records remain on your computer until you or software you control change or delete them. For hosted records, retention depends on the feature, whether an account or connection remains active, security and transaction needs, and legal recordkeeping requirements. A setup note is not automatically deleted merely because its resume link expires.

The remote service is designed to retain the latest state for a connected device and to remove resolved relay actions after seven days, unresolved actions after 30 days, and obsolete revoked-device records after a retention window. These are cleanup thresholds, not a guarantee of deletion at an exact instant. Actual removal depends on cleanup execution, bounded batches and related records; infrastructure backups and mandatory transaction records can have different retention. Ask staffmor@gmail.com about deletion of information we control. The relay-action cleanup thresholds also apply to requested image pieces stored in action replies.

We will consider and handle applicable access, correction and deletion requests after appropriately verifying identity. Some records must be retained for accounting, legal claims, fraud prevention or other lawful purposes; we will explain a relevant exception. We cannot erase information held independently by your selected AI provider or payment provider. A request to delete your Link purchase/account information can also end the related subscription; review the provider's process before submitting it.

Security and international processing

We use safeguards appropriate to the information and feature, including HTTPS connections, scoped connection credentials and verification checks. No software, device or transmission is perfectly secure. The current relay is not end-to-end encrypted, and we do not promise that only you can read every hosted payload. Your own computer, connected accounts and backups also require protection.

Hosting, payment and AI services may process information in the United States or other countries according to their infrastructure and policies. We do not promise that all information is stored exclusively in your country. Where additional contractual or legal safeguards are required, those must be established for the relevant processing.

Your rights and organization accounts

Depending on the law applicable to you, you may have rights to access, correct, delete or receive information, object to or restrict processing, withdraw consent, and complain to an appropriate privacy authority. Contact staffmor@gmail.com. These rights can have legally recognized exceptions and do not require disclosure of another person's information or a security credential. We will not retaliate for exercising applicable rights.

For an office used by an employer or other organization, that organization controls the local work environment and may determine which people, records and tools are used. Contact its administrator about that processing as well as Staffmor about information our hosted services control. A business data-processing agreement may be required for a hosted feature; a website policy alone does not substitute for one.

Children and updates

Staffmor's paid service is intended for adults and organizations, not children. If you believe a child has supplied personal information to us without appropriate authorization, contact staffmor@gmail.com.

We will show the effective date on this policy and communicate material changes through the website and, where appropriate, an account or contact notice. Where a new use requires consent, posting a policy update alone will not substitute for it.

Software downloads: when you run the installer, our hosted service records the requested version, hashed request credentials, request/approval times and the approving account relationship. Your paid browser session must explicitly approve a short-lived download. The archive is delivered privately; approving a download does not itself activate an office. Expired requests are eligible for bounded cleanup after an additional hour, which is not a promise of deletion at an exact instant.

Purchase agreement records: when you confirm a monthly order, we retain the exact selected offer, charge and renewal details, document versions and hashes, and agreement and privacy-acknowledgment timestamps. Retries preserve the accepted order. These records are separate from optional marketing preferences.