1. Scope
This Privacy Policy explains how StringsOS collects, uses, shares, and protects personal information during beta access. It applies to account creation, authentication, workspace use, support, integrations, analytics, security monitoring, and product communications.
StringsOS is currently operated by Sandun Fernando, an individual, ahead of formal company incorporation. References to "StringsOS," "we," "us," and "our" in this Policy mean Sandun Fernando as the current operator and data controller. This section will be updated to name the incorporated entity once one is formed.
This policy is a working beta draft and must be reviewed by qualified legal counsel before general availability, paid launch, or formal enterprise contracting.
2. Information We Collect
- Account data such as name, email address, authentication provider, profile metadata, organization, role, and legal acceptance records.
- Workspace data such as projects, languages, translation keys, source strings, target translations, comments, review decisions, screenshots, file imports, and export settings.
- Integration data such as GitHub repository metadata, Figma file references, OAuth identifiers, tokens or token references, webhook metadata, and provider connection status.
- AI workflow data such as prompts, source text, target locale, generated suggestions, approval decisions, overrides, quality checks, and audit logs.
- Usage and device data such as pages visited, actions taken, feature usage, browser, approximate location from IP address, diagnostics, errors, and performance events.
- Support and business communications such as requests, feedback, survey responses, marketing preferences, and onboarding notes.
3. How We Use Information
- Provide, secure, operate, debug, and improve StringsOS.
- Authenticate users, authorize access, apply roles, and isolate tenant data.
- Process localization workflows, imports, exports, reviews, AI suggestions, history, and integrations requested by users.
- Maintain audit trails for approvals, overrides, security events, and legal acceptance records.
- Communicate service updates, beta notices, security notices, support responses, and future pricing or plan information.
- Analyze product usage to improve reliability, usability, accessibility, performance, onboarding, and roadmap decisions.
- Comply with legal obligations, enforce terms, prevent abuse, and protect users, customers, and StringsOS.
4. AI and Third-Party Processing
Some features may send selected Customer Content or metadata to AI providers, infrastructure providers, analytics providers, email providers, support tools, payment processors, GitHub, Figma, Supabase, or other service providers when needed to provide the requested functionality. Production use should maintain a current sub-processor list, data processing terms, and provider-specific retention settings.
5. How We Share Information
- With service providers that help operate, secure, host, analyze, email, support, bill, or integrate the service.
- With integration providers when you connect or authorize an integration such as GitHub or Figma.
- With organization admins and authorized workspace members according to roles and permissions.
- When required by law, legal process, security investigation, rights protection, or business transfer.
- With your consent or at your direction.
6. Retention
We retain information for as long as needed to provide the beta service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and preserve audit history. Production retention periods, deletion windows, and legal hold behavior should be finalized before paid launch.
7. Security
StringsOS uses technical and organizational measures designed to protect information, including authentication, authorization, row-level security, audit logs, least-privilege access, environment separation, monitoring, and secure development practices. No system can guarantee perfect security, and beta users should avoid submitting unnecessary sensitive data.
8. Your Choices and Rights
- You can update account and workspace information through the product where supported.
- You can disconnect integrations or revoke provider access where supported by the provider and StringsOS.
- Depending on your location, you may have rights to access, correct, delete, export, restrict, object to, or opt out of certain processing of personal information.
- California residents may have rights to know, delete, correct, opt out of sale or sharing, limit certain sensitive information use, and avoid discrimination for exercising privacy rights, where the law applies.
- EU, UK, and similar-region users may have additional rights and transfer protections where applicable.
9. International Use
StringsOS may process information in countries where our team, infrastructure, and service providers operate. International transfer mechanisms, data residency options, and enterprise DPAs must be finalized before general availability for regulated customers.
10. Children
StringsOS is intended for business and professional use and is not directed to children. Do not create an account or submit personal information if you are not old enough to use business software under the laws that apply to you.
11. Changes
We may update this Privacy Policy as the beta evolves. Material privacy changes should be presented in the product or by email before they apply where required by law or commercial practice.
12. Contact
For privacy requests or questions, contact the StringsOS team using the official support or business contact channel provided to your organization.