Privacy Policy
Last updated: September 2026
1. Introduction
Sthamly ("we", "our", "us") operates the sthamly.com website and related services (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
2. Information We Collect
Account information: If you sign up, we collect your email, name, and (if you use Google login) your Google profile information.
Audit data: Brand name, target city, and website URL you submit for an AI visibility audit.
WordPress connection: If you connect a WordPress site, we store the site URL, username, and an encrypted application password used only to apply fixes you request.
Payment information: Payments are processed by Razorpay. We do not store your card details — Razorpay handles this securely under its own PCI-DSS compliant systems.
3. How We Use Your Information
- To run AI visibility audits using third-party AI models (via OpenRouter) and search data (via Serper.dev)
- To let you save and revisit your audit history
- To apply schema markup/FAQ fixes to your connected WordPress site when you purchase a fix
- To process payments securely via Razorpay
- To send you service-related communication (not marketing spam)
4. Third-Party Services
We share limited data with the following third parties strictly to provide the Service: OpenRouter (AI model queries), Serper.dev (search data), Supabase (database and authentication), Razorpay (payments), and Google (OAuth login, if used). Each of these providers has its own privacy policy governing how they handle data.
5. Data Retention
Guest audits (without login) are stored against your device only. Logged-in audits are retained until you delete your account. WordPress credentials are retained until you disconnect the site from Optimizer.
6. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us. You may also disconnect your WordPress site or delete your account from the Account page.
7. Security
We use industry-standard measures (encrypted connections, Razorpay signature verification, Supabase Row Level Security) to protect your data. No system is 100% secure, and we encourage you to use a strong, unique password.
8. Children's Privacy
The Service is not directed at individuals under 18 years of age.
9. Changes to This Policy
We may update this policy from time to time. Continued use of the Service after changes constitutes acceptance.
10. Contact Us
For any privacy-related questions, please contact us via the support option in your Account settings.