This Privacy Notice explains how personal data is processed when you visit or use Stocktag websites, web or desktop experiences, applications, APIs, support channels, community features, and related services (collectively, the “Service”). It is a notice, not a request for blanket consent. Where consent is required—for example for optional analytics, advertising measurement, or marketing—we ask for it separately and you may withdraw it without affecting earlier lawful processing.
1. Controller and scope
Stocktag is the brand used for the Service. Stocktag, as the Service operator, determines the purposes and means of the processing described here and acts as data controller unless a third party is identified as an independent controller.
Production notice requirement: the operator’s verified legal name, full service and postal address, company or tax registration details, and any required Türkiye, EEA or UK representative or data-protection contact have not been supplied in this repository. Those details must be inserted before this notice can be treated as a complete controller disclosure. Privacy requests may meanwhile be sent to support@stocktag.ai and security reports to security@stocktag.ai.
Paddle is the merchant of record for purchases and separately determines how it processes payment, tax, fraud, and transaction data under the notice presented at checkout. External AI providers, stock-content sources, search services, authentication providers, and public websites may also act as independent controllers for their own purposes.
2. Service and people covered
The Service includes Metadata Studio; image, vector, video, metadata and prompt workflows; Image Generator and image editing; Vectorizer; Prompter; desktop or local-file tools; folders, drafts, history and exports; Market Intelligence, Trends Radar, Holiday Planner and Similarity Scanner; BYOK and Stocktag-funded AI modes; public feedback, comments and community styles; referrals, credits, pricing and subscriptions; newsletters, notifications, chatbot and support; administrative, security and abuse-prevention systems; and public pages, demos, help and blog content.
This notice covers visitors, trial users, registered users, purchasers, support contacts, public contributors, referral participants and people whose data a user includes in submitted content. If you submit another person’s data, you must have a lawful basis and provide any notice required by law.
3. Data we process
- Account and identity: Firebase user ID, name, display name, email, phone number where used, profile photo, authentication provider and provider identifier, verification state, locale, country inference, plan, credits, account status, role and timestamps.
- User content and work product: uploaded images, vectors, videos and reference files; filenames, MIME types, dimensions, technical and embedded metadata; prompts, instructions, negative prompts, styles and search terms; titles, descriptions, keywords and other generated output; thumbnails, embeddings, perceptual hashes, similarity vectors, drafts, folders, processing history, recovery files, exports and destination-platform selections.
- AI and BYOK data: selected provider and model, API requests and responses, token or quota usage, generation settings, provider error data, encrypted provider keys where saved on the backend, non-secret key-presence markers, and browser/session preferences. A browser-direct workflow can transmit your key and content from your device directly to the provider.
- Billing and entitlement: Paddle customer, transaction, subscription and price identifiers; product or package; currency, amount, tax and status; renewal, trial, cancellation, refund, chargeback and management URLs; credit grants, consumption and purchase history. Stocktag does not receive the full card number or CVV.
- Public and community data: feedback posts, comments, community styles, chosen author/display name, public preview, likes, version or moderation state and timestamps. Content marked public can be viewed, copied or indexed by others.
- Communications: support and chatbot messages, email addresses, participants, subject, attachments, delivery events, campaign and unsubscribe status, notification preferences, survey or feedback content, and correspondence history.
- Product and administrative activity: page or tab, feature and button events, file name/type/count, export format/platform, provider/model/funding mode, stock-search query, request result, error and diagnostic details, support or admin actions, and aggregated usage or cost metrics.
- Network, device and security: IP address and hashed IP, user agent, request headers, referrer, timestamps, rate-limit data, Turnstile or reCAPTCHA result, browser installation identifier, canvas result, WebGL vendor/renderer, languages, platform, hardware concurrency, device memory, screen size/color depth, time zone/offset, touch and cookie capability, email/domain risk signals, device-fingerprint hash, abuse links, risk reasons and review state.
- Preferences and local data: theme, language, layout, workflow and export preferences, cookie choices, referral attribution, onboarding state, local chatbot history, locally cached history/drafts/catalogs, and authentication or checkout handoff state.
4. Sources and collection methods
- Directly from you when you register, authenticate, upload or generate content, enter prompts or search queries, configure BYOK, publish community content, buy a plan, contact support, subscribe to marketing, or change settings.
- Automatically from your browser, device and use of the Service through application logs, security controls, cookies, local/session storage, SDKs, pixels and similar technologies. Collection can be automated even when no cookie is written.
- From Firebase/Google authentication, Paddle, AI providers, Cloudflare, Resend, advertising and analytics services, referral links, public stock/search/data sources, and other integrations you request.
- By automated and non-automated means through web, API, email, support, administrative and scheduled-maintenance systems.
5. Purposes and legal bases
Where we rely on legitimate interests, you may request information about the balancing assessment and object where the law gives that right. If data is required for an account, payment, security check or requested feature, failure to provide it can prevent us from providing that part of the Service. We do not intentionally request special-category or sensitive personal data; do not upload it unless the feature expressly requires it and a valid legal basis and safeguards exist.
- Provide the requested Service—accounts, authentication, uploads, processing, AI generation, BYOK, folders/history, exports, support, community publishing, subscriptions and credits: performance of a contract or steps requested before a contract (GDPR Article 6(1)(b)); establishment or performance of a contract under KVKK Article 5(2)(c).
- Process payments, tax, accounting, refunds, records and legally required notices: contract and legal obligation (GDPR Articles 6(1)(b) and (c)); explicit legal obligation under KVKK Article 5(2)(ç). Paddle’s separate bases are stated at checkout.
- Secure the Service; enforce quotas; detect duplicate trials, referral fraud, account compromise, spam and abuse; investigate errors and legal claims: legitimate interests in security, service integrity and the establishment or protection of rights (GDPR Article 6(1)(f); KVKK Articles 5(2)(e) and 5(2)(f)), balanced against your rights, and legal obligation where applicable.
- Operate first-party product analytics, capacity, quality and cost controls: legitimate interests in understanding and improving the Service, using proportionate data and opt-out where required. Optional Google Analytics or similar device access is based on consent where law requires it.
- Publish a post, comment or community style at your request: contract/performance of your publication request and legitimate interests in operating the community. Public submission is voluntary and preceded by a publication notice; it is not consent to unrelated uses.
- Send service, security, billing and account messages: contract, legal obligation or legitimate interests. Send newsletters, offers or re-engagement messages: prior consent where required; otherwise only where applicable law permits, with an unsubscribe in each message.
- Measure ads, conversions and audiences using Google or Meta: consent where required. We do not rely on acceptance of the Terms or this Notice as consent for optional tracking.
- Comply with lawful requests, sanctions/export rules, court orders and regulator requirements; prevent or establish legal claims; complete a corporate transaction: legal obligation, rights/claims and legitimate interests, subject to applicable safeguards.
6. Content and AI processing
Depending on the selected workflow, files, prompts, reference images, metadata and related settings are sent to Stocktag servers and one or more selected providers such as OpenAI, Google Gemini, Anthropic, Groq or xAI. Some browser-direct BYOK requests go from your device to the selected provider; other requests pass through Stocktag infrastructure. Temporary Firebase Storage or provider file APIs may be used for larger-file workflows. Similarity features can create embeddings and perceptual hashes and store user-specific vectors in Qdrant or a configured vector/ML service.
Stocktag does not use private user content to train a Stocktag general-purpose model unless it first provides a separate, specific notice and obtains any legally required permission. A selected provider may process or retain data under its product, account and contract settings; provider rules can differ between Stocktag-funded, enterprise/API, browser-direct and your own BYOK account. Review the selected provider’s terms before sending confidential content.
Automated output may be inaccurate, biased, incomplete, similar to another user’s output or unsuitable for a stock marketplace. Human review is required before publication or consequential use. Do not submit secrets, full payment-card data, government identifiers, health data, biometric templates or other highly sensitive data unless expressly requested through an approved secure channel.
7. BYOK key handling
When you choose encrypted backend storage, the provider key is encrypted at rest using AES-256-GCM and decrypted only to execute an authorized request. Stocktag also stores provider/model choices and a non-secret marker indicating that a key exists. Legacy keys can remain in local or session storage on a device until removed or migrated. In browser-direct mode the key is transmitted to the selected provider without being intentionally stored by the Stocktag backend.
You may delete a saved key in settings and should revoke it with the provider if compromise is suspected. Encryption reduces risk but cannot guarantee absolute security. Provider usage, charges, logs and retention remain governed by your provider account.
8. Security profiling and automated decisions
To protect free credits, trials, referrals and accounts, Stocktag combines hashed IP and device-fingerprint signals, account age/provider, email/domain indicators, Turnstile or reCAPTCHA results, prior device/network use and referral relationships. Rules assign risk reasons and can deny or delay welcome/referral credits or place signup into manual review. They do not determine access to employment, credit, housing, insurance or another similarly essential service.
If a decision has a legal or similarly significant effect where applicable law grants protection, you may request meaningful information about the logic, human review, correction of inaccurate inputs and an opportunity to contest the decision by contacting support@stocktag.ai. Raw canvas/WebGL values are used to derive a fingerprint; server records generally store a hash rather than the original value, but hashes are still treated as personal data where linkable.
9. Public areas
Feedback, comments and community styles are intended to be public. The Service may show the content, selected display name, preview, likes and timestamps. Do not publish private, confidential or third-party personal data. Search engines and other users may copy public content before it is removed.
Stocktag minimizes internal identifiers in public responses and may moderate, de-identify or remove public material. To request takedown or correction, contact support@stocktag.ai and identify the URL or item. Removal from Stocktag does not guarantee removal of independent copies or search caches.
10. Cookies, SDKs and browser storage
Required technologies are used for authentication, security, load/session continuity, language, consent records, referral attribution, checkout handoff and user-requested settings. Optional analytics and advertising technologies remain off until an affirmative choice where consent is required. Opening Cookie Settings never preselects an optional category. You can reject optional categories as easily as accepting them and later withdraw through Cookie Settings; withdrawal does not affect prior lawful processing.
Indicative storage inventory: cookieConsent, cookieConsentVersion, cookieConsentUpdatedAt and cookiePreferences record category choices until replaced or browser data is cleared; stocktag_locale stores language for up to one year; Firebase authentication storage lasts until logout, expiry or account/browser clearing; referral attribution normally lasts up to seven days; theme, layout, workflow, drafts, local history, chatbot and cache values last until their feature clears them, they expire, or you clear browser data. Exact Firebase, Google, Meta, Paddle, Cloudflare and Trustpilot identifiers can vary by browser and vendor configuration.
Analytics category: Google Analytics and a consent-gated Trustpilot widget may receive page/device/request information to measure use or render the requested widget. Advertising category: Google Ads and Meta Pixel/Conversions API may receive event time/type/value, URL, browser/IP and advertising identifiers; matching data can include normalized and hashed email, phone, name or external ID plus fbp/fbc. Hashing is a matching safeguard, not anonymization. External fonts, links or user-requested data sources can receive IP, user agent and referrer as part of an HTTP request even when they do not set a cookie.
11. Marketing and communications
Marketing enrollment is voluntary and off unless you make an affirmative choice where consent is required. We record the choice, time, source, locale and notice version needed to demonstrate it. You can withdraw in profile settings, through the unsubscribe link, or by contacting support. Withdrawal applies to future marketing and does not stop necessary security, transaction, subscription, service or legal notices.
Resend or another configured email provider processes recipient, message, attachment, delivery, bounce, complaint and unsubscribe data. In Türkiye, commercial electronic-message consent and rejection records are handled in accordance with applicable İYS requirements where the operator is in scope.
12. Recipients and service providers
A provider can be a processor, subprocessor or independent controller depending on the feature and contract. Vendor names and roles can change; material new uses are disclosed before processing where required. We do not sell personal data for money. Consent-based advertising disclosure may nevertheless be treated as “sharing,” targeted advertising or cross-context behavioral advertising under some laws, and the applicable opt-out is honored.
- Infrastructure, hosting, database, storage, authentication and security: Google Firebase/Google Cloud, Vercel, Cloudflare Turnstile, Google reCAPTCHA and related configured services.
- AI and generation: OpenAI, Google Gemini, Anthropic, Groq and xAI, depending on model, feature, plan and BYOK selection.
- Similarity, vector and search infrastructure: Qdrant and configured embedding/ML services; Jina or similar retrieval proxy where configured.
- Payments and tax: Paddle and its payment, fraud, tax and banking partners as merchant of record.
- Email and support: Resend and configured support-inbox or delivery services.
- Consent-based measurement and advertising: Google Analytics, Google Ads, Meta Pixel and Meta Conversions API; Trustpilot for the consent-gated review widget.
- Feature-requested external data: Nager.Date, Pixabay, Pexels, Unsplash, Wikimedia, Brave Search, Google Search/Suggest/Custom Search/Translate, SerpAPI and public stock-marketplace or search pages, including Adobe Stock, Shutterstock, iStock/Getty, Freepik, Depositphotos, Dreamstime and 123RF. A query, URL, image reference, IP or user agent can be sent as needed for the requested feature.
- Professional advisers, auditors, insurers, competent authorities, courts, regulators and a buyer or successor in a genuine corporate transaction, only as legally permitted and subject to appropriate confidentiality and safeguards.
13. International transfers
The Service is global and providers can process data in Türkiye, the United States, the EEA and other locations shown in their infrastructure documentation. For EEA/UK-restricted transfers, the operator must use an applicable adequacy decision, approved standard contractual clauses or another lawful mechanism and conduct supplementary transfer-risk review where required. For transfers from Türkiye, the operator must use a KVKK Article 9 mechanism such as an adequacy decision, an approved standard contract or another available safeguard and make required notifications.
This notice does not itself create a transfer safeguard or prove that a contract was filed. The operator must verify the actual data region, contracting entity and mechanism for every active provider before production transfer. You may request a copy or description of applicable safeguards, subject to lawful redactions, at support@stocktag.ai.
14. Retention and deletion
A legal hold, fraud investigation, security incident, court order or statutory duty can extend a stated period. Deletion from active systems can be followed by delayed deletion from encrypted backups. The operator must maintain and enforce an internal retention schedule with concrete maximum periods; vague or indefinite retention is not authorized by this notice.
- Account/profile and entitlement data: while the account is active, then for the period reasonably needed to complete deletion, resolve disputes, secure the Service and meet legal obligations.
- Paddle transaction, tax, accounting, refund and chargeback data: for the statutory period applicable to the merchant of record and operator, and while a claim, audit or payment dispute remains possible.
- Folders, processing history and associated cloud files: configured to expire after 30 days unless you delete them sooner or a feature clearly states a different period. Scheduled deletion must remove parent records, nested records and stored files; disaster-recovery copies can remain for a limited backup cycle and are isolated from ordinary use.
- Temporary AI/provider uploads and processing leases: for the request and short technical retry window, then deleted or allowed to expire; the selected provider may apply its own API retention.
- Encrypted BYOK keys: until you delete the key or the account is deleted, plus a limited protected-backup cycle. Provider-side copies/logs are controlled by your provider account.
- Public content: until you delete it, request removal, moderation removes it, or the community feature ends; a limited record may remain for legal, abuse-prevention or dispute purposes.
- Support and chatbot conversations, authorized staff replies and attachments: stored on Stocktag systems while the request is open and afterward for quality, security and applicable limitation periods; the separate local chatbot copy remains on the device until cleared.
- Marketing choices, consent and unsubscribe evidence: while marketing continues and afterward for the period needed to demonstrate compliance or defend a claim.
- Device/IP hashes, signup risk, referral and free-credit records: for the active abuse-prevention and claim period, then deleted or irreversibly de-identified. Raw request/rate-limit logs are kept for a shorter operational period where practicable.
- Activity, error and administrative logs: only for the operational, security, audit and cost-control period, after which they are deleted or aggregated/de-identified.
15. Security and incidents
Measures include HTTPS, managed authentication, role and access restrictions, secret separation, encrypted BYOK storage, rate limits, abuse controls, logging and provider security controls. Access is limited according to role and operational need. No system is risk-free, so do not submit data the feature does not need.
If a personal-data breach requires notice, affected people and competent authorities will be informed within applicable deadlines. Report a suspected vulnerability without including real user data or secrets to security@stocktag.ai.
16. Your choices and general rights
Some profile, cookie, newsletter, history and key controls are available in the Service. For access, portability, account deletion, objection, appeal or another request, contact support@stocktag.ai from the account email and describe the request. We may verify identity proportionately and may refuse or charge only where law permits for manifestly unfounded or excessive requests. Account cancellation, subscription cancellation, public-content removal and privacy deletion are different actions; specify which you want.
- Access and receive information about personal data and processing.
- Correct incomplete or inaccurate data.
- Request deletion, destruction, anonymization or restriction where legal conditions are met.
- Receive portable data where applicable.
- Object to processing based on legitimate interests or to direct marketing.
- Withdraw consent at any time as easily as it was given, without affecting earlier lawful processing.
- Opt out of qualifying sale, sharing or targeted advertising and use Global Privacy Control where legally applicable.
- Request human review and contest qualifying automated decisions.
- Complain to a competent data-protection authority and seek a lawful remedy without retaliation.
Send privacy requests to support@stocktag.ai. The complete controller postal and registered application channels must be added once the operator supplies them.
17. Türkiye (KVKK) notice
For people protected by Law No. 6698, data is collected by the automated and non-automated methods described above. The categories, purposes, legal grounds, recipients and transfer purposes are set out in Sections 3–13. Processing without explicit consent is limited to a condition in KVKK Article 5(2); separate explicit consent is requested when no such condition applies. An explicit-consent request is not bundled with this notice or the Terms.
Under KVKK Article 11 you may learn whether data is processed; request information; learn the purpose and whether data is used accordingly; know domestic or foreign recipients; request correction; request deletion or destruction under Article 7; request notification of correction/deletion to recipients; object to an adverse result arising exclusively from automated analysis; and claim compensation for damage caused by unlawful processing. A valid application is answered as soon as possible and no later than 30 days. The controller’s legally valid postal/KEP/registered-email application channels must be added with the operator identity in Section 1.
18. EEA and UK information
Where GDPR or UK GDPR applies, you have the rights described in Section 16 subject to statutory conditions, including a right to complain to the supervisory authority in your habitual residence, place of work or alleged infringement. If Stocktag is required to appoint an EEA/UK representative or data protection officer, those verified details must be added to Section 1.
Stocktag does not intentionally make a decision based solely on automated processing that produces legal or similarly significant effects beyond fraud/security eligibility controls described in Section 8. Where such a decision is in scope, safeguards include information about the logic and likely consequences, human intervention, expression of your view and contesting the result.
19. United States information
State privacy rights apply only when the relevant law and business thresholds cover Stocktag and the processing. Where they apply, residents may have rights to know/access, correct, delete, obtain portability, opt out of sale/sharing/targeted advertising or certain profiling, limit use of sensitive data, use an authorized agent and appeal a refusal, without discriminatory treatment. Stocktag honors a legally applicable browser Global Privacy Control signal for qualifying advertising disclosure.
Categories collected, sources, business purposes, recipient categories and retention criteria are described above. Stocktag does not knowingly sell or share personal data of people under 18 for targeted advertising. Submit a request or appeal to support@stocktag.ai.
20. Children
The Service is for adults who are at least 18 and have legal capacity to contract. Stocktag does not knowingly offer the Service to or collect personal data from children. If you believe a child supplied data, contact support@stocktag.ai so the account and data can be investigated and deleted as required.
21. Changes to this notice
We may update this notice for product, provider, legal or security changes. The revision date and material changes will be presented before the change takes effect where required, through the Service or an account email. A new purpose or consent-based use is not authorized merely by posting an updated notice; we provide a new notice and obtain consent where the law requires it.
22. Contact
Privacy, deletion, objection and complaint requests: support@stocktag.ai.