Privacy Policy
Last updated: July 11, 2026
01
WHO CONTROLS YOUR DATA
This Privacy Policy explains how Matěj Balcar, doing business as Stemwire, with address at Jižní 315, Stěžery, Czech Republic, IČO: 19840829 ("Stemwire", "we", "us" or "our"), processes personal data when you visit our website, download an audio plugin, contact us or use Stemwire Operations.
Stemwire is the data controller for the processing described here. Polar separately controls personal data it collects to operate checkout and act as merchant of record.
02
DATA WE PROCESS
Depending on how you use Stemwire, we may process:
- website and download data, including IP address, browser and device information, requested page or file, referring page, timestamps and security logs;
- Operations account data, including name, email address, workspace, role, authentication and subscription status;
- Operations content and activity, including files and records you upload, settings, feature use and audit information;
- transaction data received from Polar, including customer and order identifiers, product, amount, currency, tax and refund or subscription status;
- support and contact data, including your email address, messages, attachments and our replies;
- security and diagnostic data, including rate-limit events, error details and information needed to investigate abuse or failures; and
- consent and measurement data from cookies, Meta Pixel or similar tools, where enabled and permitted.
We do not receive or store full payment card numbers. Polar and its payment providers process payment credentials.
A Plugin may process technical data only as described on its product page or in information supplied with it. Material telemetry, online activation or similar behaviour will be disclosed before download where applicable.
03
WHY WE PROCESS DATA
We process personal data:
- to provide requested pages and downloads and to perform our contract with you;
- to create, authenticate and administer Operations accounts and subscriptions;
- to receive transaction status, deliver purchased products, handle support, refunds and consumer claims, and keep required financial records;
- to secure Stemwire, prevent abuse, diagnose failures and improve reliability, based on our legitimate interests in operating and protecting the products;
- to comply with tax, accounting, consumer-protection and other legal duties;
- to reply to messages and send necessary product, account, security or legal notices; and
- with your consent, to use non-essential cookies or measurement and marketing tools.
Where we rely on consent, you may withdraw it for future processing at any time. We do not sell personal data.
04
POLAR CHECKOUT
Polar acts as merchant of record and authorised reseller for transactions completed through Polar Checkout. Polar collects checkout, payment, billing and tax information under its own Privacy Policy and Buyer Terms. Polar shares limited customer, order and entitlement data with Stemwire so we can identify the product, deliver it, provide support and reconcile transactions.
05
SERVICE PROVIDERS AND OTHER RECIPIENTS
We use providers that help us run Stemwire, including:
- Polar for checkout, orders, subscriptions, invoices, tax and refunds;
- Supabase for database, authentication, storage and backend infrastructure;
- Cloudflare for hosting, content delivery, downloads, DNS and security;
- Resend for transactional email;
- Sentry for error monitoring and diagnostics;
- Google reCAPTCHA for abuse prevention;
- Meta Platforms for measurement and attribution where Meta Pixel is enabled with the required consent; and
- Stripe where a customer connects Stripe to an Operations feature.
Providers may process data only for their contracted role or as otherwise permitted by law. We may also disclose data where required by law, to respond to lawful authorities, to establish or defend legal claims, or to protect people, rights and systems.
06
INTERNATIONAL TRANSFERS
Some providers may process data outside the European Economic Area, including in the United States. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses or another lawful transfer mechanism. Contact us for more information about safeguards relevant to your data.
07
RETENTION
We keep personal data only as long as needed for the purposes above:
- website, download, security and diagnostic logs are kept for a limited period appropriate to security and troubleshooting;
- Operations account and workspace data is normally kept while the account is active and may be deleted 60 days after cancellation, termination or a deletion request;
- contact and support records are kept while the request is active and afterwards where reasonably needed for follow-up or legal claims; and
- transaction, invoice, tax and accounting records are kept for the period required by law.
We may keep specific records longer where necessary for fraud prevention, security, a dispute, a legal claim or compliance with law. Backup copies may remain until the relevant backup cycle expires.
08
COOKIES AND SIMILAR TECHNOLOGIES
We use essential cookies and similar storage for authentication, security, consent choices and basic site operation. Where required by law, non-essential measurement or marketing tools are disabled until you consent. You can change your choice through the cookie settings available on the website.
09
YOUR RIGHTS
Subject to applicable law, you may ask us to:
- give you access to your personal data;
- correct inaccurate or incomplete data;
- delete data;
- restrict processing;
- provide portable data where portability applies; or
- stop processing based on legitimate interests.
You may withdraw consent where processing is based on consent. You may also complain to a data protection authority. In the Czech Republic, the authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů): https://uoou.gov.cz/
Send requests to hello@stemwire.io. We may need to verify your identity before completing a request.
10
REQUIRED DATA AND AUTOMATED DECISIONS
If you do not provide data needed for an account, checkout, support request or security check, we may be unable to provide that part of Stemwire.
Stemwire does not use solely automated decisions that produce legal or similarly significant effects on you within the meaning of GDPR Article 22. Polar or payment providers may use automated fraud-prevention checks under their own policies.
11
SECURITY
We use technical and organisational measures intended to protect personal data. No internet or storage system is completely secure, so we cannot guarantee absolute security. Please protect your account credentials and tell us promptly if you suspect unauthorised access.
12
CHANGES AND CONTACT
We may update this policy when our products, providers or legal duties change. We will post the new version and its date. We will give a more prominent notice where a change materially affects how we use personal data.
For privacy questions, rights requests or complaints, contact: