Privacy Policy
Effective: March 25, 2026
This Privacy Policy (hereinafter referred to as "this Policy") is established by Stima AI, LLC. (hereinafter referred to as "Stima AI") and applies to Apertis official website, StimaChat conversation service, Playground, Stima Legal Judgment Document Information Retrieval System (LJDIR-TW) and related services (hereinafter collectively referred to as "the Service"). This Policy explains how we collect, use, protect, and disclose your personal data.
Please read this Policy carefully before using the Service. If you do not agree with any part of this Policy, please stop using the Service immediately. Your continued use of the Service indicates your agreement to the contents of this Policy.
1. Scope of Application
This Policy applies to:
- Users browsing the Apertis official website;
- Users of StimaChat, Playground, Legal Judgment Document Information Retrieval System, and other API authorization services;
- Personal data provided or generated through the above platforms (including usage records and other data);
- Users under eighteen years of age (requires consent from legal representatives).
This Policy does not apply to third-party websites and services not operated or controlled by Stima AI.
2. Purpose and Items of Data Collection
(1) Types of Personal Data We May Collect:
- Personally identifiable information: name, address, contact information, email, account information, electronic signature, Billing ID, etc.;
- Usage records: device IP, browsing behavior, click records, usage time, browser used, etc.;
- Additional provided data: user feedback, questionnaires, technical consultations, customer service contact records, etc.
We do not actively collect any "sensitive personal data".
(2) Collection Purposes Include but Are Not Limited to:
- Providing and improving Service functions and experience;
- Establishing and maintaining user accounts and payment channels;
- Processing and analyzing usage patterns, diagnosing technical issues;
- Marketing promotion, event notifications, and customer service communication;
- Complying with legal requirements and regulatory authorities' instructions.
3. Data Processing Methods and Sharing Principles
(1) Period and Region of Use
Your personal data will be retained during the period Stima AI provides the Service and may be processed and utilized in areas where we actually provide services.
(2) Data Protection and Storage
We implement security measures aligned with industry best practices, including OWASP Top 10 guidelines and the NIST Cybersecurity Framework:
- Full TLS/SSL encryption for transmission;
- Regular security audits;
- Continuous monitoring and threat detection;
- Role-based access controls;
- Payment processing handled by PCI DSS Level 1 certified provider (Stripe).
For personal data of children and adolescents, we take additional protective measures, including but not limited to:
- Restricting access to such data
- Implementing anonymization
- Strictly reviewing data usage scope
(3) Third-Party Sharing Principles
Except for the following circumstances, we will not provide your personal data to third parties without your written consent:
- When necessary to provide you with services;
- Cooperation with service providers who must comply with equivalent privacy standards;
- Sharing information required for payment processing with payment service providers ("Stripe"), including but not limited to your payment information and order details;
- Data used for statistics, research, development, and other non-identifying purposes after de-identification;
- Legal requirements or cooperation with judicial and government authorities;
- To protect your or others' life, freedom, or property rights;
- When necessary for identification, contact, or legal action when users violate terms of use or infringe on others' rights;
- Providing additional protection for children and adolescents' data, strictly limiting purposes and access scope in accordance with applicable law.
4. Cookies and Tracking Technologies
We use Cookies to improve service quality and user experience, including but not limited to usage analysis, advertising tracking, and user preference storage.
You can refuse Cookies through browser settings, but some functions may not work properly as a result.
5. Protection of Children and Adolescents' Personal Data
We comply with applicable child protection laws and implement the following additional protective measures for users under eighteen:
- Restricting access to such data;
- Implementing anonymization;
- Strictly limiting data usage scope;
- No collection, use, or disclosure without legal representative consent.
If you are a legal representative and discover unauthorized data provision, please contact us immediately, and we will assist in deleting such data.
If we become aware that we have collected personal information from a user under the age of 18, we will promptly delete such information and terminate the associated account.
6. User Rights
You may exercise the following rights under applicable data protection laws:
- Query or request to review personal data;
- Request copies;
- Request supplements or corrections;
- Request to stop collection, processing, or use;
- Request data deletion.
You can submit applications through the "Contact Us" section of this website or customer service hotline.
We may require you to provide identification documents for identity verification. Data access and deletion requests are provided free of charge.
If you refuse to provide or request deletion of data, we may be unable to continue providing the Service.
7. Account and Password Security
If you log in to the service using an account and password, you should properly maintain such information.
Stima AI is not responsible for personal data leakage caused by your negligence resulting in account compromise.
8. Third-Party Links
The Service may contain links to third-party websites or services, which are not bound by this Policy.
Please review their privacy policies before use, especially when children and adolescents are using such services.
9. Policy Updates and Notifications
We may update this Policy due to regulatory changes or business needs and will post it on this website.
We will provide separate notification for significant changes.
If you do not raise objections or continue to use the Service within seven (7) days after notification, you are deemed to have agreed to the updated content.
10. Contact Information
If you have any questions about this Policy or personal data processing, please contact us:
- Email: hi@apertis.ai
- Phone: +1 814-731-3793
11. Governing Law and Dispute Resolution
This Policy is governed by the laws of the State of Wyoming, United States, and shall be interpreted and applied in accordance with the laws of the State of Wyoming.
Any disputes arising from this Policy or the Service shall be resolved through good-faith negotiation between the parties.
If negotiations fail within thirty (30) days, both parties agree that the Sheridan County, Wyoming, United States, court shall have jurisdiction as the court of first instance.
12. Data Retention and Deletion
- Account information: Retained for the duration of your account. When you delete your account, all personal data is immediately and permanently removed through a cascade deletion process. API keys are deleted, usage logs are anonymized (statistical data preserved without personal identifiers), and feedback content is removed.
- Prompt and response content: Retained for 30 days, then automatically deleted.
- API usage logs: Personal identifiers (username, token name, user agent) are automatically anonymized after 12 months. Anonymized statistical data (model used, token counts, quota) is retained for billing audit purposes.
- Payment records: Retained as required by applicable tax and accounting laws. Stripe processes and retains payment data under its own privacy policy.
- Support records: Retained for 1 year after resolution of the inquiry.
13. Data Controller and Subprocessors
Stima AI, LLC. is the data controller for personal data collected through the Service.
We may share data with the following subprocessors:
- AI Model Providers — OpenAI, Anthropic, Google (Gemini/Vertex AI), Amazon Web Services (Bedrock), Microsoft Azure, Alibaba Cloud, Baidu, Tencent, Cohere, Cloudflare Workers AI, DeepL, Zhipu AI, and other providers as listed on our models page — API request processing
- Payment Processors — Stripe, Inc. (payment processing)
- Infrastructure — Google Cloud Platform (compute hosting), Cloudflare, Inc. (CDN, DNS, security), Supabase (database hosting)
- Authentication — GitHub, Google, and Apple (OAuth single sign-on)
For enterprise customers, we offer a Data Processing Agreement (DPA) upon request. Please contact us at hi@apertis.ai to obtain a copy.
14. GDPR, California, and International Rights
European Economic Area (GDPR): If you are located in the EEA, we process your personal data based on the following legal grounds: (a) contract performance — to provide the Service you signed up for; (b) legitimate interests — to improve our services, prevent fraud, and ensure security; (c) consent — where you have given explicit consent. You have the right to access, rectify, erase, restrict processing, data portability, and object to processing. You may also lodge a complaint with your local data protection authority. To exercise these rights, contact hi@apertis.ai.
California residents (CCPA): We do not sell your personal information. Under the California Consumer Privacy Act, you have the right to access, delete, and opt out.
International data transfers: Your data is stored and processed in the United States. For transfers from the EEA, we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms to ensure adequate protection of your data. By using the Service, you acknowledge that your data may be transferred to and processed in the United States.
Nothing in this Policy shall affect your statutory rights under applicable data protection laws that cannot be waived by contract.
15. HIPAA Compliance & Verbatim Product
Apertis Verbatim, operated by Stima AI, LLC., is a HIPAA Business Associate service for healthcare-adjacent and legal-medical use cases that involve Protected Health Information (PHI) as defined in 45 CFR §160.103.
Stima AI, LLC. has executed Business Associate Agreements (BAAs) with the following infrastructure providers as of 2026-05-19, all of which may process or transit PHI on behalf of Stima AI, LLC.'s Verbatim customers:
- Google Workspace and Cloud Identity (HIPAA BAA v3.9)
- Google Cloud Platform — Compute Engine, Cloud Storage, Cloud SQL, and related HIPAA-eligible services (HIPAA BAA)
- Amazon Web Services — Bedrock, S3, EC2, RDS, SES, and related HIPAA-eligible services (HIPAA BAA)
Stripe payment processing is intentionally outside the HIPAA BAA scope. Stripe does not sign HIPAA Business Associate Agreements; in line with Stripe's published policy, Stima AI, LLC. uses Stripe solely for subscription billing and excludes Protected Health Information (PHI) from all Stripe data fields including customer name, email, billing address, payment metadata, transaction description, and statement descriptor. PHI does not transit Stripe systems.
A countersigned copy of the Stima AI, LLC. BAA is available to qualified Covered Entities and Business Associates upon request via hi@apertis.ai.
Stima AI, LLC. has designated Yu-Ting Lee (also known as Leo Lee) as HIPAA Security Officer and Privacy Officer pursuant to 45 CFR §164.308(a)(2) and 45 CFR §164.530(a)(1). Inquiries related to PHI handling, breach notification, or BAA requests should be directed to security@apertis.ai.
This section applies only to Apertis Verbatim. Other Stima AI, LLC. products (including the general Apertis API platform and StimaChat) do not currently operate under a HIPAA BAA and must not be used to process PHI.