StableState
STABLESTATE
← Back to portal

Privacy Policy & Data Handling

Last updated: April 12, 2026Version 1.0StableState LLC

1. Overview

This Privacy Policy describes how StableState LLC ("StableState") collects, uses, and protects information when you use the IronFist AI platform at https://www.ironfistai.com. This policy also includes our Data Handling Policy, which details how your data flows through our infrastructure.

2. What We Collect

Account information: Email address, name, company name, billing address, and jurisdiction selection provided during sign-up.

Billing data: Payment information is processed and stored by Stripe. StableState does not store credit card numbers, bank account details, or other payment instruments.

Usage telemetry: Agent activity metrics (message count, tool invocations per day, error rates). This is operational metadata used for monitoring, circuit breaker enforcement, and billing validation. It does not include message content.

Onboarding selections: Your chosen PRP template, tier, communication channel type, and integration selections.

3. What We Do Not Access

StableState does not access, read, or store: your agent's memory (facts, episodes, procedures), the content of messages between you and your agent, your API key values at rest (stored encrypted in your dedicated Key Vault), your integration credentials at rest, your agent's outputs or generated content, or your LLM token usage (this is between you and Anthropic).

Your agent's data resides in your dedicated Cosmos DB instance and Key Vault. StableState's admin panel displays only operational metadata (agent status, health, resource utilization). It does not expose memory content, procedures, or credential values.

4. How We Use Data

Account information: to provision and manage your agent infrastructure, send service communications, and process billing. Usage telemetry: to enforce circuit breakers (daily operation caps, consecutive API failure thresholds), email rate limits, and browser abuse detection thresholds. We do not sell, rent, or share your data with third parties for marketing purposes.

5. Data Handling Policy

5.1 Data Residency

All infrastructure is deployed in Azure East US region. Your dedicated Cosmos DB, Key Vault, Storage Account, and Container App reside in this region.

5.2 Encryption

Data at rest: Azure-managed encryption (AES-256) on all storage services. Key Vault secrets are stored in FIPS 140-2 Level 2 validated hardware security modules. Data in transit: TLS 1.2+ on all connections.

5.3 Tenant Isolation

Each subscriber receives a dedicated Azure resource group containing isolated Cosmos DB, Key Vault, Storage Account, and Container App instances. Your agent's managed identity has RBAC access scoped exclusively to your resource group. No cross-tenant data access is possible.

5.4 Backup Operations

Daily automated backups of your Cosmos data to your dedicated blob storage. Backup operations run under your agent's own managed identity, not a shared backup identity. No cross-tenant backup access exists.

6. Retention & Deletion

Active subscription: your data is retained for the duration of your subscription. Cancellation: your data is retained for 30 days post-cancellation for export purposes. After 30 days, your resource group and all data are permanently deleted. Failed payment grace period: 14 days of suspended service with data access, followed by deletion.

Data deletion on churn is completed within 30 days of the retention window expiry.

7. Audit Logs

Your agent's actions are logged in a write-protected audit trail stored in your Cosmos DB. Audit log entries cannot be modified or deleted by you or your agent. You have read-only access via the dashboard and channel commands.

Retention by tier: Starter: 90 days. Professional: 180 days. Business and Enterprise: 365 days. Logs are automatically purged after the retention period via Cosmos TTL policies.

8. Sub-Processors

StableState uses the following sub-processors to deliver the Platform:

Note on Browserbase: Browserbase is a client-direct relationship. You provide your own Browserbase API key. StableState does not act as an intermediary for Browserbase services and it is not a StableState sub-processor.

9. Your Rights

You may export your agent data (memory, procedures, episodes) at any time via the dashboard. You may request account deletion by contacting [email protected]. You may request a copy of the personal data we hold about you.

10. CCPA Notice (California Residents)

If you are a California resident, you have the right to know what personal information we collect, request deletion of your personal information, opt out of any sale of personal information (we do not sell personal information), and not be discriminated against for exercising these rights. To exercise these rights, contact [email protected].

11. GDPR Notice (EU/EEA Residents)

If you are located in the EU or EEA, StableState acts as a data processor on your behalf. The Data Processing Agreement governs this relationship. You have rights under GDPR including access, rectification, erasure, restriction, portability, and objection. Contact [email protected] to exercise these rights. Our legal basis for processing is contractual necessity (performance of the service contract) and legitimate interests (operating and securing the Platform).

12. Changes to This Policy

We may update this Privacy Policy with 30 days' notice via email. Continued use after the notice period constitutes acceptance.

Questions about this document?

Contact us at contact@stablestateit.com

Visit https://www.stablestateit.com for general inquiries and our contact form.

Powered by StableState  |  stablestateit.com  |  ironfistai.com
Patent pending - US Application 19/638,025