Beta privacy · Version beta-4

How Stormpine handles your data

A plain-language notice for the Stormpine beta, including Google integrations, AI-assisted analysis, feedback, product usage records, retention, and your rights.

Operator
Stormpine ApS
Contact address
Lærkevej 25, 4300 Holbæk
Privacy email
info@stormpine.com
Last updated
14 August 2026

Who is responsible

For workspace CRM content, the workspace owner is the controller. Stormpine processes that workspace CRM content on the owner's instructions. Stormpine ApS is the controller for account administration, service operations, its own security and support records, and its own product usage records. Stormpine ApS is the controller for the separate collection of Google Calendar data through the connection and its operation of that connection. Once eligible Calendar metadata becomes workspace CRM content, the workspace owner is its controller and Stormpine processes it on the owner's instructions.

What Stormpine stores for you

Stormpine stores the information you put into your workspace, including opportunities, people, organizations, notes, tasks, documents, and assessment answers. Your workspace content is used to provide Stormpine to you. Other workspaces cannot see it.

Gmail

If you connect Gmail, Stormpine stores message metadata from sent mail—senders, recipients, dates, and subject lines—to keep relationship timelines current. It does not read or store message bodies or attachments.

Google Calendar

Google grants Stormpine read-only event access to calendars you own. Stormpine requests events only from your primary calendar. Stormpine stores Google's event ID, title, time, recurrence, privacy setting, and links to matching Contacts.

To match meetings and discover potential relationships, Stormpine checks eligible attendee email addresses and their firm domains, excluding you, meeting rooms, and declined attendees. An unknown firm domain may appear in New relationships. Until a workspace owner chooses Add, Stormpine does not create a Contact or show a meeting based only on that domain. Stormpine stores the candidate domain and the Add or Ignore decision so that choice applies to later events. Add lets Stormpine create a minimal Contact from an eligible attendee email and match eligible meetings; Ignore stops the domain from resurfacing. Descriptions, locations, conference links, attachments, and other event details beyond those listed above are not imported.

Every active member of the workspace can see synced event titles, times, and matched Contacts. Private or confidential events are not shown or newly imported.

When an eligible event later becomes private, confidential, or otherwise ineligible, Stormpine removes its title and contact matches from the workspace. It keeps the Google event ID, time, recurrence, privacy setting, and a record of removed contact matches in its database and recovery backups so retries and reconnects cannot create old or duplicate meetings.

Why Stormpine processes data

Account administration and service operations are processed to provide the service under the contract with you. Gmail is processed on the basis of your consent, given through a separate affirmative connect action. Stormpine relies on your consent for the Calendar collection and connection leg. That is the connected member's consent, not consent from other attendees. The workspace owner is responsible for the lawful basis for subsequent use of synced Calendar metadata as workspace CRM content. Disconnecting stops future Calendar collection and withdraws that consent for the future. Minimal connection and reconciliation state described below remains after disconnect; Stormpine has not established a separate basis and retention period for that residual state, and Calendar remains disabled until those points and the attendee-data basis are resolved.

For AI-assisted pursuit assessment, AI-assisted conversation preparation, the AI-assisted CV-vs-brief comparison, AI-assisted CV wording drafting, the AI-assisted focused requirement re-check, AI-assisted CV extraction, and AI-assisted Profile rubric drafting, the workspace owner relies on legitimate interests under GDPR Article 6(1)(f). The workspace owner's legitimate interests are analyzing deliberately selected opportunities, preparing for deliberately chosen interviews using the professional context already held in the workspace, examining a deliberately selected outgoing application packet against selected gate context, acting on that comparison through reviewable CV wording proposals and a scoped re-check, reducing manual transcription of a deliberately uploaded CV into a reviewable Profile proposal, and turning deliberately typed notes into reviewable proposals for the executive's standing assessment criteria. Feedback and support correspondence, service security, and the minimal records needed to operate a small beta rest on Stormpine's legitimate interests in supporting users and running the service responsibly. You may object to processing based on legitimate interests.

AI-assisted analysis

When you deliberately use an AI feature, Anthropic Ireland, Limited processes the data described below for that feature.

The current interface exposes Prepare HR questions, Prepare technical questions, the CV-vs-brief comparison and its per-requirement drafting and re-check actions, CV extraction, and the Profile rubric draft assist as controls that start new AI provider work. Pursuit assessment remains a governed capability and retained history, but no current product control starts a new assessment.

Pursuit assessment

Pursuit assessment uses only the specific, pre-approved workspace information described below.

For a pursuit assessment, the selected pursuit's pre-approved fields may be processed even when the pursuit itself is marked Confidential.

The assessment may also use a composed Profile view drawn from the workspace executive's saved Career Record, together with specific shared Profile fields and the selected Profile Lens—not the whole Career Record. This can include relevant career evidence and skills; shared fields for current title, location, languages, professional presence, strengths, weaknesses, and the executive's standing assessment criteria (positioning angle, what they are looking for, must-haves, red flags, and grounding notes); and the selected Lens's name, headline, statement, target-audience labels, and emphasis labels.

Related interactions, stakeholders, tasks, and stage notes marked Confidential are excluded, as are protected strategy fields.

Names entered in a person's name fields are replaced with aliases before they are sent for AI processing.

Names or other personal information written in notes or other text may still be processed when that text is needed for the feature.

The assessment receives dismissal-status metadata: the exact count of earlier AI action suggestions recorded as dismissed that remain eligible for that pursuit. When the selected pursuit is Confidential, it may additionally receive prior AI-generated output—the titles of up to 10 of the most recently dismissed eligible suggestions.

Stormpine stores the validated assessment and suggested actions as workspace product data. It also retains an audit receipt containing the exact authorized provider request, including the system instructions, serialized assessment context, and output schema, together with run and cost records. Deleting the opportunity removes the stored assessment and action outputs and detaches the live run links, but the receipt and run/cost record—including the deleted opportunity identifier and serialized request context—remain until the workspace is deleted.

Conversation Prep

AI-assisted conversation preparation for HR interviews and AI-assisted conversation preparation for technical interviews run only when you choose the matching Prep action.

The request may use the selected opportunity's title, type, priority, organization, pipeline stage, source label, and milestone even when opportunity details are Confidential. Positioning, strategy notes, and compensation are not sent when those details are Confidential. The request may also use the selected opportunity Lens and composed Profile context drawn from the Career Record, which may include current title, location, languages, professional presence, strengths, the executive's standing assessment criteria (positioning angle, what they are looking for, must-haves, red flags, and grounding notes), selected Lens fields, selected positions and achievements, and skills, but excludes Profile weaknesses; and up to 10 recent non-Confidential, non-voided interactions.

For those interactions, dates, types, channels, summaries recorded on Manual interactions, and interaction notes may be sent. Only summaries recorded on Manual interactions are sent; Gmail-generated interaction summaries are excluded. Interaction notes may be sent as neutral, user-authored context. They are not assumed to be debriefs, transcripts, verbatim statements, or evidence.

It also adds general interview knowledge for the interview type you chose. Stormpine does not infer the interview type. It does not fetch or attach uploaded job-brief file bytes, linked Notes, Gmail message bodies, or original transcript or email artifacts for this feature. Free text you enter in included opportunity fields, summaries recorded on Manual interactions, or interaction notes may itself contain copied material and will be sent as authored context.

Request-local source IDs record which sent context the model linked to a passage. Stormpine checks those IDs against the sent source list, but this shows source linkage only: it does not prove that the linked context entails, evidences, or grounds the generated wording.

Stormpine stores the generated questions, rationale, and preparation points as workspace product data for the selected opportunity. It also stores a bounded run receipt with the job, model, opportunity and selected Lens identity, input hash and selection fingerprint, work generation, time-zone and visibility metadata, and a source manifest of IDs, kinds, and labels.

The current receipt does not store the provider request, prompts, schema wording, or the source text itself. If a legacy version-1 Conversation Prep receipt contains a top-level provider request, the database removes that request when an existing retained opportunity or work link changes from non-null to null. The same transition clears the stored generated preparation. Portable CSV restore removes a legacy top-level provider request from incoming Conversation Prep receipts. It also removes that request from a same-ID live Conversation Prep receipt when the restore keeps the live row. Receipt sanitation does not alter otherwise-admissible output or usage/cost records.

A validated portable restore may import a result with its work link already absent. The saved preparation may remain visible, but an explicit matching Prep action must revalidate and reattach it before Stormpine treats it as current for reuse.

Deleting the opportunity detaches both links. The remaining run record retains its bounded receipt—including the opportunity identifier, selected Lens identity, and source labels—and its usage/cost records until the workspace is deleted.

CV vs. brief

The AI-assisted CV-vs-brief comparison runs only when you choose Compare Lens with brief, or run a check again, on a selected opportunity. It requires a bound Lens and at least one selected gate-context source. A title or application URL alone is not gate context.

The request may use the selected opportunity's title and organization name, the bound Lens and composed outbound Profile context drawn from the Career Record, career-record evidence that is not on that Lens, and only the gate-context sources you selected: opportunity-document titles and notes, linked Note text, or pasted posting or recruiter text. You may optionally add an application URL so Stormpine can identify the application system. Stormpine does not open, submit, or fetch that URL. The raw URL is not sent to the model. It excludes Profile weaknesses, the executive's standing assessment criteria, unselected documents, raw document file bytes, unrelated contacts, conversations, and notes, and any actual outgoing PDF parse.

Stormpine stores the generated requirement review as workspace product data for the selected opportunity. It also stores a bounded run receipt with the job, model, opportunity and selected Lens identity, input hash, selection and career-record fingerprints, work generation, time-zone and visibility metadata, the selected source identities, and, for pasted posting text, that pasted text so a later resume can rebuild the same input. A current receipt may also keep a normalised application URL and the processing-system and rule snapshots used for that report. The receipt does not store document file bytes, the provider request, or prompts. Deleting the opportunity detaches the live run links. The remaining run record retains its bounded receipt and usage/cost records until the workspace is deleted.

Acting on a comparison

The AI-assisted CV wording drafting runs only when you choose Draft the change, Continue after answering its factual question, or Draft wording on a requirement in the comparison report. For Draft the change and Continue, the request carries that one requirement (its brief excerpt, explanation, and suggested move), the cited Career Record evidence rows at their current text, the bound Lens name, and, where you typed one, your answer; if a truthful draft would need a fact your record does not hold, it asks one factual question instead of guessing. When you phrase a fact of your own for a position you choose, the request carries only your typed fact — no requirement, no evidence rows, no Lens name, no position details — and wording that provably changes your fact's meaning — a new or re-bound number, a dropped negation, or an ownership, leadership, or scope claim your fact does not make — is rejected rather than shown, and every other substantive word you did not type is highlighted. Mentat's wording is never added directly, with or without highlights: you first make it your own statement — which you can edit — and the ordinary Add as written performs the save. Proposals return to your browser for review; nothing is saved until you accept — an accepted proposal becomes part of your Career Record or this CV only through the ordinary Profile save, and you can edit it first. Stormpine stores no per-run draft output; it retains limited run, cost, and error records.

The AI-assisted focused requirement re-check runs only when you choose Check this requirement after your Career Record changed. It re-judges the named requirements from the latest comparison against the relevant Career Record evidence rows at their current text; it does not re-send the brief sources and can only carry, never newly assert, a whole-record absence. Stormpine stores the scoped result with a bounded receipt naming the parent report, the requirements checked, and the exact evidence slice sent, so the product can show deterministically whether that check still describes your current record. The full report keeps showing the original comparison, and a new full comparison stays available.

CV extraction

For AI-assisted CV extraction, the entire PDF you choose—up to 8 MB—is sent to Anthropic to transcribe it into a structured Profile proposal. You can upload a CV, or export your own LinkedIn profile as a PDF and upload that; Stormpine has no connection to LinkedIn and never fetches anything from it, so the export is something you perform and hand over yourself.

The PDF can contain ordinary names, contact details, work and education history, achievements, skills, and other personal information included in the file. What comes back and is saved is your headline, your positions, your education and your skills. Every one of those is free text taken from the document's own wording, so whatever your document states in them is saved with them. Positions are recorded as your document states them, and that includes board seats, non-executive directorships, trusteeships, advisory roles and volunteer positions: if one of those is with a religious, political, trade-union or health-related organisation, that affiliation is saved as part of your career history. Stormpine does not ask you to certify what is in the file, because a document is sent whole and Stormpine cannot inspect it for you first. If you would rather a detail were not sent at all, remove it from the document before uploading, or add positions by hand instead. Declining a row during review keeps it out of your Career Record, but Stormpine still records what the document said for it in a comparison record, so the same row is not proposed again on your next upload. Deleting the whole workspace removes that comparison record from the live product; recovery copies remain only until Railway's configured retention period ends or, for restricted manual backups, until each backup's recorded deletion date. Stormpine sends no other workspace content with that request and does not store the PDF. It stores a document hash and limited run, cost, and error records, and holds the structured extraction with that run record until you resolve the review.

The structured extraction is held until you review it, so a review you started is still waiting for you if you close the page or come back later; accepting or discarding it erases that stored copy. The Career Record and derived reconciliation record—including the no-change baseline used when comparing future uploads—are saved only after you choose the Profile review's confirmation action.

Profile rubric drafting

For AI-assisted Profile rubric drafting, the notes you type into the draft panel and the current contents of the five What Mentat judges against fields—positioning angle, what the executive is looking for, must-haves, red flags, and grounding notes—are sent to Anthropic to propose improved field texts. It runs only when you choose the draft action, and no other workspace content joins the request.

Those fields and your notes are candid by design: they can state personal views, preferences, and concerns in your own words, and the proposals restate them—that is the feature's purpose. Where the draft deliberately departs from your wording—for example replacing a nationality- or group-based description with the specific behaviour it stood for—it says so in a short note shown with the proposals.

The proposals return to your browser for review. Nothing is saved until you accept a proposal, field by field, through the ordinary Profile save. Stormpine stores no per-run draft output; it retains limited run, cost, and error records.

Anthropic retention

Anthropic does not use this content to train its models.

For these API calls, Anthropic automatically deletes inputs and outputs from its backend within 30 days of receipt or generation, except when a service has longer retention under Stormpine's control, Stormpine and Anthropic have agreed otherwise, Anthropic needs longer retention to enforce its Usage Policy, or law requires retention.

Stormpine does not use Anthropic's Files API for these features and has not agreed a different retention period.

If Anthropic's automated trust and safety systems flag a request as violating its Usage Policy, Anthropic may retain the inputs and outputs for up to two years and trust-and-safety classification scores for up to seven years.

If Stormpine's contract permits it, Anthropic may anonymize organization data for research or statistical purposes and retain that anonymized information for longer; this repository does not document a contractual exclusion of that permission.

What Kamran can see

At Stormpine's current size, Kamran can see the basic account information needed to operate the service, such as the workspace, active seats, billing status, and Google connection health. That operator view does not open people, notes, documents, email subjects, Calendar titles, or other workspace content.

When you deliberately use Message Kamran, he can see that message and the coarse product area shown before you send.

Product usage records

Stormpine records a short, fixed list of core product gestures together with the workspace and time. Examples include creating a pursuit, logging an interaction, completing a task, or searching. These records contain no member identifier, names, titles, notes, search terms, page addresses, or other workspace content. In a workspace with one member, the workspace and time may still make it possible to infer who acted. Kamran can see workspace-level counts for the previous 7 and 30 days. Stormpine does not collect page views, session recordings, or a member-by-member activity history.

Google access and Limited Use

Gmail and Calendar use access to the same Google account. Disconnecting one feature may leave in place the Google access the other still needs, while removing Stormpine in Google Account permissions interrupts both. Stormpine removes its stored access to the Google account only when no connected Gmail or Calendar feature still needs it.

Stormpine's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Stormpine does not sell Google user data, use it for advertising, or use it to train general-purpose AI models.

Messages and error reports

Notes sent through Message Kamran, including error reports, are stored in an inbox accessible only to Stormpine's administrator. Stormpine may also send a feedback email to Kamran after saving your message; Resend delivers that email. It includes your message, signed-in email address as the reply address, workspace identifier, and workspace status. It does not include the broad product area, exact page, URL, record name, page contents, error reference, or message identifier. Messages are kept until Kamran has addressed them, then for 90 more days. Stormpine keeps only the workspace and time of its first message—not the message or sender—while the workspace exists so the Say hello step does not become incomplete when a message is deleted. Workspace erasure removes that marker.

Choosing Error report sends only what you type and the broad area shown beside it. Stormpine does not currently attach an error ID. Any future error-screen link or prefilled reference requires separate product and privacy review before it is enabled.

Who else processes data

Railway hosts the application, database, and recovery copies. Production document upload presigning is enabled only when Stormpine has verified the configured Cloudflare R2 endpoint, account DPA, bucket location, lifecycle and lock posture and recorded the explicit production approval required by the upload path. Without both the approved Cloudflare endpoint and exact approval, new uploads fail closed. When enabled, Cloudflare R2 stores uploaded document files. Resend delivers mandatory transactional emails for sign-in, workspace invitations and provisioning, billing, and workspace deletion review and lifecycle notices, plus the feedback emails described above. Anthropic Ireland, Limited processes only the data described above for each AI feature. Google supplies Gmail and Calendar data only after the relevant connection is authorized.

Stormpine uses no analytics company, advertising technology, or session-recording service. Document uploads use presigned object-storage requests and do not load storage-provider scripts inside the app.

Retention and deletion

Workspace content is kept until you delete it or the workspace is deleted. Gmail disconnect stops future logging; previously logged email relationship history remains in the workspace until it is deleted with the rest of the workspace.

Ordinary document removal clears the live product's file reference and then attempts object deletion. That object-store deletion is currently best-effort: a failed delete has no durable retry record and the object can remain until operator or whole-workspace cleanup. The whole-workspace erasure path uses a separate protected cleanup process. This residual deletion risk remains unless the approved storage posture provides an equivalent control or Stormpine adds durable cleanup retries.

Core product gesture records are kept for the workspace lifetime. Deleting the whole workspace removes them from the live product. Recovery copies remain only until Railway's configured retention period ends or, for restricted manual backups, until each backup's recorded deletion date, as described in Stormpine's backup schedule.

Disconnecting Calendar immediately hides synced meetings and removes their titles and contact matches from the workspace. Stormpine keeps the Google event ID, time, recurrence, privacy setting, and a record of removed contact matches in its database and recovery backups so retries and reconnects cannot duplicate or restore old events. If a synced Google Calendar meeting is manually cancelled in Stormpine, it stays hidden, but its last stored event ID, title, time, recurrence, privacy setting, and contact matches remain in the database and recovery backups.

There is no Calendar-only way to remove those records from Stormpine's live product. Deleting the whole Stormpine workspace removes them from the live product. Recovery copies remain only until Railway's configured retention period ends or, for restricted manual backups, until each backup's recorded deletion date, as described in Stormpine's backup schedule.

The Google integrations data guide explains the controls, the records kept after disconnect, and the whole-workspace erasure path.

Your rights

You can ask for access, correction, deletion, restriction, or export of your personal data; object to processing based on legitimate interests; or withdraw Google consent for the future. Requests about workspace CRM content should go to the workspace owner, who is its controller. If you do not know who the workspace owner is, or send the request to Stormpine, Stormpine will help route the request and assist the owner as processor. For personal data Stormpine controls—including Google Calendar collection and connection records, account administration, service operations, security, support, and product usage records—contact info@stormpine.com or use Message Kamran. The relevant controller may need to verify your identity before acting and will respond without undue delay, normally within one month.

You may also complain to Datatilsynet, the Danish Data Protection Agency.