Statohm / data note
Privacy Policy
Product-ready draft: This plain-language policy describes the current Statohm product direction. It is not legal advice and should be reviewed against the operator’s actual entity, vendors, retention periods, international transfers, and applicable privacy law before final publication.
1. What this policy covers
This policy explains how the Statohm service may collect, use, store, and share information when you visit the website, create an account, use the workspace, connect a data source, upload documents, or contact us.
“Statohm,” “we,” “us,” and “our” refer to the operator of the service. “You” means the individual user; “your organization” means the customer company or team that controls the workspace.
2. Information we handle
Account information
We may handle your name, work email, password authentication record, role, company name, account identifiers, and preferences.
Operational and financial information
We may handle well records, EDR or CSV data, daily drilling reports, field tickets, invoices, emails, attachments, cost data, AFE information, documents, notes, questions, and generated reports that you or your organization provide.
Technical information
Our hosting and security systems may receive IP address, browser and device information, request logs, timestamps, error information, and basic usage events needed to operate and protect the service.
3. How we use information
- To create and authenticate accounts and maintain sessions.
- To provide the workspace, well records, reports, searches, exports, and requested automations.
- To process documents, match records, troubleshoot errors, and respond to support requests.
- To secure the service, prevent abuse, enforce our Terms, and comply with law.
- To improve reliability and performance using aggregated or de-identified information where practical.
We do not sell crew data. We do not put an application on the rig merely because you use the Statohm workspace.
4. When information is shared
We may share information with service providers that process it on our instructions, such as hosting, authentication, database, storage, email, file-processing, monitoring, and security providers. The current product uses Vercel for hosting and Supabase for authentication/database infrastructure.
If an AI or assisted feature is enabled, the relevant question, document text, or selected well context may be sent to the configured model provider to return the requested output. Do not submit information to an assisted feature unless your organization permits that processing and you have confirmed the provider terms are acceptable.
Current subprocessors (as of the date above): Vercel Inc. (hosting and server functions), Supabase Inc. (authentication, database, file storage), Cloudflare Inc. (DNS and email routing), Google LLC — Gemini (document and question processing), and Groq Inc. (AI failover processing). A transactional email provider (such as Resend) may be added for password and pack emails; this policy will be updated when that happens. These providers process data only as needed to deliver the service.
We may disclose information when required by law, to protect rights and safety, to investigate abuse, or in connection with a merger, financing, sale, or transfer of the service.
5. Customer-controlled information
Your organization controls the Customer Data it submits to its workspace. You are responsible for giving appropriate notices, obtaining permissions, and following your own retention and access rules. Users should not upload information they are not authorized to provide.
We may retain and process Customer Data for as long as needed to provide the service, meet a written agreement, resolve disputes, enforce terms, maintain backups, or comply with law. The exact retention schedule should be documented in the final customer agreement.
6. Security
We use reasonable technical and organizational measures intended to protect information, including authenticated access controls, tenant separation, encrypted connections, server-side secrets, and security monitoring. No internet service is completely secure, and you are responsible for protecting credentials and limiting user access appropriately.
7. Cookies, storage, and session technologies
Statohm may use essential browser storage, cookies, or equivalent session technologies to keep you signed in, carry a session between pages, remember necessary preferences, and protect the service. We do not currently describe non-essential advertising cookies as part of the product. Browser settings may affect sign-in and some interactions.
8. Your choices and requests
Depending on where you live and the role of your organization, you may have rights to request access, correction, deletion, restriction, portability, or information about processing. Start with your organization’s Statohm administrator for Customer Data requests. For account or privacy questions, contact the Statohm operator through the legal or support address provided with your account or service agreement.
The provisional contact address is legal@statohm.com; verify that inbox and the operator’s identity before publishing formal privacy notices.
9. International processing and children
Service providers may process information in countries different from your own. The final policy should identify the applicable transfer mechanism and regional rights. Statohm is intended for business users and is not directed to children.
10. Changes and contact
We may update this policy when the service or data practices change. We will update the date above and provide notice when required. Questions about this policy should be directed to the Statohm operator using the legal or support contact associated with your account.