Privacy Policy
Effective date: July 25, 2026
Last updated: July 25, 2026
This Privacy Policy explains how Stele Inc. ("Stele," "we," "us," or "our") collects, uses, discloses, and protects information when you use our websites (including stele.health), our mobile applications, our wearable and hearable hardware, and related services (together, the "Service"). It applies to visitors, account holders, hardware purchasers, and anyone who otherwise interacts with the Service.
By using the Service, you agree to this Privacy Policy and to our Terms of Service. If you do not agree, do not use the Service.
1. Who we are and important context
Stele Inc. is a Delaware corporation. Stele builds neural-sensing hardware and software that help you understand your body: a readiness score and interpretation layer built from wearable signals, self-reported inputs, and optional blood-biomarker data.
Stele is a general-wellness and informational product. It is not a medical device, and it does not provide medical care, diagnosis, or treatment. The Service is intended to support general well-being and to help you organize and understand your own data. It is not a substitute for professional medical advice. See our Terms of Service for the full medical and AI disclaimers, which are incorporated into this Policy by reference.
HIPAA. In most circumstances, Stele is a direct-to-consumer company and is not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act ("HIPAA"). As a result, the information you provide to the Service is generally not protected by HIPAA. Instead, it is protected by this Policy and by the consumer-privacy and consumer-health-data laws described below. If we ever process health information on behalf of a HIPAA-covered provider or plan (for example, through a clinical partnership), we will handle that specific information in accordance with HIPAA and any applicable Business Associate Agreement.
2. Information we collect
We collect the following categories of information. Much of it is sensitive, and we treat it accordingly.
a. Information you provide directly
Account and profile data: name, email address, password, date of birth, and profile details.
Self-reported health inputs: food and nutrition logs, workouts, sleep, recovery activities (for example sauna), goals, symptoms, and subjective ratings of how you feel.
Blood-biomarker data that you upload or that you authorize a connected laboratory to share.
Communications: messages, support requests, survey responses, and feedback.
Payment information for subscriptions or hardware. Payments are processed by third-party processors and app stores; we do not store full payment-card numbers.
b. Biometric and neural data
Biometric and physiological data such as heart rate, heart-rate variability, sleep, respiration, activity, and related signals collected from Stele hardware or from wearables you connect.
Neural data (for example EEG-type signals) collected by Stele in-ear hardware where you use such a device.
Biometric and neural data are treated as sensitive data and, in several jurisdictions, receive heightened legal protection (see Section 10). We collect this data to provide the Service to you and do not use it to identify you to third parties.
c. Information collected automatically
Device and technical data: device model, operating system, app version, identifiers, IP address, and crash and diagnostic logs.
Usage data: features used, screens viewed, and interactions with the Service.
Cookies and similar technologies on our websites (see Section 8).
d. Information from connected services
Data from integrations you enable, such as Apple Health, wearables, or laboratory partners. We only receive what you authorize, and you can disconnect these integrations at any time.
We do not knowingly collect information from anyone under 18. See Section 12.
3. How we use information
We use information to:
Provide, operate, and maintain the Service, including calculating your readiness score and generating interpretations and optional self-directed "Experiments."
Personalize your experience and surface relevant general-wellness information.
Process transactions, subscriptions, and hardware orders, and provide support.
Communicate with you about the Service, including security and administrative messages, and (with your consent where required) marketing.
Maintain safety and security, prevent fraud and abuse, and debug and improve the Service.
Conduct research and analytics and improve our models and products, using de-identified or aggregated data wherever practicable (see Section 5).
Comply with legal obligations and enforce our agreements.
Legal bases (where GDPR/UK GDPR applies). We rely on: your consent (for sensitive, biometric, and neural data and for marketing); performance of a contract (to deliver the Service you request); our legitimate interests (to secure and improve the Service, balanced against your rights); and legal obligation. You may withdraw consent at any time.
4. How we share information
We do not sell your identifiable personal information or identifiable health, biometric, or neural data, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under California and other U.S. state privacy laws.
We disclose information only as follows:
Service providers / processors who work on our behalf (for example cloud hosting, analytics, customer support, and payment processing) under contracts that require them to protect the data and use it only for the services they provide to us.
Connected services you choose (for example a laboratory or wearable you link), only as needed to enable that integration.
Legal and safety disclosures when required by law, subpoena, or legal process, or to protect the rights, safety, and security of users, the public, or Stele.
Business transfers. If Stele is involved in a merger, acquisition, financing, or sale of assets, information may be transferred subject to this Policy; we will notify you of any change in control or use of your personal information.
With your direction or consent for any other disclosure of identifiable data, including any disclosure of identifiable health data to a research or commercial partner, which we will only make on the basis of your separate, explicit opt-in and which you can withdraw.
5. De-identified and aggregated data
We may create and use de-identified and aggregated data (data that cannot reasonably be used to identify you) for research, analytics, model training and improvement, publications, and commercial purposes, including partnerships. When we do:
We maintain the data in de-identified form and do not attempt to re-identify it, except as permitted by law to test our de-identification.
We contractually prohibit recipients from re-identifying it.
We use it to advance the science and quality of the Service and the broader field of health measurement.
De-identified and aggregated data is not "personal information" under applicable law, and this Section 5 governs it.
6. How we protect information
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, access controls and least-privilege access, logging, and vendor due diligence. We are building our security and privacy program toward SOC 2 and HIPAA-aligned standards and monitor our controls on an ongoing basis.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we learn of a security incident affecting your information, we will notify you and regulators as required by applicable law, including the U.S. FTC Health Breach Notification Rule and state breach-notification laws where they apply.
7. Data retention
We retain personal information for as long as your account is active or as needed to provide the Service, and thereafter as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete or de-identify it. You may request deletion as described in Section 11.
8. Cookies and analytics
Our websites use cookies and similar technologies for functionality, preferences, and analytics. You can control cookies through your browser settings. We do not use cookies to sell your data or to engage in cross-context behavioral advertising. Where required, we present a consent choice and honor privacy-preference signals such as Global Privacy Control (GPC).
9. Artificial intelligence: how we use it and its limitations
The Service uses artificial intelligence (AI), including machine-learning and large-language models, to interpret your data, generate your readiness score, summarize trends, and produce recommendations and optional "Experiments."
You should understand:
AI can be wrong. AI outputs may be inaccurate, incomplete, outdated, or not appropriate for your situation, and may occasionally produce content that is fabricated or misleading (sometimes called "hallucinations").
AI is not a medical professional. AI outputs are general-wellness information only. They are not medical advice, diagnosis, or treatment, and they do not create a doctor-patient or other professional relationship.
Do not rely on AI outputs alone. Always use your own judgment, and consult a qualified healthcare professional before making decisions about your health, medications, supplements, exercise, or diet. Never disregard or delay professional medical advice because of something the Service told you.
Human oversight and improvement. We test and monitor our AI systems and may use data (preferring de-identified or aggregated data per Section 5) to evaluate and improve them. We do not use your identifiable data to train third-party AI models without a lawful basis and, where required, your consent.
Your use of AI features is governed by the disclaimers and limitation-of-liability provisions in our Terms of Service.
10. Sensitive, biometric, and neural data
We collect sensitive data, including health, biometric, and neural data. We process this data to provide the Service to you, and, where required by law, only with your consent. We apply heightened protections and honor the specific rights granted by applicable laws, which may include:
Consumer health-data laws such as the Washington My Health My Data Act, Nevada SB 370, and Connecticut's health-data provisions, which govern the collection, use, and any sale of "consumer health data." We do not sell your consumer health data, and we obtain consent where these laws require it.
Neural-data protections, including amendments to the California Consumer Privacy Act (SB 1223) and the Colorado Privacy Act (HB 24-1058) that treat neural data as sensitive personal information.
Biometric-privacy laws, such as the Illinois Biometric Information Privacy Act (BIPA), the Texas CUBI Act, and Washington's biometric law, to the extent they apply to biometric identifiers we process. We obtain consent and provide notice where these laws require.
You may withdraw consent for sensitive-data processing, though doing so may prevent the Service from functioning.
11. Your privacy rights and choices
Depending on where you live, you may have the right to:
Access / know the personal information we hold about you and how we use it.
Correct inaccurate personal information.
Delete your personal information.
Port a copy of certain data.
Opt out of any sale or sharing of personal information (note: we do not sell or share personal information) and of certain profiling.
Limit the use of sensitive personal information to what is necessary to provide the Service.
Withdraw consent to sensitive-data processing.
Non-discrimination for exercising your rights.
How to exercise rights. Email [email protected] or use in-app controls. We will verify your request and respond within the timeframes required by law. You may use an authorized agent where permitted. If we deny a request, you may appeal by replying to our response; you may also contact your state attorney general.
California "Shine the Light": we do not disclose personal information to third parties for their own direct-marketing purposes.
12. Children
The Service is intended only for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact [email protected] and we will delete it.
13. International users and data transfers
Stele is based in the United States, and we process and store information in the United States and other countries. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different data-protection laws than your jurisdiction. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
14. Third-party links and services
The Service may link to or integrate third-party sites and services (for example app stores, wearables, and laboratories). Their privacy practices are governed by their own policies, not this one. Review them before use.
15. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you through the Service or by email and update the "Last updated" date above. Material changes affecting sensitive data will, where required, ask for your renewed consent. Your continued use after an update means you accept the revised Policy.
16. Contact us
Stele Inc.
Privacy: [email protected]
Legal: [email protected]
Registered agent / mailing address for legal notices:
Stele Inc., c/o Harvard Business Services, Inc.
16192 Coastal Highway, Lewes, Delaware 19958, United States
This Privacy Policy is provided for general informational purposes and does not constitute legal advice. Stele should have it reviewed by qualified privacy counsel before public launch.