Privacy
What we collect, why, and what we never collect.
Stoa is operated by SIA Cyber Unicorn (registration 40203002129), Riga, Latvia, acting as the data controller under GDPR. Contact: info@serpctrl.lv.
This site (stoaa.app)
On the marketing site, we collect what you submit through forms and the page-view counts our analytics tool returns. We use Plausible Analytics, which is cookieless and does not store personal identifiers, so you will not see a cookie banner here.
Early-access signups
If you join the consumer or therapist waitlist, we store your email and the optional metadata you provide (preferred regulation states, country of practice, caseload size). We also store a salted, daily-rotating hash of your IP address — used only to prevent abuse, not for analytics. Your email is used to send you product updates related to your signup and nothing else. You can request deletion at any time by emailing the address above.
Investor requests
If you request the investor brief, we store your name, firm, email, chosen role, and message. We deliver the brief PDF to your email and notify our investor team at the configured notification address. We do not sell or share investor request data. We retain it for the lifetime of the relationship and delete on request.
What we never collect on this site
- No third-party advertising cookies.
- No fingerprinting scripts.
- No social-platform pixels.
- No session replay.
The Stoa app (separate document)
The Stoa mobile application has its own privacy policy, with the stricter clinical-data rules required by GDPR Article 9. It will be published with the app's TestFlight release. In short: anonymous identity by default, five granular consents for clinical data, 15-year retention for clinical records (Latvian law), therapist-mediated FHIR export only, and a hard "we do not write directly to state health systems" rule.
Your rights under GDPR
You can request access, correction, deletion, restriction, and portability of your personal data. Email info@serpctrl.lv with the subject "GDPR request" and we will respond within 30 days. You can also complain to the Latvian Data State Inspectorate (Datu Valsts Inspekcija) if you believe we mishandled your data.
Changes
We will update this policy as the product evolves and post the change date here. Last updated: 19 May 2026.