Legal

Privacy Policy

Effective October 7, 2026

Who we are and what this policy covers

Michael Starr, doing business as StayNative (“StayNative”, “we”), builds and hosts a custom operating system for each of its business customers. This policy explains what information we handle, why, and the choices you have.

It covers:

  • people who use a StayNative workspace on behalf of one of our customers;
  • information our customers put into StayNative or connect to it, such as their QuickBooks Online company;
  • visitors to staynative.ai.

When we handle a customer’s business information, we do so on that customer’s behalf and under our agreement with them. The customer decides who has access and what is kept. If you use StayNative through your employer or another organization, its policies also apply to you; questions about your organization’s data can go to it or to us.

What we collect and why

We collect only what we need to run each customer’s workspace, keep it secure, and support it.

WhatExamplesWhy we use it
Account informationName, work email, role, and sign-in records such as time and IP addressTo sign you in, control what you can see and do, and protect accounts
Your organization’s recordsWhat your organization enters, imports or uploads: contacts, projects, transactions, documentsTo provide the service your organization subscribes to
Data from connected systemsInformation read from systems your organization connects, such as QuickBooks OnlineTo keep your workspace and those systems in step (next section)
Activity and audit recordsWho changed what, when, and the old and new valuesSecurity, troubleshooting, and your organization’s own audit trail
Technical and error dataBrowser type, pages requested, error reportsTo keep the service working and fix problems
Messages to usName, email and what you writeTo answer you

We do not sell personal information, use it for advertising, or use one customer’s information for another customer.

Cookies. The workspace uses only the cookies it needs: they keep you signed in and protect sign-in and connection steps. There are no advertising cookies. The staynative.ai website uses no analytics or advertising cookies. Its pages load a typeface from Google Fonts, so Google receives your browser’s IP address when you visit.

QuickBooks and other connected systems

We connect to QuickBooks Online, or another system, only when an Owner or Admin at your organization chooses to, and we use what we read only to provide your organization’s service.

  • What we read from QuickBooks Online. Your chart of accounts, vendors, customers and projects, classes, and expense transactions from a start date your organization chooses.
  • What we write. Only changes a person at your organization has approved, such as the category and project on an existing expense. We never post journal entries; QuickBooks remains your system of record for accounting.
  • How access is held. Intuit gives us an access token, not your QuickBooks password. We store it encrypted, under a key unique to your organization.
  • Disconnecting. You can disconnect at any time, from your workspace or from QuickBooks. When you disconnect from your workspace, we revoke the token with Intuit and delete it; either way we stop reading and writing.
  • No other use. We do not sell this data, share it with other customers, or use it for any purpose but your organization’s service.

AI-assisted features. Some features suggest an answer, for example a category and project for an uncategorized expense. To make a suggestion we send only the fields that task needs to Anthropic’s commercial API: for an expense, the vendor, amount, date, paying account, memo and line descriptions. A person at your organization reviews every suggestion before anything is written back. Neither StayNative nor Anthropic trains AI models on your organization’s data.

Who we share it with

We share information only with service providers that help us run StayNative, only for that purpose, and under contracts that require them to protect it.

ProviderWhat they do for usWhat they handleWhere
SupabaseDatabase, sign-in and file storageYour organization’s workspace dataUnited States (AWS US East)
VercelHosts the applicationData passing through the application, and request logsUnited States
AnthropicAI-assisted suggestionsOnly the fields a suggestion needsUnited States
ResendSends email: invitations, password resets, noticesName, email address, the messageUnited States
SentryError monitoringError reports, with personal details removed where possibleUnited States
IntuitOnly when your organization connects QuickBooks OnlineData exchanged with your QuickBooks companyUnder Intuit’s own terms
MicrosoftOnly if your organization signs in with MicrosoftYour sign-in identityUnder Microsoft’s own terms

We may also disclose information when the law requires it. If StayNative is reorganized, merged or sold, including when it moves into a company formed to operate it, information may transfer to the successor, which must honor this policy. If StayNative stops operating, our agreement with each customer provides for its database, hosting and repository to transfer to that customer.

Security, retention and deletion

Each customer’s data sits in its own database, kept separate from every other customer’s.

  • Encryption. Data is encrypted in transit (HTTPS) and at rest. Tokens for connected systems are also encrypted under a key unique to each customer.
  • Access inside a workspace. Roles set by your organization decide what each person can see and change, and the database itself enforces them.
  • Audit trail. Every change is recorded: who or what made it, when, and the old and new values.
  • StayNative staff. Staff use named accounts and access a workspace only to support it. Production credentials are held only by the hosting and build systems.

How long we keep it. We keep your organization’s data while it is a StayNative customer. When it disconnects a system, we delete that system’s access tokens at once; the information already copied stays until your organization asks us to delete it.

When a customer leaves. We provide an export on request, then delete the customer’s data within 30 days. Backups age out within 7 days after that.

If we learn of a breach affecting your information, we will notify the affected customer without undue delay and as the law requires.

Your choices, changes and contact

You can ask to see, correct or delete your personal information.

  • Where to ask. If you use StayNative through an organization, ask its administrators first, since they control its workspace. You can also write to us, and we will work with them.
  • Your rights. Depending on where you live, for example California, you may have further rights under local law. We will not treat you differently for using them.
  • Children. StayNative is a business service and is not meant for anyone under 16.
  • Changes. If we change this policy in a way that matters, we will update the date at the top and tell customers’ administrators before it takes effect.
  • Contact. [email protected], or by mail to Michael Starr, doing business as StayNative, 428 Medford St, Unit 4, Boston, MA 02129.