STADION Ai Systems

Privacy Policy

Last updated: August 2026

1. Introduction

Stadion Ai Systems ("Stadion Ai", "we", "us", or "our") operates the GeoAgent software platform and related services (the "Service"). This Privacy Policy explains what information the Service receives, why it is processed, which third parties are involved, and what happens to it afterwards.

GeoAgent is a professional tool. Its users are typically surveyors, engineers, drafters and other professionals acting in a business capacity, and the documents they upload are work product belonging to them or their clients.

2. Information We Collect

Account information

  • Name and display name
  • Email address (used to sign in and to contact you)
  • A hashed password — we do not store your password itself
  • Optional profile details you choose to provide, such as company name, job title, phone number and team size
  • Subscription tier and status

We never receive your payment card details. Card data is collected and processed directly by Stripe. We store only a Stripe customer identifier and your subscription status.

User Documents

Files you upload for processing — survey plats, deeds, legal descriptions and similar documents, as PDF, image, Word or plain text. We refer to these as "User Documents." If you use the API to submit a legal description as text rather than as a file, that text is treated the same way.

Information derived from your documents

To produce your results, the Service extracts and stores information derived from a User Document: the text read from it, the boundary calls and geometry interpreted from that text, closure and quality measurements, and survey metadata such as coordinate system or document type. This derived information is distinct from the original file and is retained on a different schedule (see Section 5).

Outputs

The CAD, image, report and data files the Service generates for you.

Operational and security information

  • IP address, browser and device type, and operating system
  • Session and authentication data
  • Records of processing activity — job status, timing, processing method, and error classifications

3. How We Use Information

We use information to:

  • Process your documents and generate the outputs you request
  • Operate and administer your account
  • Manage subscriptions, usage limits and billing
  • Keep the Service secure and prevent fraud or misuse
  • Diagnose failures and support you when something goes wrong
  • Measure and improve reliability and accuracy
  • Communicate about the Service
  • Comply with legal obligations and enforce our Terms

When we work on the accuracy and reliability of the Service, we use operational records — such as whether a job succeeded, which processing path ran, how long it took, and how a failure was classified. We do not build a library of customer documents for product development.

We do not sell personal information. We do not use it for targeted or behavioural advertising, and we do not share it with advertisers.

4. Ai Processing

Much of GeoAgent's work is deterministic: text extraction, geometry construction, closure calculation and the review of alternative interpretations run on our own systems without any external model. Optical character recognition of scanned documents also runs on our own infrastructure.

Some cases do call an external Ai model. External Ai is invoked only in specific processing paths — when the deterministic result does not meet our quality threshold and a model may be able to read the description more accurately, and in certain quality checks. A document that does not enter one of those paths is processed without any external model call.

What is sent, and what is not

  • When an Ai step runs, we send text: the legal description extracted from your document, together with the instructions and the interpretation context the model needs.
  • We do not send your original file. Image and PDF bytes are not transmitted to the model provider; there is no image-recognition path to an external model.
  • We do not send your name, email address, company, filename or account identifiers to the model provider.

Our model provider and its settings

External inference is performed by Together Ai. For the Stadion Ai organization, the following provider settings are disabled: storage of prompts and model responses, use of our organization's data for model training, and "passthrough" models that would forward content to a further third-party provider.

Two related but separate statements, both of which are true: Stadion Ai does not use your documents to train or fine-tune any model, and our provider's organization settings prohibit training on our organization's data. These settings govern how content is handled from the time they were applied onward; we do not make claims about the retroactive deletion of data processed before then.

GeoAgent does not currently offer a mode that disables external Ai entirely. If that matters to your organization, please contact us before subscribing.

Outputs are produced automatically and may contain errors. They are intended to assist professional work, not to replace professional review.

5. Retention and Deletion

Your original uploaded file

The working copy of an uploaded file is removed once processing reaches a final state — whether it succeeded, completed with issues, or failed. If a job is abandoned before it runs, the stored file content is cleared when the job is closed out. We do not keep your original document as a permanent archive, and there is no setting that makes us keep it.

Derived information and outputs

Information derived from your document, together with the outputs generated from it, is retained for 30 days from the job's creation and is then deleted automatically, along with the stored output files. Downloads remain available during that window.

Account deletion

You can ask us to delete your account. Deletion begins with a 30-day recovery period, in case the request was a mistake or you change your mind. After that period, the account and the customer content associated with it — remaining uploads, stored outputs, and the processing records that contain document-derived information — are permanently removed.

What we keep afterwards

We retain limited non-content records: billing and transaction history we are required to keep, security and operational logs, and an internal record of deletion activity showing that data was removed and when. These records are designed not to contain your documents, their contents, or your file names.

Backups

Our infrastructure providers maintain their own backups of the systems they operate. Copies of data may persist in provider backups for a period after deletion from the live Service. We do not currently publish a guaranteed backup-expiry schedule, and we will not claim one we have not verified.

6. Security

Measures we can state as fact:

  • Encryption in transit using TLS, with HTTP Strict Transport Security enabled
  • Password hashing using bcrypt — we cannot read your password
  • Authentication and session controls, including CSRF protection on state-changing actions
  • Access scoped per account, so one customer's jobs and outputs are not reachable by another
  • Upload validation by file type, size and page count
  • Output files stored in private object storage and served through short-lived, expiring links

We do not currently hold SOC 2, ISO 27001, HIPAA or similar certifications, and we do not claim them. If your procurement process requires a specific attestation, please raise it with us directly rather than assuming one exists.

No system can guarantee absolute security. Please use your own judgement about the sensitivity of documents you upload.

7. Logging and Monitoring

We keep operational logs and use an error-monitoring service so that we can detect failures and fix them. These systems are configured to record what happened rather than whose document it happened to.

Specifically, our logging and error monitoring are configured so that document text, file names, account email addresses, model prompts and model responses are not written into them, and so that request contents and in-memory variables are not captured by our error-monitoring service. What is recorded is operational: job identifiers, processing stage, status, timing, error classifications and similar technical detail.

We audit for this and test for it, but we cannot promise that no fragment of customer information could ever appear in a diagnostic record under any failure condition. Where we find one, we treat it as a defect and fix it.

8. Service Providers

We use the following providers to operate the Service. This list reflects what the Service actually uses.

Providers that may receive document-derived information

  • Railway — application hosting, database and job queue. Holds account data, derived processing information and outputs during the retention period.
  • Cloudflare R2 — private object storage for generated output files.
  • Together AiAi model inference. Receives extracted document text when an Ai step runs, as described in Section 4. Receives no file bytes and no account identifiers.

Providers that receive only account, billing or technical information

  • Stripe — payment and subscription processing. Receives your billing details directly; we do not see your card number.
  • Sentry — application error monitoring. Receives technical error information as described in Section 7.
  • Google Fonts — web fonts loaded by your browser when you view our pages, which means Google receives your IP address and browser information. This affects page viewing only and is unrelated to document processing.

We do not currently use an email delivery provider, an analytics provider, or any advertising provider. Our providers are located in the United States, except Cloudflare, which operates globally. By using the Service you acknowledge that your information may be processed in the United States.

If we add a provider that would receive document-derived information, we will update this section.

9. Cookies

The Service uses only cookies that are necessary to operate it:

  • Signing you in and keeping you signed in
  • Protecting form submissions against cross-site request forgery

We do not use advertising cookies, cross-site tracking, or behavioural profiling.

10. Your Privacy Choices

You can ask us to do the following with the personal information we hold about you:

  • Confirm what we hold and provide a copy
  • Correct information that is inaccurate
  • Delete your account and associated content
  • Ask a question about how your information is processed

Write to privacy@stadion-ai.com. These requests are handled by a person rather than through a self-service screen. We aim to respond within 30 days, and we will tell you if we need longer. We may need to verify your identity before acting on a request.

If we decline a request, you may ask us to reconsider by replying to our response. We will review the decision and give you a written answer.

Some privacy laws apply based on where you live, the size of the business, and whether you are acting personally or on behalf of an employer. We will honour the requests above for any customer who asks, without requiring you to establish that a particular law applies to you.

11. Children's Privacy

The Service is intended for professional and commercial users and is not directed to anyone under 18. We do not knowingly collect information from children.

12. Changes to This Policy

We may update this Policy. If we do, we will post the updated version here with a revised "Last updated" date. If a change materially reduces the protections described here, we will make that clear rather than relying on you to notice.

13. Contact

Questions about this Policy or about how your information is handled: privacy@stadion-ai.com.