Account and profile
Your name, email address, authentication identifiers, avatar, sign-in activity, and account preferences.
Privacy and data
This policy explains what Cornerstone collects, why it is needed, which services may process it, and the choices available to you.
Privacy contact: philip.ronald.hultgren@gmail.com
This page covers the Cornerstone platform as a whole. Each released browser extension also has a focused policy describing that tool's data, storage, permissions, and providers.
Explore every current and planned extension in the extension directory.
Cornerstone Spark signs you in to Cornerstone and synchronises the Spark work you choose to keep in your personal or shared workspace.
Read extension policy →Planned extensionPrivacy details will be published before this extension is released.
View extension roadmap →Planned extensionPrivacy details will be published before this extension is released.
View extension roadmap →We collect only the information needed to provide the tools you use, keep your work available, and operate the platform safely.
Your name, email address, authentication identifiers, avatar, sign-in activity, and account preferences.
Your selected plan, subscription status, entitlement, purchase history, and payment references. Cornerstone does not store full card numbers.
The projects, resources, notes, files, forms, workflows, and settings you choose to save in Cornerstone tools.
Admission details, attendance, connection times, progress, responses, and activity state when you host or join a Session.
Browser and device details, request information, security signals, errors, and operational logs needed to run and protect the service.
These providers support specific parts of Cornerstone. The data each receives depends on the feature you use.
Firebase services may process account identifiers, authentication activity, workspace or Session data, files, IP addresses, and device or request details to provide and secure Cornerstone.
Stripe receives payment and transaction information when you purchase a membership. Cornerstone receives status and transaction references, while Stripe handles payment-card details.
Vercel may process page paths, referrers, approximate location, and browser or device categories for aggregate traffic reporting. Its Web Analytics product does not use third-party cookies or persistent cross-site identifiers.
If you choose a connected sign-in method, the provider shares the profile and account details you approve so Cornerstone can create or authenticate your account.
When enabled for a protected request, these services assess device and request signals and return a security token used to distinguish legitimate app traffic from abuse.
Cornerstone uses local or session storage for functions such as keeping checkout details between steps, remembering Session state, and caching signed-in interface data. Authentication and anti-abuse providers may also use storage that is necessary to secure the service.
We do not run Google Analytics or advertising cookies. Vercel Web Analytics is configured as cookie-free aggregate measurement. Because there are no optional analytics or advertising cookies to accept, Cornerstone does not currently show a cookie banner. If optional cookies are introduced, they should remain off until an appropriate consent choice is made.
We collect information directly when you create an account, choose a plan, contact support, build a workspace, upload a file, or participate in a Session.
We also receive limited information automatically from the browser and from providers involved in authentication, payments, hosting, security, and aggregate site measurement.
We use information to provide the tools you choose, save and synchronise your work, authenticate access, manage memberships, process payments, support users, protect the service, and meet legal obligations.
We do not sell workspace content, use it for advertising, or use it to train AI models. We do not routinely inspect private workspace content. Access is limited to what is reasonably necessary for user-requested support, security investigation, service recovery, or legal compliance.
Cornerstone uses access controls, encrypted connections, provider security controls, and operational safeguards designed to protect personal information from loss, misuse, or unauthorised access.
Information is retained only while it is needed to provide the service, maintain security and records, resolve disputes, or meet legal and accounting obligations. When it is no longer required, it should be deleted or de-identified. You may ask us to delete your account information, subject to records we must keep.
We share information only with providers that help operate the service, when you direct us to share it, or when disclosure is required for security, legal, or regulatory reasons. We do not sell personal information.
Some providers operate infrastructure outside Australia, including in the United States and other regions. We assess the providers used by Cornerstone and take reasonable steps appropriate to the information and applicable law.
You may ask for access to personal information we hold about you, request a correction, ask for deletion where available, or make a privacy complaint by emailing philip.ronald.hultgren@gmail.com. We may need to verify your identity before acting on a request.
We will consider the request and explain the outcome. If you are not satisfied with our response, you may be able to contact the Office of the Australian Information Commissioner.
We investigate suspected unauthorised access, disclosure, or loss of personal information and take steps to reduce potential harm. Where the Notifiable Data Breaches scheme applies and serious harm is likely, affected people and the OAIC will be notified as required.
Search the public guidance and provider documentation used to describe Cornerstone’s privacy approach and current data tools.
The OAIC overview of the 13 principles governing how covered Australian organisations handle personal information.
Open source ↗APP 1Guidance on maintaining a clear, current, and accessible privacy policy that describes how personal information is managed.
Open source ↗APP 5Guidance on what people should be told at or before the time their personal information is collected.
Open source ↗APP 11OAIC guidance about reasonable security safeguards and deleting or de-identifying information that is no longer needed.
Open source ↗NDB schemeAn explanation of when covered organisations must notify affected people and the OAIC about an eligible data breach.
Open source ↗Firebase privacyGoogle’s description of how Firebase services process end-user and service data, protect it, and support privacy obligations.
Open source ↗Vercel AnalyticsVercel’s explanation of the data points used for aggregate Web Analytics and its cookie-free visitor identification approach.
Open source ↗Stripe privacyStripe’s explanation of its roles and data handling when it processes payments for a business and its customers.
Open source ↗