Legal / Privacy

Your files stay yours.

A precise account of what stays on your device, what leaves it, and what you control.

Overview

Effective and last updated: July 10, 2026

This Privacy Policy explains how Sergii Iarochevskyi, an individual operating under the Seraro brand ("Seraro," "we," "us," or "our"), handles personal data when you use the Structor desktop application, the Structor pages in Seraro Apps Hub, account and licensing services, support, and related websites (together, the Services).

Structor is a desktop file-organization application. Its core file access, indexing, search, preview, duplicate analysis, renaming, organization, and image-compression operations run on your device. Structor does not claim ownership of your files or their contents.

For privacy questions or requests, email privacy@seraro.com. For product or billing support, email support@seraro.com.

Data we process

CategoryExamplesWhy we process it
Account dataName, email address, profile image, sign-in provider, account and session identifiersAuthentication, account administration, support, and access across Seraro apps
Local file dataUser-selected folder paths; file and folder names; extensions, types, sizes, and timestamps; hashes; extracted text and OCR; previews; local embeddings; duplicate groups; organization and rename historyFile organization, local search, previews, duplicate detection, undo/recovery features, and other requested desktop functions
AI request dataFile or folder names, extensions, types, subfolder names, selected folder structure, prompts, model responses, and provider/model settingsTo categorize files or perform another AI feature you request
License and device dataProduct, plan, entitlement and license status; protected device identifier; device public-key fingerprint; activation and last-validation informationIssuing, activating, validating, recovering, and preventing abuse of desktop licenses
Purchase dataProduct and plan, price, currency, transaction/customer/subscription identifiers, purchase status and dates, refund status, and limited billing details received from the payment providerCheckout, tax and accounting, fulfillment, subscription management, refunds, fraud prevention, and customer support
Website and diagnostics dataIP address, browser or app version, operating system, timestamps, referring page, cookie/session identifiers, feature interactions, and error or security logsOperating, securing, debugging, measuring, and improving the Services
CommunicationsSupport messages, feedback, attachments you choose to provide, and email preferencesResponding to you and sending transactional or opted-in communications

We obtain this data from you, from the desktop app and browser when you use the Services, from sign-in providers you choose, from payment and licensing providers, and from systems used to operate the Services. We do not use Structor to collect precise location, contacts, health data, or advertising identifiers.

Local file access and on-device processing

Structor accesses only files and folders that you select or otherwise authorize through your operating system. Depending on the features you enable, Structor may read file metadata and content; create local previews, hashes, OCR text, summaries, and vector embeddings; watch selected folders for changes; and move, rename, compress, or remove files at your direction.

Local indexes, settings, history, model data, and recovery copies are stored on your device in Structor's application-data locations. They are not synchronized to us merely because you sign in. Removing a folder from Structor stops future management of that folder but may not immediately remove an existing local index; you can remove local application data through Structor or your operating system.

Semantic indexing is performed on-device. Structor may download signed or checksum-verified model assets from providers such as Hugging Face, but downloading a model does not upload your files to that model host.

AI providers, local models, and BYOK

You control which supported AI connection Structor uses:

  • On-device or local-network models. When you select Ollama, LM Studio, or another endpoint running on your device, AI request data is sent to that configured local endpoint. We do not receive the request. If you configure an endpoint on another computer or network, that endpoint's operator can receive it.
  • Bring your own key (BYOK). When you configure OpenAI, Anthropic, or another OpenAI-compatible provider, Structor sends the request directly to the endpoint you select under that provider's terms and privacy policy. Your provider API key is stored using the operating-system credential store where available, with encrypted local storage as a fallback. We do not use BYOK credentials to access your provider account.
  • Structor-managed AI. If you choose a Structor-hosted AI option, the request is sent through Seraro's authenticated AI service and may be processed by an underlying model provider disclosed in the product experience or documentation.

For file categorization, the request can contain file and folder names, extensions, entry types, subfolder names, and the existing folder structure. Structor does not send the file binary itself as part of that categorization request. Do not use a remote AI provider for names or folder structures that you are not permitted to disclose. Remote AI providers independently determine their security, retention, training, and international-transfer practices; review their terms before enabling them.

How and why we use data

We process personal data to:

  • provide the desktop app, accounts, authentication, licenses, purchases, updates, support, and requested AI connections;
  • maintain local indexes and perform the file operations you initiate;
  • secure the Services, validate entitlements, detect fraud or abuse, and enforce our Terms;
  • diagnose failures and improve reliability and usability;
  • send purchase, security, license, support, and service communications;
  • comply with tax, accounting, consumer-protection, sanctions, and other legal obligations; and
  • establish, exercise, or defend legal claims.

Where applicable, our legal bases are performance of our contract with you, compliance with legal obligations, our legitimate interests in operating and securing the Services, and consent where the law requires it. You may withdraw consent at any time without affecting processing already performed. We do not sell personal data, share it for cross-context behavioral advertising, or use the contents of your local files to build advertising profiles.

Service providers and disclosures

We disclose only the data reasonably needed for the relevant service:

Recipient categoryPurpose
Creem and other payment providers shown at checkoutMerchant-of-record services, checkout, payment processing, tax, invoices, subscriptions, refunds, and fraud prevention
Licensing infrastructure such as KeygenLicense issuance, activation, device limits, validation, suspension, and recovery
Google, if you choose Google sign-inAuthentication and account linking
Hosting, database, security, and content-delivery providersOperating and protecting Apps Hub, authentication, APIs, and downloads
Resend and mailing-list infrastructureTransactional email, account messages, and communications you request
Betterlytics and Umami, where enabled on Apps HubWebsite and account-linked product analytics; this can include an account identifier and basic profile fields when signed in
The AI endpoint you selectProcessing the AI request described above
Professional advisers and authoritiesLegal, audit, insurance, security, and compliance needs, or a valid legal request

Creem acts as merchant of record for purchases completed through its checkout and processes buyer data under its Privacy Notice. Google and user-selected AI providers may act as independent controllers under their own notices. We require service providers acting for us to protect personal data consistently with this Policy and applicable law.

We may disclose data in connection with a merger, financing, reorganization, or sale of all or part of the business, subject to appropriate confidentiality and notice requirements. Personal data may be processed outside your country; where required, we use recognized safeguards such as adequacy decisions or standard contractual clauses.

Retention and deletion

We retain data only for as long as reasonably necessary for the purposes above:

  • local file indexes, history, settings, secrets, model assets, and recovery copies remain on your device until you remove them, uninstall the app and its data, or an in-app retention process expires them;
  • account and session data is retained while your account is active and for a limited period afterward for security, backup, dispute, and recovery needs;
  • purchase, invoice, tax, refund, and anti-fraud records are retained for the periods required by financial, tax, consumer-protection, and limitation laws;
  • license and device-activation records are retained while needed to provide and prove the purchased license and manage device limits;
  • support and security records are retained for as long as needed to resolve the request, protect the Services, or establish legal claims; and
  • analytics data is retained according to our configured analytics retention and is aggregated or deleted when no longer needed.

Account deletion does not delete files or Structor's local application data from your devices, and uninstalling Structor does not automatically delete your Apps Hub account. Contact us if an account-deletion control is not available. We may retain a minimal record where deletion is restricted by law or needed to prevent fraud, honor an opt-out, or resolve a dispute.

Your choices and privacy rights

You can choose folders, disable folder watching or semantic search, select a local model instead of a remote provider, remove stored provider keys, disconnect sign-in where supported, manage email preferences, deactivate licensed devices, and cancel a subscription through the available account or Creem customer-portal controls.

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of personal data; object to certain processing; withdraw consent; and appeal a denied request. You may also complain to your local data-protection authority. California and other applicable U.S. laws may provide rights to know, delete, correct, and limit certain uses of personal data. We do not discriminate for exercising a privacy right.

Submit a request to privacy@seraro.com. We may verify your identity and authority before responding. An authorized agent may submit a request where local law permits it.

Security

We use administrative, technical, and organizational safeguards appropriate to the nature of the data. These include encrypted network transport, access controls, signed license payloads, protected device keys, operating-system credential storage where available, encrypted local secret storage as a fallback, and validation of downloaded update or model assets where supported.

No storage or transmission method is completely secure. You are responsible for securing your device, operating-system account, local model endpoints, provider accounts and keys, and backups. If you believe your account or data has been compromised, contact support@seraro.com.

Children

The Services are not directed to children under 16, and we do not knowingly collect personal data from children under 13. A minor may use the Services only with authorization from a parent or legal guardian where permitted by law. Contact us if you believe a child provided personal data without proper authorization.

Changes to this Policy

We may update this Policy to reflect product, provider, or legal changes. We will post the revised version here and update the date above. If a change materially affects your rights, we will provide additional notice where required.

Contact

Privacy and data requests: privacy@seraro.com

Product, license, and billing support: support@seraro.com

Data controller: Sergii Iarochevskyi, an individual operating under the Seraro brand and currently based in Poland.

Creem or another payment provider shown at checkout is independently responsible for the personal data it processes as merchant of record. The applicable merchant details for a purchase are shown at checkout and on the receipt.

© 2026 Sergii Iarochevskyi. Seraro is a brand operated by Sergii Iarochevskyi.

support@seraro.com