Privacy notice · 4 September 2026
StoneDex is a subscription tool for people who specify and supply natural stone. This notice says what it holds about you, why, where it is, and how to get rid of it. It describes what the software actually does; if something here does not match what you see, the software is wrong and we want to know.
StoneDex is operated by the operating company, whose registered name is being added here, of the registered address being added here, in the United Arab Emirates. That company is the controller of everything described below, and that address is where a data request or a complaint is posted.
| What | Why | How long |
|---|---|---|
| Your name, username, and email address if you give one | To sign you in, to let you reset your own password, and to tell you when something changes on your account | Until you close the account |
| A hash of your password, and — if you switch it on — a two-factor secret and recovery codes | To check a sign-in. The password itself is never stored and cannot be read back by anyone, including us | Until you close the account |
| The devices signed in: browser, operating system, IP address, and when each was last used | So you can see them on your account page and sign out one you do not recognise | 90 days from each sign-in, then deleted by a sweep that runs daily |
| Your projects — names, clients, locations, the stones on them, your notes and statuses | They are the product. They are held on the server so they follow you between devices | Until you delete them or close the account |
| Photographs you submit to Identify, and what you type beside them | To name the stone, and — when you confirm an answer and it is approved — to widen the reference set the library matches against. Approval is normally an administrator's; a small number of accounts are marked as verifiers, and for those the person's own confirmation is the approval | Until you close the account, except an identification approved as a library reference, which is kept whole |
| A short private note an administrator of your organisation may write against your account | So that whoever manages the accounts remembers something about yours. It is written by them, not by us, and it is about you — so it is in your export, under administrator_note | Until you close the account |
| Sourcing enquiries you send: quantity, application, project stage and location, and the stones on the enquiry | So a sourcing manager can price the job. Sent only when you press send | Until you delete them or close the account |
| Questions you ask the assistant, and the record of what you agreed to and when | To answer them, and to be able to show what terms you accepted | Until you close the account |
| One-use links you asked for: a confirmation, a password reset, or a half-finished sign-in — held as a hash of the link, with the address it was sent to and the IP address of the request that asked for it | So a link can be used once and only once, and so that a flood of requests can be stopped | The link expires in an hour to seven days; the row is deleted 30 days after that |
| Counters used to slow down repeated wrong passwords, keyed on the IP address they came from | To stop somebody guessing at a password | Cleared as soon as they lapse, and swept daily |
| Messages sent to you — a confirmation or a password-reset link — with the address they went to | So that a link that did not arrive can be found and handed over. While mail is switched off, this is where the link is read from | 90 days, then deleted by the daily sweep; and immediately when you close the account |
| A record of actions on your account: sign-ins, password changes, exports, deletions | So a question about who did what has an answer | 24 months, including after an account closes, then deleted by the same daily sweep. It records the action and the kind of device, and no IP address — the three rows above are where an address is held, and they say for how long |
fonts.googleapis.com and fonts.gstatic.com), so Google sees the IP address and browser of a device that opens StoneDex. Nothing else is sent, they set no cookie, and the fonts are being moved onto this server so that even this stops.An administrator of your StoneDex organisation sees, in the admin panel: your email address, the devices signed in, your project and client names and how many stones are on each, and any photograph you send to Identify with what you typed beside it. The panel does not show the notes or statuses inside a project.
That is what the panel shows, and it is not the same as what an administrator can reach. An administrator can set a temporary password on any account, which is how a locked-out colleague gets back in — and it means an administrator can sign in as somebody and see everything they see. Every such action is written to the audit trail with their name on it, which is the control that exists; there is no technical barrier, and we would rather say so than let you assume one.
StoneDex staff can read the contents of a project — the stones, your notes and the statuses — while sourcing help is switched on, because that is what pricing a job requires, and the app says so where you switch it on. The switch is in the app itself, on the Account tab, beside "Sourcing help". Turning it off records an instruction on your account that your projects are not to be read for pricing, and we follow it; it is not a lock on the file, because the projects are held on this server either way, and we would rather say so than imply a control that does not exist. An earlier version of this notice said staff could not read a project at all; that was wrong, and it is corrected here rather than quietly.
No other subscriber sees anything of yours.
On a single server rented from Hostinger and operated by us, in the country being stated here. Backups are held on the same server and by the hosting provider. Nothing is copied to an analytics or advertising service.
These are the only outside parties involved, and only for these purposes:
The stone identification service is not an outside party: it runs on this same server and sends nothing anywhere.
Goes: the sign-in, the password, two-factor and its recovery codes, every session, every outstanding link and any unused invitation, everything the app saved for you — projects, assistant questions, sourcing enquiries, the consent record — and every identification that was never approved, with its photographs. What the app saved is moved to an archive for thirty days in case it was a mistake, and then deleted by the daily sweep. An administrator can put it back inside those thirty days, but only onto an account that exists, so if it was a mistake say so before the thirty days are up and the account can be recreated under the same name first.
Stays: an identification you confirmed that was then approved as a library reference — the photograph and the record around it, including what you typed beside it, because other people's results are matched against it — and the log of actions taken on the account, for the 24 months above. If you would rather an approved reference went as well, ask; it can be taken out of the index.
Adding StoneDex to your home screen, or simply opening it twice, leaves things on the device itself. They are yours, they are not sent anywhere, and they go when you sign out or clear the app's data:
One cookie, named sdx. It holds a random session token and nothing else: no name, no
email, no identifier that follows you anywhere. It is HttpOnly, Secure and
SameSite=Lax, and it lasts 90 days or until you sign out — the same 90 days as the session behind it. There are no other cookies and
no third-party cookies, so there is no consent banner to click past.
StoneDex is a tool for a trade and is not directed at children. Accounts are created by an administrator for named people at work.
If this notice changes in a way that matters we will say so in the app rather than quietly re-dating the page. To ask anything about your data, or to complain, write to sarmad.alsadi@gmail.com, or by post to the registered address being added here. We answer within 30 days. Under UAE Federal Decree-Law No. 45 of 2021 you may also complain to the UAE Data Office.
The terms are the other half of this: what StoneDex is, what it does not certify, and how it is paid.
StoneDex · Privacy · Support · last updated 4 September 2026