Skip to content

Legal

Privacy Policy

What we collect, why, who it goes to, how long we keep it, and how to get it all back. Written to be read rather than to be defensible.

Draft pending legal review. This document is written to be honest and readable, but it has not yet been reviewed by a lawyer. Questions in the meantime go to support@stacked.app.

Last updated

This policy explains what we collect, why, and what you can do about it. It is written for a person, not for a compliance auditor, and it does not use "we may collect" to hide what we actually collect.

Stacked is operated by a sole trader in the United Kingdom, acting as the data controller for account data and as a processor for the content you put into the service. Contact: support@stacked.app.

The three promises this policy exists to keep

  1. We do not sell or share your data with anyone for their own purposes. Not to advertisers, not to data brokers, not to "partners".
  2. We do not train shared AI models on your content. Your material builds your own voice model and runs the tools you enabled. Nothing crosses between workspaces.
  3. You can take everything and leave, whenever you want, including after you cancel.

What we collect

Account data

Your email address, name and avatar if you provide one, timezone, language and theme preference, and the identity provider you signed in with. We never receive or store a password, because there is no password field anywhere in Stacked.

Workspace and billing data

Workspace name, plan, members and their roles, invoices and subscription state. Card details go directly to Stripe and never touch our servers — we store a customer id and the last four digits Stripe gives us for display.

Connected account data

For each platform you connect: the access tokens (encrypted at rest), the account identifiers, and whatever the connected tools need — posts and their metrics, comments, community messages for channels you have enabled, subscriber lists, orders, transcripts, calendar availability. What is collected is determined by which tools you enable, and each connection screen states it before you authorise.

Content you create

Uploads, drafts, edits, published actions, media renders and transcripts.

Usage data

Pages viewed, tools opened, features used and errors hit, via PostHog with IP anonymisation enabled. Plus server logs — request paths, status codes, timings — kept for 30 days for debugging and abuse prevention.

What we do not collect

  • Card numbers, CVCs, or bank details.
  • Passwords.
  • Direct messages or private channels you have not explicitly enabled.
  • Your contacts, your browsing history outside our own site, or anything from device fingerprinting.
  • Marketing cookies or cross-site trackers of any kind.

Why we process it, and on what basis

WhatWhyLegal basis
Account and workspace dataRun your account, authenticate youContract
Connected account dataOperate the tools you enabledContract
Content and draftsGenerate, store and publish your workContract
Billing dataTake payment, meet tax obligationsContract, legal obligation
Product analyticsUnderstand which features workLegitimate interests
Security logsPrevent abuse and fraudLegitimate interests
Product emailsTrial, billing and incident noticesContract
Marketing emailsTell you about new toolsConsent, opt in

AI processing

Drafts are generated by third-party model providers. When a tool runs, the relevant content — a transcript, a comment, a post you wrote — is sent to the model provider to produce a draft.

  • Providers are engaged under agreements that prohibit training on our data.
  • Content is not retained by providers beyond the short abuse-monitoring window their terms require.
  • Your voice model is scoped to your workspace and never applied to anyone else's.
  • The current list of providers is on the subprocessors page, which we update before a new one starts processing.

Who we share data with

Only the subprocessors listed on the subprocessors page — hosting, storage, email delivery, payments, analytics, model providers — each under a data processing agreement, each only for the purpose stated there.

Plus the platforms you connect, when you publish to them. That is you posting to your own account, through us.

We will disclose data if legally compelled. Where we are allowed to tell you, we will.

International transfers

Data is hosted in the EU and, for some subprocessors, the United States. Transfers outside the UK and EEA rely on Standard Contractual Clauses or an adequacy decision, and each transfer is noted on the subprocessors page.

How long we keep things

DataRetention
Account and workspaceWhile the account exists
Content, drafts, mediaWhile the account exists, then 90 days after cancellation
Connected account tokensUntil you disconnect, or 90 days after cancellation
Invoices7 years, because tax law requires it
Server logs30 days
Product analytics24 months
Deleted account dataPurged within 30 days of a deletion request

Your rights

Wherever you live, you can:

  • See it. Export everything from Settings → Data as JSON plus original files.
  • Correct it. Edit anything in the app, or ask us.
  • Delete it. Settings → Profile → Delete account removes the workspace and starts the purge.
  • Take it elsewhere. The export is machine-readable and yours.
  • Object. Turn off analytics from the cookie notice or by emailing us.
  • Complain. In the UK, to the Information Commissioner's Office. In the EU, to your local supervisory authority.

We answer requests within 30 days, usually within two business days.

Security

  • All traffic over TLS. All data encrypted at rest.
  • Connected account tokens encrypted with a separate key.
  • Row-level isolation between workspaces, enforced in the database rather than only in application code.
  • Access to production data is limited to what is needed to answer a support request or fix a fault, and it is logged.
  • We will notify affected users and the relevant regulator within 72 hours of becoming aware of a personal data breach.

Children

Stacked is not for under-16s and we do not knowingly collect their data. If you believe a child has an account, email us and we will delete it.

Changes

Material changes are emailed to account owners at least 30 days before they take effect, and every version is dated at the top of this page.

Contact

support@stacked.app. A person reads it.