Privacy Policy
Last updated: March 19, 2026
Stackteryx Inc. (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Stackteryx platform (“Service”). Please read this policy carefully. By using the Service, you consent to the data practices described herein.
1. INFORMATION WE COLLECT
1.1 Information You Provide
We collect information you directly provide, including:
- Account Information: Name, email address, password, and organization details when you create an account.
- Business Data: Tool catalogs, vendor information, service configurations, client details, pricing data, and proposals you create within the Service.
- Communication Data: Messages sent through the Intelligence Chat, support requests, and feedback you provide.
- Payment Information: Billing details processed through Stripe. We do not store full credit card numbers on our servers.
1.2 Information Collected Automatically
When you use the Service, we automatically collect certain information:
- Usage Data: Pages visited, features used, actions taken, and time spent on the Service.
- Device Information: Browser type, operating system, device type, and screen resolution.
- Log Data: IP address, access times, referring URLs, and error logs.
- Cookies: Session cookies for authentication and preferences. See our cookie practices below.
1.3 Information from Third Parties
We may receive information from third-party services you connect, including Google (for OAuth authentication) and Stripe (for payment status). We only collect information necessary to operate the Service.
2. HOW WE USE YOUR INFORMATION
2.1 Service Operation
We use your information to provide, maintain, and improve the Service, including processing your business data, generating AI-powered outputs, and managing your account.
2.2 AI Processing
Your business data (tool catalogs, service configurations, client information) is sent to AI providers (currently Anthropic) to generate proposals, CTO briefs, compliance analysis, and other AI-powered features. This data is processed in real-time and is not used by AI providers to train their models.
2.3 Communication
We may use your email address to send transactional emails (account verification, password resets, billing receipts), service announcements, and product updates. You may opt out of non-essential communications at any time.
2.4 Analytics and Improvement
We use aggregated, anonymized usage data to understand how Users interact with the Service, identify areas for improvement, and develop new features.
2.5 Security
We use log data and usage patterns to detect and prevent fraud, abuse, and unauthorized access to the Service.
2.6 Legal Compliance
We may process your information to comply with applicable laws, regulations, legal processes, or governmental requests.
3. HOW WE SHARE YOUR INFORMATION
3.1 Service Providers
We share information with third-party service providers who assist in operating the Service:
- Supabase: Database hosting and user authentication.
- Stripe: Payment processing and subscription management.
- Anthropic: AI model processing for content generation.
- Vercel: Application hosting and delivery.
- Sentry: Error monitoring and application performance tracking. May receive anonymized error logs to help us identify and fix issues.
3.2 Within Your Organization
If you are part of an organization account, your activity and data within the Service may be visible to other members of your organization based on their permission level.
3.3 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Stackteryx Inc., our Users, or the public.
3.4 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of the transaction. We will notify you of any such change.
3.5 No Sale of Data
We do not sell, rent, or trade your personal information or business data to third parties for marketing or advertising purposes.
4. DATA STORAGE AND SECURITY
4.1 Storage Location
Your data is stored on servers provided by Supabase and Vercel, primarily located in the United States. By using the Service, you consent to the transfer and storage of your data in the United States.
4.2 Security Measures
We implement industry-standard security measures including encryption in transit (TLS/SSL), encryption at rest, row-level security policies, secure authentication (including MFA support), and regular security audits.
4.3 Limitations
While we strive to protect your information, no electronic storage or transmission method is 100% secure. We cannot guarantee absolute security and are not responsible for unauthorized access resulting from factors beyond our reasonable control.
5. DATA RETENTION
We retain your data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete your data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, dispute resolution). Aggregated, anonymized data may be retained indefinitely for analytics purposes.
6. YOUR RIGHTS AND CHOICES
6.1 Access and Portability
You have the right to access your data and export it using the Service's built-in export features (PDF, DOCX exports for proposals and briefs).
6.2 Correction
You may update or correct your account information at any time through the Settings page.
6.3 Deletion
You may request deletion of your account and associated data by contacting support. Account deletion is permanent and cannot be reversed after the 30-day retention period.
6.4 Communication Preferences
You may opt out of non-essential emails by using the unsubscribe link in any marketing email or by updating your preferences in Settings.
6.5 Cookie Preferences
You may control cookies through your browser settings. Disabling essential cookies may affect Service functionality (e.g., authentication).
6.6 California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what data we collect, the right to request deletion, and the right to opt out of data sales (we do not sell data).
6.7 European Residents
If you are located in the European Economic Area (EEA), you have additional rights under GDPR, including the right to access, rectification, erasure, data portability, and the right to object to processing. Contact us to exercise these rights.
7. CHILDREN’S PRIVACY
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly.
8. THIRD-PARTY LINKS
The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access.
9. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before they take effect. Your continued use of the Service after changes constitutes acceptance of the updated policy. The “Last updated” date at the top of this page indicates when the policy was last revised.
10. CONTACT US
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@stackteryx.com
- Legal inquiries: legal@stackteryx.com