STACK
MENU

Privacy notice

This notice explains what STACK collects, why it is used and the choices available to you.

UPDATED 2026-09-10

1 · ABOUT THIS NOTICE

STACK is operated from Stockholm, Sweden. This notice covers the website, Console, API, MCP server and other STACK services. Privacy laws apply according to their territorial scope.

2 · DATA WE HOLD

Account data includes your email, operator profile, membership, billing status, API-key hash, agent IDs and Passport metadata. Stripe handles card details; STACK does not receive full card numbers. Identity data is processed only when you start a verification flow. Stored identity claims are encrypted, and Passports use opaque references instead of embedding the underlying identity evidence. Authority data includes the evidence, scope, approvals, status and records needed to issue and verify authority. Generated disclosure payloads are not stored; active signed requests are stored encrypted. Service data includes encrypted credentials, audit and security records, notification destinations, customer-supplied drop-offs, encrypted sealed-skill inputs and outputs, and the final screened and redacted response from a non-GET proxy operation. That proxy response is encrypted and readable for up to 24 hours. Analytics and diagnostic data can include route paths, timestamps, operator IDs, errors, IP addresses and user agents. The current dashboard keeps its signed session token in an HTTP-only cookie and in browser local storage for up to 24 hours.

3 · HOW WE USE DATA

We use data to provide and bill for STACK, secure the service, keep the audit record, deliver messages and understand product use. Under the GDPR, service and billing data is processed to perform the contract; security, audit and limited service analytics rely on our legitimate interests in operating and protecting STACK; optional browser analytics uses consent where required; and records are kept where the law requires it. The basis for identity verification depends on the provider and flow you choose.

4 · BROWSER STORAGE & ANALYTICS

Necessary browser storage supports authentication, OAuth request safety, return paths and your privacy choice. The session expires after 24 hours. Your privacy choice remains until you change it or clear site data. When PostHog browser analytics is configured, visitors in the EU, EEA and UK, and visitors whose country cannot be determined, are asked before it starts. Visitors elsewhere can turn it off through Cookie settings in the footer. Server-side service events do not read or store information in your browser and are not controlled by that setting.

STACK disables session replay, automatic element capture, campaign and referrer capture, and PostHog GeoIP enrichment. Query strings and fragments are removed before browser analytics is sent. Network providers still process an IP address to deliver and protect a request.

5 · SERVICE PROVIDERS & OTHER RECIPIENTS

FLY.IO · STOCKHOLM AND FRANKFURTApplication hosting and managed PostgreSQL for service and account data.
UPSTASH REDIS · STOCKHOLMShort-lived security and service state, including revocation, replay protection and rate limits.
CLOUDFLARE · GLOBAL NETWORKDNS, delivery, security, Turnstile and isolated storage for the public attack playground.
AWS · STOCKHOLMKMS key operations and audit archive storage when the archive is enabled.
POSTHOG CLOUD EU · EUBrowser analytics where enabled and account-linked service milestones. Session replay is disabled.
STRIPE · PROVIDER DEPENDENTSubscriptions, wallet payments, payouts and optional identity verification.
RESEND · PROVIDER DEPENDENTMagic-link, account, security and notification email delivery.
TWILIO · PROVIDER DEPENDENTSMS delivery when an operator configures an SMS notification.
SENTRY · EU PROJECTApplication error and performance monitoring. Session replay is disabled.
OPENROUTER · PROVIDER AND MODEL DEPENDENTRouting for LLM-backed detectors, sealed skill steps and the public attack challenge.
FASTMAIL · PROVIDER DEPENDENTEmail received through STACK addresses, including the public attack challenge mailbox.

Conditional providers receive data only when you use their feature. Content sent through an LLM-backed feature can be processed by OpenRouter and the selected model provider. Services, identity providers, webhook destinations and authority receivers selected by a customer receive the data needed for that customer-directed request.

6 · RETENTION & ERASURE

AUDIT RECORDS - FREE / DEVELOPER / PRO / BUSINESS / ENTERPRISE7 D / 30 D / 1 YR / 2 YR / 365 D MIN
VAULT ENTRIESUNTIL DELETED OR THE ACCOUNT IS ERASED
ENCRYPTED PROXY RESPONSE PAYLOADSUP TO 24 HOURS
AUTHORITY EVIDENCEUNTIL EXPLICITLY ERASED
SEALED-SKILL INPUTS AND OUTPUTSUNTIL ACCOUNT ERASURE
MAGIC LINKS15 MIN, SINGLE-USE
ATTACK-PLAYGROUND ENTRIESUNTIL MANUALLY DELETED

After 24 hours, STACK scrubs the stored proxy response body and headers while retaining non-payload operation metadata, timestamps and hashes. Revoking authority changes whether it is valid; it does not delete the evidence. Account erasure locks the account first, then retries deletion from the database and any configured audit archive until it succeeds. Some providers can retain records under their own legal and security obligations.

7 · WHERE DATA LIVES

STACK applications run in Stockholm and the managed PostgreSQL database runs in Frankfurt. AWS KMS key operations use the Stockholm region. PostHog uses its EU service. Email, SMS, billing, identity, monitoring, mailbox and LLM providers can process data in other countries according to the service and provider used.

8 · YOUR RIGHTS

Where the GDPR applies, you can request access, correction, erasure, portability or restriction, object to processing based on legitimate interests, and withdraw consent. We normally respond within one month; the law permits an extension for complex or numerous requests. You can start account erasure from Console Settings, or email hello@getstack.run. You can also complain to the Swedish Authority for Privacy Protection, IMY, or your local supervisory authority.

9 · SECURITY

STACK encrypts data in transit and encrypts stored credentials with AWS KMS. Passports are signed and STACK checks revocation whenever it verifies one online. Authority presentations are signed and encrypted to their intended receiver. Audit records are hash-chained so changes can be detected.

10 · CHILDREN

STACK is developer infrastructure and is not directed at children. If you believe a child provided personal data, email hello@getstack.run.

11 · AUTOMATED DECISIONS

STACK does not use personal data to make legal or similarly significant decisions about a person. Detectors evaluate agent activity and can record, notify or block according to the operator's policy. They do not set a person's price or close an account.

12 · CONTACT & CHANGES

Privacy questions, complaints and rights requests go to hello@getstack.run. The date at the top changes when this notice changes.

stack | Privacy