Last updated: August 7, 2026
Privacy Policy
StackShield ("we," "us," "our") operates a beta security scanning and remediation service for Supabase, GitHub, and Vercel projects. This Privacy Policy explains what we collect, how we use it, and your rights, for the duration of the beta program (capped at approximately 100 users).
1. What we collect
| Data | Why |
|---|---|
| Account email | Login, account recovery, service notifications |
| OAuth/API tokens for Supabase, GitHub, Vercel (whichever you connect) | To run scans and apply fixes you approve |
| Your encrypted BYOK AI provider API key | To route fix analysis through the AI provider you connect (currently Ollama Cloud) |
| Scan findings and receipt data (timestamps, findings summary, receipt IDs) | To show scan history and generate remediation receipts |
| Minimum code or configuration snippets needed to detect an issue | To identify vulnerabilities and propose fixes |
We do not request or store more access than is needed to perform the scans and fixes you initiate. For Supabase and GitHub, we connect exclusively via OAuth (short-lived, scoped tokens) — we never ask you to paste a personal access token. For Vercel, we accept an API token and project ID, which are discarded when you disconnect or refresh the page.
2. How code and configuration snippets are handled
Snippets are used transiently to detect issues and generate proposed fixes, and are sent to the AI provider you connected under your own BYOK key for analysis. Scan results and the snippets used to produce them are not persisted in our database. There is no stored scan-history table — once a scan completes and results are returned to you in your browser session, nothing about its contents remains on our servers. (Metadata like timestamps and receipt IDs, described in Section 1, may still be retained for your records — that's separate from the underlying code/config content itself.)
3. Storage and security
OAuth tokens, API tokens, and your BYOK AI key are stored encrypted at rest (AES-256-GCM) and are never stored, logged, or transmitted in plaintext. Access to production systems storing this data is restricted to what's necessary to operate the Service. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Scoped access. For Supabase and GitHub, we connect exclusively through OAuth (secure sign-in) — we never ask for personal access tokens. We hold only a short-lived access token and an encrypted refresh token, scoped to the organisation or project you approve at consent time — not account-wide access. Tokens are refreshed server-side, are never sent to your browser, and disconnecting from StackShield revokes the grant with the provider before we delete our copy. For Vercel, we accept an API token and project ID, which are used only for the duration of your scan and are discarded when you disconnect or refresh the page.
4. Who we share data with
We do not sell your data to third parties, ever. We share data only with the following categories of service providers, solely to operate the Service:
- Polar — payment processing (paid plans only)
- Our hosting and database provider (Supabase) — application hosting and database
- Ollama Cloud — only under your own BYOK credentials, at your direction, when you run a scan or fix
- Our email delivery provider — account and product emails (signup confirmation, password reset)
5. Data retention and deletion
You can delete your account at any time, instantly, from Settings → Account → Delete Account — no email request or waiting period required. On confirmation, your account, encrypted tokens, stored BYOK key, and all associated records are permanently and immediately deleted (cascading deletion across all linked data — there is no backup or recovery copy retained). If you have an active paid subscription, it is automatically cancelled as part of the deletion process, so you will not continue to be billed after your account is gone.
The following limited records are not covered by account deletion, and are retained separately:
- Payment records held by our payment processor (Polar) for accounting, tax, and fraud-prevention purposes, per their own retention policies.
- Structured operational logs (which may include your user ID and request timestamps, used for debugging and abuse prevention) are retained for a limited period as part of normal system operation, and are not linked back to a deleted account's personal profile.
6. Your rights
Regardless of where you're located, you can ask us to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (see Section 5 — or do it yourself instantly in Settings)
- Export your account data in a portable format
Contact contact@stackshield.org to exercise any of these. If you're in Kenya, the Kenya Data Protection Act 2019 applies to your data and your rights under it. If you're in the EU/UK or another jurisdiction with specific data protection rights (e.g., GDPR, CCPA), those rights apply to you in addition to what's described here.
7. Security incidents
If we become aware of a security incident affecting your account data or connected tokens, we will notify affected users without undue delay by email, and take reasonable steps to contain and remediate the issue.
8. Cookies
See our Cookie Policy for details on essential and analytics cookies used on this site.
9. Children's privacy
The Service is not directed to individuals under 18, and we do not knowingly collect data from them.
10. International users
Because StackShield is beta software with a small, global cohort, your data may be processed in a country other than your own. By using the Service, you consent to this transfer, which we handle using reasonable safeguards.
11. Sub-processors
We use the following third-party service providers to operate the Service. Each provider processes data on our behalf and under our instructions:
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Application hosting and database | Account data, encrypted tokens, scan metadata | United States |
| Polar | Payment processing | Payment details, subscription status | United States |
| Ollama Cloud | AI analysis (BYOK — your own key) | Code/config snippets (transient, not stored) | Varies by provider |
| Email delivery provider | Account and product emails | Email address only | United States |
We will update this list if we add or replace sub-processors. Material changes will be notified to active users by email or in-app notice.
12. Data Processing Addendum (DPA)
Where applicable data protection law requires a data processing agreement (e.g., GDPR Art. 28), this Privacy Policy serves as that agreement. By using the Service, you acknowledge that:
- Roles: You are the data controller; StackShield is the data processor. We process your data only on your documented instructions (i.e., to perform scans and fixes you initiate).
- Purpose limitation: We process data solely for the purposes described in this Privacy Policy. We do not use your data for marketing, profiling, or any purpose other than operating the Service.
- Confidentiality: Access to your data is restricted to personnel who need it to operate the Service, and they are bound by confidentiality obligations.
- Security: We implement appropriate technical and organizational measures including encryption at rest (AES-256-GCM), encrypted transmission (TLS), and access controls (see Section 3).
- Sub-processors: We engage sub-processors as listed in Section 11. Each sub-processor is contractually bound to process data only on our instructions and with appropriate security measures.
- Data subject assistance: We will assist you in responding to data subject requests (access, correction, deletion) by providing the tools described in Sections 5 and 6 of this Privacy Policy.
- Breach notification: We will notify you without undue delay (and no later than 72 hours) after becoming aware of a personal data breach affecting your data (see Section 7).
- Deletion on termination: Upon account deletion or termination, we will delete or return all personal data and delete existing copies, except where retention is required by applicable law (see Section 5).
If you require a separately executed DPA (e.g., for enterprise procurement or GDPR Art. 28(2) compliance), contact contact@stackshield.org and we will provide one.
13. Changes to this policy
We may update this Privacy Policy as the beta evolves. We'll update the "Last updated" date above and notify active users of material changes by email or in-app notice.
14. Contact
For privacy inquiries or to exercise your data rights: contact@stackshield.org