Skip to main content

Last updated: August 7, 2026

Privacy Policy

StackShield ("we," "us," "our") operates a beta security scanning and remediation service for Supabase, GitHub, and Vercel projects. This Privacy Policy explains what we collect, how we use it, and your rights, for the duration of the beta program (capped at approximately 100 users).

1. What we collect

DataWhy
Account emailLogin, account recovery, service notifications
OAuth/API tokens for Supabase, GitHub, Vercel (whichever you connect)To run scans and apply fixes you approve
Your encrypted BYOK AI provider API keyTo route fix analysis through the AI provider you connect (currently Ollama Cloud)
Scan findings and receipt data (timestamps, findings summary, receipt IDs)To show scan history and generate remediation receipts
Minimum code or configuration snippets needed to detect an issueTo identify vulnerabilities and propose fixes

We do not request or store more access than is needed to perform the scans and fixes you initiate. For Supabase and GitHub, we connect exclusively via OAuth (short-lived, scoped tokens) — we never ask you to paste a personal access token. For Vercel, we accept an API token and project ID, which are discarded when you disconnect or refresh the page.

2. How code and configuration snippets are handled

Snippets are used transiently to detect issues and generate proposed fixes, and are sent to the AI provider you connected under your own BYOK key for analysis. Scan results and the snippets used to produce them are not persisted in our database. There is no stored scan-history table — once a scan completes and results are returned to you in your browser session, nothing about its contents remains on our servers. (Metadata like timestamps and receipt IDs, described in Section 1, may still be retained for your records — that's separate from the underlying code/config content itself.)

3. Storage and security

OAuth tokens, API tokens, and your BYOK AI key are stored encrypted at rest (AES-256-GCM) and are never stored, logged, or transmitted in plaintext. Access to production systems storing this data is restricted to what's necessary to operate the Service. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Scoped access. For Supabase and GitHub, we connect exclusively through OAuth (secure sign-in) — we never ask for personal access tokens. We hold only a short-lived access token and an encrypted refresh token, scoped to the organisation or project you approve at consent time — not account-wide access. Tokens are refreshed server-side, are never sent to your browser, and disconnecting from StackShield revokes the grant with the provider before we delete our copy. For Vercel, we accept an API token and project ID, which are used only for the duration of your scan and are discarded when you disconnect or refresh the page.

4. Who we share data with

We do not sell your data to third parties, ever. We share data only with the following categories of service providers, solely to operate the Service:

  • Polar — payment processing (paid plans only)
  • Our hosting and database provider (Supabase) — application hosting and database
  • Ollama Cloud — only under your own BYOK credentials, at your direction, when you run a scan or fix
  • Our email delivery provider — account and product emails (signup confirmation, password reset)

5. Data retention and deletion

You can delete your account at any time, instantly, from Settings → Account → Delete Account — no email request or waiting period required. On confirmation, your account, encrypted tokens, stored BYOK key, and all associated records are permanently and immediately deleted (cascading deletion across all linked data — there is no backup or recovery copy retained). If you have an active paid subscription, it is automatically cancelled as part of the deletion process, so you will not continue to be billed after your account is gone.

The following limited records are not covered by account deletion, and are retained separately:

  • Payment records held by our payment processor (Polar) for accounting, tax, and fraud-prevention purposes, per their own retention policies.
  • Structured operational logs (which may include your user ID and request timestamps, used for debugging and abuse prevention) are retained for a limited period as part of normal system operation, and are not linked back to a deleted account's personal profile.

6. Your rights

Regardless of where you're located, you can ask us to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data (see Section 5 — or do it yourself instantly in Settings)
  • Export your account data in a portable format

Contact contact@stackshield.org to exercise any of these. If you're in Kenya, the Kenya Data Protection Act 2019 applies to your data and your rights under it. If you're in the EU/UK or another jurisdiction with specific data protection rights (e.g., GDPR, CCPA), those rights apply to you in addition to what's described here.

7. Security incidents

If we become aware of a security incident affecting your account data or connected tokens, we will notify affected users without undue delay by email, and take reasonable steps to contain and remediate the issue.

8. Cookies

See our Cookie Policy for details on essential and analytics cookies used on this site.

9. Children's privacy

The Service is not directed to individuals under 18, and we do not knowingly collect data from them.

10. International users

Because StackShield is beta software with a small, global cohort, your data may be processed in a country other than your own. By using the Service, you consent to this transfer, which we handle using reasonable safeguards.

11. Sub-processors

We use the following third-party service providers to operate the Service. Each provider processes data on our behalf and under our instructions:

ProviderPurposeData processedLocation
SupabaseApplication hosting and databaseAccount data, encrypted tokens, scan metadataUnited States
PolarPayment processingPayment details, subscription statusUnited States
Ollama CloudAI analysis (BYOK — your own key)Code/config snippets (transient, not stored)Varies by provider
Email delivery providerAccount and product emailsEmail address onlyUnited States

We will update this list if we add or replace sub-processors. Material changes will be notified to active users by email or in-app notice.

12. Data Processing Addendum (DPA)

Where applicable data protection law requires a data processing agreement (e.g., GDPR Art. 28), this Privacy Policy serves as that agreement. By using the Service, you acknowledge that:

  • Roles: You are the data controller; StackShield is the data processor. We process your data only on your documented instructions (i.e., to perform scans and fixes you initiate).
  • Purpose limitation: We process data solely for the purposes described in this Privacy Policy. We do not use your data for marketing, profiling, or any purpose other than operating the Service.
  • Confidentiality: Access to your data is restricted to personnel who need it to operate the Service, and they are bound by confidentiality obligations.
  • Security: We implement appropriate technical and organizational measures including encryption at rest (AES-256-GCM), encrypted transmission (TLS), and access controls (see Section 3).
  • Sub-processors: We engage sub-processors as listed in Section 11. Each sub-processor is contractually bound to process data only on our instructions and with appropriate security measures.
  • Data subject assistance: We will assist you in responding to data subject requests (access, correction, deletion) by providing the tools described in Sections 5 and 6 of this Privacy Policy.
  • Breach notification: We will notify you without undue delay (and no later than 72 hours) after becoming aware of a personal data breach affecting your data (see Section 7).
  • Deletion on termination: Upon account deletion or termination, we will delete or return all personal data and delete existing copies, except where retention is required by applicable law (see Section 5).

If you require a separately executed DPA (e.g., for enterprise procurement or GDPR Art. 28(2) compliance), contact contact@stackshield.org and we will provide one.

13. Changes to this policy

We may update this Privacy Policy as the beta evolves. We'll update the "Last updated" date above and notify active users of material changes by email or in-app notice.

14. Contact

For privacy inquiries or to exercise your data rights: contact@stackshield.org