Privacy Policy

Last updated: [DATE]

1. Who we are

[LEGAL BUSINESS NAME] ([CONTACT EMAIL]) is the data controller for personal data processed through Stackyard.

2. What we collect

DataWhat it isWhy
Account dataEmail address, authentication detailsTo create and secure your account
API key(s)Your Google Gemini API key(s), encrypted at restSo apps can make AI requests on your behalf
App dataData you save within an app (app_data)So your saved data (e.g. notes, history) persists across sessions/devices
Community dataData you choose to publish via an app's shared/community feature (community_data)Visible to other subscribers using that app, by your choice
Subscription/billing dataManaged by Stripe — we hold your subscription status and Stripe customer ID, never your full card detailsTo manage your subscription
Basic technical dataStandard server logs (e.g. for debugging/security)To operate and secure the Service

We do not sell your data.

3. Legal basis for processing

  • Account, app, and billing data: necessary to perform our contract with you (providing the Service you've subscribed to).
  • Community data: based on your explicit choice/consent each time you publish something via a community feature.
  • Security/technical logs: our legitimate interest in keeping the Service secure and functioning.

4. Where your data is stored

Our database is hosted in the UK (London region). Your Gemini API requests are sent, using your own key, directly to Google's Gemini API in accordance with Google's own privacy terms — we are not a party to that request beyond relaying it, and Google's handling of that data is governed by Google's own policies, not this one.

5. Who we share data with

  • Stripe — payment processing. Stripe handles your card details directly; we never see or store full card numbers.
  • Google — your Gemini API key and prompts are sent to Google's Gemini API to generate AI responses, since Stackyard is BYOK (bring-your-own-key). This happens using your own key, effectively as if you'd made the request yourself.
  • We don't share your personal data with any other third party except where required by law.

6. Community/shared data

If you publish data via an app's community feature, other subscribers using that app can see it. We strip identifying information (your user ID) before other users can see published entries — the app itself has no way to know who published what. However, you're responsible for not including personal or identifying information in anything you choose to publish this way.

7. How long we keep your data

We keep your data while your account is active. If you delete your account, we delete your account data, your saved app data, and your published community data, and cancel your Stripe subscription (see "Your rights" below for full deletion details). Some records may be retained briefly where we have a legal obligation to do so (e.g. billing records for tax purposes).

8. Your rights (UK GDPR)

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data ("right to erasure") — available directly in-app via account settings, or by contacting us.
  • Request a copy of your data in a portable format.
  • Object to certain processing.
  • Complain to the UK Information Commissioner's Office (ICO) if you believe we've mishandled your data.

To exercise any of these rights, contact [CONTACT EMAIL].

9. Cookies & tracking

[Fill in based on actual analytics/tracking used, if any — if none beyond strictly necessary session/auth cookies, state that plainly.]

10. Children

Stackyard is not directed at, and should not be used by, anyone under 16. We don't knowingly collect data from children.

11. Changes to this policy

We may update this policy from time to time; material changes will be flagged in-app where practical.

12. Contact

[CONTACT EMAIL].