Privacy Policy
Last updated: [DATE]
1. Who we are
[LEGAL BUSINESS NAME] ([CONTACT EMAIL]) is the data controller for personal data processed through Stackyard.
2. What we collect
| Data | What it is | Why |
|---|---|---|
| Account data | Email address, authentication details | To create and secure your account |
| API key(s) | Your Google Gemini API key(s), encrypted at rest | So apps can make AI requests on your behalf |
| App data | Data you save within an app (app_data) | So your saved data (e.g. notes, history) persists across sessions/devices |
| Community data | Data you choose to publish via an app's shared/community feature (community_data) | Visible to other subscribers using that app, by your choice |
| Subscription/billing data | Managed by Stripe — we hold your subscription status and Stripe customer ID, never your full card details | To manage your subscription |
| Basic technical data | Standard server logs (e.g. for debugging/security) | To operate and secure the Service |
We do not sell your data.
3. Legal basis for processing
- Account, app, and billing data: necessary to perform our contract with you (providing the Service you've subscribed to).
- Community data: based on your explicit choice/consent each time you publish something via a community feature.
- Security/technical logs: our legitimate interest in keeping the Service secure and functioning.
4. Where your data is stored
Our database is hosted in the UK (London region). Your Gemini API requests are sent, using your own key, directly to Google's Gemini API in accordance with Google's own privacy terms — we are not a party to that request beyond relaying it, and Google's handling of that data is governed by Google's own policies, not this one.
5. Who we share data with
- Stripe — payment processing. Stripe handles your card details directly; we never see or store full card numbers.
- Google — your Gemini API key and prompts are sent to Google's Gemini API to generate AI responses, since Stackyard is BYOK (bring-your-own-key). This happens using your own key, effectively as if you'd made the request yourself.
- We don't share your personal data with any other third party except where required by law.
6. Community/shared data
If you publish data via an app's community feature, other subscribers using that app can see it. We strip identifying information (your user ID) before other users can see published entries — the app itself has no way to know who published what. However, you're responsible for not including personal or identifying information in anything you choose to publish this way.
7. How long we keep your data
We keep your data while your account is active. If you delete your account, we delete your account data, your saved app data, and your published community data, and cancel your Stripe subscription (see "Your rights" below for full deletion details). Some records may be retained briefly where we have a legal obligation to do so (e.g. billing records for tax purposes).
8. Your rights (UK GDPR)
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data ("right to erasure") — available directly in-app via account settings, or by contacting us.
- Request a copy of your data in a portable format.
- Object to certain processing.
- Complain to the UK Information Commissioner's Office (ICO) if you believe we've mishandled your data.
To exercise any of these rights, contact [CONTACT EMAIL].
9. Cookies & tracking
[Fill in based on actual analytics/tracking used, if any — if none beyond strictly necessary session/auth cookies, state that plainly.]
10. Children
Stackyard is not directed at, and should not be used by, anyone under 16. We don't knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time; material changes will be flagged in-app where practical.
12. Contact
[CONTACT EMAIL].