Stackness

Privacy policy

Last updated: 2026-08-15

This policy explains what personal data Stackness processes, why, and what rights you have. It is written to satisfy both the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (revFADP).

1. Controller

The controller responsible for processing your personal data is Sergei Gordeichuk, a private individual resident in Switzerland. There is no company or other legal entity behind Stackness.

Contact: legal@stackness.dev. A full postal address is not published here for personal-safety reasons; it is available on request to that email address.

2. Scope and applicable law

Stackness is operated from Switzerland and hosted on servers in the European Union. Processing is governed by the Swiss revFADP and, where it applies to you as an EU/EEA resident or to processing carried out in the EU, the GDPR. Where the two laws differ, we apply the standard that is more protective of you.

3. Personal data we process

  • Account data: email address and a bcrypt hash of your password (we never store the password itself).
  • OAuth sign-in data: if you sign in with GitHub or Google, we receive your basic profile from that provider (account identifier, email, name, avatar). We do not receive your password.
  • Profile data: display name, bio, and avatar image you choose to upload.
  • Content you create: stacks, moves, comments, and reactions. Public content is visible to anyone, including search engines - see section 4a.
  • Technical data: your IP address, used transiently for rate limiting and abuse prevention, and a refresh-token cookie used to keep you signed in (see the Cookie policy).
  • Billing data: if you become a supporter or subscribe to a team plan, we store your Stripe customer and subscription identifiers. Your payment card details go directly to Stripe and never touch our servers.
  • Messages you send us: feedback and contact-form submissions.
  • Analytics data (opt-in only): if you accept analytics in the cookie banner, we process usage events (pages viewed, clicks, searches, feature usage) under a pseudonymous analytics identifier, and error reports from your browser session. None of this is collected without your consent.

4. Purposes and legal bases

  • Providing the service (accounts, publishing your content, subscriptions, support) - performance of a contract (Art. 6(1)(b) GDPR).
  • Security and abuse prevention (rate limiting, captcha, moderation) - legitimate interest in keeping the service safe and available (Art. 6(1)(f) GDPR).
  • Transactional email (account and billing notifications) - performance of a contract.
  • Legal compliance (accounting records for paid subscriptions) - legal obligation (Art. 6(1)(c) GDPR).
  • Product analytics and error tracking (PostHog, Sentry) - your consent (Art. 6(1)(a) GDPR), given via the cookie banner and withdrawable at any time through "Cookie settings" in the footer. Nothing is collected before you opt in.

We do not use your data for advertising and we do not sell it. Analytics runs only with your opt-in consent; which cookies and storage entries that involves is listed in the Cookie policy.

4a. Public content and search engines

Stackness is a public platform. Your profile, your stack, your moves, your comments and your reactions are readable without an account, are crawled by search engines such as Google, Bing and DuckDuckGo, and may appear in their search results and in the previews other sites and AI assistants build from them.

Public is the default for new accounts. Every account is created with profile visibility set to "public", which means the profile is listed in our sitemap and offered to crawlers. You can change this at any time in Settings → privacy by setting profile visibility to "logged in only". Your profile is then removed from the sitemap and marked as not to be indexed, and only signed-in users can open it.

Two things this setting does not do: content you posted into shared surfaces (comments on other people's moves, for example) stays visible where it was posted, and pages a search engine already crawled can remain in its index or cache until it recrawls them - see section 7.

5. Recipients and processors

We share personal data only with the service providers needed to run Stackness:

  • Cloudflare - content delivery network and proxy in front of the site, object storage (R2) for uploaded images, and the Turnstile captcha on sign-up and sign-in.
  • Stripe - payment processing for supporter and team subscriptions.
  • Resend - delivery of transactional email.
  • GitHub and Google - only if you choose to sign in with them; they act as identity providers, and their own privacy policies govern what they process.
  • PostHog - product analytics, only if you opt in via the cookie banner. Analytics events are processed in PostHog's EU region.
  • Sentry - error tracking. Browser error reports are sent only if you opt in via the cookie banner; our servers also report their own errors (which contain no tracking identifiers).
  • Our hosting provider - the servers running Stackness are rented from a hosting provider in the EU.

We do not share your data with anyone else.

6. International transfers

The application and database are hosted in the European Union. Switzerland is recognised by the EU as providing adequate data protection, and the EU is recognised as adequate under Swiss law, so data may move between the two freely.

Some providers listed above (Cloudflare, Stripe, Resend, Sentry) are US companies. Transfers to them rely on the EU–US and Swiss–US Data Privacy Frameworks and, where applicable, standard contractual clauses. PostHog analytics data is processed in PostHog's EU region and does not leave the EU.

7. Retention

  • Account and profile data: kept while your account exists, deleted on account deletion (after the 30-day grace period described in section 8).
  • Content: kept until you delete it or your account.
  • Moderation and audit records: abuse reports you filed and the log of administrative actions are retained after account deletion in anonymised form (your account reference is removed), based on our legitimate interest in keeping the service safe and our legal obligations.
  • IP addresses for rate limiting: held only transiently in short-lived counters, not stored in the database.
  • Billing records: kept for the retention period required by Swiss accounting law (10 years).
  • Feedback and support messages: kept as long as needed to handle the request.

Third-party caches and archives. Deleting content or your account removes it from Stackness, but it does not reach copies held elsewhere. Search engines may keep a cached copy of a page until they recrawl it, and web archives, scrapers and AI training sets may hold copies indefinitely. Those copies are outside our control and we cannot promise a timeline for their removal. To have one taken down, use the removal tool of the service that holds it - for example Google's "Remove outdated content" tool. We will confirm on request that the original page is gone from Stackness, which is what those tools ask for.

8. Your rights

Under the GDPR and the revFADP you have the right to:

  • access the personal data we hold about you and be informed about its processing,
  • have inaccurate data rectified,
  • have your data erased,
  • receive your data in a portable, machine-readable format,
  • object to processing based on legitimate interest, and
  • restrict processing in the cases provided by law.

You can exercise erasure and portability yourself in Settings → privacy:

  • Delete account: your account is deactivated and hidden immediately, and permanently erased after a 30-day grace period. During those 30 days you can restore the account by logging in. Erasure removes your profile, stack, moves, comments, reactions, and uploaded images, and cancels any active subscription. Anonymised moderation and audit records and billing records are retained as described in section 7. Published blog posts and community tool entries remain, attributed to "Deleted user". Copies held in search-engine caches and web archives are outside our control - section 7 explains how to request their removal.
  • Export my data: requests a machine-readable JSON archive of your profile, stack, moves, comments, reactions, saved items, and follows. A time-limited download link is emailed to you.

For anything else - or if you cannot access your account - email legal@stackness.dev from the address linked to your account. We respond within one month, as required by law.

9. Complaints

If you believe we process your data unlawfully, you can lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you are in the EU/EEA, with your local supervisory authority. We would appreciate the chance to resolve your concern first - write to legal@stackness.dev.

10. Security

Connections are encrypted with TLS, passwords are stored only as bcrypt hashes, session refresh tokens live in an HttpOnly cookie, and access to the production infrastructure is limited to the operator.

11. Children

Stackness is not directed at children. You must be at least 16 years old to create an account (see the Terms of service).

12. Changes to this policy

We will update this policy when the service or the law changes. The date at the top reflects the latest revision; material changes will be announced on the site.