Effective 28 September 2026

Privacy policy

This policy explains what AllStackd collects and why. Contact support@allstackd.com for privacy questions.

What we collect

Account data from Clerk (email, name, auth metadata). Workspace settings, AWS connection metadata, API-key identifiers and scopes, normalized delivery events, health findings, usage, and audit records. Billing identity from Stripe Checkout (name, email, address, optional business name and tax ID).

In Control mode we temporarily process From, recipients, subject, and message content to submit email through your SES account. We store key hashes and encrypted secrets — not reusable plaintext AWS credentials.

How we use data

To run the product, authenticate you, observe or send as you request, provide support, bill subscriptions, prevent abuse, and keep the service secure. We do not sell personal data or use it for advertising.

Sharing

We share data only with the subprocessors listed in the Terms (Clerk, Neon, Vercel, Stripe, and AWS in accounts you authorize; Google Analytics only if consent-gated analytics are enabled later), or when the law requires it. Email delivery happens in your AWS account under the role you install.

Retention

Message content is deleted within 24 hours. Readable recipient diagnostics and raw events within 7 days. Normalized events within 30 days. If you delete your account in Settings, sending stops immediately, Stripe billing is canceled, your sign-in is removed, and workspace data is deleted immediately. Full schedule: Terms → Retention.

Cookies and analytics

Clerk uses cookies required for sign-in and security. Product analytics (Google Analytics 4) are not loaded until a consent choice is available. We do not use advertising cookies or sell personal data for ads.

Your choices

Export your workspace or permanently delete your account in Settings, or email support@allstackd.com. Deletion removes the workspace and sign-in so you must create a new account to return. Depending on applicable law you may also request access, correction, or restriction. We may need to verify the request.

Changes

We will update the effective date when this policy changes. Continued use after the effective date means the updated policy applies, subject to rights that cannot be waived.