Privacy Policy
Last updated: January 2026
1. Data Controller
StackFu ("we", "our", or "us") is the data controller responsible for your personal data. We are based in Finland, European Union.
For any privacy-related inquiries, contact us at [email protected]
2. Data We Collect
We follow a privacy-first approach and collect only the minimum data necessary to provide our service:
Account Data (via Clerk)
- Email address
- Name (if provided)
- Organization information (if applicable)
Usage Data
- Pages visited within the application
- Features used (e.g., stacks configured, digests viewed)
Technical Data
- Browser type and version
- Device information
- Error logs (for debugging and service improvement)
3. Legal Basis for Processing (GDPR Article 6)
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide you with the StackFu service as per our Terms of Service.
- Legitimate Interests: Processing for service improvement, security, and fraud prevention, where our interests do not override your fundamental rights.
- Consent: Where you have given explicit consent for specific processing activities (e.g., marketing communications). You may withdraw consent at any time.
4. Third-Party Services
We use the following third-party services to operate StackFu:
Clerk (Authentication)
We use Clerk for user authentication. Clerk processes your email and authentication data. See Clerk's Privacy Policy.
Google Gemini (AI Processing)
We use Google Gemini to generate AI summaries of dependency updates. Content from changelogs and release notes may be sent to Google for processing. See Google's Privacy Policy.
5. Your Rights
Under GDPR, you have the right to access the personal data we hold about you and to request its deletion ("right to be forgotten"). You can also request corrections, data export, or withdraw consent at any time.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. If you're unsatisfied with our response, you may lodge a complaint with your local data protection authority.
6. Data Retention
We retain your personal data only for as long as necessary to provide our services to you:
- Active Accounts: Data is retained while your account remains active.
- Account Deletion: Upon account deletion request, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
- Logs and Analytics: Aggregated, anonymized usage data may be retained for service improvement.
7. International Data Transfers
Some of our third-party service providers (including Clerk) are based in the United States. When your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- EU-U.S. Data Privacy Framework certification
- Standard Contractual Clauses approved by the European Commission
8. Cookies
We use only essential cookies necessary for the operation of our service:
- Authentication Cookies: Required to keep you signed in and maintain your session.
We do not use tracking cookies, advertising cookies, or any non-essential cookies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes via email or through a notice on our service. The "Last updated" date at the top indicates when this policy was last revised.
10. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at: [email protected]