Privacy Policy
Last updated: September 25, 2026
STACK helps you understand, prioritize and act on your work by connecting the apps you already use. This policy explains what STACK collects, why, who it is shared with, and the control you have. We only access an app after you sign in to it and approve access yourself.
What we collect
- Account details: your name, email address and sign-in method.
- Data from apps you connect: only what you authorize. For example, from Google: email subject lines, senders and short previews, calendar event details, and Drive file names and links. From other apps: notifications, tasks, issues, meetings, deals or files, as described on each app's connection screen. STACK does not import passwords, and requests read-only access by default.
- Content you create in STACK: tasks, projects, conversations with STACK AI, and the actions you approve.
- Security records: when an app is connected or disconnected and when a sync fails. These never contain your tokens or message content.
How we use it
We use this data only to provide STACK's features to you: showing what needs your attention, answering your questions, preparing actions for your approval, and keeping your connected apps in sync. We do not sell your data. We do not use it for advertising, and we do not use it to build profiles for third parties.
Google user data
STACK's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google data only to provide and improve the user-facing features described above.
- We do not transfer Google data to others except to provide those features, to comply with the law, or as part of a merger or sale with notice to you.
- We do not use Google data for advertising, and we do not allow humans to read it unless you ask us to, it is needed for security or abuse investigation, or the law requires it.
- We do not use Google data to develop, improve or train generalized AI or machine-learning models.
AI processing
When you ask STACK AI a question, the relevant parts of your synced work (for example a few message previews or task titles) are sent to an AI model provider to produce the answer. The providers we use are Anthropic and, as a fallback, an OpenAI-compatible provider we configure. This data is sent only to answer your request, and we do not permit these providers to train their models on it.
How we protect it
- Access tokens for your connected apps are encrypted at rest and are never sent to your browser.
- Connections use each app's official sign-in (OAuth). STACK never sees your password for those apps.
- Anything that would send, change or delete something in another app needs your explicit approval first.
- You only see information you are already allowed to see in the underlying app.
Your choices
- Disconnect an app at any time from Integrations. STACK then revokes its access where the app allows it, deletes the stored credentials, and deletes the content it imported from that app.
- Revoke access yourself in the app's own settings, for example your Google Account's third-party access page.
- Delete your account and data by contacting us. We will delete your STACK data within a reasonable period.
Sharing
We share data only with service providers that run STACK for us (hosting, database, email delivery, AI processing and payments), under terms that limit them to providing those services, or when the law requires it.
Changes and contact
If we change this policy in a meaningful way, we will update the date above and, where appropriate, tell you in the product.
Questions or requests: use the contact option on our website.