Privacy Policy
Effective 2026-09-23. Stacktree (“Stacktree,” “we”) operates the service at stacktr.ee. This policy explains what we collect, why, and your choices.
1. Scope
This policy covers data you give us when you sign up, the files you upload, and the operational logs we keep to run the service. It does not cover websites you publish through Stacktree — your hosted pages are subject to your own terms with your visitors.
2. What we collect
Account data (via Clerk)
When you sign up we collect your email address and any social-provider details you choose to share (e.g. Google profile name). Authentication and session management are handled by Clerk; their privacy policy applies to those data flows.
Billing data (via Stripe)
If you subscribe to a paid plan, payment is processed by Stripe. We never see your card details. We store only a Stripe customer identifier and your current plan.
Content you upload
Files you upload are stored in Cloudflare R2. Metadata (URL, file paths, visibility, expiry, password hash, view counts) is stored in Cloudflare D1. With end-to-end encryption enabled, only ciphertext is ever transmitted to us — we cannot read those files.
When a page expires or you delete it, it stops serving at that moment, and we keep the content for 30 days so you can put the page back at the same URL. At the end of those 30 days we destroy the file in R2 and its row in D1, and the page cannot be restored after that. Two cases skip the window and are destroyed immediately: a page set to burn after reading, and a page we take down for abuse. See Retention for the timing, and for how to ask us to destroy a page now rather than in 30 days.
Operational logs
For each view of a hosted site we record a hashed IP address, user agent, referer, and timestamp. IPs are HMAC-hashed at the edge and never stored in clear text. Logs are retained for 30 days, then pruned.
Slack integration data
If your workspace installs the Stacktree Slack app, we store the workspace's Slack team ID and the OAuth tokens issued at install, used solely to operate the Host on Stacktree message shortcut. The app has no event subscriptions: it never reads messages, and it accesses a file only when a person explicitly runs the shortcut on that file's message. Uninstalling the app or emailing privacy@stacktr.ee removes the workspace record and tokens.
Cookies
We use Clerk's session cookies (__session) for authenticated dashboard requests and a signed site-scoped cookie (__stp_*) to remember password-gated site access for 24 hours per site. Those are the only two cookies we set. No third-party advertising or tracking cookies, and no analytics cookie: the Usage analytics setting in your account menu, and the product analytics described in section 5, are remembered in your browser's own storage rather than in a cookie.
3. Content you publish
Stacktree never requests or requires sensitive personal data — no health information, biometric data, government identifiers, or payment card details are solicited by the service or its integrations. Pages you publish are authored by you; for content that concerns other people, you are responsible for having a lawful basis to publish it.
Protections apply by default: publishes from AI-agent integrations run a pre-publish safety scan that blocks common sensitive patterns (such as card and government-ID number formats) unless you explicitly override it; links are unguessable; pages can be set to expire, deleted at any time, or published end-to-end encrypted so we can never read them. Passcode and email-domain gates are available on paid plans. The scan inspects content only to protect you and stores nothing.
Optional AI features. Three features send a page's content to a model provider, and only when you turn them on or buy them. The design pass sends the page you run it on to Anthropic and shows you the result before anything changes. Ask this page, switched on per page, sends that page's text and a reader's question to Anthropic (the answer itself, drawn from the page only) and the passages the answer cited to TypeSafe AI (a check on whether those passages support the answer). The same box offers find on this page, which sends the page's sentences and the reader's search to TypeSafe AI and returns which sentences match; nothing is generated or stored. Neither provider uses this content to train models under the API terms we use. We keep the questions readers ask, and the answers given, so you can see them on the page's screen in your dashboard; they are stored with a hashed IP address and no other identity, and are destroyed with the page. The box on the page says that answers are generated from the page by an AI model. Readers can use a page without ever using the box. Page video, bought per page, sends that page's text and stylesheet to Anthropic, which writes a short video of it, and each line of the video with the page's text to TypeSafe AI, which checks whether the page supports it. The video is stored with the page, shown to you before anything is published, and deleted with the page.
Automatic labels and the publish guard. Two things happen at publish without a per-page switch. First, every upload is checked by our own rules for credential-harvesting pages; a page that contains a password, one-time code, card or bank field is also put to TypeSafe AI for a yes/no judgement before it goes live, only a page with such a field is sent, and the page's screen in your dashboard tells you when that happened. Second, and only if you turn it on in Settings, each page you publish is sent once to TypeSafe AI so the dashboard can label it (a proposal, a report, a test page) and suggest a passcode or a fix where one would help: whether it states prices or a deadline, looks unfinished, or holds something that should sit behind a passcode. It is off unless you switch it on. The answers are probabilities stored with the page and shown only to you; pages published without an account are never labelled this way.
4. How we use it
- To operate the service — serve your files, enforce expiry, password-gate, audit log.
- To bill you, if you are on a paid plan.
- To detect and respond to abuse (phishing, malware) — we may share offending content hashes with abuse-reporting services.
- To send transactional email (sign-in, billing receipts) via our auth and payment providers.
We do not train AI models on your content. Every served response includes X-Robots-Tag: noai, noimageai, noindex and our robots.txt asserts the Cloudflare content-signal “no AI training”.
5. Sharing
We do not sell personal data. We share only with the sub-processors required to run the service:
- Cloudflare — Worker compute, R2 storage, D1 database, DNS, edge CDN.
- Clerk — auth, session, user management.
- Stripe — payment processing.
- Resend — transactional email (magic-link viewer verification, notifications).
- Sentry, PostHog — optional error tracking and product analytics. Events sent to these services may include URL paths, with query strings stripped, and hashed event properties; we do not send raw IPs or full request bodies. For signed-in account holders we may also record how the dashboard itself is used, to fix problems and improve the product. A recording shows the layout of your dashboard screens and what was clicked, scrolled and typed into. Every piece of text, every form input, every link, every address, every label and every other attribute of the page is masked or replaced by a blank placeholder of the same size, so a recording carries the shape of a screen and not its contents. The one address a recording carries is that of the dashboard screen you were on, including any filter held in it. Recordings never include a published page, the people who open one, or the address of one, and they are never made on the screens that carry a one-time link in their address, such as claiming a page or approving an app. The optional note you can leave when you switch between the old and new dashboard stays in our own server logs and is never sent to either service. You can turn all of this off for your browser with the Usage analytics control in your account menu.
The current list, with purposes and locations, is maintained at stacktr.ee/sub-processors.
6. Retention
- Anonymous uploads stop serving 24 hours after creation. Their content is then kept and destroyed on the same 30-day schedule as everything below. A page published without an account has no dashboard, but its claim link keeps working for those 30 days and claiming it brings it back at the same address.
- If you ask us to email you the claim link for an anonymous page, we store that address with the page and use it for exactly two emails: the link itself, and one reminder as the page runs out. We remove the address when the page is claimed, and it is destroyed with the page.
- Free-plan pages stop serving 7 days after they are published. Paid plans have no expiry unless you set one.
- Expiry and deletion happen in two stages. When a page expires, or you delete it, it stops serving at that moment: the URL goes dark and no part of the page is served to anyone again.
- We then keep the content for 30 days. During that window the file stays in R2 and the row stays in D1, recording the date the page stopped serving and why, so you can restore the page to the same URL from your dashboard or download a copy of it. Nobody can reach it through the URL in the meantime.
- At the end of the 30 days a cleanup job destroys the file in R2 and the row in D1, together with that page's view log, feedback, reactions, and any questions readers asked it. This stage is final: we keep no copy and no tombstone, and once the row is destroyed we can no longer tell a deleted link from one that never existed.
- Two cases are immediate and cannot be undone, because a 30-day window would break what they promise. A page set to burn after reading is destroyed in the same request that serves its one allowed view. A page we take down for abuse stops serving at once, is destroyed by the next hourly cleanup run, and is never restorable.
- If you want a page destroyed now rather than kept for 30 days, email privacy@stacktr.ee with the URL and we will purge it. There is no self-serve permanent delete today, so that email is the route.
- The URL keeps answering once a page stops serving, with a short page saying the link has expired or been removed. It is generated at request time and carries none of your content, title, or file names.
- Audit log entries (
site_views) are retained for 30 days then pruned by a scheduled job. - When you request account closure (email privacy@stacktr.ee), we delete your sites, API keys, and audit logs within 30 days.
- Billing records are retained for as long as required by law (typically 7 years).
7. Your rights
Depending on your jurisdiction (EU/UK GDPR, California CCPA, etc.) you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Email privacy@stacktr.ee and we will respond within 30 days. If you want a page destroyed immediately rather than kept for the 30-day restore window described in Retention, say so and give us the URL, and we will purge it instead of waiting for the cleanup job.
8. Security
Passwords are stored as PBKDF2-SHA256 hashes with per-entry salts. API keys are stored as HMAC-SHA256 hashes — the plaintext key is shown only once. All traffic is TLS 1.2+. End-to-end encrypted uploads use AES-GCM with a 256-bit key held only by you.
9. International transfers
Stacktree runs on Cloudflare's global edge — your data is replicated across regions. Cloudflare maintains EU SCC clauses for international transfers.
10. Children
Stacktree is not directed at children under 13 and we do not knowingly collect data from them.
11. Changes
If we materially change this policy, we will email registered users and update the date above. Continued use after a change constitutes acceptance.
Contact
Privacy questions: privacy@stacktr.ee. Abuse reports: abuse@stacktr.ee.
Last updated 2026-09-23.