StacOps

Privacy Policy

Effective August 21, 2026 ยท Stacware LLC

StacOps is operated by Stacware LLC ("Stacware", "we", "us"), a California limited liability company. This policy explains what we collect when you use StacOps, why we collect it, who we share it with, and what you can ask us to do about it.

StacOps is an invite-only workspace. There is no public signup, and we do not sell personal information or run advertising.

1. Information we collect

Account information

Your name, email address, and the organization you belong to. Passwords are handled by our authentication provider and stored as salted hashes; we never see or store your password in readable form.

Content you put into StacOps

Projects, tasks, comments, documents, notes, files you upload, client and contact records, quotes, invoices, contracts, and anything else you or your teammates enter. We treat this as your material, not ours.

Activity we record

Timeline entries and audit data: who changed what and when, task status changes, approvals, and time entries. This is the core of the product, so it cannot be turned off while your account is active.

Data from tools you connect

If you connect a source, we ingest what that source reports about your projects:

  • GitHub: repository, commit, branch, and pull request metadata for the repositories you link. We do not pull your source code into StacOps.
  • Claude Code and other MCP clients: progress notes, blockers, task updates, and session timing that the agent reports using an API key you create.

Technical information

Server logs containing IP address, browser user agent, requested URL, and timestamp. These are used for security, debugging, and abuse investigation.

Cookies

StacOps sets two cookies. A sealed, HttpOnly session cookie that keeps you signed in, and a small preference cookie that remembers whether you chose the light or dark theme. We do not use advertising cookies, third-party analytics, or cross-site trackers.

2. How we use information

  • To operate the product: render your workspace, run the timeline, send the notifications you asked for.
  • To authenticate you and keep accounts secure.
  • To generate summaries, recaps, and suggestions using AI features (see section 4).
  • To diagnose failures and improve reliability.
  • To send transactional email such as invitations, notifications, and account notices. We do not send marketing email.

We do not use your content to train our own models, and we do not sell or rent personal information to anyone.

3. Service providers we share data with

We use a small number of subprocessors to run StacOps. Each one is bound by its own terms and processes data only to provide its service to us.

ProviderPurposeWhat it handles
SupabaseDatabase, authentication, file storageAll workspace content, account records, uploaded files
RailwayApplication hostingRequest traffic and server logs
AnthropicAI featuresThe specific content sent for a summary, recap, or suggestion
GitHubRepository integrationOnly the repositories you choose to connect
ResendTransactional emailRecipient email address and message contents

We may also disclose information if required by law, to enforce our terms, or to protect the rights and safety of users. If Stacware is acquired or merged, information may transfer as part of that transaction; we will say so before it takes effect.

4. AI processing

Some features send project content to Anthropic's API to produce a summary, recap, or suggestion. Under Anthropic's commercial terms, content sent through the API is not used to train their models. AI output can be wrong; it is a draft for a person to check, not a decision.

5. Retention

We keep workspace content for as long as the organization's account is active. When an organization closes its account, we delete or anonymize its content within 90 days, except where we must keep records to meet a legal obligation. Server logs are retained for a shorter period, generally under 90 days.

6. Security

Traffic is encrypted in transit. Database credentials and API keys are held server-side only and are never exposed to the browser. Access to production data is limited to the people who need it to run the service. No system is perfectly secure, and we do not claim otherwise.

7. Your choices and rights

You can view and edit your own account details in the app, and ask your organization's administrator to remove your access at any time.

If you are a California resident, the CCPA gives you the right to know what personal information we collect, to request a copy of it, to request deletion, and not to be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of. To make a request, email info@stacware.com. We may need to verify your identity before acting on it.

Where content belongs to an organization rather than to you personally, we will route your request to that organization's administrator.

8. Children

StacOps is a workplace tool and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a minor has an account, contact us and we will remove it.

9. International use

StacOps is operated in the United States and data is processed there. If you use it from elsewhere, you are transferring information to the United States.

10. Changes to this policy

If we make a material change, we will update the effective date above and notify account administrators by email before it takes effect.

11. Contact

Stacware LLC, California, United States. info@stacware.com