Privacy Policy
Effective date: July 1, 2026 · Last updated: July 18, 2026
StackSight is an API service, not an ad-funded product. We collect the minimum data needed to run the service, and this policy explains exactly what that is.
1. What We Collect
- Email address -- required to create an account. We use passwordless magic link authentication, so your email is your identity. There are no passwords for us to store or leak.
- API key -- generated when you sign up, stored securely on our servers, and used only to authenticate your API requests.
- Usage counts -- the number of API requests you have used in the current billing period, so we can enforce plan quotas and show usage on your dashboard.
- IP address -- logged with requests for rate limiting, abuse prevention, and security investigation.
- Payment information -- handled entirely by Stripe. Your card number never touches our servers; we receive only a Stripe customer reference and subscription status.
2. What We Don't Collect
- No tracking pixels
- No third-party analytics (no Google Analytics, no Meta Pixel, nothing)
- No advertising identifiers
- No cookies beyond a single session cookie (
ss_session) used solely to keep you signed in to the dashboard
3. How We Use Your Data
- To deliver the API service and enforce your plan's request limits
- To send magic link sign-in emails and essential transactional emails (API key delivery, billing notices)
- To process subscription payments through Stripe
- To detect and prevent abuse, fraud, and attempts to circumvent rate limits
That's the full list. We do not use your data for advertising, profiling, or anything else.
4. Data Retention
- Magic links expire 15 minutes after they are sent
- Session tokens expire after 7 days
- Rate-limit counters are ephemeral data held in Redis and expire automatically
- Account data (email, API key, usage history, billing records) is kept while your account is active, and for 90 days after account deletion, after which it is permanently purged. We may retain billing records longer where tax or accounting law requires.
5. Third Parties
We share data only with the infrastructure providers needed to run the service:
- Stripe -- payment processing (Stripe's privacy policy)
- SendGrid / SMTP provider -- delivery of transactional email only (magic links, receipts). We never send marketing blasts through it without your consent.
- Railway -- hosting infrastructure where the application and database run
No advertising networks. No data brokers. No one else.
6. We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to anyone, for any purpose. The data our API returns about companies is derived from publicly available web pages and does not include our users' personal data.
7. Your Rights
You can access, correct, or delete your personal data at any time. To delete your account, email support@stacksight.org from your account email address and we will purge your data within 30 days, subject to the retention rules in Section 4. Depending on where you live (e.g. the EU/UK under GDPR, or California under CCPA), you may have additional statutory rights; email us and we will honor them.
8. Security
- API keys are stored securely and used only to authenticate API requests
- All traffic is served over HTTPS only
- Session cookies are secure and HttpOnly
- Rate-limit and abuse-prevention data lives in Redis and expires automatically
No system is perfectly secure, but if we ever discover a breach affecting your personal data, we will notify you by email without undue delay.
9. Changes to This Policy
If we make material changes to this policy, we will notify account holders by email before the changes take effect and update the date at the top of this page.
10. Contact
Privacy questions or requests: support@stacksight.org