Effective: June 1, 2026
Privacy Policy
Quackstack, Inc. ("Quackstack", "we", "us") respects your privacy. This Privacy Policy explains what personal information we collect when you use our website and services (collectively, the "Service"), how we use it, and the rights you have.
1. Information we collect
We collect the following categories of personal data:
- Account data: name, email, password hash, organization.
- Billing data: name, billing address, payment token (processed by Stripe).
- Usage data: requests, latency, error rates, feature flags exercised.
- Quack content: the inputs you send to the duck. By default these are ephemeral and discarded after the response is delivered.
- Cookies: as described in our Cookie Policy.
2. How we use information
We use personal data to:
- Provide, maintain, and improve the Service;
- Process payments and prevent fraud;
- Communicate about your account and material changes;
- Comply with legal obligations.
We do not sell your personal information. We do not use customer code or quack content to train shared models.
3. Legal bases (GDPR)
We process personal data under one of the following legal bases: (a) performance of a contract; (b) your consent; (c) legitimate interests (e.g. service security); or (d) compliance with law.
4. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to opt out of the sale or sharing of personal information. To exercise these rights, email [email protected].
California residents may submit "Do Not Sell or Share My Personal Information" requests through the link in our website footer.
5. Data retention
Account data is retained for the life of your account plus 30 days. Billing records are kept for 7 years for tax compliance. Quack content is ephemeral by default.
6. International transfers
Quackstack is headquartered in the United States with infrastructure in the EU and US. For transfers out of the EEA/UK we rely on Standard Contractual Clauses and supplementary measures.
7. Security
We maintain administrative, technical, and physical safeguards including TLS in transit, AES-256 at rest, role-based access controls, and SOC 2 Type II audited operations.
8. Children
The Service is not directed to children under 16.
9. Changes
We will post material changes here and notify you by email when required.
10. Contact
Quackstack, Inc., 1 Pond Lane, Helsinki, FI · [email protected]