← stacktube.io

Privacy Policy

1. Who We Are

This Privacy Policy explains how unstackd.io (“we,” “us,” “Operator”) collects and processes personal data through Stacktube (the “Service”). For users in the European Economic Area and the United Kingdom, unstackd.io is the “controller” of your personal data under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the UK GDPR. For California residents, we are the “business” under the California Consumer Privacy Act as amended by the CPRA (“CCPA”). You can reach our privacy contact at drowsynaru@gmail.com.

2. Data We Collect

We collect the following categories of personal data:

  • Account data: email address, name (optional), profile picture (if you sign in with Google or GitHub), and encrypted password (email/password accounts).
  • Usage data: analysis history (YouTube URL, video title, analysis result, timestamps), plan tier, channel subscriptions, and feature usage.
  • Integration data: OAuth tokens for Google Drive, Dropbox, and YouTube connections, stored encrypted (AES-256-GCM) at rest. You may revoke integrations at any time from the settings page or the respective provider.
  • BYOK data: if you use your own AI API keys (Unlimited plan), we store them encrypted (AES-256-GCM) and use them only to run the analyses you request.
  • Technical data: IP address, browser user agent, device identifiers, access logs, and cookies (see § 7).
  • Payment data: we do not collect or store credit card or other payment instrument details. Payment data is collected and processed directly by Paddle.com Market Ltd. as Merchant of Record.

3. How We Use Your Data and Legal Bases (GDPR Art. 6)

We process personal data for the following purposes, relying on the legal bases indicated:

  • Providing the Service (account, analyses, integrations, delivery) — performance of a contract (Art. 6(1)(b)).
  • Billing and fraud prevention (via Paddle) — performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
  • Service improvement, security, logging, and abuse preventionlegitimate interests (Art. 6(1)(f)) in operating and securing the Service, balanced against your rights.
  • Transactional emails (login notifications, analysis completion, weekly digest if enabled) — performance of a contract (Art. 6(1)(b)); digests can be turned off in settings.
  • Marketing emails — we currently do not send marketing emails. If we do in the future, we will request your consent (Art. 6(1)(a)) where required by law.
  • Compliance with legal requestslegal obligation (Art. 6(1)(c)).

We do not use your personal data, analyses, or content for automated decision-making or profiling that produces legal or similarly significant effects.

4. Retention

We retain your account and usage data for as long as your account is active. When you delete your account, we erase all personal data and analysis records tied to your account within 30 days of the request, except where retention is required by law (for example, tax records or anti-fraud logs required by Paddle). Access logs are retained for up to 90 days for security purposes.

5. Sharing, Processors, and International Transfers

We do not sell your personal data. We share personal data with the following processors strictly to operate the Service:

ProcessorCountryPurposeTransfer Safeguard
Supabase Inc.United StatesAuthentication and databaseStandard Contractual Clauses (EU/UK); SOC 2 Type II
Google LLCUnited StatesGemini API (video analysis)Standard Contractual Clauses (EU/UK); Data Processing Agreement
Anthropic PBCUnited StatesClaude API (note generation)Standard Contractual Clauses (EU/UK); TLS in transit
Paddle.com Market Ltd.United KingdomPayment (Merchant of Record)UK adequacy (EU); PCI DSS
Resend Inc.United StatesTransactional email deliveryStandard Contractual Clauses (EU/UK); SPF/DKIM
Railway Corp.United StatesApplication hostingStandard Contractual Clauses (EU/UK); TLS

Where personal data of EU/EEA or UK residents is transferred to a country that has not been recognized as providing adequate protection, we rely on the European Commission’s Standard Contractual Clauses (2021/914) and, for the UK, the UK International Data Transfer Addendum or IDTA, with appropriate supplementary measures. You may request a copy of the transfer safeguards by contacting us.

6. Your Rights

If you are in the EU/EEA or the UK (GDPR / UK GDPR), you have the right to: (a) access your personal data, (b) rectify inaccurate data, (c) erase your data (“right to be forgotten”), (d) restrict processing, (e) data portability, (f) object to processing based on legitimate interests, and (g) withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local Data Protection Authority (DPA) or the UK Information Commissioner’s Office (ICO).

If you are a California resident (CCPA / CPRA), you have the right to: (a) know what personal information we collect and how it is used and disclosed, (b) access and receive a copy of your personal information, (c) correct inaccurate personal information, (d) delete your personal information, (e) limit use and disclosure of sensitive personal information, (f) opt out of the “sale” or “sharing” of personal information, and (g) non-discrimination for exercising your rights. We do not “sell” or “share” personal information as those terms are defined under the CCPA, and we do not use or disclose sensitive personal information for purposes that require a right-to-limit notice. You may submit a verifiable consumer request by emailing drowsynaru@gmail.com; we may need to verify your identity before responding.

We respond to verified requests within 30 days (GDPR/UK GDPR) or 45 days (CCPA), with one extension permitted where the request is complex. To exercise any of the rights above, email drowsynaru@gmail.com. An authorized agent may submit requests on your behalf with written authorization.

7. Cookies

We use a minimal set of cookies:

  • Strictly necessary: Supabase auth session cookies (sb-access-token, sb-refresh-token) keep you signed in. These cannot be disabled; blocking them breaks login.
  • Payment: Paddle sets short-lived cookies during checkout to prevent fraud.
  • Analytics: Google Analytics (GA4, measurement ID G-XSS2LYYVJP) is loaded to measure aggregate traffic. Where required by law we will show a consent banner before loading analytics; you can also block analytics in your browser.

We do not use advertising cookies or third-party marketing trackers.

8. Security

We apply reasonable and appropriate technical and organizational measures to protect personal data, including: HTTPS/TLS in transit, AES-256-GCM encryption at rest for OAuth tokens and BYOK keys, Supabase Row-Level Security (RLS) for cross-user isolation, password hashing via Supabase Auth, least-privilege access to production systems, and logging with anomaly review. No method of transmission or storage is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the relevant authorities within the timeframes required by law (72 hours for GDPR and UK GDPR notifications to supervisory authorities).

9. Children

The Service is not directed to children under the age of 13 (or 16 in the EU/EEA / UK, where applicable). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, email drowsynaru@gmail.com and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or via an in-product notice before the change takes effect. Your continued use of the Service after the effective date of a change constitutes acceptance of the updated policy.

11. Contact

For privacy questions, data subject requests, or any concern about how we handle your personal data, contact us at drowsynaru@gmail.com. We do not currently have an EU or UK representative; if we appoint one in the future, their details will be listed here.

Effective date: April 22, 2026