We are performing live updates to improve preview reliability. Some previews may take longer to load. Service will be back to normal shortly.

Privacy Policy

Last updated: August 11, 2025

1. Introduction

Stakly ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered application builder service.

By using Stakly, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use our Service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password
  • Profile Information: Username, profile picture, bio
  • Payment Information: Processed securely through Stripe (we do not store card details)
  • Project Content: Code, prompts, and applications you create
  • Communications: Support tickets, feedback, email correspondence

2.2 Information Collected Automatically

  • Usage Data: Features used, generation history, token consumption
  • Device Information: Browser type, operating system, device identifiers
  • Log Data: IP address, access times, pages viewed, errors encountered
  • Cookies and Tracking: Session cookies, analytics cookies (with consent)

2.3 Information from Third Parties

  • OAuth Providers: Basic profile information from GitHub, Google (if used for login)
  • Payment Processors: Transaction confirmations from Stripe

3. How We Use Your Information

We use collected information for the following purposes:

3.1 Service Provision

  • Create and manage your account
  • Process your code generation requests
  • Store and manage your projects
  • Process payments and manage subscriptions
  • Provide customer support

3.2 Service Improvement

  • Analyze usage patterns to improve features
  • Debug and fix technical issues
  • Develop new features and services
  • Conduct research and analytics

3.3 Communication

  • Send service-related announcements
  • Respond to support requests
  • Send billing and account notifications
  • Marketing communications (with your consent)

3.4 Legal and Security

  • Comply with legal obligations
  • Enforce our Terms of Service
  • Protect against fraudulent or illegal activity
  • Protect our rights and property

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in these circumstances:

4.1 Service Providers

  • Infrastructure: Supabase (database), Vercel/Netlify (hosting)
  • Payment Processing: Stripe
  • Email Services: Resend
  • Analytics: PostHog (privacy-focused analytics)
  • AI Services: Anthropic (for code generation)

4.2 Legal Requirements

We may disclose information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights or the safety of users.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.

4.4 Aggregated Data

We may share aggregated, non-identifying information publicly or with partners for business or research purposes.

5. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest for sensitive data
  • Access controls and authentication
  • Regular security audits
  • Secure coding practices
  • Incident response procedures

However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

6. Data Retention

We retain your information for as long as necessary to provide our services and comply with legal obligations:

  • Account Data: Retained while your account is active
  • Project Data: Retained until you delete it or close your account
  • Usage Logs: Retained for 90 days
  • Billing Records: Retained for 7 years for tax purposes
  • Deleted Data: Removed within 30 days of deletion request

7. Your Rights and Choices

7.1 Access and Portability

You can access your personal information through your account settings. You may also request a copy of your data in a portable format.

7.2 Correction

You can update your account information at any time through your profile settings.

7.3 Deletion

You can request deletion of your account and associated data. Some information may be retained for legal compliance.

7.4 Communication Preferences

You can opt out of marketing communications through your account settings or by clicking unsubscribe in emails.

7.5 Cookie Choices

You can manage cookie preferences through our cookie consent tool or your browser settings.

8. GDPR Rights (European Users)

If you are in the European Economic Area, you have additional rights:

  • Right to be Informed: Clear information about data processing
  • Right of Access: Obtain a copy of your personal data
  • Right to Rectification: Correct inaccurate data
  • Right to Erasure: Request deletion ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Transfer data to another service
  • Right to Object: Object to certain processing activities
  • Rights Related to Automated Decision Making: Not be subject to solely automated decisions

To exercise these rights, contact us at privacy@stakly.dev. We will respond within 30 days.

9. California Privacy Rights

California residents have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of the sale of personal information (we do not sell data)
  • Right to delete personal information
  • Right to non-discrimination for exercising privacy rights

10. Children's Privacy

Stakly is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover we have collected information from a child under 13, we will delete it.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses.

12. AI and Machine Learning

When you use our AI code generation features:

  • Your prompts are sent to Anthropic's Claude API for processing
  • Generated code belongs to you
  • We do not use your code or prompts to train AI models
  • Prompts may be logged for debugging and abuse prevention
  • We implement prompt filtering to prevent harmful content generation

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Your continued use after changes constitutes acceptance of the updated policy.

14. Contact Information

If you have questions about this Privacy Policy or your data, please contact us:

  • Email: privacy@stakly.dev
  • Data Protection Officer: dpo@stakly.dev
  • Address: Stakly AB, Stockholm, Sweden

For GDPR inquiries, you may also contact the Swedish Data Protection Authority (Datainspektionen).