1. Who we are and how to contact us
STACKD is a communications and growth-marketing platform run by two AI operators. It drafts press releases, thought leadership, blogs and media pitches and emails those pitches to journalists. It drafts, schedules and publishes social posts to the social accounts a customer connects. It generates images, tracks search rankings and backlinks, monitors news and competitors, and bills through a credit system.
STACKD operates STACKD. For this website, for STACKD accounts and for our early-access list, STACKD is the data controller. Our registered address is Dubai, United Arab Emirates.
To ask a privacy question, exercise a right or raise a concern, email hello@stackd.bot. A person reads every message sent to that address.
This policy is written to meet the UK GDPR and the Data Protection Act 2018, and is governed by the laws of England and Wales. We acknowledge and honour the UAE Personal Data Protection Law on the same terms for customers and users in the United Arab Emirates.
2. Scope
This policy covers three things:
- the public STACKD website, including the early-access waitlist;
- the STACKD platform, once you have an account and a workspace;
- the outbound activity STACKD carries out for a customer: pitch emails sent to journalists, and social posts drafted, scheduled and published to connected accounts.
Who controls what
For account users, waitlist leads and visitors to the website, STACKD is the data controller. We decide what data we need and why, and this policy describes those decisions.
For journalist contact records and for everything a customer uploads into or generates inside their workspace, the customer is the data controller and STACKD is the processor. We act on that customer's instructions. We do not use their workspace content for our own purposes, we do not mine it, and we do not share it between workspaces.
If you are a journalist, a prospect or anyone else whose details sit inside a customer's workspace and you want them changed or removed, you can come to us directly at hello@stackd.bot. We will act, and we will tell the customer.
The processing terms between us and our customers form part of our Terms of Service. What a customer may and may not send through the platform is set out in our Acceptable Use Policy.
3. What personal data we collect and where it comes from
This table is drawn from an audit of what the platform actually stores. It is the complete picture, not a category list copied from a template.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account users | Name, email address, hashed password, two-factor secret and recovery codes, remember token, workspace role, passkey credentials, login sessions and password-reset tokens. | You, when you register or are invited, and your browser when you log in. |
| Workspace profile | Legal contact email, business description, vision, mission and any extra context given during onboarding, brand kit uploads and timezone. | You, during onboarding and in workspace settings. |
| Connected accounts | OAuth credentials for Google and Microsoft mailboxes, Google Search Console, news and data sources, and social platforms. All credentials are encrypted at rest. | The platform you connect, when you authorise STACKD. |
| Team invitations | The invitee email address, held until the invitation is accepted or expires. | The workspace member who sends the invitation. |
| Journalist contacts | Name, publication, email address, beat, articles written and outreach history. Held both in a global STACKD database and per workspace. | Public professional sources, and lists a customer supplies or builds. |
| Content and activity | AI conversations and messages, generated pitches, social plans and posts, content assets, generated images, workspace tasks and their attachments, credit transactions, and approval and legal-review records including the external reviewer email address. | You and your team, and the AI operators working on your instructions. |
| Marketing | Early-access waitlist entries, which are an email address and a company name collected before any account exists, and suppressed-email records so we do not contact someone who has opted out. | You, when you join the waitlist or opt out. |
| Technical | IP address, browser user agent, server and application logs, and the terms-acknowledgement audit trail recording who accepted, when, from which IP address and against which version of the terms. | Your browser and our servers, automatically. |
We do not ask for special category data such as health, ethnicity, religion, political opinion or biometric data, and the platform is not designed to hold it. Please do not put it into a workspace.
4. Why we use it and our lawful bases
Every use of personal data needs a lawful basis. Here is ours, purpose by purpose.
| What we do | Lawful basis |
|---|---|
| Create and run your account, workspace and team; authenticate you; keep you logged in. | Performance of a contract with you. |
| Run the AI operators: draft pitches, releases, blogs, social posts and images from the context you give us. | Performance of a contract with you. |
| Connect your mailbox, Search Console, news sources and social accounts, and use those connections to send and publish on your instruction. | Performance of a contract, together with the permission you grant on the platform consent screen when you connect the account. |
| Send pitch emails to journalists on a customer instruction, and hold journalist contact records to do so. | Legitimate interests: our customer's interest in reaching relevant journalists, and a journalist's own interest in receiving story leads that fall inside their beat. See section 5. |
| Meter credits, raise invoices and keep account records. | Performance of a contract, and legal obligation for tax and company record-keeping. |
| Keep the platform secure and available: detect abuse, rate-limit, investigate incidents, debug faults. | Legitimate interests: keeping a multi-tenant platform secure, available and free from abuse. |
| Record who accepted which version of our terms, when, and from which IP address. | Legitimate interests: being able to prove the agreement between us, and legal obligation where a regulator asks. |
| Hold early-access waitlist entries and send you news about the launch. | Your consent, which you can withdraw at any time. |
| Set any cookie that is not strictly necessary. | Your consent, given through the cookie banner. See our Cookie Policy. |
| Keep accounting and business records, and respond to regulators, courts and lawful requests. | Legal obligation. |
Where we rely on legitimate interests we have weighed our interest against your rights and freedoms. Email hello@stackd.bot and we will send you that assessment in plain English.
5. Journalist contact data
STACKD holds journalist contact records so it can pitch stories. This is third-party personal data, so we are direct about how it works.
Where it comes from
- Public professional sources: bylines, publication mastheads and staff pages, publicly listed press and tip-off addresses, and public professional profiles.
- Lists a customer supplies, imports or builds inside their own workspace.
Records are held in two places: a global STACKD database used to suggest relevant journalists, and a per-workspace copy belonging to the customer.
Our basis, and who is responsible
We rely on legitimate interests. The data is professional contact data, used to contact a journalist in their working capacity about stories inside their stated beat. It is never used for consumer marketing and it is never sold.
When a pitch is sent, the customer is the controller for that outreach. They decide who to contact and what to say. We provide the tooling and act on their instruction. Our Acceptable Use Policy requires customers to pitch honestly, to stay relevant and to honour opt-outs.
What a journalist can do
- Object. Tell us to stop and we stop. You do not have to give a reason.
- Ask for erasure. We remove your record from the global database and suppress your address so no workspace can pitch you again.
- Correct your details. Tell us your beat, publication or preferred address is wrong and we will fix it.
- Opt out from any pitch. Every pitch email carries an opt-out. Replying to ask us to stop works just as well.
Email hello@stackd.bot from the address that was contacted, or follow the steps on our Data Deletion page. Suppression is applied across the whole platform, not just to the customer who contacted you.
6. AI processing
To generate a draft, STACKD sends the relevant content to the AI providers listed in section 7: Anthropic, OpenAI, Google and, for images, Replicate. That content can include your business context, your brief, the conversation you are having with an operator and the draft being worked on.
Three things are worth being clear about:
- No training on your content. Our agreements with these providers bar them from using content submitted through our accounts to train their models.
- Output is machine-generated. Drafts, pitches, posts and images are produced by a model. They can be wrong, out of date or inadvertently misleading. A human must review anything before it is published or sent.
- No automated decisions about people. STACKD does not make decisions that produce legal effects or similarly significant effects on anyone by automated means. Nothing in the platform scores, profiles or ranks an individual in a way that decides an outcome for them.
Approval and legal-review records exist precisely so that human sign-off is recorded before something goes out.
7. Sub-processors and third parties
These are the sub-processors we currently use. We do not sell personal data and we do not share it for advertising.
| Sub-processor | What it does for us | Where it processes data |
|---|---|---|
| Anthropic | AI text generation. | United States |
| OpenAI | AI text and image generation. | United States |
| Gemini AI generation, Cloud Run hosting, Cloud SQL database, and Search Console data for rank and coverage reporting. | European Union for hosting and the database; United States for AI generation and Search Console. | |
| Replicate | Image generation. | United States |
| Firecrawl | Web and news scraping for monitoring and research. | United States |
| DataForSEO | Rank tracking and backlink data. | United States and European Union |
| X (Twitter) API | Social listening and monitoring. | United States |
| Resend and our SMTP mail provider | Delivery of transactional email and pitch email. | United States and European Union |
| Microsoft | Outlook mailbox access, when a customer connects a Microsoft mailbox. | United States and European Union |
Each sub-processor is bound by a written contract that limits them to our instructions and imposes confidentiality and security obligations. We also disclose personal data to professional advisers, and to regulators, courts or law enforcement where we are legally required to.
If we add or replace a sub-processor we will update this page. Customers can ask us to be told in advance by emailing hello@stackd.bot.
8. International transfers
STACKD is hosted on Google Cloud Run with a Google Cloud SQL database in the European Union. Some of our sub-processors operate in the United States and elsewhere, so personal data may be transferred outside the UK and the EEA.
Where that happens we rely on:
- the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, for transfers out of the UK;
- the EU Standard Contractual Clauses, for transfers out of the EEA;
- supplementary measures, including encryption in transit and at rest, access control, and contractual limits on what a sub-processor may do with the data.
For customers and users in the United Arab Emirates, we honour the UAE Personal Data Protection Law and apply the same transfer safeguards described here.
You can ask us for a copy of the transfer mechanism that covers a particular sub-processor. Email hello@stackd.bot.
9. How long we keep data
We keep business records for seven years. UK company and tax law requires it, and that obligation applies whether or not an individual asks us to delete their data.
How deletion works here
Because of that seven-year duty, we honour a deletion request by anonymising the person rather than destroying the record. When you ask us to delete your data:
- your name is replaced with "Deleted user";
- your email address is replaced with an unusable anonymised address;
- your password, two-factor secret, recovery codes, passkeys and sessions are destroyed;
- connected mailboxes and social accounts are disconnected and their stored credentials deleted;
- the underlying business records survive with no link back to you.
Anonymisation is irreversible and your login stops working immediately. The full detail is on the Data Deletion page.
Other retention periods
- Waitlist entries. Kept until you ask to be removed, or until the early-access programme closes.
- Suppressed-email records. Kept indefinitely. They exist so that we never contact someone who has opted out; deleting them would undo the opt-out.
- Team invitations. Deleted once accepted or expired.
- Server and application logs. Kept on a short rolling window of up to 30 days and not used to build profiles of anyone.
- Backups. Encrypted database backups age out within 35 days, so a deleted or anonymised record disappears from backups within that window.
- Journalist contacts. Kept while the record is accurate and outreach is relevant, and removed on request.
10. Security
The measures below are in place today, not aspirations.
- Encryption in transit and at rest. All traffic is served over TLS; stored data is encrypted at rest.
- Encrypted credentials. OAuth tokens for mailboxes, Search Console and social accounts are encrypted in the database with application-level encryption.
- Hashed passwords. Passwords are stored as one-way hashes. Nobody at STACKD can read your password.
- Two-factor authentication and passkeys. Both are supported, and we recommend turning one on.
- Private database. The production database has a private IP address only and no public interface. It cannot be reached from the internet.
- Role-based access. Workspace roles control who can see and do what inside a workspace.
- Hard tenant isolation. Every query is scoped to a workspace. One customer cannot see another customer's content.
- Least privilege internally. Access to production is limited to the people who need it, and is used for support and incident response only.
If something goes wrong
If a personal data breach occurs and it is likely to result in a risk to people's rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will tell affected individuals without undue delay where the risk to them is high. Where we are a processor, we will notify the customer without undue delay so they can meet their own obligations.
11. Your rights
You have the following rights over your personal data.
- Access. Ask what we hold about you and get a copy.
- Rectification. Have inaccurate data corrected and incomplete data completed.
- Erasure. Ask us to delete your data. See the honest note below.
- Restriction. Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability. Get the data you gave us in a structured, machine-readable format, or ask us to send it to another provider.
- Objection. Object to processing based on legitimate interests, including journalist outreach. If you object to direct marketing we stop, full stop.
- Withdraw consent. Where we rely on consent, withdraw it at any time. That does not affect processing that already happened.
- Automated decisions. The right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. STACKD makes no such decisions, so this right has nothing to bite on here.
Erasure, honestly
The right to erasure is not absolute. Where we must keep a record to meet a legal obligation, such as the seven-year record-keeping duty described in section 9, we cannot destroy that record. What we do instead is strip it of everything that identifies you: your name, email, credentials, sessions and connections all go, permanently, and the surviving record holds no personal identifiers. Where no legal obligation applies, for example a waitlist entry or a journalist contact record, we delete outright.
How to exercise a right
Email hello@stackd.bot, or write to us at Dubai, United Arab Emirates. Account holders can delete their own data from inside the app; the Data Deletion page sets out both routes step by step.
We respond within one month. If a request is unusually complex we may extend that by two further months, and we will tell you why within the first month. We do not charge a fee. We may ask you to verify your identity before we act, particularly where the request comes from an address we do not recognise.
If your data sits in a customer workspace and we are the processor, we will pass your request to that customer and help them answer it, and we will tell you who they are.
12. Complaints
Please come to us first at hello@stackd.bot. Most complaints are a misunderstanding we can fix the same day, and we would rather fix it than have you chase a regulator.
If you are not satisfied, you can complain to a supervisory authority.
- United Kingdom. The Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or at ico.org.uk.
- EEA. The data protection authority in the country where you live, work, or where the problem happened.
- United Arab Emirates. The UAE Data Office, under the Personal Data Protection Law.
Complaining to a regulator does not affect any other legal remedy you have.
14. Children
STACKD is a business tool and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email hello@stackd.bot and we will delete it.
15. Changes to this policy
We update this policy when what we do changes: a new sub-processor, a new feature that touches personal data, a change in the law. The version number and date at the top of this page tell you which edition you are reading, and every edition replaces the one before it.
For a change that materially affects you, we will tell account holders by email or through the app before it takes effect. For smaller changes, updating this page is the notice. It is worth a look now and then.
Questions about anything on this page go to hello@stackd.bot. You can also return to the STACKD home page or read our Terms of Service.