Stacktree

Sub-processors

Effective 2026-10-03. These are the third-party services (“sub-processors”) Stacktree uses to operate. Each processes data only as needed for the purpose listed, under its own data-processing terms. We do not sell personal data, and no sub-processor receives more than its purpose requires.

Sub-processorPurposeData involvedLocation
CloudflareAll hosting: Worker compute, R2 storage, D1 database, DNS, CDNHosted content, account metadata, operational logs (IPs HMAC-hashed at the edge)Global edge (EU SCCs in place)
ClerkAuthentication and sessions for the dashboardEmail address, social-provider profile, session tokensUnited States
StripePayment processing (subscriptions, pay sessions)Payment details (never visible to us), customer identifierUnited States / EU
ResendTransactional email (magic-link viewer verification, notifications)Recipient email address, message contentUnited States
SentryError monitoringError events with URL paths (query strings stripped); no raw IPs or request bodiesUnited States / EU
AnthropicModel inference for three optional features: the design pass, Ask this page (answers drawn from a page's own text), and page video (a short video of a page)The content of a page the owner runs the design pass on, has switched the question box on for, or has bought a page video for; the reader's question. Sent per request, not retained by us beyond the answer shown to the owner; not used by Anthropic to train models under its API termsUnited States
TypeSafe AIYes/no and multiple-choice judgements: whether the passages an Ask this page answer cited support it; whether a page with a password, code, card or bank field is a credential-harvesting page; what kind of page a signed-in account has published and what it contains; whether a page supports each line of its page videoThe cited passages and the answer, per question; the page's sentences and the reader's search, per find on a page with the question box on; the HTML of a page that contains a password, one-time code, card or bank field, once at publish; the text of a page published by an account that has switched automatic labels on in Settings, once at publish; the text of a page and each line of its video, when its owner makes a page videoUnited States
PostHogProduct analytics and dashboard session recordingsHashed event properties and paths; recordings of dashboard layout and interactions for signed-in account holders, with all text, inputs, links, addresses, labels and other attributes masked or blanked; the address of the dashboard screen and no other; never published pages, their readers, or the addresses of pages; no raw IPsUnited States / EU

Slack integration

The Stacktree Slack app stores your workspace's team ID and OAuth tokens on Cloudflare (above) to operate the Host on Stacktree message shortcut. Slack itself is the platform you authorize, not a sub-processor of ours; its handling of your workspace data is governed by Slack's privacy policy.

Changes to this list

If we add or replace a sub-processor, we update this page and its effective date before the change takes effect, and announce material changes to registered users by email. Questions: privacy@stacktr.ee.

Last updated 2026-10-03.