Sub-processors
Effective 2026-10-03. These are the third-party services (“sub-processors”) Stacktree uses to operate. Each processes data only as needed for the purpose listed, under its own data-processing terms. We do not sell personal data, and no sub-processor receives more than its purpose requires.
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Cloudflare | All hosting: Worker compute, R2 storage, D1 database, DNS, CDN | Hosted content, account metadata, operational logs (IPs HMAC-hashed at the edge) | Global edge (EU SCCs in place) |
| Clerk | Authentication and sessions for the dashboard | Email address, social-provider profile, session tokens | United States |
| Stripe | Payment processing (subscriptions, pay sessions) | Payment details (never visible to us), customer identifier | United States / EU |
| Resend | Transactional email (magic-link viewer verification, notifications) | Recipient email address, message content | United States |
| Sentry | Error monitoring | Error events with URL paths (query strings stripped); no raw IPs or request bodies | United States / EU |
| Anthropic | Model inference for three optional features: the design pass, Ask this page (answers drawn from a page's own text), and page video (a short video of a page) | The content of a page the owner runs the design pass on, has switched the question box on for, or has bought a page video for; the reader's question. Sent per request, not retained by us beyond the answer shown to the owner; not used by Anthropic to train models under its API terms | United States |
| TypeSafe AI | Yes/no and multiple-choice judgements: whether the passages an Ask this page answer cited support it; whether a page with a password, code, card or bank field is a credential-harvesting page; what kind of page a signed-in account has published and what it contains; whether a page supports each line of its page video | The cited passages and the answer, per question; the page's sentences and the reader's search, per find on a page with the question box on; the HTML of a page that contains a password, one-time code, card or bank field, once at publish; the text of a page published by an account that has switched automatic labels on in Settings, once at publish; the text of a page and each line of its video, when its owner makes a page video | United States |
| PostHog | Product analytics and dashboard session recordings | Hashed event properties and paths; recordings of dashboard layout and interactions for signed-in account holders, with all text, inputs, links, addresses, labels and other attributes masked or blanked; the address of the dashboard screen and no other; never published pages, their readers, or the addresses of pages; no raw IPs | United States / EU |
Slack integration
The Stacktree Slack app stores your workspace's team ID and OAuth tokens on Cloudflare (above) to operate the Host on Stacktree message shortcut. Slack itself is the platform you authorize, not a sub-processor of ours; its handling of your workspace data is governed by Slack's privacy policy.
Changes to this list
If we add or replace a sub-processor, we update this page and its effective date before the change takes effect, and announce material changes to registered users by email. Questions: privacy@stacktr.ee.
Last updated 2026-10-03.