Privacy notice
Stackquake is run by Jay Stewart, who is responsible for the data described here. Short version: we keep what we need to send you alerts, nothing more. No ads, no tracking scripts, no analytics cookies, and we don't sell data. Questions or requests: hello@stackquake.com.
What we store
- Your email address, and your GitHub user id and name if you sign in with GitHub.
- Your projects: the services you picked, how you said you use them, and what repo import found (dependency names, versions and the manifest paths they came from). If you import a private repo, the repo's name and the GitHub App installation id. We read manifest files to find dependencies; we don't keep your code.
- Alerts we sent you and your feedback on them; your Slack webhook URL if you add one (encrypted).
- For Team: your Stripe customer and subscription ids and plan status. Card details are handled by Stripe and never reach us.
- Team members' email addresses, when a Team subscriber invites them.
- Short-lived security records: hashed session and sign-in tokens, and rate-limit counters keyed by email or IP address.
Cookies
Two, both needed for the site to work: a session cookie when you're signed in, and a CSRF-protection cookie for forms.
Who processes data for us
- Cloudflare: hosting, database and storage.
- Resend: sending email (your address and the alert's content).
- Stripe: payments, for Team subscribers.
- GitHub: sign-in and repo import, when you use them.
- Anthropic: the language model that writes notes. It only sees public vendor text, never your data.
Your choices
You can change your email, turn off immediate alerts, export your vendor-risk list (Team) or delete your account in Settings. Deleting your account removes your projects, dependencies, alerts, Slack connection and sessions at once. Stripe keeps billing records as the law requires. Public event pages are about vendors, not you, and stay.