1. Data controller
- Controller: Stackedge (CIF: ESY5818456E)
- Address: Barcelona, 08026, Spain
- Contact & DPO: hello@stackedge.ai
For privacy requests or to exercise your rights, email us with “Privacy / GDPR” in the subject line.
2. Data we collect
- Contact data: email address and name (if provided).
- User identifier (user_id) managed by Clerk for authentication.
- Usage data: analyses requested, report history, credits consumed, and basic preferences.
- Billing data processed by Stripe (we do not store full card numbers).
- Minimal technical data: server logs, IP address, and session cookies.
3. Purpose and legal basis
When you register and use Thesis, the main legal basis is consent (Art. 6(1)(a) GDPR), given when you accept this policy and the Terms of Service. Consent is required for authentication, service delivery, and processing your analyses and credits.
We process data for the following purposes:
- Authentication and account management (consent and, where applicable, contract performance, Art. 6(1)(b)).
- AI research and analysis service (consent and contract performance).
- Subscriptions and payments via Stripe (contract and legal obligation, Art. 6(1)(c)).
- Support requests (legitimate interest, Art. 6(1)(f), where applicable).
- Security and platform reliability (legitimate interest).
4. Recipients and processors
We may share data with providers necessary to operate Thesis, under data processing agreements where required:
- Clerk: authentication and identity management.
- Supabase: database and storage of analyses and profiles.
- Stripe: payment and subscription processing.
- Vercel: hosting and web delivery.
- OpenAI and other AI providers: report generation (content of queries submitted).
5. Retention
We retain data while your account is active and as long as required by law. After account cancellation, personal data is kept for up to 12 months, unless a longer legal retention period applies (e.g. invoicing). After that period, data is securely deleted or anonymized.
6. Your rights
You may exercise the following rights under GDPR:
- Access to your personal data.
- Rectification of inaccurate or incomplete data.
- Erasure (“right to be forgotten”) where applicable.
- Restriction or objection to processing where legally provided.
- Data portability in a structured format.
- Withdraw consent where processing is consent-based.
- Lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
7. Cookies
We use cookies and similar technologies strictly necessary for session, security, and basic preferences. We do not use advertising or profiling cookies. See our Cookie Policy for details.
8. Security
We apply reasonable technical and organizational measures (encryption in transit, access control, backups) to protect your data. No system is completely secure; use strong passwords and do not share credentials.