Legal
Privacy
Policy.
Stackroom is designed to minimize how much private project content is available to the server while still providing a useful project workspace.
Last updated: September 28, 2026
1. Information we process
Depending on how you use Stackroom, we may process account and session information, encrypted project payloads, encrypted vault metadata, GitHub account and repository metadata, encrypted GitHub authorization tokens, and basic technical request information needed to operate and protect the service.
2. Private project content
Private project content is encrypted in your browser before it reaches Stackroom's servers. During normal encrypted project operations, Stackroom stores encrypted project payloads rather than plaintext private project content.
Your Private Vault passphrase is not sent to Stackroom's server.
3. Private Vault
Stackroom uses browser-side cryptography to protect private project data. A key derived from your vault passphrase is used to unlock an encrypted master key. Project content is then encrypted and decrypted locally in your browser.
If you lose your vault passphrase, Stackroom may not be able to recover access to encrypted project content.
4. GitHub integration
If you connect GitHub, Stackroom may process GitHub account information, repository metadata, repository identifiers, and authorization tokens needed to provide the integration.
GitHub access and refresh tokens are encrypted at rest on the server. They are not protected by the browser-side Private Vault because the backend must use them to communicate with GitHub.
5. Authentication and sessions
Stackroom uses Neon Auth for account authentication and may support third-party sign-in providers such as Google. Authentication providers may process information according to their own policies.
Stackroom uses authentication-related cookies or session mechanisms necessary to keep users signed in and protect account access. The vault passphrase is not stored as a cookie, localStorage value, sessionStorage value, or persistent browser credential.
6. Service providers
Stackroom relies on infrastructure providers for hosting, authentication, databases, and integrations. Those providers may process limited technical data necessary to provide their services.
7. Retention and deletion
Account and service data is retained for as long as reasonably necessary to operate Stackroom, provide requested functionality, maintain security, and satisfy applicable obligations.
Deleted data may remain temporarily in infrastructure backups or logs according to the retention practices of the underlying service providers.
8. Security
Stackroom uses client-side encryption for private project content, encrypted token storage, authenticated ownership checks, Content Security Policy, restricted public asset serving, request validation, and other application security controls.
No internet-connected service can guarantee absolute security.
9. Changes
This Privacy Policy may change as Stackroom evolves. The latest version will be published here with an updated revision date.
10. Contact
Privacy questions can be sent to contact@stackroom.site.