Privacy Policy
Last updated: September 5, 2026
1. Introduction
StackShield ("we", "our", "us") scans Laravel applications from the outside and reports what it finds. This policy explains what personal data we collect when you visit stackshield.io, use the dashboard, the REST API or the MCP server, who processes it on our behalf, how long we keep it and how you can exercise your rights. We are the data controller for the personal data described here.
2. What we collect
- Account data: your name, email address, password hash and, if you sign in with GitHub or Google, the identifier and email address those providers share with us.
- Billing data: your plan, invoices and the last four digits and expiry of your card. Full card details go directly to Stripe and never touch our servers.
- Application data: the domains you ask us to monitor, the scan results, issues and scan history for those domains, and any notes you attach to issues.
- Integration data: API keys you create, OAuth grants you approve for connected assistants such as ChatGPT or Claude, and any Slack webhook or notification channel you configure.
- Technical data: IP address, browser and device type, pages visited and the actions you take in the dashboard, collected through server logs and our analytics tools.
- Correspondence: anything you send to our support or newsletter addresses.
3. Why we use it
- To provide the service (performance of a contract): running scans against your domains, storing the results, showing them in the dashboard and returning them through the API and MCP server.
- To notify you (performance of a contract): emails, push notifications and Slack messages about new issues, scan failures and account events.
- To bill you (performance of a contract and legal obligation): processing subscriptions and keeping invoice records for as long as tax law requires.
- To keep the service secure (legitimate interest): rate limiting, abuse detection, audit logs of API and MCP access.
- To improve the service (legitimate interest): aggregated usage analytics that tell us which features are used and where people get stuck.
- To send you the newsletter (consent): only if you subscribe, and every issue has an unsubscribe link.
We do not sell personal data and we do not use your scan results or domains to train machine learning models.
4. Connected assistants (MCP)
You can connect StackShield to an AI assistant such as ChatGPT, Claude, Cursor or VS Code through our MCP server. When you do, the assistant asks for your consent on our OAuth screen and receives a token limited to your team. Each request the assistant makes is logged with the tool called and the team it acted on. The data a tool returns, for example a list of your domains or the issues found in a scan, is sent to the assistant you connected, and from that point on it is handled under that provider's privacy policy, not ours. We do not receive your conversations with the assistant, only the tool calls it makes. You can revoke an assistant's access at any time from the Connected Assistants list on the API Keys page in your settings.
5. Who processes data on our behalf
We use the following providers. Each one is bound by a data processing agreement and only receives the data needed for its job.
| Provider | Purpose | Data |
|---|---|---|
| Laravel Cloud | Hosting, database and queues | All data listed above |
| Stripe | Payments and invoicing | Name, email, billing address, card details |
| Our email delivery provider | Sending issue alerts, scan summaries and account emails | Email address, notification content |
| OneSignal | Push notifications and the newsletter | Email address, name, last active date |
| PostHog (EU) | Product analytics | Usage events, device and browser data |
| Google Analytics | Website analytics | Pages visited, device and browser data |
| GitHub and Google | Sign-in, if you choose it | Your identifier and email at that provider |
| Cloudflare | DNS and bot protection on forms | IP address, request metadata |
| SecurityTrails and AbuseIPDB | DNS history and IP reputation lookups during scans | The monitored domain and its IP addresses only |
| Slack | Issue notifications, if you connect a channel | Notification content |
Some of these providers process data outside the UK and EEA. Where they do, transfers rely on adequacy decisions or standard contractual clauses. We will update this list before adding a provider that handles personal data.
6. How long we keep it
- Account and application data: for as long as your account exists. When you delete your account, or ask us to, we delete your account, domains, scan results and issues within 30 days.
- Billing records: seven years after the transaction, as tax law requires.
- Server and access logs: 90 days.
- Analytics data: kept in aggregated form; identifiable events are deleted after 12 months.
- Correspondence: two years after the thread closes.
7. How we protect it
Data is encrypted in transit and at rest. API keys are stored hashed and shown once. Access to production systems is limited to the people who operate the service and is logged. If we become aware of a breach that affects your personal data we will tell you and, where required, the relevant authority without undue delay.
8. Your rights and how to use them
Under UK and EU data protection law you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we process it, or transfer it to another provider. You can also withdraw consent to the newsletter at any time.
- Delete your account: Settings, then Profile, then Delete Account. This removes everything listed under account and application data.
- Revoke an API key or a connected assistant: Settings, then API Keys.
- Export your data, or anything else: email privacy@stackshield.io from the address on your account. We answer within 30 days.
If you are not happy with how we handled a request, you can complain to the Information Commissioner's Office in the UK or your local supervisory authority in the EU.
9. Cookies
We set a session cookie and a CSRF token to keep you signed in, and analytics cookies from PostHog and Google Analytics to understand how the site is used. Your browser lets you block or delete cookies; blocking the session cookie will sign you out.
10. Changes to this policy
When we change this policy we update the date at the top. If a change affects how we use your data in a way you would not expect, we email account holders before it takes effect.
11. Contact us
Questions about this policy or your data: privacy@stackshield.io. Anything else: hello@stackshield.io.