Privacy Policy
Last updated: 5 July 2026
This Privacy Policy explains how Staxy collects, uses, discloses, and protects your personal data, and the rights you have in relation to it. It applies to the Staxy website at staxy.app, the Staxy applications for web, iOS, and Android, and the related backend services (together, the "Service").
1. Data Controller
The controller responsible for processing your personal data is:
Georgii Polianskii, acting as a registered Private Entrepreneur (individual entrepreneur) under the laws of the Republic of Armenia. Registration No. 20298661, State Register of Legal Entities, Ministry of Justice of the Republic of Armenia. Email for privacy matters: legal@staxy.app.
We have not appointed a Data Protection Officer, as we are not required to do so. All privacy enquiries should be directed to the address above.
2. Data We Collect
In connection with your use of the Service, we process the following categories of personal data.
2.1 Data you provide to us
- Account data: your email address, which is used to identify your account.
- Catalogue content: the infrastructure resources you record in the Service, including providers, units (such as servers, domains, certificates, databases, storage, DNS, mailboxes, SaaS subscriptions, and IP addresses), and projects, together with their names, descriptions, tags, notes, renewal dates, and the amounts and currencies you enter.
- Secrets you store in the vault: credentials, SSH keys, and IP addresses you choose to save. This data is end-to-end encrypted and is not readable by us (see Section 2.5).
- Support content: the subject and body of messages you send when you contact support.
- Telegram identifier: collected only if you choose to link Telegram to receive renewal reminders.
2.2 Data we collect automatically
- Account identifiers: an internal user identifier and an authentication identifier issued by our authentication provider. We do not store your password, one-time codes, or session tokens; these are managed by our authentication provider (see Section 4).
- Approximate country: derived from your IP address when you first sign in and stored as a two-letter country code, used to set sensible defaults such as currency and language.
- Settings: your language, time zone, display currency, and notification preferences.
- Subscription and payment records: your plan, subscription and transaction identifiers, amounts, currency, status, and timestamps. We do not receive or store your full card number, card security code, or billing address (see Section 2.4).
- Consent records: a record of the consents you give or withdraw, including the document version, timestamp, and the IP address and user-agent at the moment of the consent, retained as proof of consent under Article 7 GDPR.
- Technical and log data: IP address, user-agent, request metadata, and error diagnostics, processed for security, abuse prevention, and debugging.
- Product analytics: feature-usage and interaction events (pages viewed, clicks, scroll depth, page-performance metrics, and campaign parameters such as UTM tags), and, on the website, session replays of how a page is used. Replays mask all form inputs by default. Click tracking, heatmaps, session replay, and any storage on your device (cookies) are collected only where you have given your consent (see Section 8).
- Aggregate audience measurement: on our website and web app, before you make a consent choice and if you decline, we count page views and record the page address, referrer, and campaign parameters (such as UTM tags) to see which links and channels bring visitors, including across the move from the site to sign-up. This runs without storing anything on your device, does not build a profile of you, and your IP address is discarded on collection. The legal basis is our legitimate interest (Article 6(1)(f) GDPR), not consent; you can object at any time (see Sections 7 and 8).
2.3 Special category data
We do not intentionally collect special category data within the meaning of Article 9 GDPR (such as data revealing health, biometrics, or political or religious beliefs). You should not include such data in free-text fields or support messages. Where such data reaches us incidentally, we process it only to the extent necessary to handle your request and we minimise its retention. Device biometric features (such as Face ID or Touch ID) are processed locally on your device; we never receive biometric data.
2.4 Payments
Payments for purchases made in the mobile apps are processed by the relevant app store (the Apple App Store on iOS or Google Play on Android) and orchestrated through RevenueCat. Payments for purchases made on the web are processed by Polar (Polar Software, Inc.) acting as Merchant of Record. Card data is handled entirely by those providers. We never receive or store your full card number, card security code, or billing address. We retain only the subscription and transaction identifiers and the amount, currency, and status required to manage your access.
2.5 End-to-end encryption of stored secrets
The data you place in the Staxy vault, including saved credentials, SSH keys, and IP addresses, is encrypted on your device with AES-256-GCM, under a key derived from your master password using the Argon2id key-derivation function. We store only an opaque encrypted blob and never have access to the key. As a result, we cannot read this data and cannot disclose it to any third party, and we cannot recover it if you lose your master password.
3. Purposes, Legal Bases, and Retention Periods
The following table sets out the purposes for which we process your personal data, the legal basis relied upon, and the applicable retention period.
| Purpose | Data Categories | Legal Basis | Retention Period |
|---|---|---|---|
| Create and operate your account and provide the Service | Account data, catalogue content, settings | Performance of a contract, Art. 6(1)(b) | For the duration of your account; deleted or anonymised within 30 days of an account-deletion request |
| Manage subscriptions and PRO entitlements | Subscription and payment records | Performance of a contract, Art. 6(1)(b) | For the duration of the contractual relationship |
| Comply with accounting and tax obligations | Billing records | Legal obligation, Art. 6(1)(c) | As required by applicable accounting and tax law, commonly up to 7 years; related account data is anonymised on deletion |
| Maintain security, prevent abuse, and debug the Service | Technical and log data | Legitimate interests, Art. 6(1)(f) | Access logs approximately 90 days, then IP-masked; error logs up to 1 year |
| Provide and improve the Service through analytics | Product analytics | Consent, Art. 6(1)(a) | Raw events approximately 90 days; anonymous aggregates may be retained longer |
| Measure our audience and traffic sources (cookieless) | Aggregate audience measurement | Legitimate interests, Art. 6(1)(f) | Raw events approximately 90 days; anonymous aggregates may be retained longer |
| Demonstrate compliance with consent obligations | Consent records | Legitimate interests / legal obligation, Art. 6(1)(f)/(c) | Retained as proof of consent; IP and user-agent anonymised on account deletion |
| Send renewal reminders via Telegram, if linked | Telegram identifier | Consent, Art. 6(1)(a) | Until you unlink Telegram or delete your account |
| Send marketing emails, if you opt in | Consent, Art. 6(1)(a) | Until you withdraw consent | |
| Handle support requests | Support content | Performance of a contract / legitimate interests, Art. 6(1)(b)/(f) | Up to 2 to 3 years after resolution, then deleted or anonymised |
Where we rely on legitimate interests, you have the right to object as described in Section 7.
4. Recipients of Your Data
To fulfil the purposes described above, your personal data may be disclosed to the following recipients — processors acting on our instructions and, where indicated in the table, providers acting as independent controllers under their own terms:
| Recipient | Purpose | Location and safeguard |
|---|---|---|
| Clerk | Authentication (login and sessions) | United States; Standard Contractual Clauses, and the EU-U.S. Data Privacy Framework where the provider is certified (see Section 5) |
| RevenueCat | Subscription management | United States; Standard Contractual Clauses, and the EU-U.S. Data Privacy Framework where the provider is certified |
| Apple App Store, Google Play | Payment processing as Merchant of Record for purchases made in the iOS and Android apps | United States and the providers' local entities; they act as independent controllers for payment data under their own terms |
| Polar (Polar Software, Inc.) | Payment processing as Merchant of Record for purchases made on the web | United States; acts as an independent controller for payment and tax data under its own terms |
| PostHog | Product analytics — sole provider; cookie-based analytics is consent-gated, plus cookieless audience measurement on legitimate interest | European Union; no transfer outside the EEA |
| Cloud hosting (DigitalOcean or Hetzner) | Hosting of the Service and database | European Union data centres |
| Cloudflare | Content delivery, DDoS and bot protection in front of the Service, and cookieless web analytics | Cloudflare, Inc., United States, with processing at EU edge locations; Standard Contractual Clauses, and the EU-U.S. Data Privacy Framework where the provider is certified |
| Resend | Transactional email delivery (renewal reminder digests and account-related email) and, where you opt in, marketing email | Resend, Inc., United States; email is sent through Resend's EU region. Transfers are safeguarded by the Standard Contractual Clauses under Resend's Data Processing Agreement, and the EU-U.S. Data Privacy Framework where the provider is certified |
| Telegram | Delivery of renewal reminders, only if you link Telegram | Operated by Telegram outside the EEA; the reminder and your Telegram identifier are transferred at your explicit request when you link Telegram (Art. 49(1)(a) and (b) GDPR) |
Error and crash diagnostics are processed using self-hosted software running on our own infrastructure within the European Union, configured not to capture personal data; they are not shared with any third party.
We do not sell your personal data and we do not share it for cross-context behavioural advertising. We may disclose personal data where required by law, to establish, exercise, or defend legal claims, or in connection with a merger, acquisition, or sale of assets. Each processor that handles personal data on our behalf does so under a data processing agreement that meets the requirements of Article 28 GDPR.
5. International Data Transfers
Our core hosting, analytics, and error-diagnostics infrastructure is located within the European Union. Several of the recipients listed above are established outside the European Economic Area, in the United States: principally our authentication, subscription, content-delivery, and email-delivery providers, together with Polar, the Merchant of Record for purchases made on the web. In some of these cases the processing itself is carried out in an EU region (for example, our email provider sends through its EU region), but the provider is a US-incorporated company, so we treat the relationship as an international transfer. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place under Chapter V GDPR, namely the Standard Contractual Clauses approved by the European Commission and, where the recipient is certified, the EU-U.S. Data Privacy Framework. You may request information about these safeguards by contacting legal@staxy.app.
6. Retention Periods
We retain personal data only for as long as necessary for the purposes set out in Section 3. The specific periods are stated in that table. In addition: consent records are retained as proof of consent even after account deletion, with the IP address and user-agent anonymised; billing records required for accounting and tax purposes are retained for the statutory period with the related account data anonymised; and backups are retained within their rotation window of 30 to 90 days, with deletion re-applied if a backup is restored.
7. Your Rights
Under the GDPR and UK GDPR, you have the following rights regarding your personal data:
- Access (Art. 15 GDPR): obtain confirmation of whether your data is processed and receive a copy.
- Rectification (Art. 16 GDPR): have inaccurate or incomplete data corrected without undue delay.
- Erasure (Art. 17 GDPR): request deletion of your data where legally permissible.
- Restriction (Art. 18 GDPR): request temporary restriction of processing under certain conditions.
- Data portability (Art. 20 GDPR): receive your data in a structured, commonly used, machine-readable format.
- Object (Art. 21 GDPR): object to processing based on our legitimate interests; see the dedicated notice below.
- Withdraw consent (Art. 7(3) GDPR): withdraw any consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Lodge a complaint (Art. 77 GDPR): file a complaint with the supervisory authority in your country of residence within the EEA, or, in the United Kingdom, with the Information Commissioner's Office.
You can exercise several of these rights directly in the Service: you can export the personal data you provided and that we hold about your account in a machine-readable format from your account settings, delete your account from your account settings (which begins the deletion process described in Section 3), correct your profile and settings at any time, and change your analytics and marketing consent at any time. For any other request, contact legal@staxy.app. We will respond within one month, which may be extended by two further months for complex or numerous requests in accordance with Article 12(3) GDPR. We do not charge a fee unless a request is manifestly unfounded or excessive.
Right to Object (Art. 21 GDPR)
Where we process your personal data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation. Where your personal data is processed for direct marketing purposes, you have the right to object at any time, without needing to provide specific reasons. In the event of your objection, we will cease processing your data for these purposes, unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.
8. Cookies and Tracking Technologies
The Service uses cookies and similar technologies. The following table provides an overview:
| Category | Tool / Provider | Purpose | Legal Basis |
|---|---|---|---|
| Strictly necessary | First-party | Session management, security, and authentication | Not subject to consent (essential) |
| Functional | First-party | Remembering language, theme, and similar preferences | Not subject to consent (not used for tracking) |
| Analytics | PostHog (EU) | Measuring feature usage and page interactions (clicks, scrolling, session replay with masked inputs) to improve the Service | Consent, Art. 6(1)(a); off by default |
| Audience (cookieless) | PostHog (EU) | Counting page views and traffic sources (page address, referrer, UTM tags) without storing anything on your device | Legitimate interests, Art. 6(1)(f) |
Technologies that store or read information on your device, including cookie-based analytics, are not loaded until you give your consent; the analytics toggle is off by default and you can change your choice at any time in your settings. Separately, we run a cookieless audience measurement (see the row above and our Cookie Policy) that stores nothing on your device and relies on our legitimate interest; choosing "Reject non-essential" or enabling the Global Privacy Control (GPC) signal turns it off, as it does all analytics. We do not use advertising or retargeting pixels. Further detail is provided in our Cookie Policy, available at staxy.app/legal/cookies.
9. Automated Decision-Making and Artificial Intelligence
We do not use artificial intelligence or solely automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Freemium limits and renewal reminders do not constitute such decisions.
10. Data Security
We implement appropriate technical and organisational measures pursuant to Article 32 GDPR to protect your data against unauthorised access, loss, destruction, or alteration. These include encryption in transit and at rest using TLS, end-to-end encryption of the data you store in the vault (Section 2.5), least-privilege access controls, and logging practices that mask sensitive fields; we never log passwords, payment data, one-time codes, or session tokens. These measures are reviewed regularly and adapted to the state of the art. In the event of a personal data breach, we will notify the competent supervisory authority and, where required, affected individuals, in accordance with Articles 33 and 34 GDPR.
11. Children's Data
The Service is a general-audience product and is not directed at children. You must be at least 16 years old to use it. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that we have collected such data without the required consent, we will delete it without undue delay. If you believe a child has provided us with personal data, please contact legal@staxy.app.
12. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request its deletion, to request its correction, to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information.
Categories of personal information we collect. In the preceding 12 months we have collected the following CCPA categories: identifiers (such as your email address, account identifiers, IP address, approximate country, and, if you link it, your Telegram identifier); commercial information (subscription and transaction records); internet or network activity (consent-based product analytics and security logs); and other information you choose to provide (your catalogue content and support messages). We do not collect Social Security numbers, government-issued identifiers, or payment card numbers, and we do not knowingly process sensitive personal information beyond what you voluntarily provide; data you store in the vault is end-to-end encrypted and unreadable by us.
Sources of this information. We collect it directly from you, automatically from your device and your use of the Service, and from our authentication provider.
Business purposes. We use this information to provide and secure the Service, manage subscriptions, provide support, improve the Service through consent-based analytics, and comply with legal obligations, as described in Section 3.
Disclosure to third parties. We disclose personal information only to the service providers listed in Section 4 (authentication, subscription and payment processing, hosting, content delivery, analytics, and email delivery). We do not sell your personal information and we do not share it for cross-context behavioural advertising.
We honour the Global Privacy Control (GPC) signal as a valid opt-out request. To exercise your rights, contact legal@staxy.app; we will not discriminate against you for doing so.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legislation or in our practices. Each version is published as an immutable, dated version, and the current version is always available within the Service. Where changes are material, we will notify you in an appropriate manner, typically at least 30 days in advance, and will request your renewed consent where required.
14. Contact
If you have any questions about the processing of your personal data or wish to exercise your rights, you can reach us at:
Georgii Polianskii (Private Entrepreneur) Republic of Armenia Email: legal@staxy.app