Staxytaxy

Privacy Policy

Version: v2, Last updated: 2026-07-05

Privacy Policy

Last updated: 5 July 2026

This Privacy Policy explains how Staxy collects, uses, discloses, and protects your personal data, and the rights you have in relation to it. It applies to the Staxy website at staxy.app, the Staxy applications for web, iOS, and Android, and the related backend services (together, the "Service").

1. Data Controller

The controller responsible for processing your personal data is:

Georgii Polianskii, acting as a registered Private Entrepreneur (individual entrepreneur) under the laws of the Republic of Armenia. Registration No. 20298661, State Register of Legal Entities, Ministry of Justice of the Republic of Armenia. Email for privacy matters: legal@staxy.app.

We have not appointed a Data Protection Officer, as we are not required to do so. All privacy enquiries should be directed to the address above.

2. Data We Collect

In connection with your use of the Service, we process the following categories of personal data.

2.1 Data you provide to us

  • Account data: your email address, which is used to identify your account.
  • Catalogue content: the infrastructure resources you record in the Service, including providers, units (such as servers, domains, certificates, databases, storage, DNS, mailboxes, SaaS subscriptions, and IP addresses), and projects, together with their names, descriptions, tags, notes, renewal dates, and the amounts and currencies you enter.
  • Secrets you store in the vault: credentials, SSH keys, and IP addresses you choose to save. This data is end-to-end encrypted and is not readable by us (see Section 2.5).
  • Support content: the subject and body of messages you send when you contact support.
  • Telegram identifier: collected only if you choose to link Telegram to receive renewal reminders.

2.2 Data we collect automatically

  • Account identifiers: an internal user identifier and an authentication identifier issued by our authentication provider. We do not store your password, one-time codes, or session tokens; these are managed by our authentication provider (see Section 4).
  • Approximate country: derived from your IP address when you first sign in and stored as a two-letter country code, used to set sensible defaults such as currency and language.
  • Settings: your language, time zone, display currency, and notification preferences.
  • Subscription and payment records: your plan, subscription and transaction identifiers, amounts, currency, status, and timestamps. We do not receive or store your full card number, card security code, or billing address (see Section 2.4).
  • Consent records: a record of the consents you give or withdraw, including the document version, timestamp, and the IP address and user-agent at the moment of the consent, retained as proof of consent under Article 7 GDPR.
  • Technical and log data: IP address, user-agent, request metadata, and error diagnostics, processed for security, abuse prevention, and debugging.
  • Product analytics: feature-usage and interaction events (pages viewed, clicks, scroll depth, page-performance metrics, and campaign parameters such as UTM tags), and, on the website, session replays of how a page is used. Replays mask all form inputs by default. Click tracking, heatmaps, session replay, and any storage on your device (cookies) are collected only where you have given your consent (see Section 8).
  • Aggregate audience measurement: on our website and web app, before you make a consent choice and if you decline, we count page views and record the page address, referrer, and campaign parameters (such as UTM tags) to see which links and channels bring visitors, including across the move from the site to sign-up. This runs without storing anything on your device, does not build a profile of you, and your IP address is discarded on collection. The legal basis is our legitimate interest (Article 6(1)(f) GDPR), not consent; you can object at any time (see Sections 7 and 8).

2.3 Special category data

We do not intentionally collect special category data within the meaning of Article 9 GDPR (such as data revealing health, biometrics, or political or religious beliefs). You should not include such data in free-text fields or support messages. Where such data reaches us incidentally, we process it only to the extent necessary to handle your request and we minimise its retention. Device biometric features (such as Face ID or Touch ID) are processed locally on your device; we never receive biometric data.

2.4 Payments

Payments for purchases made in the mobile apps are processed by the relevant app store (the Apple App Store on iOS or Google Play on Android) and orchestrated through RevenueCat. Payments for purchases made on the web are processed by Polar (Polar Software, Inc.) acting as Merchant of Record. Card data is handled entirely by those providers. We never receive or store your full card number, card security code, or billing address. We retain only the subscription and transaction identifiers and the amount, currency, and status required to manage your access.

2.5 End-to-end encryption of stored secrets

The data you place in the Staxy vault, including saved credentials, SSH keys, and IP addresses, is encrypted on your device with AES-256-GCM, under a key derived from your master password using the Argon2id key-derivation function. We store only an opaque encrypted blob and never have access to the key. As a result, we cannot read this data and cannot disclose it to any third party, and we cannot recover it if you lose your master password.

3. Purposes, Legal Bases, and Retention Periods

The following table sets out the purposes for which we process your personal data, the legal basis relied upon, and the applicable retention period.

PurposeData CategoriesLegal BasisRetention Period
Create and operate your account and provide the ServiceAccount data, catalogue content, settingsPerformance of a contract, Art. 6(1)(b)For the duration of your account; deleted or anonymised within 30 days of an account-deletion request
Manage subscriptions and PRO entitlementsSubscription and payment recordsPerformance of a contract, Art. 6(1)(b)For the duration of the contractual relationship
Comply with accounting and tax obligationsBilling recordsLegal obligation, Art. 6(1)(c)As required by applicable accounting and tax law, commonly up to 7 years; related account data is anonymised on deletion
Maintain security, prevent abuse, and debug the ServiceTechnical and log dataLegitimate interests, Art. 6(1)(f)Access logs approximately 90 days, then IP-masked; error logs up to 1 year
Provide and improve the Service through analyticsProduct analyticsConsent, Art. 6(1)(a)Raw events approximately 90 days; anonymous aggregates may be retained longer
Measure our audience and traffic sources (cookieless)Aggregate audience measurementLegitimate interests, Art. 6(1)(f)Raw events approximately 90 days; anonymous aggregates may be retained longer
Demonstrate compliance with consent obligationsConsent recordsLegitimate interests / legal obligation, Art. 6(1)(f)/(c)Retained as proof of consent; IP and user-agent anonymised on account deletion
Send renewal reminders via Telegram, if linkedTelegram identifierConsent, Art. 6(1)(a)Until you unlink Telegram or delete your account
Send marketing emails, if you opt inEmailConsent, Art. 6(1)(a)Until you withdraw consent
Handle support requestsSupport contentPerformance of a contract / legitimate interests, Art. 6(1)(b)/(f)Up to 2 to 3 years after resolution, then deleted or anonymised

Where we rely on legitimate interests, you have the right to object as described in Section 7.

4. Recipients of Your Data

To fulfil the purposes described above, your personal data may be disclosed to the following recipients — processors acting on our instructions and, where indicated in the table, providers acting as independent controllers under their own terms:

RecipientPurposeLocation and safeguard
ClerkAuthentication (login and sessions)United States; Standard Contractual Clauses, and the EU-U.S. Data Privacy Framework where the provider is certified (see Section 5)
RevenueCatSubscription managementUnited States; Standard Contractual Clauses, and the EU-U.S. Data Privacy Framework where the provider is certified
Apple App Store, Google PlayPayment processing as Merchant of Record for purchases made in the iOS and Android appsUnited States and the providers' local entities; they act as independent controllers for payment data under their own terms
Polar (Polar Software, Inc.)Payment processing as Merchant of Record for purchases made on the webUnited States; acts as an independent controller for payment and tax data under its own terms
PostHogProduct analytics — sole provider; cookie-based analytics is consent-gated, plus cookieless audience measurement on legitimate interestEuropean Union; no transfer outside the EEA
Cloud hosting (DigitalOcean or Hetzner)Hosting of the Service and databaseEuropean Union data centres
CloudflareContent delivery, DDoS and bot protection in front of the Service, and cookieless web analyticsCloudflare, Inc., United States, with processing at EU edge locations; Standard Contractual Clauses, and the EU-U.S. Data Privacy Framework where the provider is certified
ResendTransactional email delivery (renewal reminder digests and account-related email) and, where you opt in, marketing emailResend, Inc., United States; email is sent through Resend's EU region. Transfers are safeguarded by the Standard Contractual Clauses under Resend's Data Processing Agreement, and the EU-U.S. Data Privacy Framework where the provider is certified
TelegramDelivery of renewal reminders, only if you link TelegramOperated by Telegram outside the EEA; the reminder and your Telegram identifier are transferred at your explicit request when you link Telegram (Art. 49(1)(a) and (b) GDPR)

Error and crash diagnostics are processed using self-hosted software running on our own infrastructure within the European Union, configured not to capture personal data; they are not shared with any third party.

We do not sell your personal data and we do not share it for cross-context behavioural advertising. We may disclose personal data where required by law, to establish, exercise, or defend legal claims, or in connection with a merger, acquisition, or sale of assets. Each processor that handles personal data on our behalf does so under a data processing agreement that meets the requirements of Article 28 GDPR.

5. International Data Transfers

Our core hosting, analytics, and error-diagnostics infrastructure is located within the European Union. Several of the recipients listed above are established outside the European Economic Area, in the United States: principally our authentication, subscription, content-delivery, and email-delivery providers, together with Polar, the Merchant of Record for purchases made on the web. In some of these cases the processing itself is carried out in an EU region (for example, our email provider sends through its EU region), but the provider is a US-incorporated company, so we treat the relationship as an international transfer. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place under Chapter V GDPR, namely the Standard Contractual Clauses approved by the European Commission and, where the recipient is certified, the EU-U.S. Data Privacy Framework. You may request information about these safeguards by contacting legal@staxy.app.

6. Retention Periods

We retain personal data only for as long as necessary for the purposes set out in Section 3. The specific periods are stated in that table. In addition: consent records are retained as proof of consent even after account deletion, with the IP address and user-agent anonymised; billing records required for accounting and tax purposes are retained for the statutory period with the related account data anonymised; and backups are retained within their rotation window of 30 to 90 days, with deletion re-applied if a backup is restored.

7. Your Rights

Under the GDPR and UK GDPR, you have the following rights regarding your personal data:

  • Access (Art. 15 GDPR): obtain confirmation of whether your data is processed and receive a copy.
  • Rectification (Art. 16 GDPR): have inaccurate or incomplete data corrected without undue delay.
  • Erasure (Art. 17 GDPR): request deletion of your data where legally permissible.
  • Restriction (Art. 18 GDPR): request temporary restriction of processing under certain conditions.
  • Data portability (Art. 20 GDPR): receive your data in a structured, commonly used, machine-readable format.
  • Object (Art. 21 GDPR): object to processing based on our legitimate interests; see the dedicated notice below.
  • Withdraw consent (Art. 7(3) GDPR): withdraw any consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Lodge a complaint (Art. 77 GDPR): file a complaint with the supervisory authority in your country of residence within the EEA, or, in the United Kingdom, with the Information Commissioner's Office.

You can exercise several of these rights directly in the Service: you can export the personal data you provided and that we hold about your account in a machine-readable format from your account settings, delete your account from your account settings (which begins the deletion process described in Section 3), correct your profile and settings at any time, and change your analytics and marketing consent at any time. For any other request, contact legal@staxy.app. We will respond within one month, which may be extended by two further months for complex or numerous requests in accordance with Article 12(3) GDPR. We do not charge a fee unless a request is manifestly unfounded or excessive.

Right to Object (Art. 21 GDPR)

Where we process your personal data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation. Where your personal data is processed for direct marketing purposes, you have the right to object at any time, without needing to provide specific reasons. In the event of your objection, we will cease processing your data for these purposes, unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.

8. Cookies and Tracking Technologies

The Service uses cookies and similar technologies. The following table provides an overview:

CategoryTool / ProviderPurposeLegal Basis
Strictly necessaryFirst-partySession management, security, and authenticationNot subject to consent (essential)
FunctionalFirst-partyRemembering language, theme, and similar preferencesNot subject to consent (not used for tracking)
AnalyticsPostHog (EU)Measuring feature usage and page interactions (clicks, scrolling, session replay with masked inputs) to improve the ServiceConsent, Art. 6(1)(a); off by default
Audience (cookieless)PostHog (EU)Counting page views and traffic sources (page address, referrer, UTM tags) without storing anything on your deviceLegitimate interests, Art. 6(1)(f)

Technologies that store or read information on your device, including cookie-based analytics, are not loaded until you give your consent; the analytics toggle is off by default and you can change your choice at any time in your settings. Separately, we run a cookieless audience measurement (see the row above and our Cookie Policy) that stores nothing on your device and relies on our legitimate interest; choosing "Reject non-essential" or enabling the Global Privacy Control (GPC) signal turns it off, as it does all analytics. We do not use advertising or retargeting pixels. Further detail is provided in our Cookie Policy, available at staxy.app/legal/cookies.

9. Automated Decision-Making and Artificial Intelligence

We do not use artificial intelligence or solely automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Freemium limits and renewal reminders do not constitute such decisions.

10. Data Security

We implement appropriate technical and organisational measures pursuant to Article 32 GDPR to protect your data against unauthorised access, loss, destruction, or alteration. These include encryption in transit and at rest using TLS, end-to-end encryption of the data you store in the vault (Section 2.5), least-privilege access controls, and logging practices that mask sensitive fields; we never log passwords, payment data, one-time codes, or session tokens. These measures are reviewed regularly and adapted to the state of the art. In the event of a personal data breach, we will notify the competent supervisory authority and, where required, affected individuals, in accordance with Articles 33 and 34 GDPR.

11. Children's Data

The Service is a general-audience product and is not directed at children. You must be at least 16 years old to use it. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that we have collected such data without the required consent, we will delete it without undue delay. If you believe a child has provided us with personal data, please contact legal@staxy.app.

12. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, to request its deletion, to request its correction, to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information.

Categories of personal information we collect. In the preceding 12 months we have collected the following CCPA categories: identifiers (such as your email address, account identifiers, IP address, approximate country, and, if you link it, your Telegram identifier); commercial information (subscription and transaction records); internet or network activity (consent-based product analytics and security logs); and other information you choose to provide (your catalogue content and support messages). We do not collect Social Security numbers, government-issued identifiers, or payment card numbers, and we do not knowingly process sensitive personal information beyond what you voluntarily provide; data you store in the vault is end-to-end encrypted and unreadable by us.

Sources of this information. We collect it directly from you, automatically from your device and your use of the Service, and from our authentication provider.

Business purposes. We use this information to provide and secure the Service, manage subscriptions, provide support, improve the Service through consent-based analytics, and comply with legal obligations, as described in Section 3.

Disclosure to third parties. We disclose personal information only to the service providers listed in Section 4 (authentication, subscription and payment processing, hosting, content delivery, analytics, and email delivery). We do not sell your personal information and we do not share it for cross-context behavioural advertising.

We honour the Global Privacy Control (GPC) signal as a valid opt-out request. To exercise your rights, contact legal@staxy.app; we will not discriminate against you for doing so.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in legislation or in our practices. Each version is published as an immutable, dated version, and the current version is always available within the Service. Where changes are material, we will notify you in an appropriate manner, typically at least 30 days in advance, and will request your renewed consent where required.

14. Contact

If you have any questions about the processing of your personal data or wish to exercise your rights, you can reach us at:

Georgii Polianskii (Private Entrepreneur) Republic of Armenia Email: legal@staxy.app

We use analytics, including session replay, to understand what works. No ads, no third-party data sales.

Learn more about cookies