Privacy

Last updated 22 July 2026

Who we are

Stack Robot is operated by Hello World s.r.o., Šoltésovej 720/16, 965 01 Žiar nad Hronom, Slovakia. Company ID (IČO) 52584429, Tax ID (DIČ) 2121073779. We are the data controller for the personal data described here.

For anything in this policy, write to hello@stackrobot.dev.

What we collect

Only what the service needs to work. There is no hidden collection beyond this list.

  • Your account. Your name, email address, GitHub username and avatar, taken from GitHub when you sign in.
  • Your repositories. The names of the repositories you connect, whether each one is private, and the package and tool names we read from your manifests.
  • Your digest settings. The digests you set up, the packages and projects you follow, your schedule, timezone and filters, and a record of what we've already sent you so we don't send it twice.
  • Link clicks. Links in the digests we send, and on their timeline pages, pass through a short redirect on our own domain that counts the click before sending you on. We record which release, article, or advisory was opened and which digest edition it came from — not your IP address or anything about your browser.
  • Your connections. Access tokens for GitHub and Slack, stored encrypted, plus your Slack workspace and the channel you chose.
  • Your billing state. Your plan, trial dates, and customer and subscription identifiers from Polar.
  • Technical logs. Errors and performance, both on our servers and in your browser, which can include your IP address, your browser and the page you were on. We use Better Stack for this, and its script runs on every page.

What we don't collect

  • Not your source code. Our GitHub app reads your package manifests and workspace config — the package.json files in your repository, including a monorepo's workspace packages. We parse them, keep the package and tool names, and throw the files away. Nothing else in your repositories is ever stored.
  • Not your Slack messages. Our Slack app can list your channels and post to the one you pick. It does not hold the permission needed to read messages, so it cannot read them — even if we wanted to.
  • Not your card details. Payment happens on Polar's checkout page. Card numbers never touch our servers.
  • No advertising, no marketing analytics. There are no ad networks, no tracking pixels, no cross-site tracking, and nothing that follows you around the web. The link-click counting described above happens on our own domain and stays there. We do not sell or share your data. We do run one third-party script — Better Stack, which tells us when a page breaks or runs slowly — and it's described above.

What the GitHub app can see

Read-only access to sign you in, list your repositories, and fetch your package manifests — it has no write access, so it cannot change anything. Why the permission it asks for looks broader than that, and exactly what we read, is explained on our security page.

How we use AI

Google's Gemini summarizes the public release notes and articles in a digest and writes its introduction and project overviews. We send the public source text, the names of the public projects and packages covered — vercel/next.js, say — and update metadata such as release types and security severity.

Nothing identifying you goes with it: no name, no email address, no account id. And we never send your source code, your manifests or the names of your own repositories to an AI model. Nothing of yours is involved in producing the summaries or editorial copy.

Who we share data with

We use a small number of processors to run the service. We host the app and the database in the EU, but some of these companies are based outside it and may process data there. Where they do, the transfer rests on the European Commission's standard contractual clauses.

WhoWhat forWhat they get
RenderHosting for the app and the databaseEverything we store
ResendSending email digests and account emailYour name, email address, digest content
PolarPayments, as our merchant of recordYour name, email address, IP address
Better StackMonitoring errors and performance, on our servers and in your browserTechnical logs, which can include your user id, IP address, browser and the page you're on
Google (Gemini)Summarizing public updates and writing digest editorial copyPublic release notes and articles, plus the names and update metadata of the public projects your digest covers

Your integrations work differently. The services you connect already hold your data: your code is on GitHub, your team already talks in Slack. Connecting them doesn't move anything anywhere new. It lets us read what you allow us to read, and post where you tell us to post, under permissions you grant and can withdraw at any time. What those companies do with the data they already hold is governed by their terms, not ours.

Why we're allowed to hold it

Almost everything here we hold to perform our contract with you — we cannot send you a digest without knowing what you depend on and where to send it. We keep server logs and error reports on the basis of our legitimate interest in keeping the service secure and working. Billing records we keep because Slovak law requires it.

How long we keep it

Most of what's in our database isn't about you at all: it's a library of public releases, changelogs and articles gathered from the open web, and we keep that indefinitely. The part that concerns you — your account, your repositories, your digests and your settings — we keep for as long as your account exists.

Ask us to delete your account and we'll delete it, along with your connected repositories, digests and settings, within 30 days. Billing records we have to keep for as long as Slovak tax law requires.

Your rights

Under the GDPR you can ask us for a copy of your data, correct it, have it deleted, or object to how we use it. Email hello@stackrobot.dev and we'll take care of it — there's no form to fill in.

If you think we've handled your data badly, you can complain to the Slovak data protection authority (Úrad na ochranu osobných údajov Slovenskej republiky). We'd rather you told us first, so we can put it right.

Cookies

We set one cookie ourselves, when you sign in, so we know it's you on your next request. It isn't used to track you, and we don't use cookies for advertising or marketing analytics.

Security

We host in the EU, encrypt traffic in transit and your access tokens at rest, and limit production access to the people who need it. The details — including how to revoke our access at any time — are on our security page.

No service is perfectly secure. If we ever discover a breach that puts your data at risk, we'll tell you and the regulator, as the law requires.

Changes

If we change this policy we'll update the date at the top, and we'll email you before anything that materially affects you takes effect.