StackDesign Privacy Policy

Privacy Policy

What StackDesign collects, why we collect it, which companies help us process it, what happens to what you type into the AI Designer, and how to see, export or delete all of it.

Effective date: August 22, 2026 Version 1.1

This policy is in force, and it describes how StackDesign is actually built.

Every practice below was checked against the running code on the day this version was published, not copied from a template. StackDesign is free during an open beta; the Open Beta Terms cover the beta itself, and this policy covers your personal information either way.

The short version

A plain-words summary for orientation only. It is not the policy, and the full text below governs.

1. Who we are, and what this policy covers

In plain words

This policy covers stackdesign.app and everything you do on it.

StackDesign is a web-native cabinet and room design service operated by Bespoke Woodcraft Studio LLC, a California limited liability company, whose registered business address is 688 N Rimsdale Ave, Covina, CA 91722, United States ("we", "us", "StackDesign"). Bespoke Woodcraft Studio is the data controller for the personal information described here.

This policy explains how we handle personal information on stackdesign.app and in the StackDesign tools, including the AI Designer. It works alongside our Terms of Service.

Many StackDesign tools run without an account at all. If you use the site that way, the only data we hold about you is the ordinary web server log described in section 2 and the usage measurement described in section 8.

2. What we collect

In plain words

Your sign-in details, the design work you save, your billing record, what you type to the AI Designer, standard server logs, and how the site itself gets used. That is all.

Categories of personal information StackDesign collects, and where each one comes from.
Category What is in it Where it comes from
Account and identity Your email address. If you set a password, we store only a salted hash of it, never the password itself, so nobody here can read it. If you sign in with Google, the basic profile Google returns (name, email, and profile picture reference). Sign-in timestamps and session records. You, when you create an account, or Google when you choose Google sign-in.
Your design work Projects, rooms, cabinets, dimensions, material and hardware selections, company standards, pricing rules, cut lists and saved outputs. You, as you use the tools.
Your customers' records Contact details and job notes you enter about your own customers. See section 5, which explains that we handle this on your behalf, not for our own purposes. You, when you use the customer features.
Billing Your subscription status, plan, renewal dates, and the identifiers Stripe gives us for your customer and subscription records. We do not receive or store your full card number. Stripe, when you subscribe.
AI Designer conversations The messages you send the assistant, the project context needed to answer them, and the replies you receive. See section 4. You, when you use the AI Designer.
Technical and log data IP address, browser and device type, pages requested, timestamps, and error diagnostics. These are the ordinary logs any web host produces. Automatically, when your browser requests a page.
How the site gets used Which pages and features get opened, in what order, plus browser, device type and country. A page count runs on every visit, from a service that states it sets no cookies and identifies nobody. The fuller product analytics, which stores identifiers in cookies and in your browser's local storage and is tied to your account while you are signed in, runs only if you accept the cookie banner. Section 8 has the detail. Automatically, as you use the site.
Support messages Anything you send us by email, and our replies. You, when you contact us.

We do not ask for and do not want sensitive personal information such as government identifiers, health data, precise geolocation or biometric data. Please do not enter it into StackDesign.

3. Why we use it

In plain words

To sign you in, save your work, take your payment, answer your chat, keep the service up, and follow the law.

If you are in a region with a legal-basis requirement such as the European Economic Area or the United Kingdom, our bases are: performance of our contract with you (running your account and the tools), legitimate interests (security, abuse prevention, improving the Service), legal obligation (tax and accounting), and consent where we ask for it.

4. The AI Designer: what happens to what you type

In plain words

Your chat goes to Anthropic to produce the answer. It is not used to train any model, and Anthropic deletes its own operational copy on a short rolling window.

When you use the AI Designer, your message and the project context needed to answer it are sent from our server to Anthropic's API, which generates the reply. The call is made server side, so your browser never talks to the AI provider directly and no AI provider key is exposed to you.

Under Anthropic's standard commercial API terms, which is how StackDesign uses the service:

Those three points describe Anthropic's commercial terms as they stood when this version was published. Vendor terms drift, so we re-read them whenever we publish a new version of this policy, and we will change this section rather than leave a stale promise standing.

We keep your conversation and any project facts it produced in your own workspace so the assistant has continuity between sessions. That copy is yours: you can delete it, and it goes when your account goes (see section 10).

There is a second AI provider, and it is connected but not yours to use. Your conversations are answered by Anthropic. StackDesign also carries a model switch that routes a conversation to Google instead, using Google's Gemini API, and that switch can only be turned on by one of our own platform administrator accounts. There is no address you can type, no setting in your account and no supported way for you to reach it, so no customer conversation is sent to Google. We use it for our own testing. It is disclosed here, and Google is listed in the table below, because the connection is live on our server and we would rather name a thing that exists than describe Anthropic as the only provider wired up. If we ever make a second provider available to you, we will say so on this page before any of your data reaches it. A third option labelled ChatGPT appears in the same internal switch but is not connected to anything.

We would rather tell you the switch exists than describe a single provider and leave you to discover a second one. If we connect another provider, we will name it here before any customer data reaches it.

Please do not paste anything into the assistant that you would not want processed by a third-party AI provider, including other people's personal information you have no right to share.

5. Customer records you store in StackDesign

In plain words

When you save your own customers' details in StackDesign, they are your records, not ours. You decide what goes in and why. We just hold them for you and do what you ask with them.

StackDesign lets a shop store contact records and job notes about its own customers. That information is personal information about people who are not our users, so it is worth being precise about who is responsible for what.

You are the controller. We are the processor. In plain words: you decide what customer information to collect, why you collect it, and how long to keep it. We only hold and process it on your instructions, so that the Service works for you. We do not use your customers' details for our own purposes, we do not market to them, and we do not sell or share them with anyone outside the sub-processors listed in section 6.

That means a few practical things:

Our standard agreement for this is written to Article 28 of the General Data Protection Regulation: it names the subject matter and duration of the processing, restricts us to acting on your documented instructions, binds us to confidentiality and security, passes the same obligations down to the sub-processors in section 6, and commits us to help you answer your own customers' requests. Ask us for it using the details in section 15.

6. Who processes data for us

In plain words

Nine companies. Here is exactly what each one holds and why.

Every sub-processor StackDesign uses, what it handles, and why.
Sub-processor What it handles Why
Supabase Accounts and sign-in, plus the database holding your projects, materials, standards and customer records. It is our identity provider and our database. Without it there is no account and no saved work.
Stripe Subscription payments and the card details you enter at checkout. Stripe is the payment processor. Card data goes to Stripe directly, so we never hold it.
Anthropic Your AI Designer messages and the project context needed to answer them. It provides the AI model the assistant uses by default. See section 4.
Google The same AI Designer messages and project context, but only for a conversation one of our own administrators has switched to Gemini while testing. No customer conversation is routed to Google. It provides the alternative AI model behind our internal switch, and it is listed here because the connection is live rather than because your data goes there. This is a separate matter from Sign in with Google, described under this table. See section 4.
Vercel Hosting, content delivery, and the server and function logs that come with running the site. It serves the site and runs our server-side functions.
Resend The email we send you and the address it goes to: the welcome message, account and billing notices, replies from our support address, and the newsletter if you asked for it. It is our email provider. Without it we cannot send you a receipt, a sign-in link, or an answer to a support message.
Ahrefs Web Analytics A count of page views: the page address, where the visit came from, browser and device type, and country or city. Ahrefs states that it sets no cookies, stores nothing on your device, and never keeps a raw IP address, hashing it with a daily salt instead. It tells us which pages people actually read. It runs on every visit because, on that description, there is nothing stored on your device to ask you about.
PostHog Product analytics: which features get used, in what order, and where people get stuck. It stores its identifiers in cookies and in your browser's local storage, and while you are signed in what it records is tied to your account. We run it with autocapture and session recording switched off, so it never records what you click on, what you type, or what is on your screen. Your designs, your dimensions, your customers' records and your AI Designer messages are never sent to it. It is how we learn which parts of the tool work and which do not. It loads only if you accept the cookie banner, and never if you decline. See section 8.
Upstash A short-lived counter kept against your IP address, one per endpoint you call. It holds no name, no email, no account id and nothing you typed. Each counter deletes itself when its window closes, which is a matter of hours at most. It is how we stop one caller flooding an endpoint and taking the service down for everyone else. There is no way to do that without recognising a repeat caller for a short time.

Each of these providers processes data for us under its own data processing agreement, which forms part of the terms we accepted when we opened the account and which restricts that provider to processing data for the purpose we engaged it for. Those agreements also carry the transfer protections described in section 13.

Google, if you sign in with it. This is a different thing from the Gemini row above, and the distinction matters. For the AI model, Google processes your conversation on our behalf, as our sub-processor. For sign-in it does not: When you choose Sign in with Google, you are asking Google to confirm who you are, and it hands us your name, email address and a reference to your profile picture. Google decides for itself what it records about that sign-in, under its own privacy policy, not ours. If you would rather not involve Google, use a password or an email sign-in link instead.

Beyond those nine, we share personal information only when we have to: with professional advisers under confidentiality, in response to a lawful legal request, to protect the rights or safety of people or of the Service, or to a successor if the business is sold, in which case we would tell you first.

7. What we never do

In plain words

These are hard commitments, not aspirations.

  • We never sell your personal information, and we never sell your customers' details.
  • We never share your personal information for cross-context behavioural advertising.
  • We never use your designs, dimensions, chat or customer records to train AI models, and we do not let our AI provider do so either.
  • We never run third-party advertising trackers or advertising pixels on the site.
  • We never read your projects except when you ask us for support and we need to, or where security or the law requires it.

8. Cookies, local storage and tracking

In plain words

Signing you in and remembering your settings use browser storage, and always have. Analytics cookies are a separate question, and we ask it with a banner before we set one.

StackDesign uses browser storage for three things of its own:

The cookie banner, and what each answer does

The first time you open StackDesign you get a banner asking about analytics cookies. PostHog does not load until you answer it, and the answer sticks.

What runs either way. Ahrefs Web Analytics counts page views on this site, including this page, and it sits outside the cookie choice. Ahrefs states that it sets no cookies, stores nothing on your device, collects no personal data, and never keeps a raw IP address, hashing it with a daily salt instead. We rely on that description, and it is why there is nothing here for you to consent to. Ahrefs is listed in section 6 with every other provider.

Changing your mind. Clearing it makes the banner ask again the next time you open StackDesign, and nothing goes to PostHog until you have answered it.

If you had accepted and then cleared it, PostHog stops at once in any StackDesign tab you still have open, and the cookie and the random id it kept in your browser are deleted. If no tab is open, they are deleted the next time you open StackDesign. One entry is deliberately kept: PostHog's own note that you opted out, which is the thing that stops it starting again. Clearing your browser's site data for this site removes that too.

Do Not Track and Global Privacy Control. California law requires us to tell you how we respond to Do Not Track signals. We do not follow you across other websites and we run no advertising trackers, so there is no cross-site tracking here for a Do Not Track signal to switch off. There is nothing for a Global Privacy Control signal to switch off either, because we never sell or share personal information in the first place.

9. Where your data lives, and how it is protected

In plain words

It lives in our Supabase database, it travels encrypted, and each workspace is walled off from every other one at the database level.

Your account and your work are stored in our Supabase database. Traffic between your browser, our site and our providers is encrypted in transit using TLS, and data is encrypted at rest by our providers.

Access between workspaces is enforced in the database itself, using row level security policies, so one customer's account cannot read another customer's projects, materials or customer records. Administrative access on our side is limited to the people who need it to run and support the Service.

No system is perfectly secure, and we cannot promise that a determined attacker will never succeed. If a breach affects your personal information, we will notify you and any regulator as the law requires.

10. How long we keep it, and how to delete it

In plain words

You can delete your account yourself, from your account settings. The live data goes right away. Encrypted backups take a little longer to age out, and we would rather tell you that than pretend otherwise.

We keep your account and your work for as long as your account is open, and for as long afterwards as we need to meet a legal or accounting obligation.

Deleting your account. You can delete your StackDesign account yourself from your account settings. Doing so removes your account and the project data attached to it from the live database.

Backups, honestly. Deletion from the live database does not instantly erase every encrypted backup copy. Backups roll over on a fixed schedule, and a deleted record disappears from them as they age out. We do not restore deleted data from a backup except to recover from a genuine system failure. Here is the actual number: our database runs on the Supabase Pro plan, which takes a backup once a day and keeps each one for seven days. So a record you delete today is gone from the live database immediately and out of the last backup copy within a week.

Records we keep after deletion. We retain what the law requires us to retain, which is mainly the billing and tax record of what you paid, and the record of your consent to a recurring charge, which California's automatic renewal law requires us to keep. We keep that consent record for three years, or for one year after the subscription ends, whichever is the longer of the two. Nothing is being charged during the open beta, so for most accounts there is no such record yet.

AI conversations. Your AI Designer conversation history and the project facts it produced are part of your workspace and are deleted with it.

11. Your privacy rights

In plain words

You can ask to see it, correct it, take it with you, or delete it. Ask us and we will do it, whether or not a particular law obliges us to.

Whoever you are and wherever you live, you can ask us to:

Contact us as described in section 15. We will respond within the time the applicable law allows, and we will not treat you worse for exercising a right.

If you are in California

The California Online Privacy Protection Act applies to StackDesign regardless of our size. This page is our conspicuously posted privacy policy under that law: it names the categories of personal information we collect (section 2), the third parties we share it with (section 6), how you review and change your information (section 11 and your account settings), how we announce changes to this policy (section 14), and our Do Not Track disclosure (section 8).

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to businesses above certain revenue and volume thresholds. StackDesign does not meet those thresholds today, so we are not currently a covered business under that law. We nevertheless offer the rights it grants, as a matter of practice: to know, to delete, to correct, to opt out of sale or sharing (which never happens here), and to limit the use of sensitive personal information (which we do not collect). We do not sell or share personal information as those terms are defined in that law, and we have not done so in the preceding twelve months.

If you are in the European Economic Area, the United Kingdom or Switzerland

The General Data Protection Regulation may apply to you even though we are based in the United States, because it follows the person rather than the company. You have the rights to access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where we rely on it. You also have the right to complain to your local supervisory authority.

We have not appointed an Article 27 representative, and we would rather say so plainly than leave the question open. That obligation applies to companies outside the European Union or United Kingdom that offer goods or services to people there, or monitor their behaviour, on more than an occasional basis. We are a small California company, we do not target or advertise to the European Union or the United Kingdom, and any use from there today is occasional. We review that as the business grows and will appoint a representative, and name them here, if the position changes. In the meantime you can reach us directly using section 15, and you keep every right described above, including the right to complain to your local supervisory authority.

12. Children

In plain words

This is a professional tool, not a service for children.

StackDesign is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.

13. International transfers

In plain words

We are a United States business, so your data is processed there.

StackDesign is operated from the United States, and our sub-processors process data in the United States and, depending on the provider, in other countries where they operate. If you use StackDesign from outside the United States, you are sending your information to the United States.

Where personal information is transferred out of the European Economic Area, the United Kingdom or Switzerland, our providers' data processing agreements include the European Commission's Standard Contractual Clauses, or an equivalent approved transfer mechanism.

14. Changes to this policy

In plain words

If we change something that matters, we will change the date at the top and tell you.

We will update this policy when our practices or the law change. The effective date at the top of the page always shows the current version.

If we make a material change, for example adding a sub-processor that handles personal information or starting to use a new category of data, we will post the updated policy here before the change takes effect and tell account holders by email or by a notice in the Service.

15. How to reach us

In plain words

One address for any privacy question or request.

For any privacy question, or to make a request under section 11, write to us through the contact form on our support page - we reply within one business day.

Written requests and formal notices can be posted to us at:

Bespoke Woodcraft Studio LLC
688 N Rimsdale Ave
Covina, CA 91722
United States

We have not appointed a dedicated data protection officer. One is required only of public authorities and of organisations whose core activity is large-scale monitoring or large-scale processing of sensitive data, and we are neither. Privacy requests go to the address above and are handled by the company's owner.

To help us find your records quickly, write from the email address on your StackDesign account where you can. If we cannot verify that a request comes from you, we may not be able to act on it, which is a protection for you rather than an obstacle.