Privacy

Your data, and the short list of what we do with it.

Stacklink is operated by WeCommit Ltd. Stacklink runs tool calls on behalf of your users, so we hold access tokens and operational records, plus content only when an enabled feature requires it. This page says exactly what, why, and for how long.

UPDATED 6 OCT 2026EFFECTIVE 26 AUG 2026PLAIN ENGLISH · NO DARK PATTERNS
We never train on your dataContent passing through Stacklink is not used to train models, ours or anyone's.
Tokens and governed recordsWe store credentials and the operational record needed to run and audit your calls.
You control MemoryLearning is selected by default when connecting supported accounts. You can turn it off and remove remembered data.
No card collection at launchThe controlled launch uses internal billing and does not collect card details.

01What we collect

Account data

You sign in with Google. From that we store your email address, display name and profile picture URL — nothing more from your Google account, and no access to your Gmail, Drive or Calendar comes from signing in.

Data your agents touch

When one of your users connects an app, we store an access token for that user's account and the metadata needed to refresh it. We call the provider's API on your agent's behalf and return the result. Provider content is processed to serve the request. It is persisted only where an enabled feature requires it, such as Memory, Workbench artifacts, or the operational records described below.

Operational records

Every tool call produces a log line: which tool, which arguments, which result status, how long it took, which user and which approval. This is what makes the platform auditable, and it is retained for as long as your plan's retention window allows.

Billing data

Plan, usage counters, written orders and invoices. During the controlled launch, billing is handled internally and Stacklink does not collect card details.

Meeting bookings

When you book a call with us, Cal.com processes your name, email address, selected time and any notes you submit to arrange the meeting and send booking updates. Our connected calendar and meeting provider, Google Calendar and Google Meet, receive the information needed for your invitation and call. The suggested agenda is editable and optional. Please avoid including confidential information in booking notes.

02What we do with it

  • Run what your agent asked for — find tools, sign in as your user, execute the call, return the result.
  • Keep the record so you can answer "what did the agent do?" — and so approvals are provable.
  • Meter usage against your plan. Failed calls are never counted.
  • Keep the service up — errors, performance, abuse prevention.
  • Talk to you about your account, incidents and changes that affect you.
We do not train models on your data. Content that passes through Stacklink is not used to train our models or anyone else's, and is not sold or rented. Where a feature calls a model on your behalf, it is called to serve that request only.

03Third-party accounts your users connect

This is the part that matters most, so it is worth being blunt about it. When your user connects an app through a Stacklink connect link:

  • They authenticate with the provider directly. Their password is never shown to you, to your agent, or to us.
  • The grant is scoped to what that provider's consent screen showed them, and it belongs to that user — not to a shared bot account.
  • The token is stored encrypted and used only to serve calls made under that user's identity.
  • They can disconnect at any time in Stacklink or revoke access with the provider. Disconnect stops future Stacklink calls for that connection and requests provider revocation where supported. Google connections using the same grant can be affected together.

Google user data

Connecting a Google toolkit is separate from signing in. Depending on the permissions you grant, Stacklink can access Gmail messages, drafts, labels, filters and mail settings; saved and Other Contacts; Drive files and folders; Docs content; and Sheets data, including BigQuery data accessed through Connected Sheets. These features support your requested searches, reads, edits, email actions and selected-source Memory. Connecting Sheets does not give Stacklink unrestricted BigQuery write access.

We use this data to provide the features you use, including actions by agents authorized to act for you. We do not sell Google user data, use it for advertising, or use it to train generalized AI models. Content may be passed to your authorized agent or to a model provider when needed to serve the request. The storage, retention, subprocessors and deletion controls below also apply to Google data; turning Memory off does not remove tool-call records or Workbench artifacts.

Stacklink's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

04Memory and your choices

Memory stores useful context from authorized, selected sources so later requests can use it. On supported connection screens, learning is selected by default. You can turn it off before connecting and manage source selection, pause learning or remove sources later. Google source selection controls which labels, folders, documents or spreadsheets are learned; granting API access is not the same as selecting every resource for Memory.

Memory is scoped to the project and end user. Remembered facts and their source evidence can be inspected and removed through the dashboard and API. Removing a source queues erasure of its support; it does not erase copies in the original provider, unrelated sources, tool-call records or Workbench artifacts. Disconnect and Memory deletion are separate controls.

See Data deletion for how to erase a single fact, everything about one person, or a whole tenant.

05Cookies

We use a session cookie to keep you signed in to the dashboard, and a small preference cookie for things like your theme. We do not use advertising cookies or cross-site tracking pixels on the app. Marketing pages may use privacy-respecting analytics to count visits; nothing there identifies you personally.

The Cal.com calendar loads only when you choose a booking link. Its booking service may use its own cookies and storage; its notices and any available consent controls apply inside the booking experience. You can also open the booking page directly. Read Cal.com's privacy policy for details.

06How long we keep things

DATAKEPT FORNOTES
Tool-call logs30–365 daysBy agreement: Developer 30, Growth 60, Business 90 days; Enterprise as contracted. Existing agreements retain their terms.
Connection tokensUntil disconnected or revokedActive credentials are revoked for Stacklink use on disconnect. Scoped deletion and retention controls apply to retained records.
Memory recordsUntil deletedOr sooner, if you set a retention policy on the project.
Workbench artifactsUntil deletedFiles your sandboxes produced; project deletion queues their erasure.
Memory exports7 daysDownload links expire automatically.
Billing recordsAs requiredKept while tax and accounting law requires it.

Deleting a project revokes access immediately, queues scoped data erasure, and schedules its logs for purge after seven days. The current workspace self-service action deactivates access; verified full-erasure requests are handled through privacy@stacklink.in, subject to the billing-record exception above.

07Who else processes data

We use a small set of infrastructure providers to run Stacklink — Railway for application hosting, Supabase for managed Postgres, Cloudflare for delivery, sandbox runtime and object storage, and model providers such as OpenAI only where an enabled feature calls them. They process data on our instructions. When a tool call runs, the relevant connected provider necessarily receives that request; that is the point of the call.

For calls booked through our website, we also use Cal.com for scheduling and Google Calendar and Google Meet for calendar invitations and meetings.

Want the current subprocessor list? Write to privacy@stacklink.in and we will send it as it stands, along with notice of changes.

08Your rights

You can access, correct, export or delete your data. Memory records and sources, connections, and projects have self-service controls. The workspace self-service action currently deactivates access rather than completing full erasure. For full workspace erasure or anything you cannot reach yourself, write to privacy@stacklink.in.

For meeting booking records, write to privacy@stacklink.in from the email used to book. Booking and calendar records are managed separately from your Stacklink account; deleting a Stacklink account does not automatically remove them. Cancelling a meeting also does not by itself erase its booking history.

If you are an end user of a product built on Stacklink, the company running that product is the controller of your data and your first point of contact. We will help them help you.

09Children

Stacklink is a developer product and is not directed at children. We do not knowingly collect data from anyone under 16.

10Changes

If we change this policy materially, we will update the date at the top and tell account owners by email before it takes effect. Older versions stay available on request.

11Contact

WeCommit Ltd (company number 14689906), trading as Stacklink, is responsible for this policy. Privacy questions and data requests: privacy@stacklink.in. Support, security reports and anything else: support@stacklink.in — see Security.

Pick a playbook. Keep the guardrails.

Plug in once — MCP or SDK — and every product on this page is already in the run.

30-day trial · no card · first tool call before your coffee cools