Privacy Policy

Last updated: September 9, 2026

StackSwap provides BuildSpace, a private asynchronous review workspace, and publishes software, implementation research, free GTM prompts, and related tools. This policy explains what we collect, why we collect it, and what we will not do with your information.

Private work. Your ownership. Your Builds are not a public portfolio or a shared customer library. We do not claim your ideas, sell your private Build files, or use confidential submissions to copy your product. We process the material needed to deliver the review you request, as described below.

1. Information we collect

Depending on how you use the site or engage StackSwap, we may process:

  • Information you provide: such as your name, company, email, message, LinkedIn message, project context, and any recordings, FAQs, screenshots, copy, or other materials you choose to send.
  • Project and showcase materials: recordings, FAQs, screenshots, copy, product information, or other materials you choose to send when discussing or delivering a build. We use public showcase materials only when you opt in and approve the intended use.
  • Technical data: standard server and browser information (for example device type, general location derived from IP at a coarse level, timestamps, and diagnostic logs) needed for security, reliability, and debugging.
  • Contact information: if you contact Nick by LinkedIn or email, we collect what you choose to send, such as your message and contact details.
  • Payment-related data (if you purchase): processed by Stripe; we receive billing and subscription identifiers, status, transaction references, and information needed to manage your purchase. We do not store full card numbers on our servers.

BuildSpace accounts store your sign-in identity, Builds, uploaded files and links, review requests, saved reviews, credit ledger, and subscription identifiers. A working file remains in your private Build after a review. Earlier versions and review history may remain available when you upload a replacement. We do not access other files on your machine simply because you upload one file.

Connected Builds. If you connect GitHub, we process the identity and repository access you authorize, encrypted access credentials, repository metadata, selected source text, commit references, and bounded snapshots. Public live URLs may contribute accessible page text. We also retain your stated goals and explicit decisions about recommendations. These records stay associated with your account and Build; they are not public source-code pages.

Repository ingestion is read-only. We exclude common secret-bearing and generated files and apply additional content screening, but automated screening cannot guarantee discovery of every secret. Do not deliberately include passwords, private keys, unnecessary personal data, or material you cannot authorize. A repository scan is not exhaustive security testing. Selected review evidence is processed by the review providers described below.

Disconnecting stops future use of that source and removes the stored credentials for that connection. Historical snapshots and delivered reviews are not automatically erased when you disconnect; request deletion through the contact below. You can also revoke the GitHub App directly in GitHub. Reconnecting requires a new authorization.

2. How we use information

We use information to:

  • Operate the website, free prompt library, research, and related public tools.
  • Authenticate your BuildSpace account, preserve your project context, and deliver the reviews you request.
  • Operate and secure the public site, abuse prevention, uptime, and support.
  • Diagnose service reliability and security using operational information. This does not authorize pooling confidential Build content into shared training or review knowledge.
  • Document project outcomes and permissions when needed, without publishing client materials or claims without approval.

3. Data sharing

We do not sell your personal data. We do not share your information with third parties for cross-site marketing or behavioral advertising.

We share data only where needed to run StackSwap, for example service providers (hosting, security, communications, or payments) that process it on our behalf under contract, or when required by law (such as a valid subpoena). We may also share information if we believe it is necessary to protect the safety, rights, or integrity of our users or the service.

BuildSpace uses Supabase for authentication, database records, and private file storage; Vercel for hosting; and Stripe for subscriptions. Selected project context and files are sent to the configured AI provider (Anthropic or OpenAI) to produce Brain reviews and preliminary expert briefings. Authorized StackSwap reviewers can access the materials needed for Expert Review. Limited authorized personnel may also access relevant records for support, security, or legal obligations. Other customers are not authorized to access your private work. Loom hosts expert walkthroughs. Signal is used only for direct 1:1 member communication with Nick, under Signal’s own terms. Your Build files, reviews, and project history remain inside StackSwap; they are not automatically sent to Signal. We do not sync, scrape, or import Signal conversations, run Signal bots, or use those messages as Wim or BuildSpace project memory. Share only what you choose to discuss there; keep sensitive project files in your private Build. Do not upload passwords, API keys, or sensitive records that are not needed for your review.

Project memory and improving Brain

Private project context. Brain uses the selected work, your stated goal, relevant earlier review summaries from that Build, and StackSwap's expert frameworks to prepare a review. Saving project context helps you iterate without starting over. It is not the same as fine-tuning a model or sharing your Build with other customers.

Shared improvement. Improving the service over time is a product goal, not permission to take customer ideas. The current BuildSpace review flow does not automatically add your files, prompts, reviews, or proprietary decisions to a cross-customer learning library. Any future shared-learning feature will require a separate, clear permission process before your material is used for that purpose. It will describe the scope, controls, retention, and withdrawal limits. These policy updates do not enroll existing or new Builds in shared learning.

Removing a name is not enough to make a proprietary strategy safe to reuse. Shared lessons must not disclose personal data, customer-identifying details, source files, unreleased product ideas, code, or trade secrets. Showcase permission, permission to process a review, and permission for shared learning are separate choices.

AI providers process the context sent to them under their applicable business terms and our configuration. We do not promise zero provider retention or that an uploaded file never leaves our infrastructure. Provider processing to deliver your review is distinct from StackSwap reusing your work for a new purpose.

4. Optional customer showcase

StackSwap may feature a completed client build in a public customer showcase only when the client opts in under the applicable project agreement. The client can separately approve the build, screenshots, name or logo, link destination, and any testimonial or quote.

You choose when to share. We will not publish confidential information or unapproved claims. If you need a showcase entry updated or removed from future publication, contact us and we will help where we reasonably can.

5. Data retention

We retain active Build files, context, and reviews to provide your workspace and review history. Canceling billing does not itself delete your Build. You can request deletion using the contact address below. Billing, security, dispute, and legal records may need to be retained separately for their applicable purposes. Deleted data may remain in backups until normal backup rotation and may be subject to necessary legal preservation.

You may request deletion of personal data tied to you (see below). We may need to keep certain records where the law requires or where deletion would break legitimate security or accounting obligations.

6. Security

We use reasonable technical and organizational safeguards appropriate to the nature of the service. No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we work to reduce risk and to respond if something goes wrong.

7. Your rights and choices

Depending on where you live, you may have rights to:

  • Request access to personal information we hold about you.
  • Request a copy of your Build information and files in an available portable format.
  • Request correction or deletion.
  • Object to or restrict certain processing.
  • Lodge a complaint with a supervisory authority.

To exercise these rights or to ask what applies in your case, contact us using the details below. We may need to verify your identity and the scope of the request before disclosing or deleting private information. Applicable rights, response periods, and exceptions depend on the relevant law. You may ask us to review a denied request and contact your applicable privacy regulator. We will not discriminate against you for exercising your privacy rights.

8. Changes to this policy

We may update this policy as the product evolves. When we do, we will change the "Last updated" date above. If changes are material, we will provide notice in a reasonable way (for example a banner or email if we have your contact information). We will not silently apply new shared-learning permissions to information collected under an earlier policy. Where a new purpose requires consent, we will ask separately; continued use or an updated policy date alone is not that consent.

9. Contact

Questions about privacy or this policy: nick@stackswap.ai.

← Back to Home