Legal

Privacy Policy

Last updated: July 18, 2026

1. Scope and collection status

This policy applies to the BuildStax public website, access requests, and BuildStax product services that link to it. A product feature may provide a more specific notice before collecting data. Third-party sites and services have their own notices.

This website deployment is not approved for personal-data collection. Cookieless analytics and access-request submission stay disabled until the controller identity, hosting and processor terms, transfer safeguards, retention operations, and rights-handling process are approved and configured.

2. Controller and contact details

BuildStax is a product name. The controller's full registered name and contact address have not been approved for publication, so this deployment does not enable analytics or access-request collection. Those details must appear here before collection begins.

3. Personal data we collect

  • Access requests: email address, submission time, and invitation status.
  • Website and device data: theme preference stored in your browser and, when analytics is approved, page paths and titles, referrer URLs, browser, operating system, device and screen type, language, and approximate location. The analytics configuration excludes URL queries and fragments and does not store raw IP addresses.
  • Account data: contact details, credentials or authentication identifiers, account preferences, and support communications when an account is available.
  • Product content: prompts, task descriptions, repository files, diffs, attachments, model inputs and outputs, and execution metadata needed to perform a task.
  • Billing data: subscription, transaction, invoice, tax, and limited payment-method details. Payment providers process full card or bank details; BuildStax does not store full card numbers.
  • Security and service logs: IP address, timestamps, request and error details, authentication events, and audit records needed to secure and operate the service.

We receive data from you, your browser or device, services you connect at your direction, payment and identity providers, and service providers acting for us. Do not submit secrets or another person's personal data unless you are authorized to do so.

4. Purposes and legal bases

  • Requested access and service delivery: to respond to an access request, create and administer an account, perform coding tasks, and provide support. We rely on steps you request before a contract and performance of a contract.
  • Requested email: to send invitations and availability messages covered by the access-request checkbox. We rely on your consent, which you may withdraw at any time.
  • Cookieless website analytics: to understand aggregate site use and improve public pages. We rely on our legitimate interest in operating and improving the website, subject to your right to object and any stricter local requirement.
  • Security and reliability: to prevent abuse, investigate incidents, debug failures, and maintain service integrity. We rely on our legitimate interests and legal obligations.
  • Billing and compliance: to process transactions, keep tax and accounting records, handle disputes, and comply with law. We rely on contract necessity and legal obligations.
  • Product improvement: to evaluate reliability and improve routing using minimized operational data where our legitimate interests are not overridden by your rights.

We do not use customer code or task content to train BuildStax or third-party general-purpose models by default. Any such use would require a separate, specific opt-in where legally permitted. We do not use website or waitlist data for solely automated decisions that produce legal or similarly significant effects.

5. Browser storage and cookieless analytics

  • Theme preference: local browser storage that remains until you clear it or change the preference.
  • Umami analytics: a self-hosted analytics service that does not set cookies or use a persistent cross-site identifier. It derives session metrics from limited device and request data using rotating hashes; request IP addresses may be used to derive approximate location but are not stored by Umami.
  • Data minimization: URL queries and fragments are excluded, distinct IDs and custom event data are not configured, and tracking is limited to buildstax.dev.

The site does not store an analytics consent choice because this configuration uses no analytics cookies or similar browser storage. A recognized Do Not Track or Global Privacy Control signal prevents analytics events from being sent. You can also object by contacting us at the address in section 2.

6. How we disclose personal data

We disclose only what is reasonably necessary to:

  • Clerk, our identity and waitlist provider, and other hosting, infrastructure, security, support, and email providers acting under contract;
  • AI model providers selected to process a task, such as Anthropic, OpenAI, Google, or another provider identified for the service;
  • Stripe and other approved payment, fraud-prevention, tax, or accounting providers;
  • the infrastructure providers used to host our self-managed Umami analytics service, acting under approved terms;
  • authorities, courts, advisers, or other parties when required by law or necessary to protect rights and safety; and
  • a buyer or successor in a proposed business transaction, subject to appropriate confidentiality and notice requirements.

We do not sell personal data or use it for cross-context behavioral advertising. BuildStax remains responsible for its own processing when a service provider handles data for us.

7. International transfers

BuildStax is operated from Poland, and providers may process data in other countries. Before enabling a transfer outside the European Economic Area, United Kingdom, or Switzerland, as applicable, we require an approved transfer basis such as an adequacy decision, Standard Contractual Clauses, the UK addendum or International Data Transfer Agreement, and supplementary safeguards where needed. Contact us for information about safeguards relevant to your data.

8. Retention

  • Access-request data is kept until you withdraw, the request is resolved, or 12 months pass after our last contact, whichever comes first, unless a legal obligation requires longer.
  • Umami analytics events are retained for no more than 14 months and are then deleted from the self-hosted analytics database.
  • Account and product content is kept while needed to provide the service and then deleted or de-identified under the product retention schedule shown before production processing is enabled.
  • Security records are kept only for the documented period needed to investigate abuse, establish claims, and protect the service.
  • Billing, tax, consent, and transaction records are kept for the period required by applicable law, which may be up to 10 years for records subject to EU VAT or OSS rules.

Deletion may be delayed when data is subject to a legal hold, active dispute, security investigation, or immutable backup cycle. Backup data is isolated from ordinary use and removed on its scheduled overwrite.

9. Your rights and choices

Depending on where you live and which law applies, you may request access, correction, deletion, restriction, portability, or a copy of personal data; object to processing based on legitimate interests; withdraw consent; opt out of covered sale, sharing, targeted advertising, or profiling; and appeal a denied request. You may also authorize an agent where local law allows it. We may verify identity and authority before acting, and we will not discriminate against you for exercising a right.

Send requests or withdraw a waitlist request at [email protected]. European users may complain to the supervisory authority where they live or work. The Polish authority is the President of the Personal Data Protection Office (UODO). UK users may contact the Information Commissioner's Office.

10. Children

BuildStax is not directed to children, and paid services are intended only for people aged 18 or older. We do not knowingly collect personal data from children. If you believe a child submitted data, contact us so we can investigate and delete it where required.

11. Security

We use administrative, technical, and organizational safeguards designed for the nature of the data and processing risk. No system is completely secure. If a breach creates a notification obligation, we will notify affected people and authorities as required by law.

12. Changes and contact

We may update this policy as BuildStax changes. The date above identifies the current version. We will provide additional notice or request renewed consent when a change requires it. Questions and privacy requests can be sent to [email protected].