Legal
Privacy Policy
StackSplit — A Product of StackOptimise LLC · Last Updated: May 9, 2026
This Privacy Policy explains how StackOptimise LLC ("Company," "we," "us," or "our") collects, uses, discloses, and safeguards your personal information when you access or use the StackSplit platform ("Service"). By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Service.
1. Introduction
StackOptimise LLC ("Company," "we," "us," or "our") operates the StackSplit platform ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you access or use our Service.
By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Service.
2. Information We Collect
2.1 Information You Provide Directly
Account Information: When you register for an account, we collect your first name, last name, email address, and password. If you register through a third-party authentication provider, we receive your name, email, and profile picture from that provider.
Onboarding Information: During the onboarding process, we collect your company name, company website URL, target customer description, product or service offering description, and how you heard about StackSplit.
Workspace and Business Data: You may provide company details, industry information, company size, LinkedIn URL, product descriptions, job titles, case studies, and social proof materials to configure your workspace.
Payment Information: We use Stripe as our payment processor. Your payment card details are collected and processed directly by Stripe. We do not store your full credit card number, CVV, or other sensitive payment card data on our servers. We do store your Stripe customer ID, subscription status, billing cycle dates, and transaction history for account management purposes.
File Uploads: You may upload files (PDF and plain text formats, up to 10 MB each) to provide context for AI content generation. These files are stored in our cloud storage infrastructure.
Third-Party API Keys: If you connect integrations (such as Smartlead, Instantly, or other platforms), you may provide API keys. These are stored in encrypted form on our servers.
2.2 Information Generated Through Use
User-Generated Content: All email templates, campaign sequences, custom frameworks, and other content you create or generate using the Service.
AI Generation Metadata: When you use AI generation features, we log the AI model used, framework type, custom instructions provided, number of tokens consumed, generation time, and estimated cost. This data is used for usage tracking and service improvement.
Usage and Credit Data: We track your subscription credit balance, bonus credits, and credit transaction history for billing and fair-use enforcement purposes.
2.3 Information Collected Automatically
Authentication Cookies: We use essential cookies managed by Supabase (our authentication and database provider) to maintain your login session. These are strictly necessary for the Service to function and are not used for tracking or advertising purposes.
Server Logs: Our servers automatically record standard log information, including your IP address, browser type, referring URL, pages visited, and timestamps. This information is used for security monitoring and debugging purposes.
2.4 Information We Do Not Collect
StackSplit is a copywriting platform. We do not collect, store, or process any personal data about the recipients of emails or campaigns you create using the Service. We do not manage contact lists, prospect databases, or recipient information of any kind.
We do not use third-party analytics, advertising, or behavioral tracking tools. We do not serve ads or share your data with advertisers.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: To operate, maintain, and deliver the features and functionality of StackSplit, including AI content generation, workspace management, and content export.
- Account Management: To create and manage your account, process payments, enforce usage limits, and communicate with you about your account.
- Security and Integrity: To protect against fraud, unauthorized access, and other harmful activities, and to maintain the security and integrity of our systems.
- Service Improvement: To analyze usage patterns (in aggregate and anonymized form) to improve the Service, develop new features, and optimize performance.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
- Communication: To send you service-related notices, including billing confirmations, usage alerts, security warnings, and updates to these policies.
4. How We Share Your Information
We do not sell, rent, or trade your personal information. We share your information only with the service providers listed below and in the limited circumstances described.
4.1 Subprocessors
The following third-party service providers ("Subprocessors") process your data on our behalf to deliver the Service:
- Supabase, Inc. — Database hosting, user authentication, and file storage. Processes: account data, authentication credentials, workspace data, user-generated content, uploaded files.
- Stripe, Inc. — Payment processing (PCI-DSS compliant). Processes: payment card data (directly), billing and subscription information.
- OpenRouter / Google (Gemini) — AI model inference for content generation. Processes: workspace context (company info, target audience, custom instructions). Does not receive your personal account information (name, email, payment details). The specific AI model provider may change without notice.
- Vercel, Inc. — Application hosting and deployment. Processes: server logs, request metadata.
We will notify you before adding any new Subprocessor that processes personal data. You may subscribe to Subprocessor change notifications by contacting us at privacy@stacksplit.ai.
4.2 User-Initiated Integrations
When you choose to export content to third-party platforms (Smartlead, Instantly, HeyReach, etc.), your generated content and relevant campaign data are transmitted to those platforms using the API credentials you provide. These transmissions are initiated by you and governed by the respective third party's terms and privacy policies.
4.3 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity. We will notify you via email or prominent notice on the Service before your information becomes subject to a different privacy policy.
5. Data Storage and Security
Your data is stored on servers managed by Supabase and protected by industry-standard security measures, including:
- Row-Level Security (RLS) policies ensuring users can only access their own data.
- Encryption of sensitive data, including third-party API keys.
- Secure HTTPS connections for all data transmissions.
- Authentication middleware to protect all application routes.
- Stripe webhook signature verification to prevent payment fraud.
While we implement commercially reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
6. Data Breach Notification
In the event of a security breach that results in the unauthorized access, disclosure, or loss of your personal information, we will:
- Investigate and take immediate steps to contain and remediate the breach.
- Notify affected users without undue delay and, where required by applicable law, within seventy-two (72) hours of becoming aware of the breach.
- Provide you with information about the nature of the breach, the types of data affected, the measures we have taken to address the breach, and recommendations for steps you can take to protect yourself.
- Notify relevant regulatory authorities as required by applicable law, including data protection authorities under GDPR and state attorneys general under US state breach notification laws.
7. Data Retention
Active Accounts: We retain your personal information and User Content for as long as your account is active and as needed to provide you with the Service.
After Cancellation or Termination: Upon cancellation or termination of your account, we retain your data for ninety (90) days. After this period, your data is permanently deleted from our systems.
Billing Records: We may retain billing and transaction records for longer periods as required by applicable tax and financial regulations.
Anonymized Data: We may retain anonymized, aggregated data that cannot be used to identify you for analytical and service improvement purposes indefinitely.
8. Your Rights and Choices
8.1 All Users
Regardless of your location, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Delete your account and associated personal data.
- Export your User Content through the Service's built-in export features.
- Withdraw consent to data processing (which may require closing your account).
8.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purposes for collection, and the categories of third parties with whom we share your information.
- Right to Delete: You may request that we delete your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising. Therefore, there is no need to opt out.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
To exercise your CCPA/CPRA rights, contact us at the information provided in Section 14 below. We will respond to verifiable consumer requests within 45 days.
8.3 EEA, UK, and Swiss Residents (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR:
- Legal Basis for Processing: We process your data on the basis of: (a) contractual necessity (to provide the Service you subscribed to); (b) legitimate interests (security, fraud prevention, service improvement); and (c) your consent (where applicable).
- Right to Portability: You may request a copy of your personal data in a structured, commonly used, machine-readable format.
- Right to Restrict Processing: You may request that we limit how we use your data in certain circumstances.
- Right to Object: You may object to processing based on legitimate interests.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority.
International Data Transfers: Your data is processed and stored in the United States. By using the Service, you consent to the transfer of your data to the United States. We ensure that such transfers comply with applicable data protection laws through appropriate safeguards.
9. Cookies
We use only essential, strictly necessary cookies to maintain your authentication session. We do not use cookies for analytics, advertising, or tracking purposes.
Because our cookies are strictly necessary for the Service to function, they do not require separate consent under applicable cookie laws. You may configure your browser to block cookies, but doing so will prevent you from using the Service.
10. Do Not Track
Some web browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no universally accepted standard for how to respond to DNT signals, we do not currently respond to them. However, as described in this Privacy Policy, we do not engage in tracking, profiling, or targeted advertising of any kind.
11. Children's Privacy
The Service is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly. If you believe a child under 13 has provided us with personal information, please contact us immediately.
12. Third-Party Links and Services
The Service may contain links to or integrations with third-party websites and services that are not owned or controlled by us. This Privacy Policy applies only to our Service. We are not responsible for the privacy practices of any third-party websites or services. We encourage you to review the privacy policies of any third-party services you access through our Service.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Privacy Policy on the Service, updating the "Last Updated" date, and sending you an email notification. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about our data practices, please contact us at:
For GDPR-related inquiries, you may also contact your local data protection authority.