Stackleaks
Sign in

Privacy Policy

Last updated August 23, 2026

Stackleaks is operated by Entrysoft BV, Warandestraat 98, 9140 Temse, Belgium (BE 0866.747.854). Contact: [email protected]. All data is hosted in the European Union.

What we collect, and why

  • Your account — email address and password hash, to sign you in and send you the reports you asked for.
  • Organization data from connectors — when you connect a tool (e.g. Google Workspace), we read, with minimal read-only scopes, member lists, license assignments, and coarse activity signals. We use this solely to produce your waste report. We never write to your tools.
  • Cookieless analytics — for public pages we log the path, referrer domain, country, coarse device class, and a visitor digest: a one-way hash of a daily-rotating server secret, IP address, and browser signature. The raw IP address is never stored, and the daily rotation makes visitors unlinkable across days. No analytics cookies are involved.
  • Google Analytics 4 — with your consent (EU visitors choose in the cookie banner; the script does not load before you accept), Google processes usage data on our behalf to show us how the site is used. Advertising features are disabled via Consent Mode v2 and GA4 does not log or store IP addresses. See Google's privacy policy and our Cookie Policy.
  • Consent choices — when EU visitors answer the cookie banner we record the choice, timestamp, and country (no IP address) for accountability.

Roles

For account and analytics data we are the controller. For personal data inside your connected tools (names and emails of your team members), we act as processor on your instructions; a DPA is available.

Google user data

When you connect Google Workspace, the data we receive through Google APIs is your organisation's member directory: names, email addresses, organisational unit, admin status, licence assignments and last sign-in times. We use it for one purpose only: producing your access and licence report inside your own account.

We do not sell Google user data, and we do not share, transfer or disclose it to anyone, with three narrow exceptions: the sub-processors listed below, strictly as needed to operate the service (hosting, and error monitoring with request parameters filtered); the administrators of your own Stackleaks account, who see it in their reports; and disclosure where the law requires it. Google user data is never used for advertising, never transferred to data brokers, and never used to train AI or machine-learning models.

Humans at Entrysoft do not read this data except with your permission (for example when you ask for support), where necessary for security or abuse investigation, or to comply with applicable law.

Stackleaks' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Sub-processors

ProviderPurposeRegion
Mailgun (Sinch)Transactional emailEU
HetznerHostingEU (Germany/Finland)
CloudflareCDN / DDoS protectionGlobal edge, EU settings
Google Ireland LtdGoogle Analytics 4 (consent-gated)EU; transfers under the EU–US Data Privacy Framework
SentryError monitoring (request parameters filtered)US; EU–US Data Privacy Framework

Retention

Raw analytics pageviews are deleted after 90 days (aggregates are kept). Connector syncs replace the previous snapshot — we keep no history of past member lists. Disconnecting a connector deletes the data we read through it immediately, along with its tokens; encrypted backups roll off within 30 days. Deletion requests to [email protected] are acknowledged within 2 business days and executed within 7. The full vendor list lives at Sub-processors.

How we protect your data

All connections to Stackleaks are encrypted in transit with TLS; unencrypted connections are refused. OAuth access and refresh tokens — the most sensitive data we hold — are additionally encrypted at the application layer (AES-256-GCM) before they are stored, so they are unreadable even with direct database access. We request the minimal read-only scopes each connector offers and never ask for write access, backups are encrypted and roll off within 30 days, production access is restricted to authorised Entrysoft personnel over authenticated connections, and disconnecting a connector immediately deletes the data read through it together with its tokens.

Your rights

You can request access, correction, deletion, portability, or restriction of your personal data, and object to processing, by mailing [email protected]. You can also complain to your supervisory authority — in Belgium, the GBA/APD.