OwnStack
LEGAL / PRIVACY

OwnStack Privacy Policy

We collect only the information needed to provide sign-in, cloud progress saving, and payments. Your third-party accounts, passwords, code, domains, and data remain yours.

Effective date: July 18, 2026

The short version

  • We do not store passwords for GitHub, Vercel, Supabase, Cloudflare, Resend, Creem, or Stripe.
  • If you enable automatic setup, we store encrypted authorization tokens for GitHub, Supabase, and Vercel. You can revoke access on each provider.
  • Google sign-in requests only basic account information: your name, email address, and profile image.
  • We do not access Gmail, Google Drive, or your Google Account password.
  • Payment details are processed by the payment provider; OwnStack does not store complete card numbers.

1. Information we collect

  • Account information: your email address and, when you use Google sign-in, the name and profile image supplied by Google.
  • Project information: project names, selected launch steps, completion status, and progress you save in OwnStack.
  • Provider connection information: when you enable automatic setup, the authorization token, approved scopes, account identifier, and created-resource results supplied by GitHub, Supabase, or Vercel. We do not receive provider passwords.
  • Transaction information: order identifiers, purchased plan, amount, currency, and payment status.
  • Technical information: basic request, device, browser, and error-log information needed for security and troubleshooting.
  • Support information: the email address, problem description, and project context you choose to send us.
  • Community submissions: the provider, region, device, payment-method category, test date, explanation, and public evidence link you choose to submit. We do not request or permit full card numbers, passwords, verification codes, or private keys.

2. Google sign-in data

When you choose Google sign-in, OwnStack receives basic profile details through Supabase Auth so we can create and protect your account. We request only the openid, email, and profile scopes.

We do not use Google user data for advertising, sell it, or use it to train general-purpose AI models. You can revoke OwnStack’s access at any time from the third-party connections area of your Google Account.

3. How we use information

  • Create your account, complete sign-in, and prevent unauthorized access.
  • Save projects, launch routes, and progress across your devices.
  • After you clearly authorize it, create repositories, database projects, deployments, and required environment variables on your behalf.
  • Process purchases, subscriptions, refunds, and post-transaction support.
  • Respond to support requests, improve guidance, and keep the service secure and reliable.
  • Meet applicable legal, tax, accounting, fraud-prevention, and dispute-resolution obligations.

4. Service providers and international processing

OwnStack uses Supabase for authentication and data storage, Vercel for website hosting, Google for optional sign-in, and Creem or another clearly identified payment provider for transactions. If automatic setup is enabled, GitHub, Supabase, and Vercel also process the creation requests you approve. These providers process information only as needed to provide their respective services.

Your information may be processed outside your country or region. We rely on the security and compliance safeguards made available by our service providers when handling these transfers.

5. Retention and security

We retain account and project data while your account remains active. After an account deletion request, we delete or anonymize related data within a reasonable period, except records we must retain for legal, tax, accounting, fraud-prevention, or dispute-resolution purposes.

We use reasonable measures including row-level access controls, separation of server-only credentials, and HTTPS. No internet service, however, can guarantee absolute security.

Third-party authorization tokens are used only on the server and stored in encrypted form. We do not send them to the browser or store third-party passwords.

6. Your choices and rights

  • Access, update, or correct your basic account information.
  • Revoke the Google connection and use email magic-link sign-in instead.
  • Revoke OwnStack’s provider access at any time from the authorization or integration settings in GitHub, Supabase, or Vercel.
  • Request an export or deletion of your account and project data.
  • Control cookies through your browser; blocking essential cookies may prevent sign-in.

7. Children

OwnStack is not directed to children under 16, and we do not knowingly collect personal information from them.

8. Changes to this policy

We may update this policy as our service, laws, or providers change. If a change is material, we will post a notice on the website and update the effective date.

9. Contact us

To request access, correction, export, or deletion of personal data, contact us through the support page or email support@lexigo.art.

Go to support