Skip to content
Production Review Services Checklist img-forge Plans Company Docs Blog

Privacy Policy

1. Information We Collect

Stackbilder collects the following information when you use our service:

  • Account information (name, email address) via OAuth providers
  • Authentication session data for access management
  • Flow execution data (intentions, scaffold artifacts, governance output)
  • Image generation data (prompts, quality tier selections)
  • Voice-demo contact details and transcripts when you explicitly submit the follow-up form
  • Website usage and interaction metrics collected through Google Analytics

2. How We Use Your Information

We use collected information to:

  • Provide and maintain the scaffolding and image generation services
  • Authenticate and authorize access to your account
  • Improve quality of generated artifacts and governance output
  • Monitor service health and performance
  • Understand page usage and conversion-funnel performance through Google Analytics
  • Deliver requested voice transcripts and respond to consented follow-up requests

3. Data Storage and Retention

Your data is stored on Cloudflare's global network using D1, KV, and R2 storage. Flow artifacts and generated images are associated with your account and are not shared with other users. Session tokens are managed via secure HTTP-only cookies.

  • Generated images — stored in R2 and retained for 30 days from creation, then automatically deleted. You may delete images sooner via the API (DELETE /v2/jobs/:id).
  • Transient inputs — source images and mask files uploaded for inpainting or img2img operations are deleted within 24 hours of job completion.
  • Job history and prompts — retained alongside generated images and deleted on the same 30-day schedule or on account deletion.
  • Session and routing data — MCP gateway session tokens and anonymized intent-routing logs are stored in Cloudflare KV and expire after 90 days.
  • Voice demo — per-call messages are deleted from the voice session when the call ends. A transcript emailed only to yourself is not copied to Stackbilt. If you submit the follow-up form, the reviewed contact details and transcript are delivered to Stackbilt and retained as needed to respond or until you request deletion.

The live retention policy for image generation is available at GET /v2/retention-policy.

4. Third-Party Services

Stackbilder uses the following third-party services:

  • Cloudflare Workers AI (image generation — Draft and Standard tiers)
  • Google Gemini API (image generation — Ultra and Ultra+ tiers)
  • OpenAI API (image generation — ultra-tier accounts with Stackbilt-managed access; prompts sent to OpenAI are subject to OpenAI's privacy policy)
  • Cerebras API (optional LLM polish for Pro tier scaffolds)
  • GitHub and Google (OAuth authentication)
  • Resend (delivery of contact requests and voice-demo transcripts)
  • Google Analytics (website measurement — page URLs, referrers, browser/device information, approximate geography, and interactions such as checkout starts and returns, account creation and login method, completed purchases and amounts, accepted generation jobs, and accepted inquiries)

Prompts and flow context may be sent to these providers as part of the generation process. No personal account information is shared with AI providers.

Google Analytics loads when a page opens and uses first-party cookies to distinguish users and sessions. Server-recorded account and purchase events use pseudonymous identifiers derived with a server-only key; we do not send Google your name, email address, payment details, session token, or raw Stackbilder account ID. Google processes Analytics data under its own privacy policy. Event-level and user-level Analytics data is retained according to the retention period configured for our Google Analytics property; aggregated reports may remain available longer. You can limit collection with browser privacy controls, content blockers, or Google's Analytics opt-out browser add-on.

The site does not currently present a separate analytics consent control. Whether collection must wait for consent in a visitor's region is a policy and legal-review decision; we will update both the control and this notice if that decision changes.

5. Your Rights

You can delete individual generated images via DELETE /v2/jobs/:id — this removes both the job record and the associated R2 object immediately. For full account deletion and removal of all associated data, contact us at the address below. Flow artifacts and generated images can be exported before deletion.

6. Contact

For privacy inquiries, contact us at admin@stackbilt.dev.

Last updated: September 2026

Terms of Service