Privacy Policy
Your privacy is fundamental to how we built StackerScan
Last updated: January 31, 2025
StackerScan is designed with privacy at its core. We understand that precious metals ownership is sensitive financial information, and we've built our platform to give you complete control over your data.
Key Privacy Features:
- Optional anonymous username accounts
- Ability to opt-out of server receipt storage
- Complete account deletion at any time
- End-to-end encryption for all sensitive data
Account Information
- Email address (optional - you can use anonymous username)
- Username (if chosen over email)
- Encrypted password hash
Portfolio Data
- Precious metals transaction details (encrypted)
- Receipt images (optional - can be disabled)
- Portfolio preferences and settings
Usage Information
- Login timestamps
- Feature usage analytics (anonymized)
- Error logs for troubleshooting
- •Portfolio Tracking: To track and display your precious metals holdings, calculate values, and provide performance analytics.
- •Receipt Processing: To extract transaction data from uploaded receipts using AI (processing happens securely, and original receipts can be deleted).
- •Account Security: To authenticate your access and protect your account from unauthorized use.
- •Service Improvement: Anonymized usage data helps us understand which features are most valuable and where to focus development.
- •Customer Support: To respond to your inquiries and provide assistance when needed.
- ✕Sell or share your personal information with third parties
- ✕Use your portfolio data for marketing purposes
- ✕Store unencrypted sensitive financial information
- ✕Share your precious metals holdings with anyone
- ✕Require real identity verification for basic features
Encryption
All sensitive data is encrypted using industry-standard AES-256 encryption at rest and TLS 1.3 for data in transit.
Data Location
Your data is stored in secure, SOC 2 compliant data centers. We use redundant backups to ensure your portfolio information is never lost, while maintaining strict access controls.
Access Controls
Only essential personnel have access to production systems, and all access is logged and audited. We use multi-factor authentication and principle of least privilege for all internal access.
You have the right to:
- Access all data we have about you
- Export your portfolio data in standard formats
- Delete your account and all associated data
- Opt-out of receipt storage on our servers
- Use the service with an anonymous username
Data Deletion
When you delete your account, all your personal information, portfolio data, and uploaded receipts are permanently removed from our servers within 48 hours. This action is irreversible.
We use minimal third-party services to provide our service:
Essential Services
- Stripe: Payment processing (we never see your card details)
- Azure: Cloud infrastructure for receipt processing
- Anthropic:AI receipt processing
- Supabase: Authentication and database services
These services are carefully selected for their strong privacy practices and compliance with data protection regulations. We share only the minimum necessary information with these providers.
- Active Accounts: Your data is retained as long as your account is active.
- Deleted Accounts: All data is permanently removed within 48 hours of deletion request.
- Receipts: If you opt-out of server storage, receipts are deleted immediately after processing.
If you have any questions about this Privacy Policy or how we handle your data, please don't hesitate to contact us:
This privacy policy is effective as of January 31, 2025 and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page. We reserve the right to update or change our Privacy Policy at any time, and you should check this Privacy Policy periodically.