stackstack os

Legal — Privacy

Privacy Policy

ThinkSwift Pty Ltd (stack, we, us, our) builds an AI-native business operating system for Australian professional services firms. This policy explains what personal information we collect, how we use it, and the rights you have under the Australian Privacy Principles set out in the Privacy Act 1988 (Cth).

It applies to stackos.com.au, to app.stackos.com.au, and to the stack iOS and Android applications distributed via the Apple App Store and Google Play.

Effective date26 May 2026

Section 01

The information we collect

Information you give us directly. Your name, work email address and mobile number when you sign up for stack or contact us. Any details you include in an email or enquiry — for example, your role, the size of your firm, or what you are hoping stack can help with.

Workspace content you create or import. When you use stack to manage email, calendar, tasks, contacts, documents or notes, the content of those records is stored in your workspace. If you connect a third-party account (Gmail, Google Calendar, Microsoft 365, Twilio, Stripe, Xero, and similar), we retrieve and store the data needed to provide the connected features. You stay in control of which accounts are connected and can disconnect them at any time in Settings → Integrations.

Information collected automatically. Basic request metadata when you visit stackos.com.au or use the stack web or mobile app — IP address, user agent, referring page, and the pages or screens you viewed. We use this to keep the service running and to diagnose problems.

Mobile applications. The stack iOS and Android apps load the same hosted service at app.stackos.com.au and collect no personal information beyond what the web app collects. The native shell uses standard device identifiers for session management, crash diagnostics and push-notification routing (when push is enabled in a future release).

We do not knowingly collect personal information from anyone under the age of 16. stack is a business product intended for use by adults.

Section 02

How we use your information

We use the information we collect to:

  • create and operate your stack account,
  • respond to enquiries and support requests,
  • improve our website and product,
  • meet our legal, tax, and accounting obligations.

We will not send you marketing you have not asked for, and we will never sell your personal information.

Section 03

How we share your information

We only share personal information with:

  • Service providers that help us operate stack. Each is bound by its own data protection terms:
    • Vercel — application hosting and content delivery.
    • Supabase — primary database, authentication and file storage.
    • Resend — transactional email delivery.
    • Stripe — payment processing and subscription billing. Card details are entered directly into Stripe's systems and never touch our servers.
    • Anthropic and Google (Vertex AI / Gemini) — large-language-model providers that power Penny, stack's AI assistant. Workspace content is sent only as needed to answer the request you initiated.
    • ElevenLabs — voice synthesis for Penny's spoken responses.
    • DeepInfra — embedding generation for in-workspace semantic search.
    • Twilio — SMS delivery for two-factor authentication and workspace telephony features.
    • Google Workspace and Microsoft 365 — when you connect your Gmail, Google Calendar, or Microsoft 365 account, we exchange data with those services under the scopes you authorise. You can disconnect at any time.
  • Advisors and auditors, where engaged to help us run the business.
  • Law enforcement or regulators, where we are required to disclose information by Australian law.

Some of our service providers are located outside Australia, including in the United States and the European Union. Where that is the case, we take reasonable steps to ensure they handle your information in a way that is consistent with the Australian Privacy Principles.

We do not share your information with advertisers.

Section 04

Storage and security

We store personal information on infrastructure operated by Vercel and Supabase. We apply reasonable technical and organisational measures to protect it — encryption in transit, role-based access controls, and audited production access.

No system is perfectly secure. If we become aware of a data breach that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.

Section 05

Cookies

The stack marketing site uses Meta Pixel to measure the performance of our advertising campaigns and to help us reach people who might be interested in stack. Meta Pixel sets a first-party _fbp cookie and may read Meta's own fr cookie if you are signed in to Facebook or Instagram in the same browser. You can opt out of personalised advertising in your Meta ad preferences or block third-party cookies in your browser.

We also use a small amount of browser storage to remember your theme preference (light or dark).

If we add analytics or session cookies in future, we will update this policy and give you the option to decline any cookie that is not strictly necessary.

Section 06

Your rights

Under the Australian Privacy Principles, you have the right to:

  • access the personal information we hold about you,
  • correct information that is inaccurate, out of date, or incomplete,
  • delete your account yourself at any time from Settings → Profile → Danger zone inside the app, or ask us to delete your personal information by email — subject to any legal obligation we have to keep it. See how account deletion works for the full procedure and what is retained,
  • opt out of any non-essential email communication at any time,
  • make a complaint about how we have handled your information.

To exercise any of these rights, email us at hello@thinkswift.au. We will respond within 30 days.

If you are not satisfied with our response, you can contact the OAIC at oaic.gov.au.

Section 07

How long we keep your information

We keep personal information only for as long as we need it for the purpose it was collected, or for as long as Australian law requires.

While your account is active. Your account data is retained for the life of your subscription so stack can function. You can export it at any time and you can delete your account at any time from inside the app.

When you delete your account. Your sign-in credentials, personal profile (name, avatar, phone, timezone), and active subscription are removed immediately. Your workspace content (emails, calendar events, tasks, contacts, files, AI conversation history) is soft-archived and retained for approximately seven years to satisfy Australian business-record retention obligations under the Corporations Act 2001 (Cth) and the Income Tax Assessment Act 1997 (Cth), then permanently destroyed. During the retention period the data is encrypted at rest and not accessible to any stack user. A short audit record of the deletion itself (timestamp, email at time of deletion, workspace identifier) is kept indefinitely to satisfy App Store and Google Play compliance requirements.

Billing records. Invoices and payment receipts held by our payment processor (Stripe) are retained for the period required by Australian tax law, independent of account status.

Full procedure and recovery options: Delete your stack account.

Section 08

Changes to this policy

We may update this policy from time to time. If we make a material change, we will post a notice on the website and, where appropriate, contact you directly. The effective date at the top of this page will always reflect the most recent version.

Section 09

Contact us

If you have any questions about this policy or about how we handle your personal information, please get in touch.

ThinkSwift Pty Ltd

Built by ThinkSwift, Melbourne, Australia

hello@thinkswift.au