Skip to main content

Legal

Privacy Policy

Last updated: August 7, 2026

1. Who we are

Code Stacked ("we", "us") operates the company site at codestacked.dev and products we publish under that brand, including Deprecast (deprecast.codestacked.dev).

2. Company-wide account (one identity)

Your Code Stacked account is a single company identity. It is used across Code Stacked products you access with the same verified email — not a separate login per product.

  • Sign-in is passwordless via email magic link from the account surface on codestacked.dev.
  • The same email is the join key: if you already used a product (for example Deprecast) with that email, product data is associated with this identity rather than creating a second account.
  • Future Code Stacked products may attach to the same identity under this policy.

3. Data we collect

  • Account email — collected to authenticate you, send magic links, and operate account-related notices.
  • Session and security data — session tokens (stored in secure cookies where applicable), limited request metadata (such as IP address, user agent, and timestamps) for abuse prevention and reliability.
  • Billing data — payment method and subscription details are processed by Stripe on our behalf. We store Stripe customer and subscription identifiers and entitlement state needed to gate product features. We do not store full card numbers on our servers.
  • Product data (Deprecast) — product-specific content you create or configure in Deprecast (for example watchlist preferences, mute state, and optional notification destinations such as a Slack incoming webhook URL), plus operational logs needed to run the product.
  • Contact form messages — if you write to us via the contact form, we receive the details you submit.

Deprecast monitors public vendor signals only (for example public OpenAPI/Swagger specs, changelogs, and RSS). We do not require your external API keys, OAuth client secrets, database credentials, or application source code to use Deprecast.

4. How we use data (including cross-product)

We use the information above to:

  • Create and maintain your Code Stacked identity and sign you in across products.
  • Hand off authentication from the company account to products you open (so you are not forced through a second long-term product-only signup).
  • Manage billing at the company level — one Stripe customer per identity, with product plans as entitlements under that customer (for example Deprecast Indie).
  • Deliver product features and notifications you configure (email digests, urgent alerts, optional Slack).
  • Secure the service, prevent abuse, debug outages, and improve reliability.
  • Respond to support and legal requests.

We do not sell, rent, or trade your personal data or email address to third parties.

5. Processors and subprocessors

We use service providers to operate the company site and products, including:

  • Hosting and infrastructure providers for application and database hosting.
  • Email delivery for magic links and product notifications.
  • Stripe for payment processing and the customer billing portal.

These providers process data only as needed to provide their services to us under their respective terms and data processing arrangements.

6. Retention

  • Account identity is retained while your account is active and for a reasonable period afterward if needed for security, fraud prevention, or legal obligations.
  • Billing records are retained as required for accounting, tax, chargebacks, and Stripe's retention practices.
  • Deprecast product data (watchlist and related settings) is retained while associated with your account so the product continues to work when you return. You may request deletion as described below.
  • Operational logs are retained briefly for security and reliability, then deleted or aggregated.
  • Magic-link tokens are short-lived and expire after use or timeout.

7. Your choices and requests

You can sign out of your session from Account. To request access, correction, or deletion of personal data associated with your Code Stacked account (including linked Deprecast product data where applicable), email Support. We may need to verify control of the account email before acting.

8. Security

We use industry-standard safeguards appropriate to a small product company, including encrypted transport (HTTPS), hashed session handling, and short-lived magic links. No method of transmission or storage is perfectly secure; we work to protect your data and improve controls over time.

9. Children

Our services are directed to adults and professional users. We do not knowingly collect personal information from children.

10. Changes

We may update this Privacy Policy as the company and products evolve. The "Last updated" date at the top will change when we do. Material changes that expand how a company-wide account is used across products will be reflected here before we publicly market that capability.

11. Contact

Privacy questions: Support. Product-specific Deprecast support may also be reached via the contact paths shown on Deprecast.

Related: Terms of Service.