Back

Privacy Policy for StackClock

Last updated: October 4, 2026 OhMyLabs ("we", "us") runs StackClock (https://stackclock.app). This policy explains what we collect, why, and what you can do about it. 1. What we collect 1.1 Account data: your email address, name, and, if you use them, your passkeys' public keys and an encrypted two-factor secret. No passwords: we don't have any. 1.2 Workspace data: the domains, certificates, dates, packages, products, notes and settings you add. Never secret values like passwords or API keys. 1.3 Billing data: handled by Stripe. We store the Stripe customer and subscription IDs, never your card. 1.4 Security data: sign-in events and an audit log of important actions. IP addresses are stored only as keyed hashes, never in clear. 1.5 Free tools: the domain you check (result kept 7 days), or the package names and versions from your file (kept only until the check is done; flagged results kept 1 day). 2. Why we use it To run StackClock for you, to keep it secure and free of abuse, and to meet legal obligations like accounting. For the data your workspace adds, we act on behalf of the workspace owner. We don't sell your data and we don't use advertising trackers. We don't use analytics. We only set the cookies needed to sign you in (https://stackclock.app/cookies). 3. Who we share it with Only the services we need to run StackClock: - Stripe, for payments - Resend, for emails - Our hosting provider, for servers and backups - Google, only if you sign in with Google - Slack or your own webhooks, only if you connect them When we check your domains and packages, we send the domain or package name to registries, OSV.dev and endoflife.date. Never your personal data. 4. How long we keep it As long as your account or workspace exists. Deleted workspaces and accounts are erased after 14 days, and backups roll over within 14 days. Audit logs are kept 30 days to 1 year depending on your plan. Expired sessions, sign-in links and rate-limit counters are deleted automatically. 5. Your rights You can access, export, correct or delete your data at any time, and object to or restrict how we use it. Workspace owners can export everything from the settings; for anything else, email us. In the EU, EEA or UK, you can also complain to your data protection authority. 6. Children StackClock isn't meant for anyone under 16, and we don't knowingly collect their data. 7. Updates We may update this policy. If a change matters, we'll email you. Contact us at [email protected]