StackyapperLegal center

Effective 2026-07-27

Privacy Policy

This Policy explains StackYapper’s personal-data practices for website visitors, account users, administrators, and people whose data customers direct the Service to process.

StackYapper is a service of Symao Systems, doing business as StackYapper, located at 2106 Morthland Drive #1079, Valparaiso, Indiana 46383, United States.

1. Roles and scope

StackYapper is the controller of account, billing, website, support, and security information used to operate its business. For personal data contained in Customer’s connected systems or sent through Customer-configured workflows, Customer is the controller and StackYapper acts as its processor or service provider. This Policy does not govern third-party systems, AI clients, or websites.

2. Information we collect

  • Account and organization data: name, work email, company, verified domain, identity-provider identifiers, role, group and membership information.
  • Billing data: billing email, plan, subscription and checkout identifiers, status, quantity, invoices, and limited payment metadata. Stripe collects and processes full payment-card details; StackYapper does not store full card numbers.
  • Connection data: encrypted credentials, service configuration, provider tenant or workspace identifiers, permission grants, and connection status.
  • Service and security data: IP address, approximate location our infrastructure provider derives from that address (country, region, and city), the autonomous system number and network operator the request came from, connection metadata such as HTTP protocol and TLS version, user agent, session and API-key identifiers, request time, selected tool and service, outcome, latency, confirmation and policy events, and diagnostic data. The client IP address, country, and network details are stored on operational audit records so authorized administrators can investigate account and tool activity. Audit logs are designed to exclude prompts and provider response bodies unless a specific feature clearly says otherwise.
  • Customer-routed content: requests and results may pass through memory while StackYapper calls connected vendors and returns results to the AI client or workflow Customer selected. Some workflows may intentionally persist an approved output or run record; the product identifies those features.
  • Communications: support, security, sales, and other messages sent to us.

Examples of how data moves through StackYapper

Reading a service ticket: when an authorized user or agent requests a ticket, StackYapper may process the user and organization identifiers, selected connector and tool, ticket identifier, encrypted connection credential, provider response, result status, timing, and client/session identifiers. The provider response is returned to the Customer-selected AI client or workflow. Standard operational tool-call logs record metadata about the call, not the tool arguments or provider response body.

Running a write or delete tool: when an authorized user or agent requests a change, StackYapper may process the instruction and fields needed by the connected provider, confirmation state, tool risk class, authenticated actor, connected customer workspace, result status, and timing. The connected provider may retain the resulting change under Customer’s agreement with that provider.

Administering an MSP workspace: when an administrator changes a role, group, connector grant, customer workspace, or security setting, StackYapper may retain the acting administrator, affected organization or resource, action, outcome, and time so authorized MSP administrators can investigate activity and demonstrate accountability.

3. Sources

We receive information from users and administrators, identity providers, Customer-configured connected services, AI clients and automation systems, payment and email providers, and automatically from use of the Service.

4. How we use information

We use information to provide and authenticate the Service; execute Customer instructions; maintain tenant and permission boundaries; provide MSP and customer administrators with activity, security, usage, and compliance audit capabilities; process subscriptions; communicate transactional and support messages; prevent fraud and abuse; investigate incidents; maintain and improve reliability; enforce agreements; and comply with law. We do not sell personal information, share it for cross-context behavioral advertising, serve targeted ads, or use Customer content to train general-purpose AI models.

Audit records

Operational audit records may identify the MSP and customer workspace, actor and role, connector service, tool name, read/write/destructive/credential-sensitive risk class, status, duration, billable state, MCP client and session identifiers, the client IP address and the country, region, city, and network operator derived from it, and relevant administrative-action details. Router and intent auditing retains provenance, a SHA-256 hash and character length of supplied intent text, selected tool, and candidate count. Verbatim intent text is never retained. A client may still send a text-retention flag for wire compatibility; StackYapper ignores it, so a connecting client cannot cause intent text to be stored. StackYapper does not ordinarily place tool arguments, secrets, full prompts, or provider result bodies in operational tool-call logs because they may contain customer content. Denied or failed calls may retain a bounded, sanitized error category or message.

Authorized MSP administrators may audit activity across customer workspaces they manage; authorized customer administrators may receive reporting scoped to their own workspace where the Service provides that access. Customer is responsible for informing its users and personnel about this organizational monitoring and for configuring access consistently with applicable law and workplace policy.

5. Disclosure

We disclose information to the subprocessors needed to operate the Service; to connected vendors and AI clients at Customer’s direction; to professional advisers under confidentiality; during a corporate transaction; or when required to protect rights, safety, security, and comply with law. Stripe acts as an independent controller for some payment processing activities under its own privacy policy.

6. Cookies and similar technology

StackYapper uses essential cookies and local storage for authentication, security, OAuth state, preferences, and basic product operation. The public site and hosted portal do not currently use advertising cookies, cross-site tracking pixels, or third-party behavioral analytics. Because only essential technology is used, StackYapper does not display a consent banner. If nonessential tracking is introduced, this Policy and the consent experience will be updated first.

7. Retention

Account, billing, and contract records are retained while the account is active and afterward as reasonably needed for legal, tax, fraud-prevention, and dispute purposes. Active sessions and OAuth state are short-lived. Operational audit and intent records are retained for the period needed to provide security, accountability, usage reporting, and contractual audit features. The retention period depends on the workspace’s plan: Standard workspaces keep 90 days of audit history and Business workspaces keep 365 days. The period is resolved from the billing account, so a managed customer workspace inherits the retention period of the provider that manages it. A different period may apply if disclosed for a feature, agreed with a customer, or required by an order, legal hold, or law. Aggregated or de-identified usage records may be retained longer. Encrypted connection credentials are deleted or disabled when the applicable connection or account is removed, subject to backup and legal-retention cycles. Customer-routed content is not intentionally retained unless an enabled feature requires it. We securely delete or de-identify data when it is no longer needed.

8. Security and international processing

We use administrative, technical, and organizational safeguards including encryption in transit, encryption or cryptographic protection at rest for credentials, tenant-scoped authorization, audit logging, and access controls. No system is perfectly secure. Cloudflare and other providers may process data in the United States and other countries where they operate. Where required, transfers are supported by contractual safeguards.

9. Rights and choices

Depending on location, individuals may have rights to confirm processing; access, correct, delete, or obtain a portable copy of personal data; opt out of targeted advertising, sale, or qualifying profiling; and appeal a denied request. StackYapper does not sell personal data, use it for targeted advertising, or profile individuals to make decisions producing legal or similarly significant effects. Submit requests or appeals to legal@stackyapper.dev. We will respond within the period required by applicable law and explain how to contact the appropriate regulator if an appeal is denied. If StackYapper processes data for a Customer, we will direct the request to that Customer and assist as required by contract and law. We may verify identity and authority before acting.

10. Children

The Service is for businesses and is not directed to children. We do not knowingly collect personal information from children under 13, or a higher minimum age where local law requires it. Contact us if you believe a child provided information.

11. Contact and changes

Questions and privacy requests may be sent to legal@stackyapper.dev. StackYapper will post updates here and change the effective date. Material changes will be communicated through the Service or account email when required.


Symao Systems, doing business as StackYapper
2106 Morthland Drive #1079, Valparaiso, IN 46383, United States
legal@stackyapper.dev