Privacy Policy

Last updated: 6 September 2026

1. Who we are

Stack Almanac (“we”, “us”, “our”) operates the website stackalmanac.com and the web application at app.stackalmanac.com. We are committed to protecting your privacy and handling your personal data responsibly.

2. Data we collect

We collect the following categories of data:

  • Account data: email address, display name, and authentication credentials when you create an account.
  • Supplement data: your supplement stack, dosages, time blocks, logging history, and compliance data.
  • Bio-profile data: optional biological information you provide (sex, age, weight, health goals, genetic variants). This is special category data under GDPR Article 9 and requires your explicit consent.
  • Health metrics: optional self-reported data (sleep, energy, mood, focus scores) and data from connected health services.
  • AI conversation data: messages exchanged with the Almanac Advisor to provide personalised recommendations.
  • Usage data: how you interact with the application, including feature usage and session information.
  • Payment data: processed securely by Stripe. We do not store your card details.

3. How we use your data

  • To provide and personalise the Stack Almanac service
  • To power the Almanac Advisor with context about your routine, goals, and bio-profile
  • To generate your personal insights
  • To send reminders and notifications you have opted into
  • To process payments and manage your subscription
  • To improve the product and fix issues

4. Data storage and security

Your data is stored securely using Supabase (hosted on AWS infrastructure). All data is encrypted in transit (TLS) and at rest. Row Level Security ensures users can only access their own data. Bio-profile data is stored with additional access controls as required by GDPR Article 9.

5. Service providers and sub-processors

We use the following providers to operate Stack Almanac. They may handle account, usage, payment, conversation, or connected health data, depending on the feature you use. Some may also act as independent controllers for services you choose to use, such as payments, social sign-in, or messaging.

  • Supabase: database, authentication, file storage, and serverless functions
  • Vercel: website and application hosting, content delivery, and web analytics
  • PostHog: product and funnel analytics
  • Sentry: error and performance monitoring
  • Anthropic (Claude): AI processing for the Almanac Advisor, safety checks, and quality analysis
  • Stripe: payment processing. Subject to Stripe’s Privacy Policy.
  • Resend: transactional and opted-in email delivery
  • Sanity: website content management, including approved contributor or testimonial data
  • Upstash: request rate limiting and abuse prevention
  • Groq: voice transcription when you use voice input
  • Meta (WhatsApp), Telegram, and Twilio: messaging and notifications when you connect or enable those channels
  • Oura and WHOOP: health and activity data import when you connect those services
  • Google and Apple: optional sign-in and platform integrations that you choose to use

Providers may use infrastructure partners listed in their own sub-processor notices. We review this list when our services change and update this policy when a change materially affects how personal data is handled.

6. Your rights (GDPR)

If you are in the UK or EEA, you have the right to:

  • Access, correct, or delete your personal data
  • Export your data in a portable format (CSV/JSON)
  • Withdraw consent for bio-profile data processing
  • Object to processing or request restriction
  • Lodge a complaint with the ICO (UK) or your local DPA

You can export or delete your data from the Account section of the app at any time.

7. Cookies

We use cookies and similar storage for authentication, security, account preferences, and, when you allow it, analytics and first-touch attribution. We do not use them for third-party advertising.

  • Essential authentication and security storage keeps you signed in and protects your account.
  • The sa_analytics_consent preference keeps your choice for up to one year and is shared between our website and web application.
  • If you allow analytics, PostHog and Vercel Analytics help us understand feature use and whether the service is working. PostHog autocapture and session recording are disabled.
  • If you allow analytics, the sa_attr cookie keeps first-touch campaign and referrer information for up to 90 days across our website and application.

Optional analytics and attribution storage stay off until you choose Allow analytics. You can withdraw that choice at any time through Cookie settings in the website footer or Privacy in the app. Withdrawing clears the optional analytics and attribution storage available to the browser.

8. Data retention

Your data is retained for as long as your account is active. If you delete your account, all personal data is permanently removed within 30 days. Anonymised, aggregated data may be retained for product improvement.

9. Children

Stack Almanac is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or in-app notification. The “last updated” date at the top reflects the most recent revision.

11. Contact

For privacy enquiries, use our contact form.