Skip to content
Stackcut
Recipes Leaderboard How it works Get your free stack audit Add to Chrome
Effective September 24, 2026

Privacy policy

How Stackcut handles your email, card and bank data. Plain words, specific to how the product works.

  1. The short version
  2. What we collect
  3. What we store and for how long
  4. How we use it
  5. Who processes it
  6. Google user data
  7. Deleting your data
  8. Security
  9. Other details
  10. Contact

The short version

  • We use your data only to build your stack audit and savings plan.
  • We don't sell your data, we don't show ads, and we don't use your data to train AI models.
  • Email text is classified by a third-party AI service with zero data retention, then discarded. From billing emails we keep the facts: vendor, plan, amount and date (plus the sender and subject line).
  • Card statement CSVs are read in your browser. We store only the date, amount, merchant description and account label of each charge.
  • You can delete your scan at any time with Delete my scan on your results page.

Stackcut ("we", "us") runs the website stackcut.io, the results app at stackcut.io/app, and the Stackcut Chrome extension. This policy covers all three. Stackcut is in public beta.

What we collect

What we receive depends on how you run your stack audit.

From Gmail, with the Chrome extension

  • Page mode (shown as Quick scan; no Google sign-in, for everyone): the extension runs searches for receipts, renewals and trials in your own Gmail tab and reads the search result rows. For each row it sends us the sender name and address, the subject, the short preview snippet Gmail shows, and the date. When a row looks like a receipt but shows no price, the extension opens that email in your Gmail tab (up to 150 per scan) and sends us up to 2,000 characters of its visible text so the amount can be read; that text is classified and discarded like receipt text in Deep scan. Opening an email this way marks it as read in Gmail. Page mode does not use Google APIs and never reads attachments. All of this happens in your own browser tab.
  • Deep scan (Google sign-in, test users only for now): you sign in with Google OAuth and grant read-only Gmail access (gmail.readonly). The extension then uses the Gmail API. For each matching message it sends us the sender, subject, snippet, date, whether the message has an unsubscribe header, and up to 2,000 characters of the message text. It never reads attachments.
  • The extension only looks at messages that match its receipt and billing searches from the last 3 months. It never sends, deletes, moves or labels email.
  • We send the subject, snippet and (in Deep scan) receipt text to a third-party AI service, TypeSafe (Jev model), to classify it: is it a bill, which vendor, which plan, what amount. TypeSafe processes it with zero data retention. We discard the text as soon as it is classified and never store email bodies or snippets.

From card statement CSV files

Files you upload on stackcut.io are read in your browser. Payments and transfers are skipped in your browser. For each remaining charge we receive and store only the date, amount and merchant description, plus the account label you type (for example "Amex ••1004"). The file itself is never uploaded.

From Plaid (optional), only if you connect a bank

Connecting a card through Plaid is optional and available only with an invite code. If you use it, Plaid sends us up to 2 years of transactions for the accounts you pick: date, amount, merchant name or description, category, and the last digits of the account number. We never see your bank username or password. We use Plaid's access only for the one import, then remove our access to the account.

From you, in the results app

Your choices for each subscription (Keep, Cancel, Replace, Not mine), the features you tick, and how often you use each tool.

From the "Get updates" form

Your email address. We also record which page you signed up on, a referral code if the link had one, and your browser's user agent.

Technical data

  • To limit abuse, we count how many audits start from an IP address. We store a one-way hash of the IP address with a salt that changes every day, not the IP address itself.
  • Our hosting providers keep standard request logs (such as IP address, time and the page or endpoint requested) for security and operations.
  • Our pages load fonts from Google Fonts, so Google receives your IP address when a page loads.
  • We don't use advertising or analytics cookies. The results app keeps your private audit link and unsaved answers in your browser's session storage, which clears when you close the tab.

What we store and for how long

DataWhat we keepHow long
Email text (subjects and snippets in Page mode, plus the text of receipts it opens to read a price; receipt text in Deep scan)Nothing. It is classified to find the vendor, plan and amount, then discarded.Only while it is processed
Facts from billing emailsSender name and domain, subject line, date, and the facts we found: vendor, plan, amount, currency, billing period and email type (for example receipt or trial ending).Until you delete your scan, and never more than 90 days after it
Card transaction rows (CSV or Plaid)Date, amount, merchant description, account label or last digits, category (Plaid only).Until you delete your scan, and never more than 90 days after it
Your subscription list and savings planVendor, plan, monthly cost, dates, your answers, and our recommendations.Until you delete your scan, and never more than 90 days after it
A shared savings card (only if you click Share my savings)Your totals: yearly savings, yearly spend, number of subscriptions, and savings by type. Tool names only if you tick "Show my biggest moves". Anyone with the link can see it.Until you delete your scan. After the 90-day scan purge the card stays up, unlinked from your scan, so posted links keep working; email us to remove it.
Plaid access tokenHeld only while the import runs.Deleted when the import finishes
"Get updates" sign-upsThe fields listed above.Until you ask us to remove you

How we use it

  • To find your subscriptions, match them to known tools, and build your savings plan.
  • To run, secure and fix the service, including rate limits against abuse.
  • To email you about the Chrome Web Store launch and the Grok plugin, if you signed up for updates. Every email lets you unsubscribe.

We don't sell or rent your data. We don't use it for advertising. We don't use it to train AI models. People at Stackcut don't read your email data, except when you ask us to (for example to fix a problem with your scan), when needed for security, or when the law requires it.

Who processes it

We use these service providers to run Stackcut. They process data only on our instructions.

ProviderWhat they do
SupabaseHosting, database and backend functions. Stores the data listed above.
VercelHosts the website and results app.
TypeSafe (Jev model)Third-party AI that classifies email text and your answers, for example "is this a receipt", "which vendor" and "which recommendation fits". Used with zero data retention: it doesn't keep what we send, and doesn't train on it.
Plaid (optional)Bank connection, only if you connect a bank with an invite code. Plaid's own end user privacy policy applies to what you share with Plaid.

We may disclose data if the law requires it, or to protect the safety of our users or the service. If Stackcut is sold or merged, we will tell you before your data moves to a new owner, and this policy will still apply to it.

Google user data

Stackcut's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We use Gmail data only to find subscriptions and build your stack audit, features you can see in the extension and results app.
  • We transfer Gmail data to others only as needed to provide those features (the processors above), to comply with the law, or as part of a merger or sale with notice to you.
  • We never use Gmail data for advertising, and never sell it.
  • We never use Gmail data to train AI or machine learning models.
  • People don't read your Gmail data unless you give permission for specific messages, it is needed for security or to comply with the law, or the data is aggregated and anonymized for internal operations.

Deep scan asks Google for read-only Gmail access (gmail.readonly). You can remove it at any time at myaccount.google.com/permissions. Page mode (Quick scan) doesn't use Google APIs or OAuth; it reads Gmail search-result rows, and opens receipts that show no price, in your own browser tab.

Deleting your data

  • Delete my scan: on your results page, click Delete my scan. This deletes your subscriptions, email facts, transactions, answers, savings plan and any shared savings card from our database right away. It can't be undone.
  • By email: write to msanchezgrice@gmail.com with your results link or the email you signed up with. We delete within 30 days and confirm by email.
  • The extension keeps scan progress in Chrome's session storage, which clears when Chrome quits. Removing the extension removes it too.
  • Get updates: use the unsubscribe link in any email, or write to us.

Copies in our providers' backups and logs are removed on their normal schedules.

Security

  • Your results link carries a private token in the part of the URL after #, which browsers don't send to servers. We store only a hash of that token.
  • All traffic uses HTTPS. Database rules let only our server read your audit data.
  • Anyone with your results link can see your audit. Don't share it if you don't want others to see it.

Other details

  • Age: Stackcut is for people 18 and older. We don't knowingly collect data from children.
  • Where data is processed: our providers may process data in the United States and other countries.
  • Your rights: you can ask for a copy of your data, a correction, or deletion. The results app also lets you download your subscription list as CSV.
  • Changes: if we change this policy, we update the date at the top. If a change affects how we use data we already have, we ask first.

Contact

Questions or requests: msanchezgrice@gmail.com.

See also our terms of use.

Stackcut Free stack audit for founders and indie devs
Recipes Leaderboard For AI agents (MCP) How it works Extension Privacy Terms For Grok Bot