PocketStack bear holding a stack of databases

Legal

Privacy Policy

PocketStack is built and run by one person (Rafael Vieiras, referred to as “we”/“I” below). This page describes what is collected when you use pocketstack.host and app.pocketstack.host (the “Studio”), why, and who it passes through on the way. It does not describe what happens inside the apps you build with PocketStack. That data is yours, and is covered separately below under “Data inside your apps.”

1. What we collect

When you create a PocketStack account, we store:

  • Your email address and a hashed password (we never store your password in plain text).
  • An optional display name.
  • Account metadata: your plan tier, when you accepted these terms, whether your email is verified.
  • The apps you create under your account (app names, ids, and which app belongs to which account).

When you visit the marketing site or sign up, Cloudflare Turnstile runs a bot check that may process your IP address and browser signals; we also log signup/login attempts by IP for abuse prevention (rate limiting), kept only long enough to enforce that limit.

We do not collect payment information today: Premium billing has not launched yet (see the pricing page). This policy will be updated before billing opens.

2. Why we collect it

  • To create and secure your account (authentication, password reset, email verification).
  • To provision and route your apps (each app needs to know which account owns it).
  • To send you transactional email: welcome, verification, password reset. We do not send marketing email.
  • To prevent abuse: bot signups, credential stuffing, brute-force login attempts.

3. Who it's shared with

We do not sell your data, and we do not share it with anyone except the infrastructure providers that make the service run. Every one of them only processes data on our behalf, under their own security commitments:

  • Amazon Web Services (SES): sends transactional email (welcome, verification, password reset).
  • Cloudflare: DNS, the Turnstile bot-check widget on signup, and R2 object storage for app file uploads and backups.
  • Linode: hosts the backend server and the SQLite database for every app.
  • Vercel: hosts the Studio (app.pocketstack.host) and this marketing site.

4. Data inside your apps

Data your end users put into the apps you build (their own accounts, records, uploaded files) belongs to you, the app owner. We do not read, use, or train on it. It lives in your app's own SQLite database and, for file uploads, in the shared Cloudflare R2 bucket, isolated per tenant. Deciding what you collect from your own end users, and complying with privacy law for them, is your responsibility as the operator of your app.

5. Retention and deletion

  • Operational logs are kept for 7 days on the Free tier, 30 days on Premium, then deleted.
  • If you delete your account, your apps and their data are deleted from our infrastructure. Export anything you want to keep first. See the Commitments page.
  • Abuse-prevention IP logs are kept only for the rate-limit window (currently up to one hour) and are not used for any other purpose.

6. Your rights

You can export all of your data (your account's apps as raw PocketBase SQLite files, plus uploads) at any time, no questions asked. You can ask us to delete your account and its data by emailing us (below). If you are in the EU/UK or another jurisdiction with statutory data-subject rights (access, correction, portability, erasure), those requests go through the same channel.

7. Cookies

The Studio sets one HTTP-only session cookie to keep you signed in. It is not used for tracking or advertising. The marketing site does not use analytics or advertising cookies.

8. Children

PocketStack is not directed at children under 16, and we do not knowingly collect data from them.

9. Changes to this policy

If this policy changes in a material way, we will update the date below and, for signed-in accounts, note it in the Studio. Continuing to use PocketStack after a change means you accept the update.

10. Contact

Questions about this policy, or a request to export or delete your data: reach out through the community Discord linked in the footer, or the support channel listed in the Studio once you are signed in.

Last updated: September 2026