UnderStack
EnglishEspañolDansk

UnderStack · Astridsvej 7, 8220 Brabrand (Aarhus), Denmark · CVR 46327608 · info@understack.dk · understack.dk/legal/privacy

Privacy Policy — UnderStack

Last updated 25 September 2026 · Download as PDF

Version 1.0 · 25 September 2026

This policy explains how UnderStack processes personal data when you visit understack.dk, buy UnderStack Code, contact us, or use the app. It follows the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act.

1. Controller

UnderStack, Astridsvej 7, 8220 Brabrand (Aarhus), Denmark · CVR 46327608 · info@understack.dk · +45 91 40 67 22. We have not appointed a data protection officer; write to info@understack.dk about anything in this policy.

2. The app: your data stays on your Mac

UnderStack Code is local-first. The AI models run on your Mac. Your prompts, projects, files, conversations, screenshots, generated images, project memory and settings are stored only on your Mac. The app has no telemetry, no analytics and no account, and it sends nothing to UnderStack. Secrets you enter (for example API tokens) are kept in the macOS Keychain.

We are therefore not the controller of what you do in the app. Some features you choose to use contact third parties directly from your Mac. In those cases the third party receives the data listed below, under its own privacy policy:

Feature (when you use it) Who is contacted What is sent
Model downloads (Settings › Models) Ollama (ollama.com), Hugging Face (huggingface.co), Python Package Index (pypi.org) Your IP address and the requested model or package
Web search (⌕ Web or agent research) Brave Search API with your own key, or DuckDuckGo Your search query and IP address
Website checks and the built-in browser The websites you ask the agent to open Normal web requests (IP address, browser data)
Vercel previews Vercel Inc. with your own token The project files you approved for upload (files like .env are never uploaded)
Update check (off by default) The update address shown in Settings › Updates Your IP address and the app version

Every network request the app makes is listed under Settings › Permissions › Network activity. Before sending text to a web service, the app removes secrets it recognises (keys, tokens, passwords).

3. Data we process as controller

Purpose Data Legal basis Kept for
Selling and delivering the licence, invoicing Name, email, billing address, country, VAT number (businesses), order, licence key, consent records from checkout Contract (GDPR art. 6(1)(b)); legal obligation for bookkeeping and VAT (art. 6(1)(c), Danish Bookkeeping Act) 5 years after the end of the financial year (bookkeeping); licence data while the licence is valid
Payment Payment status, last digits and type of card, transaction ID — card details are handled by Revolut Contract As bookkeeping
Support and correspondence Email address, name, content of your message, attachments you send Contract or legitimate interest in answering you (art. 6(1)(f)) 2 years after the case is closed
Security reports (security@understack.dk) Reporter's contact data and report Legal obligation under the EU Cyber Resilience Act (art. 6(1)(c)); legitimate interest 10 years (CRA documentation)
Informing customers about security updates and serious problems Email address Legal obligation (CRA art. 14(8)) and contract While the licence is supported
Product news by email (only if you opt in) Email address Consent (art. 6(1)(a)) — withdraw at any time via the link in each email Until you withdraw
Quote and contact requests (the For You form, email, SMS, telephone) Name, email, phone number, the service and budget you choose, your message Steps at your request before a contract (art. 6(1)(b)) or legitimate interest in answering you (art. 6(1)(f)) 2 years after the last contact
Client issue portal (/tickets, for existing clients) Client account, contact email, report content, screenshots you upload Contract with the client (art. 6(1)(b)) 2 years after the issue is closed
Operating the website IP address and technical data in server logs Legitimate interest in running a secure website 30 days

We do not sell personal data, do not use it for profiling and make no automated decisions with legal effect.

4. Cookies

understack.dk uses cookies that are strictly necessary for the website and checkout to work; they need no consent.

With your consent, we also use Google Analytics 4 (Google Ireland Limited; Google LLC in the United States as sub-processor) to measure how the website is used: pages visited, approximate location derived from a shortened IP address, device and browser type, and where you came from. Google Analytics sets the cookies _ga and _ga_<ID>, which are kept for up to 2 years. Analytics data is kept for 14 months. The legal basis is your consent (GDPR art. 6(1)(a) and the Danish cookie order); Google Analytics only runs after you click Accept in the cookie banner. You can change or withdraw your consent at any time via Cookie settings in the website footer. Transfers to the United States are covered by the EU-US Data Privacy Framework, under which Google LLC is certified.

Your consent choice itself is stored in your browser (understack_consent) for 12 months; after that we ask again.

5. Recipients

  • Revolut Bank UAB / Revolut Business — payment processing (independent controller for payment data).
  • Cloudflare, Inc. — hosting of understack.dk (static website and server functions on Cloudflare Workers; processor, data transfers under the EU-US Data Privacy Framework). The website code is deployed from GitHub; GitHub does not receive customer data.
  • Our email hosting provider — mailboxes for @understack.dk (processor).
  • Neon, Inc. — database for orders (processor).
  • Resend, Inc. — delivery of emails from the website: order confirmations, form messages (processor).
  • Google Ireland Limited / Google LLC — website analytics, only with your consent (processor).
  • Our accountant and the Danish tax authorities (Skattestyrelsen), when required for bookkeeping and VAT.
  • Public authorities where the law requires it, for example the CSIRT through the ENISA reporting platform in a security incident (normally without personal data of customers).

6. Transfers outside the EU/EEA

If a provider processes data outside the EU/EEA (for example in the United States), we rely on an adequacy decision (such as the EU-US Data Privacy Framework) or the EU standard contractual clauses. You can ask us for a copy of the safeguards.

7. Your rights

You have the right to access, rectification, erasure, restriction, data portability and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time. Write to info@understack.dk; we answer within one month.

You can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk, www.datatilsynet.dk, or to the authority in your country.

8. Children

Our products are not directed at children under 16, and we do not knowingly collect their data.

9. Changes

We will publish changes here and notify customers by email if they are significant.

ImprintPrivacySecurityUnderStack · CVR 46327608

UnderStack · Astridsvej 7, 8220 Brabrand (Aarhus), Denmark · info@understack.dk · +45 91 40 67 22