UnderStack · Astridsvej 7, 8220 Brabrand (Aarhus), Denmark · CVR 46327608 · info@understack.dk · understack.dk/legal/privacy
Privacy Policy — UnderStack
Version 1.0 · 25 September 2026
This policy explains how UnderStack processes personal data when you visit understack.dk, buy UnderStack Code, contact us, or use the app. It follows the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act.
1. Controller
UnderStack, Astridsvej 7, 8220 Brabrand (Aarhus), Denmark · CVR 46327608 · info@understack.dk · +45 91 40 67 22. We have not appointed a data protection officer; write to info@understack.dk about anything in this policy.
2. The app: your data stays on your Mac
UnderStack Code is local-first. The AI models run on your Mac. Your prompts, projects, files, conversations, screenshots, generated images, project memory and settings are stored only on your Mac. The app has no telemetry, no analytics and no account, and it sends nothing to UnderStack. Secrets you enter (for example API tokens) are kept in the macOS Keychain.
We are therefore not the controller of what you do in the app. Some features you choose to use contact third parties directly from your Mac. In those cases the third party receives the data listed below, under its own privacy policy:
| Feature (when you use it) | Who is contacted | What is sent |
|---|---|---|
| Model downloads (Settings › Models) | Ollama (ollama.com), Hugging Face (huggingface.co), Python Package Index (pypi.org) | Your IP address and the requested model or package |
| Web search (⌕ Web or agent research) | Brave Search API with your own key, or DuckDuckGo | Your search query and IP address |
| Website checks and the built-in browser | The websites you ask the agent to open | Normal web requests (IP address, browser data) |
| Vercel previews | Vercel Inc. with your own token | The project files you approved for upload (files like .env are never uploaded) |
| Update check (off by default) | The update address shown in Settings › Updates | Your IP address and the app version |
Every network request the app makes is listed under Settings › Permissions › Network activity. Before sending text to a web service, the app removes secrets it recognises (keys, tokens, passwords).
3. Data we process as controller
| Purpose | Data | Legal basis | Kept for |
|---|---|---|---|
| Selling and delivering the licence, invoicing | Name, email, billing address, country, VAT number (businesses), order, licence key, consent records from checkout | Contract (GDPR art. 6(1)(b)); legal obligation for bookkeeping and VAT (art. 6(1)(c), Danish Bookkeeping Act) | 5 years after the end of the financial year (bookkeeping); licence data while the licence is valid |
| Payment | Payment status, last digits and type of card, transaction ID — card details are handled by Revolut | Contract | As bookkeeping |
| Support and correspondence | Email address, name, content of your message, attachments you send | Contract or legitimate interest in answering you (art. 6(1)(f)) | 2 years after the case is closed |
| Security reports (security@understack.dk) | Reporter's contact data and report | Legal obligation under the EU Cyber Resilience Act (art. 6(1)(c)); legitimate interest | 10 years (CRA documentation) |
| Informing customers about security updates and serious problems | Email address | Legal obligation (CRA art. 14(8)) and contract | While the licence is supported |
| Product news by email (only if you opt in) | Email address | Consent (art. 6(1)(a)) — withdraw at any time via the link in each email | Until you withdraw |
| Quote and contact requests (the For You form, email, SMS, telephone) | Name, email, phone number, the service and budget you choose, your message | Steps at your request before a contract (art. 6(1)(b)) or legitimate interest in answering you (art. 6(1)(f)) | 2 years after the last contact |
Client issue portal (/tickets, for existing clients) |
Client account, contact email, report content, screenshots you upload | Contract with the client (art. 6(1)(b)) | 2 years after the issue is closed |
| Operating the website | IP address and technical data in server logs | Legitimate interest in running a secure website | 30 days |
We do not sell personal data, do not use it for profiling and make no automated decisions with legal effect.
4. Cookies
understack.dk uses cookies that are strictly necessary for the website and checkout to work; they need no consent.
With your consent, we also use Google Analytics 4 (Google Ireland Limited; Google LLC in the United States as sub-processor) to measure how the website is used: pages visited, approximate location derived from a shortened IP address, device and browser type, and where you came from. Google Analytics sets the cookies _ga and _ga_<ID>, which are kept for up to 2 years. Analytics data is kept for 14 months. The legal basis is your consent (GDPR art. 6(1)(a) and the Danish cookie order); Google Analytics only runs after you click Accept in the cookie banner. You can change or withdraw your consent at any time via Cookie settings in the website footer. Transfers to the United States are covered by the EU-US Data Privacy Framework, under which Google LLC is certified.
Your consent choice itself is stored in your browser (understack_consent) for 12 months; after that we ask again.
5. Recipients
- Revolut Bank UAB / Revolut Business — payment processing (independent controller for payment data).
- Cloudflare, Inc. — hosting of understack.dk (static website and server functions on Cloudflare Workers; processor, data transfers under the EU-US Data Privacy Framework). The website code is deployed from GitHub; GitHub does not receive customer data.
- Our email hosting provider — mailboxes for @understack.dk (processor).
- Neon, Inc. — database for orders (processor).
- Resend, Inc. — delivery of emails from the website: order confirmations, form messages (processor).
- Google Ireland Limited / Google LLC — website analytics, only with your consent (processor).
- Our accountant and the Danish tax authorities (Skattestyrelsen), when required for bookkeeping and VAT.
- Public authorities where the law requires it, for example the CSIRT through the ENISA reporting platform in a security incident (normally without personal data of customers).
6. Transfers outside the EU/EEA
If a provider processes data outside the EU/EEA (for example in the United States), we rely on an adequacy decision (such as the EU-US Data Privacy Framework) or the EU standard contractual clauses. You can ask us for a copy of the safeguards.
7. Your rights
You have the right to access, rectification, erasure, restriction, data portability and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time. Write to info@understack.dk; we answer within one month.
You can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk, www.datatilsynet.dk, or to the authority in your country.
8. Children
Our products are not directed at children under 16, and we do not knowingly collect their data.
9. Changes
We will publish changes here and notify customers by email if they are significant.