Privacy Policy
Last updated: August 20, 2026
Overview
stackgate.ai (“we”, “us”) provides an AI infrastructure platform that connects AI assistants to services you authorize. This policy explains what personal data we process, why we process it, and your choices.
Data we collect
- Account data — email address, name, and organization details when you register.
- Integration credentials — API tokens, OAuth tokens, and other secrets needed to call third-party services on your behalf. These are stored encrypted and scoped to your account or organization.
- Open Banking data — if you connect Enable Banking, we receive account information you authorize at your bank (for example account identifiers, balances, and transactions) through Enable Banking’s API. We do not initiate payments through this integration.
- Stripe merchant data — if you connect Stripe as an integration, we store OAuth tokens or a Restricted API Key and proxy MCP tool calls to Stripe so AI clients can read or write Stripe resources you authorize (for example customers, payments, subscriptions, and invoices). Tool results are returned to your AI client. This is separate from Stripe as our billing subprocessor for stackgate.ai subscriptions.
- Meeting intelligence data — if you connect Fireflies.ai (or a similar meeting transcript integration), we store your API key encrypted and retrieve meeting transcripts, summaries, and action items when an AI client calls a tool. Tool results are returned to your AI client. We do not keep transcript content in the hub unless you explicitly copy it to Temp Storage for cross-tool handoff.
- Too Good To Go account data — if you connect Too Good To Go, we store encrypted session tokens for your consumer account and proxy MCP tool calls so AI clients can list nearby offers and create or manage reservations on your behalf. Location coordinates or a default search address you supply for nearby search are used only to fulfill that tool call (addresses may be resolved via public geocoding services such as DAWA or OpenStreetMap Nominatim). We do not store your card details; payment is handled by Too Good To Go and its payment providers.
- Saxo Bank brokerage data — if you connect Saxo Bank, we store encrypted OAuth tokens and account identifiers and proxy MCP tool calls so AI clients can read portfolio information you authorize (for example balances, positions, and orders) and place or cancel trades when Write access is enabled. Tool results are returned to your AI client. See Saxo Bank user data below.
- Google user data — if you connect a Google account integration (such as Gmail, Google Drive, or Google Calendar), we receive and process Google user data only when you authorize OAuth scopes and an AI client calls a tool on your behalf. See Google user data below.
- LinkedIn user data — if you connect LinkedIn, we receive and process LinkedIn profile, organization, post, media, comment, reaction, and statistics data only when you authorize OAuth scopes and an AI client calls a LinkedIn tool on your behalf. See LinkedIn user data below.
- DocuSign user data - if you connect DocuSign, we receive and process envelope, recipient, template, and document data only when you authorize OAuth scopes and an AI client calls a DocuSign tool on your behalf. See DocuSign user data below.
- Usage and audit logs — MCP tool calls, authentication events, and operational logs needed to run and secure the service.
- Indexed public legal corpora — for integrations such as Danish Citizen Support, we synchronize and store publicly available legal documents, principle decisions, and related metadata from official sources (for example Retsinformation) so MCP tools can search a hub-maintained index. Tool results are returned to your AI client with source citations.
How we use data
We use your data only to operate stackgate.ai: authenticate you, store your integrations, fulfill MCP tool requests from AI clients you connect, and maintain security and audit trails. We do not sell personal data.
Bank account data accessed via Enable Banking is used solely to respond to your requests through connected AI tools until the bank session expires or you disconnect the bank in My Integrations.
Stripe merchant data accessed via the Stripe integration is used solely to fulfill MCP tool requests from AI clients you connect until you disconnect Stripe in My Integrations. We do not use that Stripe account data for advertising or AI model training.
Meeting intelligence data (for example Fireflies transcripts and summaries) is used solely to fulfill MCP tool requests from AI clients you connect until you disconnect the integration. We do not use that meeting content for advertising or AI model training.
Too Good To Go account data is used solely to fulfill MCP tool requests from AI clients you connect until you disconnect the integration. We do not use that account data for advertising or AI model training.
Saxo Bank brokerage data is used solely to fulfill MCP tool requests from AI clients you connect until you disconnect the integration. We do not use that brokerage data for advertising or AI model training.
Google user data is used solely to operate the Google integrations you connect and to return tool results to AI clients you configure. We do not use Google user data for advertising or AI model training.
LinkedIn user data is used solely to operate the LinkedIn integration you connect and to return tool results to AI clients you configure. We do not use LinkedIn user data for advertising or AI model training.
DocuSign user data is used solely to operate the DocuSign integration you connect and to return tool results to AI clients you configure. We do not use DocuSign user data for advertising or AI model training.
Indexed public legal corpora are used solely to fulfill MCP tool requests for the related integrations. We do not use that public legal content for advertising or AI model training.
Saxo Bank user data
When you connect Saxo Bank on stackgate.ai, we process brokerage account data only when you authorize the Saxo OpenAPI connection and an AI client calls a Saxo Bank tool on your behalf.
- Access — After you sign in with Saxo Bank and approve the authorization screen, we call Saxo OpenAPI when a connected AI client invokes a Saxo Bank MCP tool. Access is limited to the permissions granted to our OpenAPI application and any tool-access settings you configure in My Integrations.
- Use — Portfolio reads and order actions are performed only to return results to your AI client. We do not provide investment advice.
- Storage — Encrypted OAuth tokens, client/account keys, and integration preferences are retained while the integration stays connected. MCP audit logs record tool names, status, and error summaries — not full order tickets or portfolio snapshots.
Google user data
When you connect Google account integrations on stackgate.ai (for example Gmail, Google Drive, Google Calendar, Google Search Console, Google Analytics 4, YouTube, Google Health, or other Google OAuth integrations we offer), the following applies to information received from Google APIs.
- Access — After you sign in with Google and approve the scopes shown on Google’s OAuth consent screen, we call Google APIs when a connected AI client invokes an MCP tool. Access is limited to the scopes you granted and any folder, calendar, or account settings you configure in My Integrations.
- Use — We use Google user data only to provide and operate the integration features you use: fetching, searching, sending, or updating your Google content and returning the result to your AI client. We do not use Google user data for serving ads, retargeting, interest-based advertising, determining creditworthiness, or training machine learning or AI models.
- Storage — Encrypted OAuth tokens and integration preferences are retained while the integration stays connected. MCP audit logs record tool names, status, and error summaries — not the contents of your emails, files, calendar events, or other Google data. If you store a Gmail attachment or Drive file in Temp Storage for cross-tool handoff, that copy is kept only for the configured time-to-live (default two hours, maximum twenty-four hours) and is then deleted automatically.
- Sharing — Google user data retrieved for a tool call is returned to the AI client that requested it (for example Cursor, ChatGPT, or Claude). You choose and configure those clients; their privacy policies apply to how they handle data after we return it. We do not sell Google user data or transfer it to data brokers or advertising platforms.
- Human access — Our staff do not read your Google emails, files, or other Google content except where necessary to investigate a security issue or comply with applicable law, consistent with Google’s Limited Use requirements.
- Limited Use — Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Your choices — Disconnect the integration in My Integrations or revoke stackgate.ai in your Google Account permissions. Revocation stops new API access; stored tokens are removed when you disconnect.
LinkedIn user data
When you connect LinkedIn on stackgate.ai, the following applies to information received from LinkedIn APIs.
- Access — After you sign in with LinkedIn and approve the scopes shown on LinkedIn’s OAuth consent screen, we call LinkedIn APIs when a connected AI client invokes a LinkedIn MCP tool. Access is limited to the scopes you granted and any default organization settings you configure in My Integrations or through LinkedIn tools.
- Use — We use LinkedIn user data only to provide and operate the integration features you use: reading your connected profile, listing organizations, publishing or updating posts, uploading media, managing comments and reactions, reading social metadata, and returning statistics to your AI client. We do not use LinkedIn user data for serving ads, retargeting, interest-based advertising, determining creditworthiness, or training machine learning or AI models.
- Storage — Encrypted OAuth tokens, connected profile metadata, and integration preferences are retained while the integration stays connected. MCP audit logs record tool names, status, and error summaries — not the contents of your LinkedIn posts, media, comments, reactions, or organization statistics. If you store media in Temp Storage for upload handoff, that copy is kept only for the configured time-to-live (default two hours, maximum twenty-four hours) and is then deleted automatically.
- Sharing — LinkedIn user data retrieved for a tool call is returned to the AI client that requested it (for example Cursor, ChatGPT, or Claude). You choose and configure those clients; their privacy policies apply to how they handle data after we return it. We do not sell LinkedIn user data or transfer it to data brokers or advertising platforms.
- Human access — Our staff do not read your LinkedIn content except where necessary to investigate a security issue or comply with applicable law.
- Your choices — Disconnect the integration in My Integrations or revoke stackgate.ai in your LinkedIn account settings. Revocation stops new API access; stored tokens are removed when you disconnect.
DocuSign user data
When you connect DocuSign on stackgate.ai, the following applies to information received from DocuSign eSignature APIs.
- Access - After you sign in with DocuSign and approve the scopes shown on DocuSign's OAuth consent screen, we call DocuSign APIs when a connected AI client invokes a DocuSign MCP tool. Access is limited to the scopes you granted and the account you select in My Integrations.
- Use - We use DocuSign user data only to provide and operate the integration features you use: listing envelopes and templates, reading recipient status, creating or voiding envelopes, downloading documents, and returning the result to your AI client. We do not use DocuSign user data for advertising or AI model training.
- Storage - Encrypted OAuth tokens, account identifiers, base URI, and integration preferences are retained while the integration stays connected. MCP audit logs record tool names, status, and error summaries - not envelope contents, recipient lists, or PDF bytes. If you store a DocuSign document in Temp Storage for cross-tool handoff, that copy is kept only for the configured time-to-live (default two hours, maximum twenty-four hours) and is then deleted automatically.
- Sharing - DocuSign user data retrieved for a tool call is returned to the AI client that requested it (for example Cursor, ChatGPT, or Claude). You choose and configure those clients; their privacy policies apply to how they handle data after we return it. We do not sell DocuSign user data or transfer it to data brokers or advertising platforms.
- Human access - Our staff do not read your envelopes, recipients, or documents except where necessary to investigate a security issue or comply with applicable law.
- Your choices - Disconnect the integration in My Integrations or revoke stackgate.ai in your DocuSign account settings. Revocation stops new API access; stored tokens are removed when you disconnect.
Third-party services
When you connect an integration (Trello, Gmail, Enable Banking, Stripe, and others), we exchange data with that provider according to the permissions you grant. Enable Banking acts as an intermediary to your bank; their terms and privacy policy apply to that part of the flow. When you connect Stripe, Stripe’s terms and privacy policy apply to data processed in your Stripe account; we proxy authorized MCP calls and return results to your AI client.
We use subprocessors to operate stackgate.ai (hosting, billing, email, and analytics). See our Data Processing Agreement for the current list and locations.
Retention and security
We retain account and integration data while your account is active. Open Banking session metadata is kept until you disconnect or the session expires at the bank. Google OAuth tokens are kept until you disconnect the relevant integration or delete your account. Files copied to Temp Storage from Google integrations or meeting intelligence tools are deleted when their time-to-live expires or when you delete them through Temp Storage tools. LinkedIn OAuth tokens are kept until you disconnect LinkedIn or delete your account. Media copied to Temp Storage for LinkedIn uploads is deleted when its time-to-live expires or when you delete it through Temp Storage tools. DocuSign OAuth tokens are kept until you disconnect DocuSign or delete your account. Documents copied to Temp Storage from DocuSign are deleted when their time-to-live expires or when you delete them through Temp Storage tools. Saxo Bank OAuth tokens are kept until you disconnect Saxo Bank or delete your account. Indexed public legal corpora are retained and refreshed according to each source’s synchronization schedule while the integration remains offered. We apply encryption, access controls, and least-privilege design for stored credentials.
Your rights
You may disconnect integrations, delete your account, or contact us to request access, correction, or deletion of personal data where applicable law provides those rights.
Business customers
If you use stackgate.ai on behalf of an organization, our Data Processing Agreement applies in addition to this Privacy Policy.
Contact
Data protection and privacy inquiries: andreas@gwdhost.dk