Last updated: 13 September 2026
StackyOps is a self-hosted platform that includes a password manager and authenticator (the “Vault”) and an optional browser extension, StackyOps Vault. This policy explains what data the platform and the extension handle, and how. The guiding principle is simple: StackyOps is self-hosted— your data lives in the StackyOps instance you or your organization runs, and it is never sold, rented, or shared with third parties.
StackyOps runs on a server that you or your organization operate (self-hosted, or hosted on your behalf). That server — not the makers of StackyOps — is where your accounts, vault items, and settings are stored. When you use a hosted instance, your organization is the controller of that data and its own privacy terms also apply.
chrome.storage.local). The token authenticates the extension to your server; it is never sent anywhere else.The data involved is authentication information (passwords, credentials, and any 2FA keys you store) and personal identifiers that may appear in a saved login, such as a username or email address. The extension does not collect health, financial, or location data, personal communications, browsing history, keystrokes, or general page content.
The extension communicates only with the StackyOps server you pair it with. It contains no analytics, no advertising, and no third-party trackers, and sends no data to the makers of StackyOps or any outside service. We do not sell or transfer your data to third parties, do not use it for any purpose unrelated to running the vault, and never use it to determine creditworthiness or for lending.
Traffic between the extension and your server is encrypted in transit (HTTPS). Shared vault secrets are encrypted at rest on your server and are only returned on an explicit, audit-logged reveal. Your private “My Passwords” vault is end-to-end encrypted: it is unlocked with a master password and decrypted only in your browser, so the server never sees those secrets or your master password.
Local extension settings and the device token remain in your browser until you disconnect the extension or remove it. You can revoke a device token at any time from Settings → Developer → Browser extension, and add, edit, or delete vault items from the StackyOps app. Vault data is retained according to your StackyOps instance and your organization’s policies.
StackyOps is a workplace tool and is not directed to children under 13, and we do not knowingly collect their data.
We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date.
Questions about this policy or your data? Contact us at devops@excelit-it.com or visit stackyops.com.