← StackyOps

Privacy Policy

Last updated: 13 September 2026

StackyOps is a self-hosted platform that includes a password manager and authenticator (the “Vault”) and an optional browser extension, StackyOps Vault. This policy explains what data the platform and the extension handle, and how. The guiding principle is simple: StackyOps is self-hosted— your data lives in the StackyOps instance you or your organization runs, and it is never sold, rented, or shared with third parties.

Who controls your data

StackyOps runs on a server that you or your organization operate (self-hosted, or hosted on your behalf). That server — not the makers of StackyOps — is where your accounts, vault items, and settings are stored. When you use a hosted instance, your organization is the controller of that data and its own privacy terms also apply.

What the browser extension handles

  • Connection settings & a device token. When you pair the extension to your StackyOps server, the server URL, a device pairing token, and your preferences are stored locally in the browser (chrome.storage.local). The token authenticates the extension to your server; it is never sent anywhere else.
  • The current site’s address.When you open the extension or trigger autofill, it reads the active tab’s domain to find a matching saved login. It does not build or transmit a history of the pages you visit.
  • Login details you choose to fill or save.On your action, the extension fills a saved username and password into a page’s sign-in form, and can offer to save a login you have just entered. Credentials are sent only to your own StackyOps server.
  • Vault items. To show and fill your logins (and, where enabled, 2FA codes), the extension reads and writes vault items on your StackyOps server over an authenticated, encrypted connection.

Categories of data

The data involved is authentication information (passwords, credentials, and any 2FA keys you store) and personal identifiers that may appear in a saved login, such as a username or email address. The extension does not collect health, financial, or location data, personal communications, browsing history, keystrokes, or general page content.

Where data goes

The extension communicates only with the StackyOps server you pair it with. It contains no analytics, no advertising, and no third-party trackers, and sends no data to the makers of StackyOps or any outside service. We do not sell or transfer your data to third parties, do not use it for any purpose unrelated to running the vault, and never use it to determine creditworthiness or for lending.

How data is protected

Traffic between the extension and your server is encrypted in transit (HTTPS). Shared vault secrets are encrypted at rest on your server and are only returned on an explicit, audit-logged reveal. Your private “My Passwords” vault is end-to-end encrypted: it is unlocked with a master password and decrypted only in your browser, so the server never sees those secrets or your master password.

Retention and your controls

Local extension settings and the device token remain in your browser until you disconnect the extension or remove it. You can revoke a device token at any time from Settings → Developer → Browser extension, and add, edit, or delete vault items from the StackyOps app. Vault data is retained according to your StackyOps instance and your organization’s policies.

Children

StackyOps is a workplace tool and is not directed to children under 13, and we do not knowingly collect their data.

Changes

We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date.

Contact

Questions about this policy or your data? Contact us at devops@excelit-it.com or visit stackyops.com.