Privacy policy
Last updated 5 October 2026
The controller of your personal data is Whizzy Digital Solutions Lda, Portugal (info@askyourstack.com). We process it to provide the service you signed up for and to meet our legal obligations, such as keeping invoices.
What we keep
- Your account: email address, name if you sign in with Google, and sign-in sessions.
- Billing: handled by Stripe. We keep your Stripe customer id and plan, not your card details.
- Servers: name, hostname, the facts the agent reports (operating system, memory, disk, running services) and when it last checked in.
- Known vulnerabilities (Pro and Agency): to check what is installed on your sites against public feeds, we send the names and versions of WordPress plugins and themes to WPVulnerability (wpvulnerability.net) and of composer packages to OSV (osv.dev). Nothing else about you or your server goes with them, and answers are cached a day.
- Alert channels you add: a webhook address, or the Telegram chat you connect to our bot (its chat id and name). Problems and fixes are sent there; nothing is read from the chat except the Start and /stop commands.
- Support: tickets you send, and AI Support chats (kept 90 days and sent to Anthropic, which runs the AI, to answer them).
- Activity: every tool call your AI makes through AskYourStack, with its arguments and result (including command output and files it read), so you can see what happened. The log keeps only the length of files it writes; an approval request keeps the full content so you can check it.
Sites you connect without a server
If you connect a WordPress site on the Sites & Apps page, WordPress makes a password only for AskYourStack (an application password) after you approve it in your own WordPress admin. Your own WordPress password is never asked for or seen by us.
- We keep that application password encrypted, the site's address and the WordPress user name it belongs to.
- We use it only for the content tool calls your AI makes for that site: reading posts, pages and media, and, as far as the mode you chose allows, saving drafts, uploading images or publishing.
- So that every change can be undone, we keep what a change replaced (the old title, text or other field of that post or page) for 90 days, then delete it. The activity log keeps which tool was called and on which item, not the content.
- Disconnect a site at any time on the Sites & Apps page: we delete the password and the kept old versions and ask your site to cancel the password. You can also cancel it yourself in your WordPress profile.
If you connect a WhizzyCommerce shop, you sign in at WhizzyCommerce, pick the shop and press Allow. WhizzyCommerce then gives AskYourStack a token for that one shop; your WhizzyCommerce password is never asked for or seen by us.
- We keep that token encrypted, with the shop's name, address, plan and language.
- We use it only for the calls your AI makes for that shop. What it may read or propose is what you switched on under Agents in your WhizzyCommerce dashboard, and a change only happens when you confirm it there.
- We do not store what the shop answers (orders, customers, products). The activity log keeps which capability was called and the names of its arguments, not their values.
- Disconnect on the Sites & Apps page at any time: we delete the token and ask WhizzyCommerce to cancel it.
If you connect Cloudflare, you make an API token at Cloudflare for the zones you choose and paste it on the Sites & Apps page. Your Cloudflare password is never asked for.
- We keep that token encrypted, the names of the zones it sees and what it may do.
- We use it only for the Cloudflare tool calls your AI makes: reading and, as far as the mode you chose allows, changing DNS records, clearing the cache, firewall rules, zone settings, and reading traffic figures. Traffic figures are not stored; the activity log keeps the tool, the zone and the arguments.
- So that every change can be undone, we keep what a change replaced (the old record, rule or setting) for 90 days, then delete it.
- Disconnect on the Sites & Apps page at any time: we delete the token and the kept old values. The token itself you delete at Cloudflare.
If you connect Bing Webmaster Tools, you either sign in at Bing and allow AskYourStack to view and manage your Bing Webmaster data, or paste the API key from your Bing Webmaster account. We keep that access or key encrypted and the list of sites you picked, use it only for the Bing tool calls your AI makes (performance, crawl, keyword, link and sitemap data, and submitting pages or sitemaps when your AI is asked to), store none of the data, and delete the access when you disconnect on the SEO page.
The keyword tools (search volumes, keyword ideas, live Google results, what a domain ranks for) are answered by a data provider, DataForSEO, from our own account: the keywords, domains and countries your AI asks about are sent to them to be answered and are not tied to you there; nothing about you or your account goes with them, and we store only the activity log entry (the tool and its arguments).
Google Search Console and Google Analytics data
If you connect Google, you sign in with Google and allow AskYourStack to view Search Console data for your verified sites (the read-only webmasters.readonly permission) and, on plans that include it, your Google Analytics data (the read-only analytics.readonly permission), plus your Google email address so you can see which account is connected.
- We use it only to answer the Search Console and Google Analytics tool calls your AI makes for the properties you picked, and to list your properties so you can pick them. Nothing is changed in Search Console or Google Analytics.
- We keep the Google access grant encrypted, the connected email address and the list of properties you picked. The Search Console and Analytics data itself goes straight to your AI client and is not stored by us; the activity log keeps only which tool was called, its arguments and how many rows came back.
- Only if you switch on “History and alerts” on that page, we store once a day, for each property you picked, the day's totals (Search Console clicks, impressions, click rate and average position; Analytics sessions, key events and revenue; Core Web Vitals) and the addresses and index status of your ten pages with the most clicks. We use them to show you trends and to warn you when clicks fall, a page leaves the index or a vital turns poor. They stay while the switch is on and are deleted when you switch it off or close your account.
- Protection: the Google access grant is encrypted at rest with a key that lives only on our server, every request to Google and to your AI client travels over TLS, and only the account that connected Google can use its grant. Our servers are in Germany (Hetzner) and reachable by SSH key only.
- Retention and deletion: the grant, the connected email address and your picks are deleted the moment you disconnect Google or delete your account. The daily history is kept only while “History and alerts” is on; switching it off, disconnecting Google or deleting your account deletes it at once. Nothing else from Google is stored.
- We do not sell this data, use it for advertising, share it with anyone other than the AI client you connected, or use it to train AI models. People at AskYourStack do not read it, except with your permission for support, for security, or where the law requires.
- Disconnect at any time on the Search Console page of your dashboard (we delete the grant and ask Google to revoke it) or in your Google account's security settings.
AskYourStack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies and analytics
The site uses Google Analytics to see which pages are useful. Its cookies are only set if you choose Accept in the cookie notice; if you decline, Google receives only anonymous signals without cookies. You can change your mind by clearing this site's data in your browser. Signing in uses one necessary cookie for your session.
What we do not keep
No SSH keys or server passwords. Your conversations with your AI stay with your AI provider; we only see the tool calls it sends us.
Who else sees it
Stripe (payments), Anthropic (AI Support answers), Google (email for sign-in and alerts, Google sign-in and Search Console if you use them, and Analytics if you accept it) and our hosting provider (Hetzner, in Germany). We do not sell data or use it for advertising.
How long
Your activity, approvals and alerts are shown to you for 90 days. After 90 days we delete the output of each tool call and keep only what was asked, when and from which address, as a record of the service; that record and your sign-in history are deleted after 2 years. A server you remove from your list is hidden from you but stays in that record. The notes your AI saves about your servers stay until you or your AI delete them (you see and delete them on the Activity page), and its work summaries are deleted after 2 years. When your AI changes SEO titles, descriptions or image texts on your site through AskYourStack, the texts it replaced are kept for 90 days so the change can be undone. When you connect an AI client by signing in, we keep which app it is, where it sent you back, when it connected and was last used, and the address it connected from, until 30 days after you disconnect it; its access tokens are stored only as hashes. Deleting your account deletes your servers, activity, approvals and any Google connection. Billing records are kept as tax law requires. On your servers, the agent deletes background job output and database dumps it made after 7 days.
Your rights
You can ask for a copy of your data, a correction or deletion at info@askyourstack.com. You can also complain to the Portuguese data protection authority (CNPD) or the one where you live.