Privacy Policy

Last updated: July 16, 2026

This Privacy Policy explains how Willow Stories FlexCo, Rotenlöwengasse 15/5, 1090 Vienna, Austria ("we", "us", "Willow Stories") collects, uses, shares, and protects personal data in connection with the Quack Stack service ("the Service"). We comply with the EU General Data Protection Regulation (GDPR) and Austrian data protection law.

This policy covers personal data relating to:

  • Visitors to our marketing website at quack-stack.com.
  • Users of the Quack Stack application at app.quack-stack.com.
  • End users whose personal data appears in Customer Data (for example, names in interview transcripts or support tickets that a customer uploads).

Who we are (data controller)

For personal data of website visitors and account holders, the data controller is:

Willow Stories FlexCo
Rotenlöwengasse 15/5
1090 Vienna, Austria
Privacy contact: [email protected]

We do not have a statutory Data Protection Officer. For data protection questions, please contact [email protected].

For personal data contained in Customer Data that a paying customer uploads to the Service (for example, interview transcripts, support tickets, or CRM exports), our customer is the data controller and we act as a data processor on their behalf. See the "Data Processing Addendum" section below for the data processing terms that apply in that relationship.

What we collect

Account and workspace data

  • Name
  • Email address
  • Password (stored only as a hash)
  • Two-factor authentication settings, if you enable them (the authenticator secret is stored encrypted; recovery codes only as hashes)
  • Profile photo (if you upload one)
  • Workspace name and membership
  • Timezone, locale, and display preferences

Billing data (for paid Subscriptions, not yet active)

  • Billing contact name and email
  • Company name and billing address
  • VAT number (where applicable)
  • Payment method details (processed by our payment provider, we do not store full card numbers)
  • Invoice history

Usage and telemetry

  • Pages visited and features used within the Service
  • Clicks, scroll depth, and interaction events
  • Session timestamps and duration
  • Browser type, operating system, device type, approximate location (from IP), and referring URL
  • Error reports and stack traces (with related context such as URL, user ID, and request parameters, see the note on Sentry below)

Customer Data that you submit to the Service, which may include:

  • URLs, web pages, and content you ask us to scrape or analyse
  • Documents and files you upload
  • Competitor names, pricing information, and positioning notes
  • Interview transcripts, meeting recordings, and support conversations
  • Slack messages from channels you connect to the Service
  • Strategy documents, experiment plans, and research notes
  • Anything you type into Quack Stack's chat interfaces

Customer Data often incidentally contains personal data of third parties (for example, the name of an interviewee or a support ticket author). The "Data Processing Addendum" section below explains our role in respect of that data.

Communications

  • Messages you send us via email, in-app chat, or support channels.
  • Responses to surveys and feedback forms.

How we collect it

  • Directly from you: when you create an Account, subscribe to a plan, upload content, send us a message, or use the Service.
  • From your browser or device: when you visit our website or use the Service (cookies, session tokens, analytics events).
  • From third-party integrations you connect: when you authorise the Service to access a third-party tool such as Slack, JustCall, Zendesk, Intercom, Help Scout, Granola, or tl;dv, we collect data from that tool within the scope of the permissions you grant.
  • From public sources: when the Service crawls public web pages you direct it to (for example, a competitor's website) or runs broad market research, it may collect publicly available information that incidentally includes personal data of third parties (names of authors, quotes from public forums, and so on).

Why we process it (purposes and legal bases)

Under GDPR Article 6, every processing activity needs a lawful basis. Ours are:

  • Providing the Service to you (creating your account, running analyses, generating insights), Account data, Customer Data, usage data. Legal basis: Contract (Art. 6(1)(b)), performance of our Terms of Service.
  • Taking steps at your request before you enter into a contract (for example, during trial), Account data, Customer Data you upload during trial. Legal basis: Contract (Art. 6(1)(b)), pre-contractual measures.
  • Sending service emails (password resets, billing notices, security alerts), Account data, email address. Legal basis: Contract (Art. 6(1)(b)).
  • Sending product updates, tips, and marketing emails: Email address, name, engagement signals. Legal basis: Consent (Art. 6(1)(a)), opt-in at signup or from the marketing site, with an unsubscribe link in every email.
  • Error reporting and debugging (for example, Sentry error reports and diagnostic logs), Usage data, error reports. Legal basis: Legitimate interest (Art. 6(1)(f)), our interest in running a reliable service, balanced against your privacy.
  • Product usage analytics on the marketing website (PostHog), Usage data. Legal basis: Consent (Art. 6(1)(a)), given or withdrawn via the cookie banner and the controls described in the Cookies section below. Analytics is not loaded on the marketing website unless you consent.
  • Product usage analytics in the web application (PostHog, cookieless), Usage data (account ID, pages and features used, tied to your account, no cookies set). Legal basis: Legitimate interest (Art. 6(1)(f)), improving a product you use under contract with us, balanced against your privacy: nothing is stored on your device, so no cookie consent question arises, and you can object at any time in your profile's Privacy settings.
  • Billing and accounting: Billing data, usage data. Legal basis: Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)), tax and accounting law.
  • Preventing fraud, abuse, and unauthorised access: Account data, IP addresses, device fingerprints, error reports. Legal basis: Legitimate interest (Art. 6(1)(f)).
  • Responding to legal requests and enforcing our Terms: any applicable data. Legal basis: Legal obligation (Art. 6(1)(c)) or legitimate interest (Art. 6(1)(f)).

Automated decision-making. The Service ranks, scores, and prioritises opportunities, experiments, and findings using AI models. These scores are decision-support outputs shown to humans who make the actual decisions. We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing within the meaning of GDPR Article 22.

Third-party subprocessors

To operate the Service we share personal data with the following subprocessors. All of them are bound by contractual obligations to protect the data and to process it only on our instructions.

  • Neon: PostgreSQL database hosting. Account data and Customer Data. EU (Frankfurt).
  • Railway: application hosting, compute, and persistent volume storage for project files. All data in transit, application logs, files written to the mounted volume. EU West, Amsterdam, Netherlands (GCP europe-west4). Single-region deployment with no replicas outside the EU.
  • Cloudflare: CDN, DNS, R2 object storage (including encrypted project backups), DDoS protection, and hosting for experiment landing pages, including the form submissions respondents make on those pages (name and contact details they choose to submit). Global edge network with EU data residency options. International transfers under EU Standard Contractual Clauses and Cloudflare's Data Processing Addendum.
  • Anthropic (Claude), AI analysis of Customer Data. Customer Data sent for analysis. USA (our contracting entity is Anthropic Ireland, Limited). Transfers under EU Standard Contractual Clauses. Anthropic's commercial terms prohibit training models on customer inputs, and inputs and outputs are deleted from Anthropic's systems within 30 days.
  • Voyage AI (a MongoDB company): text embeddings that power semantic search and duplicate detection. Short text snippets from Customer Data (for example, a finding quote or an opportunity summary) are sent for vectorisation; the resulting vectors are stored in our EU database. Our account is configured so Voyage does not train on inputs and deletes them immediately after processing. USA. Transfers under EU Standard Contractual Clauses; MongoDB is certified under the EU-US Data Privacy Framework.
  • Inngest: orchestration of our research pipelines (scheduling and tracking workflow runs). Receives workflow events containing project and workspace identifiers and pipeline names only. Customer Data content and personal data such as names and emails are not sent to Inngest; they stay on our EU infrastructure. USA.
  • Apify: managed web crawling for market and competitor research. Receives the target URLs and crawl parameters we request and returns public page content; no Account data or Customer Data is sent. Apify Technologies s.r.o. is an EU (Czech) company; processing may occur in the EU and the US under its Data Processing Addendum (EU Standard Contractual Clauses).
  • Brave Search and Serper: web search APIs for market and competitor research. They receive the research search queries we run for your project, not your uploaded Customer Data. Brave is US-based.
  • OpenAI, Perplexity, and Replicate: brand-visibility checks (testing whether AI assistants cite your product) and image generation for generated articles. They receive search-style queries about your brand and market, and image prompts. They do not receive transcripts, conversations, or other end-user personal data. USA.
  • Loops: transactional and marketing email delivery. Name, email, email engagement events. USA. Transfers under EU Standard Contractual Clauses.
  • PostHog: product analytics, on different terms for each surface. On the marketing website, anonymous usage events, IP address, only if you consent via the cookie banner, and only ever with cookies. In the web application, identified usage events tied to your account ID, email, name, and role, kept in memory with no analytics cookies and no persistent tracking storage, under legitimate interest, and you can object at any time in your profile's Privacy settings. The only thing stored on your device there is a record of your own opt-out choice if you use it, the same strictly-necessary exception as the qs_consent cookie below. We do not use session recording on either surface. EU cloud (eu.i.posthog.com). No transfer outside the EU for the analytics service.
  • Sentry: error monitoring on our servers. IP address, user agent, request URLs and headers, error stack traces, user ID, breadcrumbs (which may include partial Customer Data surfaced in error contexts). EU region. No transfer outside the EU for error reports.
  • Slack: our internal team Slack receives contact-form submissions and in-product feedback (name, email, message) so we can respond to you. USA. Transfers under EU Standard Contractual Clauses. If you connect your own Slack workspace to the Service, that content stays in your workspace and Slack processes it under your organisation's own agreement with Slack (see "Tools you connect" below).

About Sentry specifically. Our Sentry configuration has sendDefaultPii enabled, which means error reports include the IP address, user agent, URL, request headers, cookies, and related context of the request that triggered the error. If an error occurs during processing of Customer Data, incidental portions of that Customer Data may appear in the error context (for example, in a stack trace or request body). We use this information solely to diagnose and fix errors. Error reports are retained for 30 days, after which Sentry automatically deletes them in line with the retention policy of our Developer plan.

About Google AI. The Service uses Google's Gemini API for two narrow purposes: generating stock imagery and illustrations from prompts we write ourselves (for example, expert panel avatars and campaign visuals), and brand-visibility checks using search-style queries about your market. Your uploaded Customer Data (transcripts, conversations, documents) is not sent to Google for analysis, with one exception: if your workspace connects its own Gemini API key (bring your own key), content from your workspace is processed by Google under your own agreement with Google. Research synthesis and chat conversations are otherwise handled by Anthropic, with Voyage AI providing text embeddings (see above).

Tools you connect. When you connect an integration (for example Slack, JustCall, Zendesk, Intercom, Help Scout, Granola, tl;dv, GitHub, or a coding agent such as Cursor or Claude Code), that vendor processes data under your own agreement with them, and we exchange data with it on your instruction: we pull in the content the integration is scoped to (for example, call transcripts from JustCall or messages from connected Slack channels) or send out what the integration needs (for example, a task brief to a coding agent). We store the access credentials encrypted and stop the data flow when you disconnect the integration.

Payment provider. Paid Subscriptions are not yet live. When they are, we will use Stripe as our payment processor and will update this subprocessor list with the specific data categories shared with it (typically billing contact, billing address, VAT number, and tokenised payment method, we do not see or store full card numbers). Stripe is US-based; transfers rely on EU Standard Contractual Clauses.

Changes to subprocessors. We may add or change subprocessors from time to time. Paying customers can request prior notice of material subprocessor changes by emailing [email protected].

International data transfers

The Service is operated from the European Union. Our core infrastructure, application hosting (Railway, Amsterdam), database (Neon, Frankfurt), product analytics (PostHog, EU cloud), and error monitoring (Sentry, EU region), is located within the EU/EEA. No personal data is transferred outside the EU/EEA for these services.

Some of our subprocessors are located in the United States:

  • Anthropic: Customer Data sent for AI analysis.
  • Voyage AI: short Customer Data snippets sent for text embeddings.
  • Inngest: workflow identifiers and run metadata (no Customer Data content, no names or emails).
  • Brave Search, Serper, OpenAI, Perplexity, Replicate: research queries, brand-visibility queries, and image prompts.
  • Cloudflare: CDN, DNS, and object storage, with EU data residency configured where available.
  • Loops: transactional and marketing email delivery.
  • Slack: internal relay of contact-form submissions and feedback. Your own workspace's Slack use is governed by your agreement with Slack.
  • Google: image generation and brand-visibility prompts; Customer Data only where your workspace connects its own Gemini key.

For these US transfers we rely on:

  • EU Standard Contractual Clauses (Commission Decision 2021/914).
  • EU-US Data Privacy Framework where the recipient is certified under that framework.
  • Technical and organisational safeguards such as encryption in transit and at rest.

You can request copies of the relevant transfer agreements by emailing [email protected].

How long we keep it

  • Account data: for as long as your Account is active, then up to 30 days after deletion.
  • Customer Data: for as long as the Workspace that contains it is active, then up to 30 days after Workspace termination for export, then deleted.
  • Backups (including Customer Data), up to 90 days, then overwritten.
  • Billing records and invoices: 7 years (Austrian tax law requirement).
  • Marketing email subscribers: until you unsubscribe, then email is removed within 30 days.
  • Error reports (Sentry): 30 days (Sentry Developer plan).
  • Product analytics events (PostHog, marketing website): 1 year guaranteed, then moved to cold storage (PostHog free plan).
  • Product analytics events (PostHog, web application): not stored on your device at all (cookieless, in-memory only); the events themselves follow the same PostHog retention as above once received by PostHog's EU cloud.
  • Session recordings: not applicable, we do not use session recording anywhere in the Service.
  • Server access logs: 30 days.
  • Aggregated, anonymised data: indefinitely (no longer personal data once anonymised).

We will retain data longer where required by law, to resolve disputes, or to enforce our Terms.

Your rights under GDPR

You have the following rights regarding your personal data:

  • Access: ask what personal data we hold about you and receive a copy.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"), ask us to delete your personal data, subject to legal retention obligations.
  • Restriction: ask us to limit how we process your data.
  • Objection: object to processing based on legitimate interests.
  • Portability: receive your data in a structured, commonly-used, machine-readable format and ask us to transmit it to another controller.
  • Withdraw consent: where processing is based on consent (for example, marketing emails), you can withdraw consent at any time.
  • Not be subject to automated decisions: you can ask for human review of any automated decision that has a legal or similarly significant effect on you. (We do not believe we make such decisions, but you can always ask.)

To exercise any of these rights, email [email protected]. We will respond within one month (extendable to three months for complex requests, with notice to you). We do not charge for responding to rights requests unless they are manifestly unfounded or excessive.

If your personal data is in Customer Data held by one of our customers (for example, you are an interviewee whose transcript was uploaded to the Service), please contact that customer directly. They are the data controller. We will forward requests to the relevant customer where we can identify them.

Right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Austrian Data Protection Authority (Datenschutzbehörde):

Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Vienna, Austria
https://www.dsb.gv.at

You may also lodge a complaint with the supervisory authority in your EU member state of residence.

Cookies and similar technologies

We use cookies and similar technologies sparingly, and they work differently on our two surfaces:

  • Essential session cookie: qs_session. Keeps you logged in to the web application. Strictly necessary for the Service to function, so it is never gated and no consent is required for it.
  • Consent record (marketing website only): qs_consent. Stores your cookie choice for about six months so we do not ask again on every page. Strictly necessary, and it only ever holds your choice.
  • PostHog analytics cookies on the marketing website: first-party cookies for product analytics, set only if you agree to them at quack-stack.com, sending data to the EU cloud (eu.i.posthog.com). If you decline, the PostHog software is never loaded at all, so it sets no cookies and receives nothing about your visit.
  • PostHog inside the web application (app.quack-stack.com): no analytics cookies, no tracking storage. PostHog runs there too, tied to your account, but it is configured to keep tracking data in memory and never write it to a cookie or to your browser's storage. The only thing it stores on your device is a record of your own opt-out choice, if you use it, strictly necessary and not tracking data, the same exception that applies to the qs_consent record above, so there is nothing to ask consent for under cookie law there either. Instead, because tracking itself runs under legitimate interest, you can object at any time in the Privacy section of your profile, see "Why we process it" above.
  • Session recording. We do not use session recording (also called session replay) anywhere in the Service. This is disabled in code on both the marketing website and the web application.
  • No third-party advertising or tracking cookies. We do not use Google Analytics, advertising pixels, remarketing tags, or cross-site tracking.

On the marketing website, analytics cookies rest on your consent, which you give or refuse when you first visit. Change your mind any time with the "Cookie settings" link in the website footer, it takes effect immediately. Inside the web application, product analytics runs by default because it sets no cookies and is not a consent question, you can turn it off any time in the Privacy section of your profile.

Security

We take reasonable technical and organisational measures to protect personal data, including:

  • Encryption in transit (TLS 1.2+) for all traffic to and from the Service.
  • Encryption at rest for databases and object storage.
  • Password hashing using industry-standard algorithms.
  • Role-based access controls on our infrastructure.
  • Regular backups with access restricted to authorised personnel.
  • Logging and monitoring of administrative actions.
  • Security reviews of code and infrastructure.

No internet-based service can be 100% secure. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Austrian Datenschutzbehörde within 72 hours of becoming aware (as required by GDPR Article 33) and, where required, notify affected users without undue delay.

Children

The Service is not intended for, directed at, or designed for use by children under 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact [email protected] and we will delete it.

Data Processing Addendum (inline DPA)

When this section applies. When you (as a customer, represented by a Workspace Owner) upload Customer Data to the Service that contains personal data of third parties (your employees, your customers, interviewees, support ticket authors, and similar), you act as the data controller of that personal data and we act as your data processor. This section, together with the Terms of Service, constitutes the data processing agreement between us under GDPR Article 28. No separate signed DPA is required for you to have GDPR-compliant processing terms in place with us, these apply automatically when you use the Service.

Subject matter and duration. We process personal data on your behalf for the duration of your Subscription, for the purpose of providing the Service as described in our Terms.

Nature and purpose of processing. Hosting, storing, structuring, analysing, synthesising, and returning insights derived from the Customer Data you upload, using the AI providers and other subprocessors listed in "Third-party subprocessors" above.

Types of personal data and categories of data subjects. Determined by you, but typically include: names, email addresses, job titles, organisations, quotes, and free-text content relating to your customers, prospects, employees, interviewees, competitors' public communications, and support ticket authors.

Our obligations as processor (GDPR Art. 28(3)). We will:

  • Process personal data only on your documented instructions, which include your use of the Service and any written instructions you give us through the Service. If applicable law requires us to process data beyond your instructions, we will inform you before doing so unless that law prohibits such notification.
  • Ensure that personnel authorised to process personal data are bound by confidentiality.
  • Implement appropriate technical and organisational measures as described in the "Security" section above.
  • Engage subprocessors only under written agreements that impose data protection obligations equivalent to those in this section. Current subprocessors are listed in "Third-party subprocessors" above. We will give you notice of material changes to the subprocessor list and you may object by terminating your Subscription.
  • Assist you, taking into account the nature of processing and the information available to us, with responding to data subject rights requests, data protection impact assessments, and consultations with supervisory authorities.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your Customer Data.
  • On termination of your Subscription, delete or return (at your choice) all Customer Data, except where applicable law requires retention. Backups will be overwritten within 90 days.
  • Make available to you information reasonably necessary to demonstrate compliance with Article 28. Subject to confidentiality obligations, we will respond to reasonable audit requests (which we normally satisfy with existing certifications, reports, and documentation rather than on-site audits).

Your obligations as controller. You represent and warrant that:

  • You have a lawful basis to process the personal data you upload and to have us process it on your behalf.
  • You have provided all required notices to data subjects.
  • Your instructions to us comply with applicable data protection law.
  • You will not upload personal data where the Service is not an appropriate processor (for example, where a specific regulatory regime applies that we have not agreed to support).

International transfers. Where your Customer Data contains personal data of EU/EEA data subjects and we transfer that data to a subprocessor outside the EU/EEA, we rely on the EU Standard Contractual Clauses and additional safeguards as described in "International data transfers" above.

Signed DPA. If your compliance programme requires a separately signed Data Processing Agreement on paper or your own template, email [email protected] and we will provide one. The inline DPA in this section is the default and applies to all paying Subscriptions automatically.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify registered users by email and/or in-app notification at least 14 days before the changes take effect. The "Last updated" date at the top of this policy shows when it was most recently revised.

Contact

For any privacy question, complaint, or to exercise your rights:

Email: [email protected]

Post:
Willow Stories FlexCo
Attn: Privacy
Rotenlöwengasse 15/5
1090 Vienna, Austria

The newsletter

Occasional notes from the Quack Stack team on what we're learning.