Privacy Policy
Last updated: 17 August 2026
Pemystack ("we", "us", "our") builds and operates software products including developer tools, SaaS applications, and AI-powered services. This policy explains how we collect, use, and protect your data across all Pemystack products and services, in compliance with the EU General Data Protection Regulation (GDPR) and the Kenya Data Protection Act, 2019.
1. Data controller
The data controller is Pemystack.
Contact: kennedy@pemystack.com
2. What data we collect
2.1 Account data
When you sign up for or install a Pemystack product, we collect your name, email address, and account identifiers from the authentication provider you use (Google, GitHub, or email). We store this to provide and manage your account.
2.2 Product usage data
We track aggregated usage metrics (e.g., feature usage counts, API call counts) to enforce plan limits and improve our products. This data is stored as counters with no content attached.
2.3 User-provided content
Some products allow you to upload or input content (documents, case files, tasks, leads, etc.). This content is stored securely and used only to provide the service you requested. We do not use your content to train AI models.
2.4 AI processing
Several Pemystack products use AI for analysis and generation. Where we use a BYOK (bring your own key) model, your API keys are passed at runtime and never stored. Where we use our own AI integration, data is sent to the AI provider only for the duration of the request and is not retained by the provider for training.
2.5 Website analytics
We use Umami (privacy-focused, cookie-free analytics) to measure page views. No personally identifiable information is collected. No cookies are set.
3. Legal basis for processing (GDPR Art. 6)
- Contract performance: Processing your account and usage data is necessary to provide the service you subscribed to.
- Legitimate interest: Usage counting, abuse prevention, and product improvement.
- Consent: Where applicable, such as marketing communications.
4. Data sharing
We do not sell, rent, or share your personal data with third parties. Data flows only to:
- AI providers (Anthropic, OpenAI, or Google) for product features that use AI analysis.
- Infrastructure providers (Vercel, Neon/PostgreSQL) for hosting and data storage.
- Payment processors (GitHub Marketplace, M-Pesa/IntaSend) for billing where applicable.
- Email services (Resend) for transactional emails.
5. Data retention
- Account data is retained while your account is active and deleted within 30 days of account closure.
- Usage counters are retained for 90 days.
- User-provided content is retained while your account is active. You can request deletion at any time.
6. Your rights
Under GDPR and the Kenya Data Protection Act, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Request erasure of your data
- Restrict or object to processing
- Data portability
- Lodge a complaint with a supervisory authority
To exercise any of these rights, contact kennedy@pemystack.com. We will respond within 30 days.
7. Security
- All traffic is encrypted via HTTPS/TLS.
- Databases are encrypted at rest.
- Webhook payloads are verified using cryptographic signatures.
- Infrastructure is hosted on Vercel and Neon with SOC 2 compliance.
8. International transfers
Data may be processed in the United States and Europe via our infrastructure providers. These transfers are covered by the providers' standard contractual clauses and data processing agreements.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or in-product notification.
10. Contact
For privacy-related questions or requests:
kennedy@pemystack.com