skip to content
← mystack.bio

Legal

Privacy policy

What we collect, why, and how you stay in control of it.

1. Who we are

MyStack is operated by Pablo M. Hernandez, from Portugal. Contact: hello@mystack.bio for anything general, or privacy@mystack.bio for privacy and data-rights requests specifically.

The supervisory authority for data protection in Portugal is the CNPD (Comissão Nacional de Proteção de Dados). You can lodge a complaint with them at any time, whether or not you contact us first.

2. What this service is

MyStack lets you document your own health protocol — supplements, experiments, lab measurements, life events, diet, training, and sleep — and decide, item by item, whether to publish it on your public page. Nothing is public until you choose to make it so.

3. Data we process

  • Account and profile. Email, password hash, your handle, and the optional profile fields you fill in: display name, bio, location, links, and an avatar image.
  • Health data you enter. Supplements and medications with doses and dose periods, lab measurements, experiments, life events, diet periods, training blocks, sleep averages and sleep goals, and any free-text notes you write. This is special-category data under GDPR Article 9.
  • Imports (pastes and lab-report files). If you use the importer, the text you paste — or the PDF / photo of a lab report you upload — is sent to an AI model to be structured into rows. It is not used to train any model, and uploaded files are processed in memory and never stored; only a count of your document imports is kept (they're capped per account).
  • Technical data. Server logs (IP address, user agent) kept for security purposes, and cookieless analytics on public pages only — your dashboard is never tracked.
  • Cookies. Only the session cookie needed to keep you signed in. No tracking or advertising cookies.
  • Local storage. While you review an import before saving it, a working copy is kept in your browser's local storage so a dropped connection doesn't lose your edits. It never leaves your device; it is cleared when you save, sign out, or delete your account, and after seven days it is discarded — never restored, and removed the next time you open the importer.

4. Legal bases

We process account and health data under contract, to run the service you asked for. Making any piece of health data public requires your explicit consent (Article 9(2)(a)) — recorded with a timestamp and the version of the consent text you agreed to, visible in your settings. Security and abuse-prevention processing rests on our legitimate interest in keeping the service usable.

You can withdraw consent at any time by unpublishing (instant) or deleting your account. Withdrawing consent doesn't undo the lawfulness of processing that already happened.

5. Cohort aggregates (opt-in)

A cohort documents people who independently chose to follow one protocol. Joining one is private by default. One of its three separate opt-ins is inclusion in anonymous aggregate statistics: if you give that consent (its own explicit Article 9(2)(a) consent, recorded with a timestamp and text version), the before/after values you link to that cohort's experiment — for the cohort's primary marker only — are combined into medians and interquartile ranges with participant counts. No aggregate is shown below 10 consenting, completed participants, your individual values are never shown, and markers in the hormone, adrenal, and thyroid categories are never aggregated at all.

You can withdraw this consent at any time from your cohorts page. Withdrawal removes your values from all future renders of the aggregate; cached link-preview images may take a few minutes to catch up. (The defensibility of the 10-person anonymization threshold for special-category data is flagged for the same formal legal review noted below, before we scale up.)

6. Where data lives

Your data is stored in Postgres, hosted in Frankfurt, Germany (Neon, EU region). The application is hosted and delivered by Vercel, including the global CDN that makes public pages fast to load — that CDN reach is what "public" means for a page you choose to publish.

7. Who else processes data on our behalf

ProcessorPurposeWhere
VercelHosting, delivery, function executionGlobal (US-based company, SCCs)
NeonDatabaseFrankfurt, EU
Vercel AI Gateway → AnthropicStructuring the text or lab-report files you submit to the importer only; no training, transientUS, SCCs / DPF
ResendTransactional email only (password reset, email verification and change)US, SCCs / DPF
GoogleSign-in, only if you choose Google sign-inUS, SCCs / DPF
Vercel Web AnalyticsCookieless analytics, public pages onlyGlobal (US-based company, SCCs)
SentryError monitoringEU region

Error monitoring (Sentry). If something breaks, we send a technical error report to Sentry (hosted in their EU region) so we can fix it. A report contains the error, the page path with any share or claim tokens removed, and browser/runtime details. We configure Sentry to drop user identifiers, IP addresses, and cookies, and reports never include your health data. Reports are retained on Sentry's standard schedule (~90 days).

8. Publishing means public

A page you publish is on the open web: it can be crawled by search engines, cached, and shared as a preview card on social platforms. Unpublishing removes it from MyStack immediately, but copies cached elsewhere — a search index, a chat app's link-preview cache — may persist for a while outside our control.

9. Private share links

You can create a link that shows your page — including private entries — to anyone who has the link. Links are optional, expire on the schedule you choose (or never, if you say so), and can be revoked at any time in Settings. Creating your first link records a consent entry with a timestamp, the same way publishing does. Share-link pages are excluded from analytics and search engines, and a link preview in a chat app reveals nothing about you or your page.

10. Connected apps (AI assistants)

You can connect an AI assistant — such as Claude or ChatGPT — to your account. Connecting is your explicit instruction to transmit your data, including private entries, to the AI provider you choose. That transfer happens under that provider's own terms, on infrastructure outside our EU boundary; for what the assistant's provider retains or does with it, we are not the controller. If you would rather your health data never leave for a third-party model, simply don't connect one — the paste importer and the dashboard editors do everything a connected app does, in-house.

A connected app can read everything in your account (private entries included) and add new entries, which always land private — exactly as if you had entered them yourself. It can never publish, delete, or export your data, change your account settings, or record consent on your behalf; those remain deliberate acts you take in this interface.

We log connect-time consent (date, time, and the version of the consent wording you agreed to) and the scopes you granted, and the Settings page lists your active connections. Disconnecting an app cuts off renewal immediately; any access token already issued stops working within about fifteen minutes. Entries an app created stay in your account after you disconnect — disconnecting removes access, not your data. Entries created via a connected app are marked as such in your account and in your export.

This is an access channel, not a new category of collection — we gather nothing new about you here. (Our OAuth-provider obligations, the "user-directed transfer" framing above, and whether the connect-consent wording should reference your data-portability right are flagged for the formal legal review before we scale up.)

11. Retention

We keep your data until you delete it. Deleting your account is immediate and permanent — there is no soft-delete limbo. Database backups age out on our provider's normal cycle. (Whether a minimal record of past consent may be retained after account deletion, for our own legal defensibility, is a question we're parking for a formal legal review before we scale up; today, your consent log is deleted along with everything else.)

12. Your rights

  • Access / portability. The "download my data" button in settings gives you a complete JSON export.
  • Rectification. Edit anything yourself, any time, in the dashboard editors.
  • Erasure. The delete-account button in settings.
  • Objection, restriction, complaint. Email us, or contact the CNPD directly.

13. No profiling, no ads

We don't build profiles of you, we don't make automated decisions about you, we don't run ads, and we never sell your data.

14. Minors

MyStack is for adults. You must be 18 or older to use it.

15. Changes to this policy

This policy is versioned. If we make a material change, we'll announce it on the site, not just quietly edit this page.

Last updated 2 August 2026 · questions to hello@mystack.bio