Skip to main content
Security, Privacy & Data

Customer Data and Privacy

This page explains what StackJack records about your tool calls, what support diagnostics contain, and how to delete an entire StackJack organization. Organization deletion is not the same as removing…

Written By Christopher Scaminaci

Last updated 2 days ago

This page explains what StackJack records about your tool calls, what support diagnostics contain, and how to delete an entire StackJack organization. Organization deletion is not the same as removing one member or disconnecting one connector: it is an irreversible deprovisioning operation.

Before requesting organization deletion

Only an active organization Owner can start deletion from the Team page. This includes the Primary Owner and an active co-owner; administrators and members cannot start it on an owner's behalf. Export anything you need and resolve ownership or billing questions before starting.

Deletion removes the organization's database record and the tenant-scoped records that depend on it, including team memberships and invitations, connector configuration, credential references, MCP clients, usage and activity records, agents and runs, failure and approval notification records, and support-ticket records. It also requests removal of the organization's sign-in directory and stored tenant secrets.

There are important boundaries to that scope:

  • StackJack keeps the cross-region directory entry as a deprovisioned routing/audit record. It includes the home region and account identifiers; it is not an active organization or a copy of its working content.
  • Stored secrets are deleted after the database records.
  • Organization deletion removes ticket and attachment records from the database. It also deletes every file StackJack stores for the organization's support tickets — attachment files and diagnostic files, for open and closed tickets alike. These files are deleted after the database records.
  • When a single ticket is closed, StackJack deletes that ticket's attachment files and diagnostic files. A ticket closed while your organization is moving between StackJack regions keeps them until the move is complete; they are deleted shortly after it.
  • Files you attach in the support widget are uploaded to Featurebase, not to StackJack. Featurebase holds them under its own terms, and StackJack cannot delete them.
  • Organization deletion first deletes the transcripts of your automations' runs, from StackJack and from our AI provider, and switches your automations off while that finishes. The deletion waits for it for at most 24 hours; it normally takes minutes. A transcript stored in your organization's own Anthropic account that StackJack cannot reach in that time stays there, and you can delete it in the Anthropic Console. See Deleting run transcripts.
  • Organization deletion does not remove the Anthropic agents or memory stores your automations created, or the raw knowledge files. It does delete the recorded test files behind your test scenarios and the large tool results StackJack stored for your organization. Automation and knowledge records are deleted with the organization, but the audit record of memory changes is kept. Each provider keeps data under its own terms.
  • External processors apply their own retention and deletion terms. See External Data Processing.

Requesting deletion in the Portal

The Portal lane is an owner-authorized request; it does not send a second confirmation link.

  1. Open Team, find the Data & Privacy card, and select Request Data Deletion.
  2. Read the scope and irreversibility warning in the dialog that opens.
  3. Type the organization's name exactly. Request Deletion stays disabled until it matches.
  4. Submit the request. StackJack records the request against your signed-in identity, and refuses it unless you are an active Owner of that organization at that moment. The request then goes into the operator queue.

The Team page shows the active request and its customer-facing status. Only an organization Owner sees the Data & Privacy card and its actions. Use Cancel Request only while the Team page offers that action. Withdrawing changes the request record: it does not interrupt a deprovisioning run that has already started, and it cannot restore data that has already been deleted. A terminal request is no longer shown as active and cannot be cancelled — the server refuses, naming the state the request is already in.

Requesting deletion by email

If you cannot use the Portal, email support@stackjack.io. After Support records the request, StackJack attempts to send the seven-day confirmation link to the organization's on-file owner email address—not necessarily the person who first contacted Support. The request is saved before that delivery attempt. Both intake lanes — the Portal and email — look for an existing active request first and refuse a second one, so a normal duplicate request lands on the existing request rather than starting a parallel deletion path. If the message does not arrive, contact Support to verify the address and re-send or cancel the request.

The email link opens /confirm-deletion/{Token} and is:

  • valid for 7 days;
  • single-use; and
  • protected by a human-verification check on the confirmation page.

The full link is a bearer secret and is necessarily included in the transactional message sent through StackJack's email processor. Do not forward or publish it. StackJack stores only its hash on the request and scrubs this path segment from configured error telemetry; see External Data Processing.

The page repeats the deletion scope before you confirm. An invalid, expired, or already used link shows the same neutral “no longer valid or already used” result and directs you to Support. An expired unconfirmed request no longer prevents a fresh request. If you need to stop an emailed request before confirming it, contact Support; there is no public cancel button on the emailed-link page.

Billing consequences

Deprovisioning attempts to end the organization's supported paid subscriptions. A linked Paddle subscription is canceled immediately when Paddle is configured, and legacy WooCommerce subscription cancellation is attempted. A request can be blocked for operator resolution when required Paddle linkage cannot be handled safely.

Provider cancellation calls are best-effort after the safety checks pass. Confirm that billing has stopped and email support@stackjack.io immediately if a legacy or external subscription still appears active. The deletion flow does not call a payment-provider refund operation.

What each deletion result means

State you seeWhat it meansWhat to do
Awaiting email confirmationSupport recorded an email request and attempted to send the seven-day link to the organization's on-file owner address. This state means deprovisioning has not been authorized through that link; it does not prove that email delivery succeeded.Use the emailed link if it arrives. If it does not, contact Support to re-send or cancel the request. You can also use Cancel Request if the Team page offers it.
ProcessingThis customer-facing label covers two cases: a Portal request waiting for operator action, and a request whose deletion could not be finished automatically—a safety guard refused it, or the attempt failed—and which now waits for an operator. There is no automatic retry.Use Cancel Request only while it remains available. Wait for the completion email; contact Support if the status does not clear.
CompletedStackJack completed deprovisioning and attempted to send the owner a completion email.No further Portal action is available.
Could not start / failed before confirmationThe request or confirmation step was not accepted; the page states that deletion did not start.Retry only as directed, or contact Support with the displayed message.
Link no longer valid or already usedThe emailed token is expired, invalid, or consumed.Email Support to verify the request or obtain a new link.

Once deprovisioning completes, StackJack does not provide a recovery path and cannot turn the request into a cancellation. A deletion that could not be finished automatically—because a safety guard refused it or the attempt failed—waits for an operator to review and finish it; it is not retried on a timer. Contact support@stackjack.io for a status check, a blocked request, a link problem, or a billing concern.

What usage records contain

Every tool call your AI assistants make through StackJack writes one usage record. This is the canonical description of what that record holds. The usage pages under Usage, Limits & Troubleshooting link here rather than repeating it.

A usage record holds metadata about the call:

  • Which organization, which member or MCP client credential, and which connector.
  • The tool name, when the call ran, how long it took, and whether it succeeded.

A usage record does not hold the content of a successful call. StackJack does not write the request parameters your AI sent, and it does not write the response body the vendor returned. A successful call leaves the metadata above and nothing more.

A failed call additionally stores an error message, and that is different. The error message is the diagnostic text needed to tell you why the call failed, so it commonly includes text produced by the vendor's API. Read that honestly:

  • Vendor error text is not guaranteed to be free of your data. Vendors write their own error messages. A message can echo a value from the request, name a record, or quote a field, so it can contain customer names, email addresses, asset identifiers, or other details from your systems.
  • Recognized secrets are masked, and that is not the same as removing personal data. StackJack replaces values it recognizes as credential material — things named like client_secret, access_token, api_key, password and their common variants — with a redaction marker before the message is stored. That is a targeted defense against leaking credentials. It is not a general scrub of personal or customer information, and text the pattern does not recognize is stored as the vendor wrote it.
  • The stored message is bounded. It is truncated rather than kept in full.

The accurate summary for a compliance review is therefore "call metadata, plus a vendor error message on failures" — not "no customer data at all".

Who can see it. Usage records for your organization are visible to your own team on the usage and activity surfaces, and to StackJack staff during support work. Retention is covered in Usage Data Retention.

If a specific error message worries you, email support@stackjack.io with the connector, the tool name, and the time, and ask for that record to be reviewed.

Support diagnostics and privacy

Support diagnostics are a separate collection from usage records, and they are richer.

When they are collected. StackJack assembles a diagnostic report on the server when a support ticket is created for your organization. It happens for a ticket opened through the in-product Support widget and for a ticket an AI assistant files on your behalf. It is not a manual attachment you build and it is not something you upload.

What the default report contains. Organization and submitter identity, member and invitation details, permissions, subscription and recent usage information, credential validation state, MCP client metadata, and tool grants. Recent MCP server logs are collected separately when they are available. Connector secrets themselves are not part of the report — validation state is, the credential is not.

Who sees it and for how long. The report is meant for StackJack support staff working your ticket. It is not shown in your ticket conversation, and it is not returned to the AI assistant that filed the ticket. The people who can retrieve it are signed-in members of your organization, StackJack support staff, and your organization's current managing support partner, if you have one. Closing a ticket deletes its diagnostics. See Submitting a Support Ticket for the complete field, access, masking, and retention disclosure.

Automations have two separate opt-ins, and both are off by default. One controls whether an automation may file a support ticket at all when it hits an error. The other controls whether the identity detail is included in that ticket's diagnostic report. They are set per automation, they are independent, and neither is on unless somebody turns it on. See Guardrails and safety.

StackJack attaches a diagnostic report to the tickets described above, and this section is the notice. If you need to raise a ticket without a diagnostic report being assembled, say so in the ticket and ask support to remove it.