| Microsoft Azure regional stores — core StackJack hosting | Tenant database rows, cached state, ticket and diagnostic blobs, raw knowledge-upload blobs, opt-in automation evaluation fixture and scenario blobs, and tenant secrets are stored in the organization's assigned region. Evaluation fixtures can contain canonical tool arguments and scrubbed JSON read-response bodies or write-response skeletons; a non-JSON body can remain verbatim after the fixture scrubber runs. | US home: East US. EU home: Sweden Central. Retention rules vary by feature; see Usage Data Retention and Customer Data & Privacy. |
| SendGrid — transactional email delivery and invite-delivery diagnostics | When StackJack sends tenant, support, partner-provisioning, billing, migration, or deletion email, it transmits the recipient address and name, the subject, the rendered plain-text and HTML content, embedded action links, and any reply-to or header metadata. A deletion-confirmation message contains the organization name, the expiry, and the full single-use confirmation link. The Team invite-delivery diagnostic also queries SendGrid Email Activity with a normalized recipient address and reads matching message subjects, delivery status, and last-event time. | SendGrid processes and retains this email under its own terms. |
| Featurebase — support ticketing, product feedback, and changelog delivery | Support conversations are exchanged with Featurebase: ticket subject and body text, support replies (including internal notes drafted with AI assistance), and your contact identity (name, email, organization) are transmitted and stored there, and attachments submitted through the support widget are uploaded to it directly. A nightly directory sync also registers every active organization as a Featurebase company (name, organization identifiers, plan, region, billing customer ID, an estimated monthly spend figure, and the organization's creation date) and every active member as a contact (user ID — or email for an invited user who has not signed in yet — plus email, name, region, and organization ID), whether or not anyone ever contacts support. The support and feedback widget loads on every signed-in Portal page and sends a signed identity payload (user ID, email, name, profile picture, roles, and company) wherever it loads. Changelog publishing sends release-note content; StackJack always disables Featurebase's subscriber emails on publish. | Featurebase processes and retains this data under its own terms. |
| Anthropic — support-AI research, drafting, and refinement | This does not run automatically. Creating a ticket or replying to one sends nothing to Anthropic. A run happens only when StackJack support staff deliberately start one — from the support console, a support-workflow action, or StackJack's operator tooling — or when a partner escalates a managed ticket. When a run does happen, StackJack sends the ticket subject and customer text plus selected evidence. Evidence can include tenant diagnostics, relevant product documents and past tickets, Sentry and Azure Monitor results, and billing context. Draft refinement can send the current draft, the support engineer's refinement instruction, distilled corrections or feedback, and supporting evidence. | Anthropic processes and retains this data under its own terms. This is a StackJack support path, separate from your own automations' Anthropic workspace. |
| Anthropic — automation builder, AI assist, and token counting | Wizard turns send the conversation history and latest user message, the current draft and readiness state, the plan-visible tool catalog and metadata, and—when available—recent run status, tool sequence, and cost. AI-assist sends either the automation description plus tool names or the full system prompt, depending on the requested suggestion. Token counting sends the selected model, full system prompt, and messages. The builder also runs live tool tests against your real connectors, and their results go to Anthropic. During an interview the model can execute eligible read-only tools against your live connector credentials — real systems, real data, capped per interview — and up to 4,000 characters of each raw result is placed into the conversation for later turns. So genuine ticket, asset, device, and client data from your own systems can reach Anthropic through the builder, not only text you typed. Write and destructive tools are never executed during an interview. | These calls use StackJack's own Anthropic key even when you have BYOK, and they cost you zero credits in BYOK mode. Anthropic processes and retains this data under its own terms. |
| Anthropic — tenant automation agents | Provisioning sends the agent name, description, model and effort, composed system instructions, enabled native and MCP tool configuration, StackJack MCP endpoint, restricted environment host, and a StackJack MCP bearer credential stored in the Anthropic vault. Instructions can contain tenant-authored prompt text, tool policy and chains, knowledge display names, full source URLs, fetched URL text, and server-extracted text from uploaded files. Each run sends agent and task context, current time and dry-run instructions where applicable, user or default context or the webhook body, and only the outputs of preparation gathers bound to that run. Managed-agent native and MCP tool arguments and results, model responses, session events, and the full session transcript pass through Anthropic; post-run verification results are evaluated outside that session and are not sent as run input. If memory is enabled, memory-store identifiers, paths, content, and version operations are also handled there. StackJack does not inspect or sanitize the contents written to the Anthropic memory store. | Anthropic processes and retains this data under its own terms. Anthropic keeps the full session transcript and StackJack fetches it live. StackJack's regional store does not hold the full transcript or full tool-result bodies, but it does hold a filtered trigger payload, session ID and provenance, summary, error and usage, pending tool input, and transcript-derived tool names, bounded arguments, order, and status. The raw bytes of uploaded knowledge files remain in the regional blob store; StackJack sends extracted text, not those raw bytes. Raw connector credentials remain in StackJack, but tool exchanges can contain provider data. With BYOK, managed agent, environment, vault, session, transcript, and memory resources use your own Anthropic account, workspace, and key; the payload categories do not change. Normal automation deletion archives sessions and memory, while hard memory erasure is a separate operation. BYOK migration copies memory into the new workspace and then archives the old store. |
| TypeSafe AI — fast decisions (typed judgements) | A second AI vendor, separate from Anthropic and used for short typed judgements rather than generated text. Five paths send it data. Decision steps: when an automation's fixed start steps include one, StackJack sends that step's composed state, which can carry the run's trigger payload and the results of earlier gather steps, plus the author's own question text. Smart filters: when a webhook trigger carries one, StackJack sends the automation's filtered trigger payload — the same payload the run would have received, never the raw body — for every inbound delivery. Smart tool search and tool suggestions: your search text, plus tool and connector names and short tool descriptions. Support AI: the ticket text and classification context, on the same deliberate-trigger rule as the Anthropic support path above. The automation builder assistant: the conversation transcript, to repair a field the text model left blank or invalid. Answers are probabilities and short typed values, not generated prose. | TypeSafe AI processes and retains this data under its own terms. It is hosted outside the European Union. Organizations with a US storage home use it by default. Organizations with an EU storage home must opt in per organization — until they do, nothing is sent on any of these paths and each feature behaves the way it did before fast decisions existed; see Fast Decisions and Your Own TypeSafe Key. An organization can supply its own TypeSafe key, which changes the account the decision-step and smart-filter calls are made on but not what is sent. StackJack's own regional store keeps a record of each call — the surface, the organization, timing, token counts and the outcome — and, for decision steps and smart filters, the judgement itself so a restarted run replays it. |
| Zitadel — identity and access | StackJack's management client sends organization names and IDs, user names, email addresses, user IDs, and roles for organization and user provisioning, invitations and password setup, and ownership and role management. Sign-in itself happens on the identity provider's own hosted pages through OIDC, so the session and authentication-factor data in that flow is handled by the provider rather than by StackJack. | The identity provider processes and retains this data under its own terms. |
| Cloudflare Turnstile — signup abuse protection | Completing the signup challenge runs on Cloudflare's widget, and StackJack's server-side verification then sends the challenge response token and the signup request's IP address to Cloudflare. This happens at signup only. | Cloudflare processes and retains this data under its own terms. |
| Sentry — application error and performance telemetry | StackJack's Portal, MCP server, automation runner, and operator console send application telemetry to Sentry. Errors, traces, logs, tags, correlation IDs, tenant IDs, and surrounding application context can be transmitted when captured. Support AI can query Sentry events scoped to your organization or to a correlation ID as evidence. | Sentry processes and retains this telemetry under its own terms. |
| Discord — staff support notifications and release notes | When a ticket is filed through an AI assistant or a support reply is posted, a notification is sent to StackJack's staff Discord channel carrying the ticket subject, up to the first 1,024 characters of the message or description, the organization name, the requester's email address, priority, status, and the ticket ID. Release-note publishing posts patch-note content, which carries no customer data. | Discord processes and retains this data under its own terms. |
| Azure Monitor / Log Analytics — optional support evidence | Support AI can read error and run-failure logs scoped to your organization as evidence. This evidence source is off by default. | Microsoft processes and retains this data under its own terms. |
| OpenTelemetry destination — application telemetry | StackJack exports application logs, traces, and metrics to an OpenTelemetry destination only when one is configured. | The destination service processes and retains this telemetry under its own terms. |
| Paddle — current subscription and payment processing | Checkout, customer and subscription management, transactions, invoices, and webhooks exchange billing identity, price, payment, subscription, and transaction and event data. Support AI can read matching Paddle event history as evidence. | Paddle processes and retains this data under its own terms. |
| WooCommerce — legacy subscription handling | StackJack still reads, reconciles, and attempts cancellation of linked legacy WooCommerce subscriptions, which involves tenant and subscription identifiers and billing state. | WooCommerce processes and retains this data under its own terms. |