Back to home

Privacy Policy

How StaxQ collects, uses, and protects personal information worldwide.

Last updated: 22 August 2026

1. Who we are

StaxQ ("we", "us", "our") operates a web application for tracking bullion and numismatic holdings. This Privacy Policy applies to all users regardless of country of residence, unless local law requires additional notices.

2. Information we collect

Account data: email address, display name fields, country and currency preferences, subscription tier, and authentication metadata (e.g. last sign-in).

Encrypted vault data: holdings, purchase history, notes, and optional Pro attachments (one photo and one invoice/receipt per holding) are encrypted on your device in your browser before transmission. We receive and store only ciphertext (encrypted blobs) and related cryptographic metadata (such as salts and wrapped key material). We do not receive, store, or process plaintext ledger contents, vault decryption keys, passwords, or Recovery Keys.

Waitlist: if beta signup is full, we collect your email address to notify you when access opens.

Support & feedback: messages you send via in-app feedback or general contact (bug reports, feature requests, and general questions), including optional contact email and page context — not vault contents.

Technical & usage data: basic logs and product telemetry (e.g. signup country, account creation dates, tier changes, churn survey responses on delete). We do not sell personal information or use your holdings for advertising profiles.

Third-party API usage (metadata only): when you use features that query external services (e.g. market-data or sold-listing lookups), we may process search queries, marketplace identifiers, and aggregated results on our servers. Such requests do not include decrypted vault contents.

AI Vault Analyst (Pro): when enabled in your account, questions are parsed on your device — keyword rules and a small on-device model in a Web Worker. Your decrypted holdings, weights, purchase prices, photos, and computed totals are never included. StaxQ does not use OpenAI or any other third-party AI provider for this feature. Chat text is not sent to our servers by default; you may optionally share a typed phrase when the parser fails so we can improve it. You can disable the assistant in Menu → Pro & trading — when off, no parsing runs. See Help — AI Vault Analyst for a plain-language summary.

3. How we use information

  • Provide, secure, and improve the StaxQ service
  • Authenticate you and enforce Row Level Security on your account
  • Process subscriptions when billing is enabled
  • Respond to feedback and support requests
  • Send service emails (confirmation, password reset, waitlist updates)
  • Operate optional integrations with third-party data providers at your request
  • Comply with law and protect against abuse

4. Zero-knowledge vault architecture

StaxQ is designed around a zero-knowledge model for portfolio data:

  • Your holdings are encrypted client-side (in your browser) using keys derived from secrets only you control.
  • Our servers and database providers store unreadable ciphertext only — not the contents of your portfolio in plain form.
  • We cannot inspect, search, or export your individual holdings, photos, or notes without your password and Recovery Key (and we do not store those secrets).
  • If you lose both your password and Recovery Key, encrypted data cannot be recovered — by design.

What we can still see: account and billing metadata described in section 2 (e.g. email, tier, timestamps), encrypted blob sizes, and non-content telemetry. We treat that metadata as personal information and protect it accordingly — but it is separate from your encrypted vault contents.

See Security and Help — Privacy & Security for a plain-language summary.

Ask StaxQ (marketing site): the public help widget answers from curated Help, Trust, and Pricing content using keyword retrieval on StaxQ servers — not external AI. It cannot access your account or vault.

5. Processors & international transfers

We use third-party infrastructure providers (including managed database, authentication, hosting, email delivery, analytics, and payment processing when enabled). Optional features may call external APIs (e.g. spot price, FX, or marketplace data providers). Data may be processed in countries other than yours.

Providers are selected for security practices and contractual safeguards where applicable. Third-party providers may change their terms, regions, or availability; see our Terms & Conditions for how service changes may affect integrated features.

6. Retention & deletion

We retain account data while your account is active. You may delete your account and all associated data from the in-app Menu (Danger Zone). Deletion is permanent. Waitlist emails are retained until you unsubscribe or we remove them after a launch campaign.

Cached third-party API responses (where used) are retained only as long as needed to operate the feature and are not a copy of your decrypted vault.

7. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or export personal information we hold about you. Because vault holdings are encrypted with keys we do not possess, we cannot decrypt or export your portfolio contents on your behalf — you export from the app while signed in and unlocked.

To exercise rights relating to account metadata, use in-app account tools or contact us via Contact us. We will respond within reasonable timeframes required by applicable law (including the Australian Privacy Act and Australian Privacy Principles (APPs), GDPR, UK GDPR, and similar frameworks).

Australian users: you may complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled personal information. We encourage you to contact us first so we can try to resolve your concern.

8. Children

StaxQ is not directed at children under 16. We do not knowingly collect personal information from children. Contact us if you believe a child has created an account.

9. Changes

We may update this policy. Material changes will be reflected on this page with an updated date. Continued use after changes constitutes acceptance where permitted by law.

This document is provided for transparency and is not legal advice. If you need advice about your obligations, consult a qualified lawyer in your jurisdiction. Questions: contact us.