Privacy Policy
Last updated: February 27, 2026
What we collect
Stockyard collects the minimum data necessary to provide our services.
Self-hosted (Community & Pro): We collect nothing. The binary runs entirely on your infrastructure. No telemetry, no phone-home, no analytics. Your LLM traffic, API keys, prompts, and responses never leave your machine.
Cloud tier: When you sign up for Stockyard Cloud, we collect:
- Email address (for account management and communication)
- Organization name (for your workspace)
- Payment information (processed by Stripe; we never see or store your full card number)
Website: stockyard.dev does not use cookies, tracking pixels, or third-party analytics. We use basic server-side request logs (IP, timestamp, path) for operational monitoring, retained for 30 days.
How we use your data
Cloud tier data is used solely to operate your Stockyard Cloud instance, send transactional emails (receipts, security alerts), and respond to support requests. We do not sell, share, or monetize your data in any way.
LLM traffic
Whether self-hosted or on Stockyard Cloud, your LLM requests and responses pass through the Stockyard proxy to your configured providers. Stockyard Cloud stores trace metadata (model, token count, latency, cost) per your retention settings. Prompt and response content is stored only if you explicitly enable it in Observe settings. You can delete all trace data at any time via the API.
Provider API keys
API keys you configure for LLM providers (OpenAI, Anthropic, etc.) are encrypted at rest using AES-256-GCM. On self-hosted deployments, keys are stored in your local SQLite database. On Cloud, keys are stored in encrypted storage with per-tenant isolation.
Data retention
Cloud tier data is retained according to your plan: 7 days (Community), 30 days (Cloud), unlimited (Pro self-hosted), or per your agreement (Enterprise). You can export or delete your data at any time. Upon account deletion, all data is purged within 30 days.
Third parties
We use Stripe for payment processing and Railway for Cloud infrastructure hosting. We do not share data with any other third parties. We do not use any advertising networks or data brokers.
Security
Stockyard Cloud uses TLS for all connections, encrypts sensitive data at rest, and maintains a hash-chained audit ledger (the Trust app) for tamper-evident logging. If you discover a security vulnerability, please report it to security@stockyard.dev.
Changes
We may update this policy as our services evolve. Material changes will be announced via email to Cloud users and posted to our changelog. Continued use after changes constitutes acceptance.
Contact
Questions about privacy? Email privacy@stockyard.dev.