Last updated: August 4, 2026
Your stack is nobody's business but yours.
We built Stackore because we stack too — and we know exactly how uncomfortable it is to type what you own into someone else's app. So we designed it to hold as little about you as possible, and to lock down everything it does hold.
What we collect: your email address, a display name you choose, and the holdings you choose to enter.
What we never collect: your home address, your phone number, your age, your location, your Social Security number, your bank or brokerage accounts, photos of your holdings, or your contacts.
We do not sell your data. We do not share it with advertisers. We do not run ads.
We are not a broker. We never touch your metal and we never touch your money. Stackore is a ledger you control — nothing more.
Everything below lives in your account and is visible only to you.
We want to be specific, because "we respect your privacy" is easy to say and hard to prove.
One exception, clearly stated: if you earn a physical reward through our referral program, we will ask you separately for a shipping address so we can mail it to you. That address is collected only from winners, only for shipping, and is deleted once your reward is sent. It is never stored in the app.
If you enable the optional Face ID lock, biometric authentication is handled entirely by your device's operating system. Your biometric data never leaves your device and is never accessible to us.
Security isn't a paragraph we added at the end. It's the reason the app is built the way it is.
Row-level security on every single table. This is the important one. Every table containing user data — your holdings, your stacks, your history, your alerts, your transactions — enforces access rules at the database level itself, not just in the app. The database is physically incapable of returning another user's data to you, or yours to them, even if someone found a flaw in the app. Access control lives in the deepest layer, not the outermost one.
Nothing user-related is publicly accessible. We regularly audit this. The only publicly readable data in our entire system is the live spot price feed, which is identical for everyone and contains nothing about you.
Encrypted in transit and at rest. All traffic between your phone and our servers is encrypted with TLS. All data stored on disk is encrypted at rest by our infrastructure provider.
Passwords are hashed, never stored. We cannot read your password. If you ask us what it is, the honest answer is that we don't know.
Continuous security auditing. We run automated security advisors against our database on an ongoing basis, checking for exposed tables, missing access controls, and misconfigured permissions. As of the last review, there are zero critical findings.
Built by someone who takes this seriously. Stackore's developer works professionally as an engineering contractor on government systems, and has been running versions of this app for his own stack since 2020. The security posture here reflects that background.
We'd rather answer this plainly than let you wonder.
Assume the worst — someone gets a complete copy of our database. Here is the entirety of what they would learn about you:
An email address, the display name you chose, and a list of items with quantities.
They would not learn your address. They would not learn your phone number, your city, your state, or your country. They would not find a photo of your holdings or a clue about where you keep them. There would be no serial numbers, no safe or vault details, no shipping records, no purchase receipts tied to a merchant, and no location data of any kind — because none of that exists in our system to take.
This is the single most important design decision in Stackore, and it was deliberate. The most effective protection against data being stolen, subpoenaed, or leaked is not holding it in the first place. Every field we chose not to add — and every field we've since removed — is a field that cannot be turned against you later.
Being straight with you about the limit: an email address is not nothing. If you use an email that identifies you publicly, that email is a thread someone could pull on using sources that have nothing to do with us. If that concerns you, use an address that isn't tied to your name — a free alias, or Apple's Hide My Email. Stackore works exactly the same either way, and we will never ask you to verify who you really are.
We think you deserve specifics rather than reassurance here.
Where your data lives. Our database is hosted in the United States and is therefore subject to United States legal process. We are not going to claim otherwise, or imply that a foreign jurisdiction or clever corporate structure puts your data beyond the reach of a lawful order. Any company telling you that is selling you something.
What we would be able to hand over. Only what we hold: an email address, the display name you chose, and a list of items. We could not produce a home address or a location, because we have never collected them.
What we commit to.
The honest caveat. No policy document overrides a lawful court order, and we won't pretend ours does. What a policy can do is guarantee there is very little to give — and that part is already true and already built.
We keep this list as short as we can.
That's the entire list. We have no advertising partners, no data brokers, and no analytics resale arrangements. We have never sold user data and we will not.
Stackore is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we'll remove it.
If we ever change what we collect or how we protect it, we'll update this page and change the date at the top. If the change is significant, we'll notify you in the app rather than quietly editing this page.
Questions about privacy, security, or your data — or a security concern you'd like to report — reach us at:
We answer security questions directly and take reports seriously. If you've found something, please tell us.