Legal
Privacy Policy
TechStack is an iPhone app for mapping software projects, storing credentials, and tracking infrastructure cost. This policy describes what the app stores and what it does not.
Who we are
TechStack is published by Nutiverse. Questions: use the Support page.
What TechStack stores
All of the following is created by you and stored on your device (and, if you turn iCloud sync on, in your iCloud account):
- Project names, notes, tags, and architecture
- Service catalog entries and how they connect
- Encrypted credential values and related metadata (name, service, expiry)
- Cost amounts, currencies, and payment history
- App preferences such as Face ID lock and MCP pairing
TechStack does not require an account. There is no TechStack server that receives your projects, secrets, or costs.
Encryption and Face ID
Credential values are encrypted on the device with AES-256-GCM before they are saved. The encryption key is kept in Keychain and can sync through iCloud Keychain so your other devices can decrypt the same data. Face ID, if you enable it, only unlocks the Credentials tab — it is not sent anywhere.
iCloud
iCloud sync is optional. When it is on, CloudKit transports project data using your Apple ID. Encrypted credential blobs stay encrypted in transit. Apple’s iCloud terms apply to that sync.
Local MCP server
If you enable AI Assistant Access, TechStack runs an MCP server on your local network while the app is in the foreground. A client you pair (for example Claude Code on the same Wi-Fi) can manage projects, services, and costs. MCP tools can see names, tags, and similar metadata. They cannot read decrypted credential values. The pairing token stays on the device until you regenerate it.
Advertising (AdMob)
The free version of TechStack may show a Google AdMob app-open ad when you open the app. TechStack Plus removes ads.
Google may collect device and advertising identifiers, coarse location, and interaction data to serve and measure ads, subject to your consent (Google UMP) and Apple’s App Tracking Transparency prompt. We do not send your projects, credentials, costs, or MCP data to Google for advertising.
You can manage ad privacy from Settings when Google requires a privacy-options entry point, limit tracking in iOS Settings, or remove ads with TechStack Plus.
Google’s policies: https://policies.google.com/privacy and https://support.google.com/admob/answer/6128543
Analytics and crash reports
The app uses Firebase Analytics and Firebase Crashlytics so we can see aggregate usage and fix crashes. These SDKs run on the device and talk to Google. They do not receive your project names, credential values, costs, or MCP traffic.
What we do not collect
We do not sell data. We do not use your stack or secrets to train models. There is no TechStack account and no TechStack server that stores your projects.
Notifications
Expiry reminders for credentials are scheduled locally on the device.
Your choices
You can export data, turn iCloud sync off, regenerate the MCP token, or delete the app. Deleting the app removes on-device data. iCloud copies remain in your iCloud account until you delete them there.
Children
TechStack is not directed at children under 13.
Changes
If this policy changes, the date at the top will be updated.