Privacy Policy
Last updated 10 Oct 2026
Information collection
We collect and use your personal information to deliver, improve, and ensure the safe operation of our Services. The types of information we may collect include:
Personal Identification Information: name, email address, company name
Agent Email Addresses: AI agents within our platform are assigned unique email addresses from the stdbl.com domain. These email addresses are used exclusively to identify AI agents, enable them to sign in, receive inbound emails, and use passwordless authentication. Only AI agents use this email domain, and it serves as a method to distinguish them from human users.
Usage Data: Information on how the Services are accessed and used, including your computer's IP address, browser type, browser version, our Service pages that you visit, the time and date of your visit, the pages visited, actions taken, and the duration of visits to those pages.
Use of data
We use the collected data for various purposes:
- To provide and maintain our services
- To notify you about changes to our Services
- To enable you to participate in interactive features of our services
- To provide customer support
- To gather analysis or valuable information so that we can improve our Services
- To monitor the usage of our services
- To detect, prevent, and address technical issues
Disclosure of data
Your privacy is important to us. We do not share, sell, or rent your personal information to third parties. Your data may be used to enable service providers (sub-processors) to perform functions and services on our behalf, such as hosting, authentication, browser automation, AI model inference, email delivery, payments, website analytics, and performance monitoring. The sub-processors we currently rely on are:
- Supabase – authentication, database, storage, and realtime
- Vercel – application hosting, edge delivery, and AI Gateway
- Amazon Web Services (AWS) – underlying cloud infrastructure for several of our sub-processors
- Cloudflare – network, edge, and inbound email handling
- Google Cloud – Vertex AI model hosting and Google sign-in
- Google Analytics (Google LLC) – website traffic measurement on stuntdouble.io and index.stuntdouble.io, processing page views, device and approximate location data, and cookie identifiers on our behalf (see Website Analytics below)
- Google Ads (Google LLC) – measuring which of our ads lead to sign-ups, and showing our ads to past visitors, unless you turn advertising cookies off (in the EEA, the UK and Switzerland, only if you allow them; see Website Analytics below)
- Anthropic and OpenAI – AI models that power our agents (Anthropic models are accessed via Google Vertex AI)
- Browserbase – hosted browser sessions used by our AI actors
- Trigger.dev – background task and workflow orchestration
- Resend – transactional and notification email delivery
- Stripe – billing and payment processing
- Opinly – blog content management, and first-party analytics across our website and the product (see Website Analytics below)
- GitHub, Figma, Linear, and Slack – optional integrations you choose to connect (see Third-Party Integrations below)
These parties are obligated not to disclose or use your data for any purpose other than providing their services to us. Where a sub-processor is located outside your region, transfers are made under appropriate safeguards.
Third-party integrations
Some features let you connect Stunt Double to third-party accounts. Connecting an integration is always optional and initiated by you. We request only the minimum OAuth scopes needed for the feature, access only the data those scopes permit, use it solely to provide the functionality you have requested, and never sell it. You can revoke access at any time from your connection settings or from the provider directly, after which we stop accessing new data.
- GitHub – your basic profile, email address, and the repository content you authorise, so actors can review and work with your code.
- Figma – your profile, file metadata and content, and file comments, so actors can test and comment on your designs and prototypes.
- Linear – read and write access to issues and comments, so we can create and update issues on your behalf.
- Slack – reading and posting messages in the channels you authorise, so we can deliver notifications and respond to mentions.
- Vercel – project and deployment metadata for the Vercel Marketplace integration, used for provisioning and billing.
We also support passwordless sign-in with Google, GitHub, and Figma, which shares only the profile and email information needed to create and authenticate your account.
AI assistants and the MCP server
You can connect Stunt Double to an AI assistant such as Claude, Claude Code or Cursor through our Model Context Protocol (MCP) server at app.stuntdouble.io/api/mcp. The connection is always initiated by you, and you sign in and approve it on a Stunt Double consent screen that names the access requested.
- What it can reach – the connection acts as you and reaches only the workspaces you are a member of, limited to the scopes you approve: read, write, and starting runs.
- What we receive – the arguments the assistant passes to each tool call (for example a checklist name or a URL to test) and the access token that identifies the connection. We do not receive or read the rest of your conversation with the assistant, its memory, or its files.
- What we store – anything a tool call creates (projects, actors, checklists, runs, interviews, feedback updates) is saved to your workspace and treated like the same content created in the dashboard. For each connection we keep a hashed copy of its access token, the client it was issued to, the scopes you approved and when it expires.
- What we return – tool results are sent back to the assistant you connected. How that assistant stores them is governed by its provider’s own privacy policy.
You can disconnect at any time in your assistant, which removes its copy of the token. To revoke a token on our side before it expires, open your account settings, choose Security, and remove it under Connected apps.
Figma plugin
When you use the Stunt Double plugin in Figma, we receive what you choose to send: an image of the frame you select, the frame, page and file names, any instructions, feedback text or questions you write, and, if you paste one, the file’s Figma link. Frame images are stored in your workspace and deleted on your plan’s retention schedule.
The plugin signs in with an access token that lasts 90 days. Once the plugin has picked it up we store only a hash of it (the token itself is held for at most 15 minutes while you approve the connection), and you can end it at any time by signing out in the plugin or revoking it in Settings. The plugin saves the project this file is linked to, and which frame each review looked at, inside the Figma file itself so collaborators land in the same place. We do not read any other part of your Figma files through the plugin.
Website analytics
Our public websites (stuntdouble.io and index.stuntdouble.io) use Opinly for first-party analytics, and stuntdouble.io uses it to publish part of our blog. The Opinly analytics are first-party: the data is ours, and no third-party advertising network sits in the middle.
On our public websites the Opinly pixel follows the same rule as Google Analytics below: in the EEA, the UK and Switzerland it only loads if you allow analytics in the cookie banner, and elsewhere it loads unless you turn analytics off. You can change this at any time from Cookie settings in the footer, and turning it off also deletes the identifiers it stored. When it is on, Opinly records:
- Page views and client-side navigation, along with the page path and title, your screen and viewport size, browser language, and timezone
- Clicks on links and buttons, and the fact that a form was submitted, including the names of the fields in that form but never the values you typed into them
- How you arrived: the referring site, any campaign (UTM) tags, and any advertising click identifier in the URL
- A two-letter country code derived from your IP address at the network edge. The IP address itself is not stored
- An anonymous visitor identifier, held in your browser’s own local storage rather than in a cookie, so that repeat visits can be recognised
Email addresses. If you enter your email address into a form on our website, it is sent to Opinly and stored only as a SHA-256 hash; the address itself is never written to disk there. The hash lets us connect an enquiry to the visit that produced it. Because the hash is deterministic, we treat it as pseudonymised personal data rather than anonymous data, and it is covered by the data protection rights set out below. Password fields and hidden fields are never captured, and no other value you type is ever read.
Enquiries. When you submit our feedback or contact form, we record the fact that an enquiry was received (together with the enquiry type and the page you sent it from) so we can tell which parts of our site are useful. The content of your message is not sent to Opinly.
Inside the product. The same analytics run on the signed-in product at app.stuntdouble.io, so that we can tell which of our marketing actually leads to people using and paying for the Services. When you are signed in we link your visit to your account using your email address, which is stored as a hash as described above, and your user identifier. When a subscription payment succeeds we record the amount, the currency and the transaction identifier so that revenue can be attributed to the campaign that introduced you. We do not send the content of anything you create in the product, your actors, checklists, interviews, runs or results, to our analytics provider. Signing in to index.stuntdouble.io links your visit to your account in the same way.
Google Analytics. Our public websites, stuntdouble.io and index.stuntdouble.io, and the product at app.stuntdouble.io also use Google Analytics, provided by Google LLC, to measure aggregate traffic. Google acts as our data processor: it processes this data on our instructions and only to provide the analytics service to us. In the European Economic Area, the United Kingdom and Switzerland, or when we cannot tell where you are, Google Analytics only sets cookies if you allow it in the cookie banner. Until then, and if you decline, it receives cookieless signals only (Google’s consent mode), with no identifier that could recognise you on a later visit. Everywhere else, it is on by default and no banner is shown, and you can turn it off at any time. We work out which applies from your approximate location and keep only the result, not the location, for a day in a cookie named sd_consent_region. Your choice is kept for a year in a cookie named sd_consent, shared by all three, and you can change it at any time from Cookie settings in either public site’s footer or in your account settings in the product; declining also deletes the Google Analytics and Google Ads cookies already set. When it is on, Google Analytics records:
- The pages you view, how long you stay, and scrolls, outbound clicks and downloads
- How you arrived: the referring site and any campaign (UTM) tags in the URL
- Your browser, operating system, device type, screen size and language
- Your approximate location (country, region and city), derived from your IP address. Google Analytics does not log or store the IP address itself
- A randomly generated identifier kept in first-party cookies (
_gaand_ga_*, which last up to two years) so that repeat visits can be recognised
Advertising. The same choice covers advertising cookies. We advertise on Google, and when they are on, Google Ads can set its own first-party cookies (_gcl_*) and use your visit, through our Google Analytics property, to tell us which ads lead to sign-ups and to show our ads to people who have visited our websites. We do not use them for any other kind of profiling, and we do not sell your data. If you arrive from one of our ads, the ad’s click identifier travels with you to app.stuntdouble.io so that a sign-up can be credited to the ad that led to it. You can also manage how Google personalises ads at My Ad Center.
On the signed-in product at app.stuntdouble.io, we do not send Google Analytics your name, email address in plain text, or anything you type into a form. The data may be processed by Google in the United States and other countries where Google operates, under the safeguards described in Disclosure of data above. We keep event-level Google Analytics data for no longer than 14 months, after which only aggregated reports remain. Google’s own handling of this data is described in How Google uses information from sites that use its services. You can block the cookies in your browser settings, or opt out of Google Analytics on every site with Google’s browser add-on.
Data retention
We keep your account and workspace data for as long as your account is active, so the Services can show you your history, runs and reports. Archiving a project hides it but does not delete it.
An archived workspace is kept for 90 days, so it can be restored, and is then deleted with its content and files. We email the workspace owner at least seven days before that happens. An account that belongs to no workspace is deleted after a year without a sign-in, or 30 days after sign-up if it was never used. An account whose email address is never verified is deleted seven days after sign-up, with the workspace created for it.
Run captures (screenshots, recordings and interview videos) are kept for the history window of your workspace’s plan, as shown on our pricing page, plus seven days, and are then deleted automatically. The results, findings and transcripts of those runs are kept. Enterprise plans keep captures for as long as the account is active.
Feedback comments left on your projects, with their replies and screenshots, are kept for the same window, counted from the latest comment in each thread, plus seven days. They are then archived and hidden, and upgrading brings them back. Archived comments are deleted automatically 30 days later, and we email the workspace owner at least seven days before that happens. Enterprise plans keep them for as long as the account is active.
When you ask us to delete your account or a workspace, we delete the associated personal data and workspace content, except where we must keep a record to meet a legal, tax or accounting obligation (such as invoices), to resolve a dispute, or to enforce our agreements. You can delete your account yourself from your account settings: you are signed out straight away, and your account, and any workspace only you belong to, are deleted within a day. Content you created in a workspace you share with others stays with that workspace. MCP access tokens expire automatically and can be revoked sooner. Website analytics collected by Google Analytics are kept for no longer than 14 months. To request deletion another way, email us at the address in Contact us below.
Security of data
The security of your data is important to us. We ensure that our security controls and policies align with recognised industry frameworks such as ISO/IEC 27001:2022, NIST Cybersecurity Framework (CSF), or equivalent. Where such frameworks are not explicitly adopted, we demonstrate comparable security maturity.
While we strive to use commercially acceptable means to protect your personal information and implement robust security controls, no method of transmission over the Internet or method of electronic storage is 100% secure. We adopt a zero trust approach to security and minimise the amount of data we store.
Compliance
We shall at all times throughout the term of any agreement comply with information security requirements and other applicable security legislation (including, but not limited to intellectual property, cryptography restrictions, and retention of records) and shall:
- Not be entitled to use information except to the extent strictly necessary to perform our obligations under any agreement;
- Not provide information to any unauthorised third party; and
- Upon request, provide evidence of the existence, adequacy, and effectiveness of the controls implemented to comply with any agreement.
When available, we provide regularly to customers an internationally recognised type of report (as prescribed, for example, by ISO 27001, PCI DSS, ISAE 3402, SSAE 16) issued by an independent party, providing assurance that we have appropriate and effective security controls in place. This may also include SOC 2 Type II, ISO 27701 (privacy management), or ISO 22301 (business continuity), where relevant and available from our suppliers.
Security incident management
A Security Incident is defined, with respect to information and services, as any event leading to or reasonably likely to lead to:
- Information loss;
- Information corruption;
- Unauthorised access to systems storing or processing information;
- Unauthorised access to physical locations storing or processing information;
- Negligence or gross misconduct of any employee who had access to information or services;
- Outage due to DDoS and other mass attack events; or
- Any other security event relating to information that could damage or harm business operations, legal/regulatory compliance, or reputation of customers.
If at any time we suspect or have reason to believe that a Security Incident has occurred impacting customer information or services, we shall:
- Notify customers of the Security Incident as soon as it is reasonably practicable (and in any event within 48 hours) and thereafter provide customers as soon as possible with the available details of the Security Incident. Subject to our legal obligations, we shall not report any Security Incidents relating to information to any authority without consultation with customers.
- In consultation with customers, take all reasonable steps necessary to mitigate the consequences of the Security Incident or (if applicable) to protect against a threatened Security Incident.
- Notify customers of the progress, closure of the Security Incident, and remedial action we propose to take to prevent any similar Security Incident occurring in the future.
Your data protection rights
Under data protection laws, you have rights, including:
- The right to access – You have the right to request copies of your personal data from us.
- The right to rectification – You have the right to request that we correct any information you believe is inaccurate or incomplete.
- The right to erasure – You have the right to request that we erase your personal data, under certain conditions.
- The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.
- The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.
- The right to data portability – You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Changes to this Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes.
Contact us
If you have any questions about this Privacy Policy, please contact us:
Email: hello@stuntdouble.io
Address: 66 Paul Street, London
This Privacy Policy forms part of our Terms of Service and should be read in conjunction with them. By accessing or using our Services, you agree to the collection and use of your information in accordance with this Privacy Policy.