MARSHAL STACK How it runs Console Studio · soon Docs ENRURO Contact

← Marshal Stack

Privacy Policy

Last updated 23 September 2026

Marshal Stack is a monitor for the things you have shipped: your apps in the stores, the sites and APIs behind them, and the servers you run. The app talks to exactly one server — our relay at relay.marshalstack.com, hosted in the EU — over TLS. This page lists everything that server keeps about you and how to remove it.

What we store

Nothing is stored until you sign in. In demo mode the app makes no network request at all — everything on screen is sample data inside the app. Once you sign in with GitHub, the relay keeps:

  • Your account — your GitHub user id and login, which name the account; a random device token for each phone or computer you sign in from; on iOS, a push notification token.
  • What you connect — the GitHub repositories you bring in, the projects you build from them, their website and backend addresses, the tasks and activity that come from your issues and boards, and the servers you enrol: their names, CPU, memory, disk and load, the names of the heaviest processes and the ports they open. Never file contents, never command lines, never environment variables — unless you switch the night watch on yourself, see the next line.
  • Store keys, if you add them — an App Store Connect API key or a Google Play service account. They are secrets: they stay on the relay, are never shown again, and are used only to read your own apps' ratings, reviews and release state with the official Apple and Google APIs.
  • The night watch, if you switch it on — off by default on every server. When you turn it on for one server, you approve a fixed list of read-only commands (free space, heaviest processes, failed services, the service journal and system journal around the failure). The relay never sends a command line: it names an operation, and the agent on your machine builds the command itself. Passwords, keys, tokens and e-mail addresses are scrubbed on your machine before anything is sent; what is collected is kept 30 days and goes the moment you delete the server. The verdict is made by rules on the relay — no logs are sent to any AI model.

All of it belongs to the account that created it. The relay filters every request by account, so no other user can read, list or change your rows.

What we do not collect

The app contains no analytics, advertising, attribution or crash-reporting SDKs and no third-party trackers. It does not read your location, contacts, photos, health data or microphone, and it does not track you across other apps or sites. No data is sold, and none is shared for advertising.

Who else sees data

Only the services you connect yourself, and only with your own credentials: GitHub (sign-in and the repositories you choose), Apple's App Store Connect API and Google's Play Developer API (your own app data, read with your keys), Apple Push Notification service (alerts on iOS). The optional autonomous-agent feature sends the task you dispatch to Anthropic's Claude; the monitor itself sends nothing to Anthropic. The studio page has a form that asks for an email address; if you submit it, that address is stored on the relay so we can write back, and for nothing else — ask us and we will delete it.

Log out and delete

Both are inside the app, under Settings → Account. Log out removes this device from the relay and clears the local token; your account and its data stay, and you can sign back in with GitHub. Delete account permanently removes the account and every row that belongs to it — devices, GitHub connections, store keys, projects, tasks, activity, runs, health checks, budgets and servers — immediately and irreversibly. Step-by-step instructions: Delete your account.

On your device

The only thing the app stores locally is the device token, in the system keychain (iOS) or encrypted preferences (Android), excluded from backups. Deleting the app removes it.

Retention

Data is kept for as long as the account exists and is deleted the moment you delete the account. The relay takes a nightly backup of its database for disaster recovery, kept for 14 days on our own servers in the EU and never restored except to recover from a failure — so a deleted account can survive in those copies for at most 14 days. What the night watch collected is kept 30 days and then erased, whatever happens to the account. The relay keeps no request logs that contain tokens or personal data.

Children

Marshal Stack is a developer tool and is not directed at children under 13.

Changes

If this policy changes, the updated version will be posted on this page with a new date above.

Contact

Questions: [email protected]

© 2026 Marshal Stack
Studio · soon Docs Privacy Terms Contact