Privacy
StackSignal by Compound 30™ · not affiliated with Substack · Last updated 7 October 2026
Who is responsible
A Roll Media (FZE), Sharjah, United Arab Emirates, is the controller of your personal data for StackSignal. Contact: hello@compound30.com.
The short version
- We collect only what StackSignal needs to run your dashboard.
- Your private numbers are shown only to you. We never sell your data, show ads, build advertising profiles or use your data to train AI models.
- You can delete your account and all your data yourself, any time, in Settings → Account → Delete my account and data. See Data deletion.
What we collect
- Account: your email address, sign-in times, and the consent you gave to join the Compound 30 Substack. If you sign in with Google, Google tells us only your verified email address and an account ID that links your Google sign-in to your StackSignal account. We don't receive your name, photo, contacts or Gmail.
- Billing: your Stripe customer and subscription status. Card details go straight to Stripe and never touch our servers.
- Handles you add: your Substack, LinkedIn and Instagram handles and up to 5 competitor handles per platform.
- Public data: public profile counts, posts, Notes and engagement for those handles. We fetch it from public pages, in part through Apify. For competitors this is public counts and public posts only.
- Stats you enter or upload: numbers you choose to add from your own stats (revenue, views, open rate, new subscribers, podcast plays) and any screenshot of your own stats page you attach, which is kept private to you.
- Accounts you connect (only if and when you choose to): if you connect an account through the platform's own sign-in screen, we receive a secure access token and read only the data you approved on that screen. See “Accounts you connect” below.
- Subscriber CSV (optional): if you upload your Substack subscriber export, your browser reads it on your device. Raw email addresses never reach us. We keep totals, monthly join counts, the display names of your top 20 most engaged readers and of up to 50 recent joiners, each with their paid status and activity stars (or a masked email like “q•••@gmail.com” when there's no name), and a fingerprint of each email scrambled with a key unique to your account so your next upload can count who left. We keep only your two latest uploads, and you can remove them any time in Settings. You decide whether to upload; you're responsible for having your readers' data lawfully.
- Goals and settings: your weekly goals and whether you hit them, your time zone and your display choices.
- Security logs: IP address and browser details for sign-in protection and rate limiting.
Accounts you connect
StackSignal may let you connect your own Instagram, LinkedIn or Stripe account so your numbers update by themselves. This is always your choice, and you approve exactly what is shared on the platform's own screen before anything reaches us.
- Instagram (Business or Creator accounts): your account ID and username, follower counts, views, reach and interactions on your posts, stories and reels, and aggregated audience information that Instagram provides, such as top locations and age ranges. We do not read your messages, comments, contacts or anything you didn't approve.
- LinkedIn: impressions, reactions, comments, shares and follower figures for your own posts and profile, as LinkedIn provides them.
- Stripe (read-only): revenue totals and paid-subscription counts from the Stripe account that receives your Substack payments. We cannot move money, refund, or change anything in your Stripe account.
What we do with connected data: show it to you, and only you, in your dashboard and in the emails we send you. We don't sell it, share it with anyone else, use it for advertising, use it to train AI or machine-learning models, or combine it with other people's data to identify anyone. Access tokens are stored encrypted and used only to fetch your data. You can disconnect at any time in Settings or in the platform's own settings (Instagram: Apps and websites; LinkedIn: Settings & Privacy → Data privacy → Permitted services; Stripe: your Dashboard's connected apps). Disconnecting stops all access straight away, and we delete the token and the data we fetched through it within 30 days.
Where a platform sets stricter limits on how long we may keep its data, we follow the stricter limit.
How we use it
Only to run StackSignal: sign you in, bill you, show your dashboard, send the emails you'd expect from the service (sign-in codes, receipts and an optional weekly summary) and keep the service secure. We don't sell your data or use it for advertising. Your private stats and connected-account data are only ever shown to you. We don't use artificial intelligence to profile you or make decisions about you.
Why we're allowed to
To provide the service you signed up for (contract); to keep it secure and working (our legitimate interests); and, for joining the Compound 30 Substack, your consent, which you can withdraw by unsubscribing. For connected accounts, your consent on the platform's approval screen, which you can withdraw by disconnecting.
Who processes it
These companies process data for us, only to provide their service to us and under their data-protection terms. We don't sell or rent your data to anyone.
- Vercel (hosting) · Supabase (database, Mumbai region) · Stripe (payments) · Resend (sign-in and service emails)
- Kit (our mailing list for customer emails, such as the welcome series)
- Google (only if you choose “Continue with Google”, to confirm your email)
- Apify (fetching public LinkedIn and Instagram data)
- Substack (your newsletter subscription)
- Instagram (Meta) and LinkedIn (Microsoft), only for accounts you choose to connect
We may also disclose data when the law requires it.
Where it's stored
Our processors work in several countries, including the United States, India (database, Mumbai) and the European Union. Where data moves between countries, it's covered by the processor's standard data-protection terms.
How long we keep it
For as long as your account is open. Sign-in codes expire after 10 minutes and sessions after 90 days of inactivity. Handles stop refreshing automatically as soon as an account is closed or its plan ends. When you delete your account (yourself, in Settings, or by emailing us) we remove your email, handles, uploads, private stats, screenshots, goals, connected-account tokens and data, and sign-in history, and take you off our mailing list. Self-service deletion happens immediately; an emailed request is completed within 30 days. We keep only the billing records the law requires, with no link to your handles or stats.
Security
Everything travels over HTTPS. Data sits in access-controlled databases with row-level security, sign-in codes are stored only as one-way hashes, and card details never touch our servers. If a breach ever affects your data we will tell you and the authorities as the law requires.
Your rights
Wherever you live, you can ask for a copy of your data, a correction, to object, or for deletion, at any time. If you are in the EEA, the UK, the UAE or a US state with a privacy law, these rights are set out in the law that applies to you and we honour them for everyone. We don't discriminate against you for using them. We reply within 30 days. You can complain to your local data-protection authority.
To delete your data, see Data deletion. If your public profile has been added to someone's competitor list and you want your handle's data removed from StackSignal, email us and we'll do it.
Children
StackSignal is for adults only (18+). We don't knowingly collect data from anyone under 18 and will delete it if we learn we have.
Changes
If we change this policy in a way that matters, we'll tell you by email before it takes effect, and we'll ask for your permission again if we ever want to use connected-account data for something new.
Contact
Email hello@compound30.com or reply to any StackSignal email.