Privacy Policy
Last updated 28 September 2026
An earlier version. Read the current one.
In short: Stuga runs on your own computer and sends us nothing on its own: no telemetry and none of your documents. Our online services (Stuga ID, remote access and billing) need a small set of information to work, and this page lists all of it. With remote access, your traffic passes through our relay encrypted, and the relay can’t read it. We never sell personal information, use it for advertising or use it to train AI models.
Who we are and what this covers
PillarXYZ, Inc., a New York corporation, makes Stuga. We are responsible for the personal information described on this page. Send questions and requests to hello@stuga.dev.
This page covers:
- the Stuga software and Stuga for Claude, which run on your own computers;
- this website, stuga.dev;
- our online services: Stuga ID, remote access and billing;
- people who visit a node through its Stuga address;
- email you send us.
The website and the software are available everywhere, and this page applies to everyone who uses them. For now, Stuga ID and paid plans are available only to people in the United States and in Canada outside Québec.
Words we use
- We, us, our: PillarXYZ, Inc.
- You: whoever is reading this. That could be someone who uses Stuga, visits our site or visits someone else’s node.
- Stuga: the Stuga software, which you run yourself.
- Your node: a computer running Stuga that you or your team control, such as your own Mac.
- Stuga ID: your account at id.stuga.dev.
- Remote access: our paid service that lets people reach your node from anywhere.
- Your Stuga address: your node’s web address with remote access, such as
https://abc123.mystuga.com. - The relay: our server that passes remote access connections on to your node.
Stuga, the software
Stuga sends us nothing on its own. It has no telemetry. Stuga never sends us your documents or tables, or what you do in them. With remote access, they pass through our relay encrypted, and the relay can’t read them.
A node connects out only for features in use on it:
- the AI providers its administrator sets up;
- notifications and webhooks they configure;
- an identity provider they add;
- images an agent adds by address, which the node downloads and serves itself;
- the information page an app publishes about itself, when that app signs in to Stuga;
- the sample workspaces under Create a workspace, which come from GitHub or from a mirror its administrator sets;
- once a day, the list of Stuga releases from GitHub. The request carries nothing about the node, and Check for new versions in its settings turns it off;
- on a Mac, the installer for a new version from GitHub, when an administrator chooses Update now.
What a node sends to those providers is between its administrator and them.
Only if you turn on Stuga ID or remote access
Your node contacts us only if its administrator turns one of these on:
- Stuga ID sign-in. When someone signs in with Stuga ID, the node confirms the sign-in with id.stuga.dev.
- Remote access. The node:
- checks in with our account service to get your Stuga address, send its public key and renew its access to the relay;
- asks us to publish a temporary DNS record so it can get its certificate;
- keeps a connection open to the relay through a connector program, which it downloads when an administrator turns remote access on.
- Let’s Encrypt. With remote access, your node gets its certificate directly from Let’s Encrypt, a nonprofit certificate authority. Let’s Encrypt handles the IP addresses that contact it under its own privacy policy.
Stuga for Claude
The plugin’s connector is the npm package @stuga/mcp, which you download from the npm registry. It runs on your computer and sends Claude’s requests only to the node address you enter. It keeps your sign-in on your computer, in ~/.config/stuga/oauth.json.
Anthropic processes what Claude reads and writes in Stuga, under Anthropic’s privacy policy. You can stop Claude’s access at any time in Stuga, under Settings → Your own AI → Connected agents.
This website
stuga.dev sets no cookies and has no forms. Sign-in, account and checkout pages are on id.stuga.dev.
Cloudflare serves stuga.dev. To deliver a page, it handles your IP address and browser details under its privacy policy.
We count visits with Cloudflare Web Analytics. It records:
- the page you read and the page that sent you;
- your country;
- your type of browser and device;
- how fast the page loaded.
Cloudflare says it stores nothing in your browser and doesn’t fingerprint you. We see only totals.
Downloads come from GitHub, under GitHub’s privacy statement.
Stuga ID
Stuga ID is a free account at id.stuga.dev. Stuga works without it. You need it only for remote access and to sign in to nodes that accept it. You sign in with your email address and passkeys. There is no password.
What we keep
- Your email address. We check it by sending you a code.
- A suggested username, if you give one. Nodes offer it to you when you first sign in.
- Your passkeys. For each one we keep only the public key, an identifier, and when you added it and last used it. The private key stays on your device or in your passkey manager. We never receive your fingerprint, face or device PIN.
- Your nodes. We keep the nodes you own and the ones you have joined, and when you first and last signed in to each. We also keep whether you agreed to share your email address with each one.
- Which version of our Terms you accepted, and when.
- A security log. It records sign-ins, failed attempts, passkeys added or removed, and email changes, each with the IP address and type of device used.
We use this information to run your account, sign you in and keep your account safe from misuse. id.stuga.dev uses one cookie, which keeps you signed in and does nothing else. We send sign-in codes through Cloudflare’s email service.
What we see when you sign in to a node. Every Stuga ID sign-in passes through id.stuga.dev, so we see which node you signed in to and when. We don’t see what you read or write there. Once you are in, the node gives you its own session.
What a node receives when you sign in
- An identifier made for that node only. Each node gets a different one, so the owners of two nodes can’t match you by comparing them.
- Your suggested username.
- Your email address, only if you agree to share it with that node.
The node’s owner decides what happens on the node, including what happens to the information it received. We don’t receive that information, and we don’t control what the owner does with it.
Remote access
Remote access is a paid service, with one subscription per node. It gives your node its own Stuga address, so people can reach it from anywhere.
How the connection works. Your node keeps a connection open to our relay. Today there is one relay, on a server we rent from Akamai (Linode) in Newark, New Jersey. When someone opens your Stuga address, the relay reads which address they asked for and passes the connection on to your node. The connection is encrypted between the visitor’s device and your node. The relay has no key to read it. The key for your Stuga address is created on your node and is never sent to us.
What the relay sees
- Your Stuga address. Browsers send it in readable form when they connect, so the relay and the networks along the way can see it.
- IP addresses: each visitor’s, and your node’s.
- Times and sizes: when each connection starts and ends, including your node’s own connection to the relay, and how many bytes pass each way.
- Details your node reports when it connects: your computer’s name (for example “Livs-MacBook-Air”), its operating system and the connector program’s version.
What the relay can’t see. It can’t see anything inside the encrypted connection. That includes pages, documents, searches, messages, passwords, sign-in tokens and what agents do.
The relay passes each visitor’s IP address on to your node, so your node can limit abuse and keep its own log. Visitors see the relay’s IP address, not your node’s.
What we keep
- The relay log. It holds everything listed under What the relay sees. We use it to run the relay and look into abuse, and we delete it after 30 days. We keep a record longer only in two cases: it is part of a specific abuse case, or an authority lawfully asks us to preserve it.
- Monthly traffic totals for each node. They contain no IP addresses, and we keep them for 13 months. We use them to keep the relay fair and to answer billing questions. To keep the relay fair for everyone, we may limit each node’s speed.
- Your node’s record. It holds your node’s random identifier, its Stuga address, its public key, which Stuga ID owns it and whether its subscription is active. We also keep its check-ins with our account service, with the time and IP address of each, for 90 days.
Your Stuga address is public
- Every certificate for a web address is recorded in public Certificate Transparency logs. So your Stuga address becomes public for good, and so do the dates its certificates were issued. Nobody can remove these records, including us.
- When your node gets a certificate, we publish a temporary DNS record for it and then remove it.
- Your address is random and says nothing about you. Anyone can still find it and try to connect, which is why everyone who opens your node has to sign in.
- We never give your Stuga address to anyone else, even after you cancel. It stays reserved for your node. If you delete your Stuga ID, the address is retired for good.
If you visit a node through its Stuga address
You may not be our customer, but our relay carries your connection. It sees your IP address, the Stuga address you opened, the time and how many bytes passed. It keeps these in the relay log for 30 days, to run the relay and deal with abuse. We keep a record longer only if it is part of a specific abuse case or an authority lawfully asks us to preserve it. The relay also passes your IP address to the node you visit.
That node belongs to someone else. Its owner decides what happens there, including what happens to your IP address and to anything you do or share on the node. Ask the owner about it. To ask about our relay’s records, write to hello@stuga.dev with the Stuga address and the time of your visit.
Billing
Stripe handles payments, tax, receipts and trial reminders for us. You enter your card on Stripe’s pages, and we never see the full card number or its security code.
Before checkout. Checkout starts on id.stuga.dev and has three steps before Stripe:
- You sign in with your Stuga ID.
- Cloudflare Turnstile checks that a person, not a script, is starting the checkout. It looks at your IP address and browser details. We set it up so that it sets no cookies. Cloudflare also uses these details, as a controller, to improve its bot detection, under its Turnstile privacy addendum.
- We check a daily limit on how many checkouts can be started.
What we get from Stripe
- your name and email address;
- your billing country and postal code, or your full billing address where tax rules need it;
- your business tax ID, if you give one;
- your card’s brand, last four digits and expiry date;
- your plan, your trial and renewal dates, and your invoices, amounts and taxes;
- which invite or discount code you used;
- a record that you agreed to the renewal terms at checkout.
We use this information to take payments, keep the records tax law requires and answer your billing questions.
Stripe’s own use of your information. Stripe also uses payment information for its own purposes, such as preventing fraud and meeting financial rules. To detect fraud across its network, it uses details about your device. It does this under Stripe’s privacy policy. Stripe’s checkout and billing pages set Stripe’s own cookies. Stripe may decline a payment automatically if it looks like fraud. If that happens to you, write to us and a person will look at it.
Emails. Stripe sends receipts and the reminder before a free trial ends. We send sign-in codes, the other reminders described in our Refund and Cancellation Policy and service notices through Cloudflare’s email service.
Email you send us
- hello@stuga.dev is for questions, support and privacy requests. Security reports about our online services come here too, with “Security” in the subject. We use your address and message to reply. We keep a short record of privacy requests and our answers, so we can show how we handled them.
- abuse@mystuga.com is for abuse reports. If it doesn’t reach us, use hello@stuga.dev.
- We use your report to look into the problem, and we may tell the node’s owner what was reported.
- We don’t give them your name or email address unless you agree or the law requires it.
- Copyright complaints are the exception. We forward them to the node’s owner in full, including who sent them.
- If Akamai or Cloudflare passed a complaint on to us, we tell them what we did.
- Security problems in the Stuga software go through GitHub’s private reporting, as our security policy describes. GitHub handles these reports under its privacy statement. If we publish an advisory, it credits you unless you ask us not to name you.
What we never collect
We never collect:
- anything in your workspaces: documents, tables, files, comments, searches, AI prompts, or what agents do;
- the usernames and passwords of accounts on your node;
- your node’s private keys;
- your passkeys’ private keys, or your fingerprint or face data;
- your full card number;
- telemetry, meaning reports from the software about how you use it.
What we still control
The relay can’t read your traffic. We still run other parts of the system, and you should know what that lets us do:
- We run the DNS for mystuga.com. That means we could get a certificate for your Stuga address. Any such certificate would appear in the public Certificate Transparency logs, where anyone, including you, can look for it.
- Two older certificates still cover every Stuga address. They stay valid until 23 December 2026. Cloudflare, which runs our DNS, holds their keys, and both certificates are in the public logs.
- We run Stuga ID. A node that accepts Stuga ID trusts us to say who is signing in. So we, or someone who broke into Stuga ID, could sign in to that node as a person who uses Stuga ID there. Node accounts with their own passwords don’t depend on us.
- We publish Stuga updates. A node installs an update only when an administrator chooses to. Release files on GitHub can’t be replaced after they are published.
- We can turn off remote access for a Stuga address, for example after abuse or unpaid bills. Your node and everything on it keep working on your own network.
Who else handles your information
Cloudflare, Akamai and Stripe handle information for us, under our instructions and their data processing terms. As described above, Cloudflare and Stripe also use some of it for their own bot and fraud prevention. GitHub works under its own terms.
| Provider | What they do for us | Where |
|---|---|---|
| Cloudflare | Serves stuga.dev and counts visits. Runs our DNS. Hosts Stuga ID and our account services. Sends sign-in codes, reminders and notices. Runs the check before checkout | Account data is stored in the United States. Website requests are handled at the Cloudflare data centre nearest you |
| Akamai (Linode) | Hosts the relay | Newark, New Jersey, United States |
| Stripe | Payments, tax, receipts and trial reminders | United States and other countries |
| GitHub | Software downloads and releases, and reports of security problems in the software | United States |
Apple hosts our mailboxes (iCloud Mail) in the United States, under its iCloud terms.
We also share information in these cases:
- With the owners of nodes you sign in to, as described under Stuga ID.
- For legal reasons. We share information only when valid legal process requires it, or voluntarily when someone faces a risk of death or serious physical injury. We hold no workspace content, so we can hand over only what this page lists. We tell you first, unless the law forbids it or telling you would put someone at risk of harm. As US law requires, we report apparent child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC).
- If our company is sold or merged. The new owner must keep to this policy. We tell you before your information becomes subject to a different privacy policy.
We don’t sell personal information or share it for advertising. We run no ads, and we don’t use your information to train AI models.
Where your information is processed
We are a US company, and we store and process your information in the United States. If you visit stuga.dev from another country, Cloudflare may handle your request at a data centre near you.
If you are in Canada, your information is stored in the United States. There, US courts, law enforcement and national security authorities may access it under US law.
How long we keep it
| What | How long |
|---|---|
| Website visits | Nothing per visitor. We see only totals |
| Request logs of our online services | None. We turn them off |
| Sign-in codes | 15 minutes |
| Sign-ups never verified | 7 days |
| Sign-in sessions | 30 days, or until you sign out |
| Stuga ID security log (sign-ins, IP address, device type) | 90 days |
| Your Stuga ID and your node’s record | Until you delete your Stuga ID |
| A free Stuga ID no one has signed in to for 24 months | Deleted, after a warning email |
| Your Stuga address after you delete your Stuga ID | Kept, marked as retired and linked to no one, so it is never given out again |
| Your node’s check-ins (times and IP address) | 90 days |
| Relay log (see Remote access) | 30 days. Longer only for records in a specific abuse case or that an authority lawfully asks us to preserve |
| Monthly traffic totals per node (no IP addresses) | 13 months |
| Billing and tax records | 7 years |
| Email you send us | 2 years |
| Abuse cases | 3 years after the case closes |
| Record of privacy requests and our answers | 3 years |
| Reports we make to NCMEC | At least 1 year, as US law requires |
| Backups | 30 days |
| Certificate Transparency entries for your Stuga address | Permanent and public. We don’t control them |
When a period ends, we delete the information or remove anything that identifies you. We keep something longer only when the law requires it, for example when an authority asks us to preserve records.
Your rights
Wherever you live, you can ask us to:
- show you the personal information we hold about you;
- correct it;
- delete it;
- give you a copy in a format a computer can read, so you can take it elsewhere;
- stop using it for a purpose you object to.
We may keep information the law requires us to keep, such as billing and tax records. Nothing on this page takes away rights the law gives you.
How to ask. Email hello@stuga.dev. If you have a Stuga ID, send your request from the email address on your account. We may ask you to confirm it’s you. Asking is free. We reply within 30 days. If you are in Canada and your request is complex, we may take up to 30 more days, and we tell you why before the first 30 days are up.
Things you can do yourself at id.stuga.dev
- Stop sharing your email address with a node. The node keeps what it already received.
- Cancel remote access. Your Stuga ID account links to the billing portal.
- Delete your Stuga ID.
Deleting your Stuga ID
- Your subscriptions end and remote access stops right away. Unused time isn’t refunded, except as the Refund and Cancellation Policy says.
- Your node’s Stuga address is retired for good.
- Accounts you have on other people’s nodes stay there, but you can no longer sign in to them with Stuga ID. If you want to keep using them, set a password on each one first.
- We keep billing and tax records for as long as the law requires.
Information on a node belongs to the node’s owner. Ask the owner about it. We don’t have it.
What you have to give us. Stuga ID needs a verified email address. Remote access needs payment details, including for the free trial, unless an invite code gives you free access. Without them, we can’t provide those services. Everything else in Stuga works without us.
Complaints. Please tell us first, at hello@stuga.dev. If you are in Canada, you can also complain to the Office of the Privacy Commissioner of Canada. In the United States, you can contact your state’s attorney general.
Do Not Track. We don’t track you across sites, and we treat every visit the same whether or not your browser sends Do Not Track or Global Privacy Control. We don’t use stuga.dev or our services to track you for advertising. When you buy a plan, two providers use your browser and device details to spot bots and fraud across the sites they serve: Cloudflare during the check before checkout, and Stripe on its checkout pages. They do this under their own policies.
Children
Stuga ID is for people 16 and older. To buy a plan, you must be 18, or the age of majority where you live if that is higher. Our services aren’t meant for children. If we learn that a child under 16 has given us personal information, we delete it. If you think that has happened, write to hello@stuga.dev.
How we look after it
- We collect little. We hold no workspace content and no card numbers.
- Stuga ID has no passwords to steal. Passkeys give us only public keys.
- The relay holds no key for your Stuga address.
- Access is limited. Only the people who run our services can reach the systems that hold your information.
No system is perfect. If a breach affects your personal information, we tell you without undue delay when it puts you at risk or when the law requires it. We explain what happened, what it means for you and what we are doing about it. Where the law requires, we also tell regulators.
Changes
We date every change to this page at the top, and we link earlier versions from here. If a change matters to how we use your information, we email Stuga ID holders at least 30 days before it takes effect. We won’t use information we already have for a new purpose without telling you first.
Contact
PillarXYZ, Inc., 800 Third Avenue, New York, NY 10022, United States
- Questions, support and privacy requests: hello@stuga.dev
- Abuse reports: abuse@mystuga.com, or hello@stuga.dev if that doesn’t reach us
- Security problems in our online services: hello@stuga.dev with “Security” in the subject
- Security problems in the Stuga software: GitHub private reporting, as our security policy describes
- Our security contacts are also in https://stuga.dev/.well-known/security.txt
Our Chief Executive Officer is responsible for privacy at PillarXYZ. You can reach them at hello@stuga.dev.