Security and Data Handling

Last updated: September 27, 2026

This page describes how the Stack For Wellness internal operations platform (the "Service") protects the data it handles. Stonepath Brands LLC, doing business as Stack For Wellness, operates the Service.

Hosting

The Service runs on infrastructure operated by Stonepath Brands LLC in the United States. It is not a shared, multi-tenant service.

Data in transit

All connections to Google APIs and to AI model providers use HTTPS (TLS). This website is served only over HTTPS.

Access control

Only the business owner operates the Service. There are no outside user accounts. The Service accesses Google data only through Google's OAuth consent process, and only for Google Accounts owned or operated by Stonepath Brands LLC or its owner.

Credentials

OAuth credentials are stored in files that only the operator's system account can read. They are never committed to source control and never shared.

Least use

The Service uses Google user data only for the features described on our home page and in our Privacy Policy.

Retention

Email, documents, and other Google user data remain in the connected Google Account. Working copies made while completing a task are kept only as long as needed for business operations and records, and are deleted on request.

Revoking access

The owner of a connected Google Account can remove the Service's access at any time at myaccount.google.com/permissions.

Reporting a security issue

Email joel@stackforwellness.com.