Data Processing
This page explains the data-processing relationships between you, JindoPrompt, and the third-party services used to deliver LockStack. It complements our Privacy Policy.
1. Why a separate page
LockStack is unusual: the desktop application processes no customer data on our infrastructure. Your prompts, generated content, and saved campaigns stay on your computer. We are therefore not a “data processor” in the traditional GDPR sense for content-generation work — there is nothing for us to process. We are a data controller only for the small amount of personal data collected during the purchase flow (email address and order metadata).
2. Data flow during purchase
- You click Buy on lockstack.net → redirected to a Lemon Squeezy checkout.
- You enter your email + payment details on Lemon Squeezy. Lemon Squeezy is the merchant of record.
- Lemon Squeezy sends us a signed webhook with your email + order details.
- Our server generates a licence key, writes a row to our database, and triggers Resend to send your licence email.
- You receive two emails: order confirmation from Lemon Squeezy, and your licence key from us via Resend.
3. Subprocessors
The complete list of third parties that may process personal data on our behalf:
| Subprocessor | Purpose | Data received | Location |
|---|---|---|---|
| Lemon Squeezy | Payment processing, merchant of record, tax handling | Email, payment details, billing address, order metadata | United States |
| Resend | Transactional email delivery (licence keys, support replies) | Email address, message content | United States / EU |
| Render | Web hosting for lockstack.net | Standard server logs (IP address, user agent, request paths) | United States |
We will update this list before adding any new subprocessor that processes personal data, and notify customers by email where required.
4. Desktop application — no data processing
The LockStack desktop application:
- Generates content entirely on your local CPU using a bundled GGUF model and a local
llama-serversubprocess listening on127.0.0.1. - Sends no telemetry, analytics, or usage data to us or any third party.
- Reads and writes only to folders you have granted access to (your Downloads folder by default).
- Does not require an internet connection after install. Licence verification is offline.
Because the app does not transmit your input or output anywhere, no data-processing agreement is required for the content-generation work itself. The only personal data we process — the purchase email and order metadata — is governed by our Privacy Policy and the contracts we hold with the subprocessors listed above.
5. Data subject requests
To exercise your rights under GDPR or PIPA — access, correction, deletion, portability, objection — email hello@lockstack.net. We respond within 30 days. For data held by Lemon Squeezy or Resend on our behalf, we will coordinate with them to fulfil the request.
6. Security incidents
If we become aware of a personal-data breach affecting you, we will notify you and any required supervisory authority without undue delay (and within 72 hours where GDPR applies).
7. Contact
Data-processing or DPA-specific questions: hello@lockstack.net. We are happy to provide a counter-signed DPA on request for enterprise customers with procurement requirements.