Privacy policy
Last updated 3 October 2026
Stickly.live is a widget that lets a product reward its own users. Two different groups of people are involved and they are treated differently: the customer, who signs in and installs the widget, and the customer's end user, who sees it inside their product.
If you are a customer
You sign in with Google. We ask Google for your name, email address and profile picture, and nothing else — no Drive, no contacts, no calendar. We store those three fields, your workspace settings, your reward tasks and your API keys.
Your API secret keys are stored only as a SHA-256 hash and a last-four fragment. We cannot show you a secret key again after it is created, because we no longer have it.
If you are an end user
When the widget loads inside a product you use, we receive the user identifier that product assigns to you, and we record which tasks you claimed and when. We do not receive your name or your email from the widget, we do not set advertising cookies, and we do not track you across sites.
Clicking a task opens that platform in a new tab. What happens there is governed by that platform's own privacy policy, not this one. Stickly cannot see whether you completed the action.
Who else sees it
Our hosting and database run on Amazon Web Services in the Mumbai region (ap-south-1). Google sees your sign-in because you chose Google to sign in with. There is no one else: we do not sell data and we do not share it with advertisers or data brokers.
Keeping and deleting
Customer data is kept while the workspace exists. Claim records are kept while the customer's workspace exists, because they are the ledger that decides whether a reward was already paid.
To get a copy of your data or have it deleted, email privacy@stickly.live. End users should contact the product they used the widget in first — they are the ones who hold your account.
Changes
If this policy changes in a way that affects what we collect, the date at the top changes and customers are emailed.