Privacy policy
Last updated 2026-08-29. Plain English, no lawyer-speak; the short version is that your label data is processed in memory and not kept, and the little we do store is listed below.
Who we are
Stripy Horse (stripyhorse.io) is run by Ben Faerber, a software engineer in the United States. Questions about anything on this page: the contact form.
Label data you send us
The converters, the viewer, preflight and the API take ZPL, PDFs, images and HTML and turn them into something else. That input is processed in memory and discarded when the response is sent. We do not keep your labels, your PDFs or the addresses on them, and we do not look at them.
Two deliberate exceptions, both under your control:
- Virtual printers you create capture the jobs sent to them; that is what they are for. Captured jobs stay in your account for the retention window of your plan (the last 25 jobs on the free tier, 30 days on Starter, 90 days on Pro) or until you delete the printer.
- The public demo printer shows what it receives on a public wall. Every text field is masked before anything is stored (real words and personal data never appear) and embedded graphics are stripped. Do not send it anything confidential anyway.
Account data
You sign in with GitHub or Google. We store the email address and display name the provider gives us, the API keys you create (hashed; the plaintext is shown once and never stored), the printers and IP claims you set up, and a count of API calls per key per month for quotas. We never see or store a password.
Payments
Paid plans are billed by Stripe. Your card details go to Stripe directly and never touch our servers; we store only Stripe's customer and subscription identifiers and the current status of your plan.
Logs, errors and email
- Request logs (path, status, timing, IP address, user agent) are kept for abuse prevention and debugging and pruned automatically.
- Error reports from the server and from the browser tools are recorded so bugs get fixed; they include the page or endpoint and the error message, never the label data. Error events are also sent to Sentry.
- Email (quota warnings, plan changes, replies to the contact form) is sent through ZeptoMail. We do not send marketing email.
Cookies
A session cookie keeps you signed in, a short-lived cookie protects the sign-in handshake, and during private preview a cookie remembers the preview password. No advertising or cross-site tracking cookies, and no third-party analytics scripts.
Where data lives
Servers are hosted by OVH in the United States. Nightly database backups are encrypted at rest and kept for a limited number of days.
Your choices
Delete printers and keys any time from your account. To delete the account itself, or to get a copy of what we hold about you, ask and it is done within a few days. Self-hosted deployments keep every byte on your own infrastructure; nothing is sent to us.
Changes
If this page changes in a way that matters, the date at the top moves and signed-in users are told by email.