LEGAL
Privacy Policy
This Privacy Policy explains how we collect, use, share, and protect personal data when you use the Stoop mobile application (the "App"). It is written in plain language wherever possible and structured to meet our obligations under the EU General Data Protection Regulation 2016/679 ("GDPR"), the California Consumer Privacy Act as amended by CPRA ("CCPA"), and Apple's App Store Review Guidelines.
1. Who we are (Data Controller)
The data controller responsible for processing personal data through the App is:
- Anton Yakymenko, an independent developer based in Valencia, Spain.
- Email: [email protected]
Because we operate as an independent developer below the threshold set by Article 37 of the GDPR, we have not designated a Data Protection Officer. For any privacy enquiry, please use the email address above.
2. Categories of personal data we process
We deliberately limit personal data processing to what is strictly necessary to deliver the App's core functionality. The categories are:
- Anonymous device identifier. A UUID generated on first launch and stored in your device's iCloud Keychain. It is not linked to your Apple ID, name, email, telephone number, or any other identifier external to the App.
- Posture measurements. Numerical values derived from on-device Apple Vision body-pose detection: forward-head offset in centimetres, craniovertebral angle in degrees, shoulder protraction, shoulder asymmetry, hip levelness, and an overall score. The underlying camera frames are processed transiently in device memory and discarded immediately.
- Journal content. Free-text entries and predefined tags you write in the Journal feature.
- Routine and exercise history. Which routines you started, which exercises you completed or skipped, and your post-session pain self-reports.
- App preferences. Body preset, lifestyle persona, reminder times, voice cue toggle, language override, appearance mode, units.
- Subscription metadata. Through our subscription processor (RevenueCat), we receive the anonymous device identifier, the App Store receipt validation result, and your subscription status. We do not see your name, payment card, billing address, or any other payment detail.
- Technical diagnostics. If you have Apple Analytics enabled at the iOS system level and have separately opted in within the App, anonymised crash reports may be transmitted to Apple. Apple is the controller for that data; see Apple's Privacy Policy.
3. How we use personal data and our lawful basis (GDPR Article 6)
| Purpose | Lawful basis |
|---|---|
| Deliver the App's core features (scan, routine, journal, history) | Article 6(1)(b) — performance of contract |
| Generate AI commentary, routine rationale, and pattern insights | Article 6(1)(b) — performance of contract |
| Process subscription payments via the App Store and RevenueCat | Article 6(1)(b) — performance of contract |
| Apply rate limits and cache AI responses for cost control | Article 6(1)(f) — legitimate interest in operating sustainably |
| Comply with legal obligations (e.g., tax records on subscription revenue) | Article 6(1)(c) — legal obligation |
| Optional analytics (only if you opt in) | Article 6(1)(a) — consent (withdrawable in Settings) |
4. Recipients of personal data
We share personal data only with the following processors (each acting under a Data Processing Agreement compliant with GDPR Article 28):
- Cloudflare, Inc. — workers infrastructure that receives your scan numbers, journal entries, and routine summaries to forward to Anthropic and to store cached responses temporarily. Cloudflare Privacy Policy.
- Anthropic PBC — operator of the Claude API used to generate AI commentary, journal correlation, history narrative, and end-of-session debriefs. Anthropic processes the data we send and returns model output. Per Anthropic's commercial terms, inputs are not used to train their models. Anthropic Privacy Policy.
- Apple Inc. — operator of the App Store, the StoreKit subscription infrastructure, and the App's distribution channel. Apple Privacy Policy.
- RevenueCat, Inc. — subscription management infrastructure that validates App Store receipts and exposes your subscription status to the App. RevenueCat Privacy Policy.
We do not sell or rent personal data, and we do not share it with advertisers, data brokers, or analytics providers (such as Google Analytics, Facebook SDK, Mixpanel, AppsFlyer, Adjust, Segment, etc.). The App contains no advertising and no third-party tracking SDKs.
5. International data transfers
Cloudflare and Anthropic process data on servers located in the United States and other jurisdictions. Where personal data leaves the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) incorporated into our agreements with each processor. The anonymous device identifier is the only identifier transmitted; no directly identifying personal data is sent.
6. Data retention
- On-device data (scans, journal entries, routines, preferences) is retained on your device until you delete it via Settings → Privacy & Data → Delete all scans, until you uninstall the App, or until you erase the device.
- AI response cache on our Cloudflare KV store is automatically purged 12 hours after creation.
- Rate-limit counters on Cloudflare KV are automatically purged 24 hours after creation.
- Subscription receipts retained by Apple and RevenueCat are governed by their respective retention policies and applicable tax and consumer-protection law (typically 5-7 years for accounting purposes).
7. Your rights under the GDPR
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights with respect to your personal data:
- Right of access (Article 15): obtain a copy of the personal data we hold about you.
- Right to rectification (Article 16): correct inaccurate or incomplete data.
- Right to erasure (Article 17, "right to be forgotten"): request deletion of your data.
- Right to restriction (Article 18): limit how we process your data.
- Right to data portability (Article 20): receive your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21): object to processing based on our legitimate interest.
- Right to withdraw consent (Article 7(3)): where processing is based on consent, withdraw at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint (Article 77): with your local supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (aepd.es).
To exercise any of these rights, email [email protected]. We respond within 30 days as required by Article 12(3). Because we do not collect identifying information beyond the anonymous device identifier, you will need to supply that identifier (visible in the App under Settings → About) to enable us to locate any data relating to you.
8. Your rights under the CCPA / CPRA (California residents)
If you are a California resident, you have additional rights under the CCPA as amended by the CPRA: the right to know, the right to delete, the right to correct, the right to opt out of "sale" or "sharing" of personal information, and the right to limit use of sensitive personal information. We do not sell or share personal information as those terms are defined under the CCPA, and we do not collect sensitive personal information beyond what is necessary for the App's wellness functionality. To exercise your rights, email [email protected].
9. Children's data
The App is not directed at children under 13, and we do not knowingly collect personal data from children under 13. The App is rated 12+ on the App Store. If you believe a child under 13 has used the App, please contact us at [email protected] and we will delete any data we hold.
10. Security
Personal data in transit between your device and our infrastructure is encrypted using TLS 1.3. On-device data is protected by iOS sandboxing and, for the anonymous device identifier, by the iOS Keychain hardware-backed secure storage. Our processors apply industry-standard security measures (SOC 2 Type II certification for Cloudflare and Anthropic; PCI-DSS for payment-card handling by Apple). No system is perfectly secure, and we cannot guarantee absolute security, but we apply the standard of care expected of an independent developer operating at this scale.
11. Cookies, tracking, advertising identifiers
The App does not use cookies (cookies are a web concept). The App does not access, read, or transmit your iOS advertising identifier (IDFA). The App does not contain advertising SDKs, retargeting pixels, or any third-party tracking technology. App Tracking Transparency permission is therefore not requested.
12. Automated decision-making and profiling
The AI commentary, routine selection, and journal correlations produced by the App involve automated processing of your posture data and journal entries to generate descriptive text. These outputs are not decisions that produce legal effects or similarly significantly affect you within the meaning of Article 22 of the GDPR — they are wellness suggestions and do not, for example, determine your access to credit, employment, healthcare, or insurance. You may opt out of all AI processing via Settings → Privacy → AI insights, in which case the App falls back to deterministic on-device templates.
13. Changes to this policy
We may amend this Privacy Policy as the App evolves. The "Last updated" date at the top of this page indicates when the current version became effective. For material changes that broaden the scope of data we process or change the legal basis for processing, we will give you reasonable notice in-App before the change takes effect (typically by a sheet shown on first launch after the change).
14. Contact
For any question about this Privacy Policy or to exercise any of your rights, please contact us at [email protected]. We aim to respond within 5 business days, and in any event within the 30-day statutory window under Article 12(3) of the GDPR.