Privacy policy
The short version: we store the time entries you log and the email you sign in with, on servers in the EU. We look at your content only to show it back to you. No analytics, no trackers, no ads, and nothing is ever sold or shared for marketing. You can download everything or delete everything, any time, from Settings.
Who we are
Stintify is run by Stenite AB (org.nr 559007-2848), a Swedish company, which is the data controller for everything described here. For anything privacy-related, email [email protected].
What we store
- Your account: email address, timezone, settings, and plan. Sign-in is passwordless, so there is no password to store.
- Your time data: entries (start, end, category, an optional note) and the categories you create.
- Your devices: watch model, a hashed pairing token, and when the device last synced.
That is the whole list. We run no analytics or tracking of any kind, and we never see your location.
What we do — and don't do — with your content
Entry notes and category names are yours and can be as personal as you make them. We store them and display them back to you; we do not read, analyze, sell, or use them for anything else. If we ever add further features that process your content, they will be strictly opt-in, explained before you enable them, and reflected here first.
AI analysis (optional, off by default): Pro accounts can turn on an Analyze button for day and week views. It runs only when you press it — never automatically. When you do, that period's entries (times, category names, descriptions, work/life marks, and your notes) plus aggregate totals from your recent history are processed by an AI model running on our own servers. No third-party AI service is involved and this data never leaves our infrastructure for it. The resulting text is stored with your account (so unchanged data isn't re-processed), is included in your data download, and is deleted with your account. Consent (GDPR art. 6.1a) is the legal basis; you can withdraw it anytime under Settings, which stops all analysis immediately.
Why we're allowed to process this (legal bases)
- Providing the service (contract, GDPR art. 6.1b): storing and syncing your entries, signing you in, sending sign-in emails.
- Legitimate interest (art. 6.1f): abuse prevention — an address that never completes a sign-in gets exactly one email, tracked only as an anonymized hash of the address, never the address itself; short-lived security logs; and the occasional email about important service changes, which you can opt out of.
We use one cookie: the strictly necessary session cookie that keeps you signed in (90 days). No third-party cookies, which is why there is no cookie banner.
Where your data lives
All storage and email sending happens in the EU (Stockholm). We use:
- Supabase — database hosting (AWS eu-north-1, Stockholm).
- Amazon Web Services (SES) — delivers sign-in emails (eu-north-1).
- Cloudflare — DNS, and routing of email you send to us.
- Garmin — entries logged on a watch travel through the Garmin Connect app on your phone on their way to us. Data you submit to Stintify is submitted to us, not to Garmin.
How long we keep things
- Your account and entries: until you delete them.
- Entries you delete: fully purged within 90 days (the delay lets an offline watch learn about the deletion instead of re-uploading the entry).
- The anti-abuse email hashes: at most 12 months.
- Server logs (the only place an IP address can appear): at most 30 days.
- Database backups, where kept: at most 30 days.
Your rights
- See and take your data: Settings → "Download my data" gives you everything as one machine-readable file, on any plan.
- Fix it: everything is editable in the dashboard.
- Delete it: Settings → "Delete account". Your watch stops syncing immediately and everything is permanently erased after 30 days — sign in again within those 30 days if you change your mind. You can also just email us.
- Object or restrict: email [email protected] and we'll sort it out. You can also complain to the Swedish data protection authority (IMY) or your local one.
Age
Stintify is for people aged 16 and over.
Changes
Changes to this policy are posted here; if a change matters, we email you about it before it takes effect.