Privacy policy
The short version: we store the time entries you log and the email you sign in with, on servers in the EU. We look at your content only to show it back to you. No ads, no third-party trackers, no analytics script in your browser, and nothing is ever sold or shared for marketing. We do count, on our own servers, which features get used — never what you wrote. You can download everything or delete everything, any time, from Settings.
Who we are
Stintify is run by Stenite AB (org.nr 559007-2848), a Swedish company, which is the data controller for everything described here. For anything privacy-related, email privacy@stintify.app.
What we store
- Your account: email address, timezone, and settings. Sign-in is passwordless, so there is no password to store.
- Your time data: entries (start, end, category, an optional note) and the categories you create.
- Your devices: watch model, a hashed pairing token, and when the device last synced.
- Feedback you send us (only if you send some): what you wrote, and the email address you gave — your account's, or one you typed on the form if you weren't signed in. Unlike everything else here, we read this: that's the point of it. We use it to answer you and to fix what you reported, nothing else.
- Waitlist entry (only if you ask for one): while we cap how many accounts exist, signing in with an address that has no account puts that address on a waitlist instead. We store the address, the date you asked, and whether you confirmed it by email — nothing else. We use it to send you the confirmation email and, when a place opens, one invite. Nothing else.
- Watch entries before you have an account: the watch app works without an account, and while it does, it backs up the entries you log (start, end, category) together with the watch model under a random identity that isn't linked to you — we don't know whose they are, and there is nothing in them we could use to find out. If you later pair the watch with an account, that history becomes part of your account; if you never do, it is deleted 6 months after the watch last synced.
- Usage events: which features of Stintify get used — things like "a page of the dashboard was opened" or "an entry was logged on the watch" — tied to a random identifier: your account's internal id for the dashboard, the watch's own device identifier for the watch app. Never your name or email. These events never contain your entries, notes, category names, email address, or location. There is no analytics script in your browser and no tracking cookie: dashboard events are recorded by our own servers, and the watch app reports its own. They are stored with PostHog, an analytics service, on their EU servers, which we configure to discard IP addresses. We use them for one thing: seeing which parts of Stintify are used, so we know what to improve.
That is the whole list. There is no tracking script or third-party tracker in your browser, we never see your location, and your content is never used for anything but showing it back to you.
What we do — and don't do — with your content
Entry notes and category names are yours and can be as personal as you make them. We store them and display them back to you; we do not read, analyze, sell, or use them for anything else. (The one thing a person here does read is feedback you deliberately send us through the feedback form — you wrote it to be read.) If we ever add further features that process your content, they will be strictly opt-in, explained before you enable them, and reflected here first.
AI analysis (optional, off by default): You can turn on an Analyze button for day and week views. It runs only when you press it — never automatically. When you do, that period's entries (times, category names, descriptions, work/life marks, and your notes) plus aggregate totals from your recent history are processed by an AI model running on our own servers. No third-party AI service is involved and this data never leaves our infrastructure for it. The resulting text is stored with your account (so unchanged data isn't re-processed), is included in your data download, and is deleted with your account. Consent (GDPR art. 6.1a) is the legal basis; you can withdraw it anytime under Settings, which stops all analysis immediately.
Why we're allowed to process this (legal bases)
- Providing the service (contract, GDPR art. 6.1b): storing and syncing your entries, signing you in, sending sign-in emails.
- Waitlist (consent, art. 6.1a): you give us the address so we can tell you when a spot opens. Reply to any invite, or email us, to be taken off the list at once.
- Feedback (consent, art. 6.1a): you chose to write to us. Ask and we delete it, and the address with it.
- Pre-account watch backup (legitimate interest, art. 6.1f): keeping the entries an unpaired watch logs so your history is complete if you later create an account. The data carries no name, email, or anything else that points at you, and deletes itself after 6 idle months. Don't want it at all? Pair the watch, or email us the pairing code it shows and we'll delete its data.
- Legitimate interest (art. 6.1f): abuse prevention — an address that never completes a sign-in gets exactly one email, tracked only as an anonymized hash of the address, never the address itself; short-lived security logs; and the occasional email about important service changes, which you can opt out of.
- Usage statistics (legitimate interest, art. 6.1f): counting feature use as described above, so we can improve the product. The events are pseudonymous and content-free by design. Object anytime by emailing us and we exclude your account.
We use one cookie: the strictly necessary session cookie that keeps you signed in (90 days). No third-party cookies, which is why there is no cookie banner.
Where your data lives
Everything stays in the EU. We use:
- Supabase — database hosting (AWS eu-north-1, Stockholm).
- Amazon Web Services (SES) — delivers sign-in emails (eu-north-1).
- Cloudflare — DNS, and routing of email you send to us.
- PostHog — stores the usage events described above, on their EU cloud (Frankfurt). Your content and email never go there, and we configure it to discard IP addresses.
- Garmin — entries logged on a watch travel through the Garmin Connect app on your phone on their way to us. Data you submit to Stintify is submitted to us, not to Garmin.
How long we keep things
- Your account and entries: until you delete them.
- Entries from a watch that was never paired with an account: 6 months after that watch last synced, then everything under its random identity is erased.
- Entries you delete: fully purged within 90 days (the delay lets an offline watch learn about the deletion instead of re-uploading the entry).
- The anti-abuse email hashes: at most 12 months.
- A waitlist address: deleted 30 days after we send your invite; 30 days after you asked if you never confirm the address; 6 months if you confirmed it but we never got to you.
- Feedback and trouble reports: 12 months from when you sent them, or sooner if you ask. If you were signed in, they go with your account.
- Usage events: at most 12 months.
- Server logs (the only place an IP address can appear): at most 30 days.
- Database backups, where kept: at most 30 days.
Your rights
- See and take your data: Settings → "Download my data" gives you everything as one machine-readable file.
- Fix it: everything is editable in the dashboard.
- Delete it: Settings → "Delete account". Your watch stops syncing immediately and everything is permanently erased after 30 days — sign in again within those 30 days if you change your mind. You can also just email us.
- Object or restrict: email privacy@stintify.app and we'll sort it out. You can also complain to the Swedish data protection authority (IMY) or your local one.
Age
Stintify is for people aged 16 and over.
Changes
Changes to this policy are posted here; if a change matters, we email you about it before it takes effect.