Privacy Policy
Last updated: July 18, 2026
Stack (the “App”, “we”, “us”, “our”) is operated by Cedar Hills Studio LLC. Questions: hello@trackyourstack.app.
- Your health data lives on your device, in an encrypted database — and stays there unless you turn on Cloud backup.
- Stack requires a Stack account: you sign in with your email using a one-time link or code — no password. The account holds only your email, never what you take (Section 3b).
- We never sell, rent, share, or harvest your data — not your medications, not your results, nothing. That is the promise.
- Beyond the required account email, features that send data off your device are opt-in: Cloud backup (an encrypted copy for recovery), product-update emails, and sending feedback. Details in Sections 3b and 5.
- If you buy Plus on the web, your email and payment details go to our payment processor (Stripe) and subscription manager (RevenueCat); we receive only your subscription status, never full card numbers (Section 8).
- We show no ads and use no advertising identifiers or cross-app tracking. We do use anonymous, aggregate analytics and crash reporting to improve the App; these never include your health data (Section 3a).
- The account only knows your email; unless you turn on Cloud backup, your health data never leaves your device.
- Label scanning runs on your device; the App does not upload your photos.
1. Scope
This policy covers the Stack mobile application and the Stack website account and web checkout at trackyourstack.app. It does not cover any third-party service you choose to send your data to (for example, a cloud drive where you save a backup).
2. What the App stores on your device
Everything you enter is stored locally on your device, including:
- Compounds/medications, doses, units, titration ladders, schedules, and reminders;
- Injection sites and rotation history;
- Vial/supply amounts and projections;
- Bloodwork/lab results, weight entries, side effects, and notes;
- Adherence history, streaks, titles/milestones, and app settings.
This is held in an encrypted on-device database (SQLCipher). The encryption key is stored in your device’s secure storage (Android Keystore). We do not have a copy and cannot access it.
3. What we never collect, sell, or share
Whatever you do in the App, we never collect, receive, store, sell, rent, or share:
- Your name, real-world identity, location, contacts, or advertising identifiers;
- Anything used to track you across other apps or services.
We never sell, rent, trade, or harvest any of your information, full stop — including anything you send us through the optional features in Sections 3b and 5. We use your data only to run the feature you asked for (reach you about Stack, restore your backup, answer your feedback). By default the App does not transmit your personal or health data anywhere; the only thing that leaves automatically is the anonymous analytics and crash reports described next. The optional features that can send data off your device — email, cloud backup, and feedback — are covered in Sections 3b and 5, and each is off until you turn it on.
3a. Anonymous analytics and crash reports
To see which features are used and to fix bugs, the App uses two privacy-preserving tools. Neither ever receives your health, medication, dose, weight, or personal data, and neither can tie anything back to you.
- Aptabase (anonymous usage analytics): records anonymous, aggregate events — for example, that a screen was opened or a dose was logged — with no user identifier and no personal content. We only ever see counts, in aggregate.
- Sentry (crash reporting): if the App crashes, it sends an anonymous crash report with the technical error and your device model, OS, and app version. It is configured to never send your IP address, identity, or any of your data.
There are no advertising identifiers and no cross-app tracking. Think of these as a usage counter and a smoke detector — never a window into your stack.
3b. Your account, and optional features that send data off your device
Your account (required). Stack is a sign-in app. You create an account with your email and authenticate with a one-time link or code — no password. We store that email and use Supabase (Section 8) to send the code and keep you signed in across your devices and the web. The account holds only your email — it is never linked to what you take, and your health data stays encrypted on your device.
Everything below is opt-in. Each one is off until you turn it on, and none is required to use the App. When they do send data, it goes to Supabase, the backend hosting provider we use (see Section 8). We use it only for the feature you enabled, and we never sell or share it.
- Email (product updates): if you choose to join our updates list, we store the email address you enter, along with an anonymous install identifier, the source of the sign-up, and your app/OS version, so we can email you about Stack and avoid duplicate sign-ups. You can leave the list at any time using the unsubscribe link in any email or by contacting us. We do not use your email for anything but Stack, and we never sell it.
- Cloud backup (optional recovery): if you turn on Cloud backup, we store your email (used to sign you in with a one-time code) and an encrypted copy of your Stack data on our backend so you can restore everything on a new phone. Your data is encrypted on your device before it is uploaded. Important, in plain terms: so that we can restore your data even if you lose your phone and every password, the App also stores the decryption key alongside the backup. This means Cloud backup is a convenience feature, not a zero-knowledge one — while we never look at, sell, or share your data, the encrypted copy on our backend is technically accessible to us, unlike the copy on your device. This is a deliberate trade-off for painless recovery. If you want your health data to stay only on your device, simply leave Cloud backup off (it is off by default). You can turn it off and request deletion of your cloud copy at any time (Section 10).
- Anonymous install identifier: each install of the App generates a random identifier that is not your name and does not identify you in the real world. It is used to de-duplicate sign-ups and, if you enable an optional feature above, to link that install's records. It only becomes associated with your email if you choose to give us one.
- Feedback: if you send feedback from within the App, we receive your message and basic technical context (app version, device/OS) so we can act on it. Please don't include health details you'd rather keep private in a feedback message.
4. Camera and photos (label scanning)
The “Scan a label” feature uses your camera, or a photo you choose, and reads the text entirely on your device using Google’s ML Kit on-device text recognition. The image is processed locally to pre-fill fields. The App does not upload your photos, and it does not save the image after reading it.
5. Backups and sharing — you’re in control
- Local backup file: You can create an encrypted backup file protected by a password you choose. The App writes the file and hands it to your device’s share sheet so you can save it wherever you like. Once you send it somewhere, that destination’s own terms apply. We never receive this file, and we cannot recover its password — keep it safe.
- Cloud backup (optional): If you turn it on, an encrypted copy of your data is stored on our backend so you can recover it on a new phone with an emailed code. See Section 3b for exactly what is stored and the convenience-vs-zero-knowledge trade-off. It is off by default, and you can turn it off and delete the cloud copy at any time (Section 10).
- Stack sharing: Stack-share codes/QR are encrypted and shared directly by you with whoever you choose. These do not pass through our backend.
6. Notifications
Dose reminders are local notifications generated and shown on your device. They are not sent through any server.
7. Permissions the App may request, and why
- Notifications / exact alarms — to deliver your dose reminders on time.
- Camera — only when you use “Scan a label.”
- Photos / media — only when you pick a label image or save/share a backup file.
- Biometric / device credential — only if you enable the optional app lock; this is handled by your operating system and we never receive your biometrics.
You can grant or revoke these in your device settings; some features won’t work without them.
8. Third-party components
- Google ML Kit (on-device text recognition) — runs locally for label scanning; the App does not send your images to Google.
- Aptabase (anonymous usage analytics) and Sentry (crash reporting) — see Section 3a; neither receives your health or personal data.
- Supabase (backend hosting + account authentication) — stores your account email and sends your sign-in code, and stores the data from the opt-in features in Section 3b (your email, your encrypted Cloud backup, and feedback you send). Governed by Supabase's own security and privacy terms.
- RevenueCat (subscription management) and Stripe (payment processing) — used only if you buy Stack Plus on the web. At checkout, your email and payment details go to Stripe (the payment processor/merchant of record) and your subscription is managed by RevenueCat; Stack receives only your resulting subscription status tied to your account. We never see or store full card numbers. Each is governed by its own privacy terms.
- Your operating system, and any app you choose to receive a shared backup or stack code.
We integrate no advertising and no cross-app tracking SDKs. Beyond the anonymous analytics and crash reporting in Section 3a and the opt-in features in Section 3b, the App does not transmit your data.
9. How your data is protected
- On-device database encryption (SQLCipher); key stored in your OS secure storage;
- Optional biometric/PIN lock to open the App;
- Backup files are encrypted with your password before they leave the App.
No system is perfectly secure; you are responsible for securing your device and your backups.
10. Keeping and deleting your data
Your on-device data is yours to control. You can:
- Delete individual entries in the App;
- Use Settings → wipe all data to erase everything on the device (irreversible);
- Uninstall the App to remove its data from your device.
For the opt-in features that store data on our backend (Section 3b): you can turn off Cloud backup and request deletion of your cloud copy, and you can leave the updates list via any email's unsubscribe link. To have us delete your email and/or your Cloud backup from our backend, contact hello@trackyourstack.app and we will remove it. If you never used those features, we hold nothing to delete.
11. Children
Stack is intended for adults (18+) and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you are under 18, do not use the App. If you believe a child has provided us an email or other data through an opt-in feature, contact us and we will delete it.
12. Your privacy rights (GDPR / UK GDPR / CCPA-CPRA and similar)
Because your personal and health data stays on your device by default, you can exercise rights such as access, correction, deletion, and portability directly in the App (view, edit, export via backup, or wipe). For any data you sent us through an opt-in feature (Section 3b) — your email or a Cloud backup — you can access, correct, or delete it by contacting us at the email above. We do not “sell” or “share” personal information as those terms are defined under U.S. state laws. Questions about your rights: contact us at the email above.
13. International users
The App runs locally on your device wherever you are. If you use an opt-in feature in Section 3b, the data for that feature is stored on our backend provider's servers, which may be located in the United States; by using those features you consent to that processing. Everything else stays on your device.
14. Changes to this policy
We may update this policy as the App changes. When we add or change an optional feature that sends data off your device, we describe it here and update the app stores’ data-safety information before that release. Material changes are reflected by the “Last updated” date.
15. Contact
Stack — hello@trackyourstack.app
← Back to Stack