Still

Privacy Policy

Effective date:

Overview

This Privacy Policy explains what data Still ("we", "us", "the app") handles, how it is used, and the choices you have. Still is a fridge and pantry tracker for Android and iOS: you log food in three taps, Still works out when each item needs using, and it reminds you the day before.

Still is built around a simple principle: the food you log stays on your device. We do not run a server, there is no account or sign-in, and we never receive the names, dates, or storage places of the items you track.

The limited data that does leave your device (subscription status, anonymous usage analytics and crash reports) is described in detail below.

1. Data You Create Stays on Your Device

The items you add (category, item, storage place such as fridge, freezer or pantry, the date you added them and the date Still calculates they should be used by) and your settings are stored only on your device, in a local database (still.db) and the app's preferences, on both Android and iOS.

This data is not transmitted to us or to any third party. We do not have a server that could store it.

If you uninstall the app, the operating system deletes this local data. On Android, your items and settings may be included in your Google account's automatic backup and in device-to-device transfers if you have those features turned on, so they come back when you restore a device; you can review or disable Auto Backup in your device's Google settings (developer.android.com/identity/data/autobackup). On iOS, the app's data is part of your device backup (iCloud or computer) under Apple's backup settings.

2. Subscriptions and Payments

Still requires Pro, offered as a monthly subscription (with a free trial where shown) or a one-time lifetime purchase. Purchases, billing, renewals and refunds are processed by Google Play on Android and by the Apple App Store on iOS, under your store account. We do not receive or store your payment details (card number, billing address, etc.).

To validate purchases and keep Pro unlocked across reinstalls and devices, we use RevenueCat as a subscription and entitlement processor. RevenueCat receives:

RevenueCat does not receive your name, your email address, or any of the items, dates, or storage places you enter into Still. RevenueCat's privacy policy: revenuecat.com/privacy.

You can restore previous purchases at any time from Settings > Restore Purchases, and manage or cancel your subscription from Settings > Manage Subscription (which opens your Google Play or App Store subscriptions page).

3. Analytics and Crash Reporting (Android and iOS)

Usage analytics (PostHog). The app sends usage events so we can understand which features help and where people get stuck. Events are built from fixed labels, counts and durations, for example: onboarding steps completed, an item added with its category and storage place (such as "dairy" and "fridge", never the item's name or dates), an item marked used or tossed, the sort order chosen, paywall shown, plan selected, purchase started or completed, reminders permission granted or denied, and app opened or backgrounded. Each event also carries the device model, operating system, app version and language.

Events are tied to a random ID, linked to the RevenueCat app user ID described above; no name, email or contact detail is ever attached. PostHog uses the IP address of each request to derive an approximate location (country and city). It does not receive precise location.

Crash and error reporting (Sentry). When the app crashes or hits an unexpected error, Sentry receives a diagnostic report so we can fix it: the stack trace, recent technical steps leading to the error (such as screens opened), device model, operating system and app version, and the RevenueCat app user ID so related reports can be grouped. Reports do not include the contents of your screen or the items you entered.

PostHog's privacy policy: posthog.com/privacy. Sentry's privacy policy: sentry.io/privacy.

Website analytics (jdgarita.dev/still). This applies to the Still web page, not the app. The landing page records each page view and each click on its store buttons, so we can see how visitors find Still and whether they head to the store. Each event includes the page address (without its query string), the referring site, any campaign tags in the link (UTM parameters), the page language, and the country derived by our hosting provider. The only identifier is a random ID stored in your browser's session storage for that one tab; it is deleted when the tab closes. No cookie is set, and no third-party script is loaded. Events go first to our own server on jdgarita.dev, which forwards them to PostHog without your IP address. The privacy policy and terms pages do not record anything.

4. Reminders and Notifications

Still sends a local notification the day before an item should be used. All reminder scheduling happens on your device through the operating system; the content of every reminder (such as the item's name) stays on the device and is never sent to us or to any third party.

To deliver these notifications, Still uses operating system permissions:

You can turn reminders off at any time by revoking the notification permission in your device's settings.

5. How We Use the Data We Receive

The limited information we (or our processors on our behalf) receive is used only to:

We do not sell this data. We do not use it for advertising, and we do not track you across other companies' apps or websites. We do not share it with third parties beyond the processors named in this policy and as required by law.

6. Third-Party Services We Rely On

Google Play Billing

Apple App Store

RevenueCat

PostHog

Sentry

These providers may process data in the United States and other countries where they operate, under their own safeguards for international transfers.

7. Data Retention

Because Still has no account system, there is no Still account to delete. To remove your local data, uninstall the app. To ask us to delete analytics and crash data linked to your app user ID, contact us at the email below (Settings shows nothing personal, so tell us the approximate date you installed the app and your platform). To remove purchase records, contact Google Play, Apple or RevenueCat directly.

8. Children's Privacy

Still is not directed to children under the age of 13, and we do not knowingly collect personally identifiable information from anyone under 13. If you believe we have inadvertently received such information, please contact us at the address below and we will take steps to address it.

9. Your Rights — GDPR (European Union / EEA / United Kingdom)

If you are located in the European Union, the European Economic Area, or the United Kingdom, the General Data Protection Regulation (GDPR) and equivalent UK legislation give you specific rights over your personal data.

Data controller. The data controller for Still is Juan Diego Garita. You can reach the controller at the contact email below.

Legal bases. Where GDPR applies, our legal bases for processing are:

Your rights. You have the right to access, rectify, erase, restrict, port, or object to the processing of your personal data. Because the data you create lives only on your device, the most direct way to exercise these rights over it is to manage it in the app or to uninstall; for analytics and crash data, contact us.

Right to lodge a complaint. You may also lodge a complaint with your local data protection supervisory authority.

10. Your Rights — CCPA (California)

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you specific rights:

To make a CCPA request, contact us at the email below.

11. Changes to This Privacy Policy

We may update this Privacy Policy as the app evolves. The "Effective date" at the top of this page reflects the most recent revision. Material changes will be reflected on this page, which the app links to from Settings and the paywall.

12. Contact

If you have questions about this Privacy Policy or how Still handles your data:

Email: hello@jdgarita.dev