STCKD

Privacy Policy

Last updated: September 11, 2026 · Version 2

STCKD is an iOS app for tracking supplements and peptides. This policy explains what data the app and this website handle, why, who processes it, how long it is kept, and what you can do about it. It is written to meet the GDPR (EU), the UK GDPR, the CCPA/CPRA (California) and PIPEDA (Canada).

1. Who is responsible

The data controller is Mário Otruba, an individual developer, Martina Hattalu 2973, Slovakia (European Union). Contact: support@stckd.app. There is no separate data-protection officer; the same address handles every privacy request.

2. What we collect and why

DataWhyLegal basis (GDPR)
Account: your email address, and an anonymous identifier from Apple or Google if you sign in with themCreate and secure your account, send sign-up confirmation and password-reset emailsContract (Art. 6(1)(b))
What you track: supplements and peptides, doses, stacks, schedules, intake history, notes, and your mood and energy logShow it back to you and sync it between your devices when you are signed inContract (Art. 6(1)(b)); for health-related entries, your explicit consent given by entering them (Art. 9(2)(a))
Age confirmation: that you confirmed you are 18 or older, and whenKeep the app adult-onlyLegal obligation and legitimate interest (Art. 6(1)(c), (f))
Technical logs: IP address and request metadata recorded briefly by our hosting providerSecurity, abuse prevention, rate limitingLegitimate interest (Art. 6(1)(f))
Purchase status: whether a STCKD Pro subscription is activeUnlock Pro featuresContract (Art. 6(1)(b))

We never store your date of birth, payment details, location, contacts, photos or health-app data. The app does not use analytics, advertising SDKs, tracking pixels or session recording. If you use STCKD without an account, everything stays on your device and never reaches our servers.

3. Health-related information

Entries about compounds you take and how you feel can be health data. You decide what to enter. We store it only so the app can display it to you and sync it between your devices. It is never analyzed for medical purposes, never shared, and never used to make decisions about you. STCKD is a tracking tool, not a medical service, and nothing in it is medical advice.

4. Who processes it for us

ProviderWhat they doWhereSafeguard
SupabaseDatabase, authentication, secure storage of your synced dataUnited States (us-east)Data-processing agreement with EU Standard Contractual Clauses; encryption in transit and at rest; row-level security so only your account can read your rows
ResendSends account emails (confirmation, password reset)United StatesData-processing agreement with Standard Contractual Clauses
AppleSign in with Apple, App Store purchases and subscriptions, optional crash reports you choose to share with developersGlobalApple Developer Program License Agreement; we never see payment details
GoogleSign in with Google, only if you choose itGlobalGoogle API Services terms; we receive only your email and an identifier
GitHub PagesHosts this websiteGlobalStatic pages only; no cookies set by us

We do not sell or share personal information for advertising, and we do not use it for cross-context behavioral advertising. No other third party receives your data.

5. International transfers

Our servers are in the United States. Transfers from the EU/EEA and UK rely on the providers' Standard Contractual Clauses listed above, plus encryption in transit and at rest.

6. How long we keep it

7. Your rights and how to use them

California residents: you have the rights to know, delete, correct, and to non-discrimination. We do not sell or share personal information, so there is nothing to opt out of. Canada: you may withdraw consent and access or correct your information through the same channels.

8. Children

STCKD is for adults. You must be 18 or older to create an account or use the app, and the app asks you to confirm this. We do not knowingly collect data from anyone under 18; if we learn we have, we delete the account. Parents or guardians can write to support@stckd.app.

9. Security

All traffic uses HTTPS. On iOS your session token is stored in the system Keychain. Synced data is encrypted at rest and protected by row-level security, so only your authenticated account can read or write your records. Reminders are local notifications generated on your device; nothing is sent to a push server. No system is perfectly secure, so please use a strong, unique password.

10. Cookies and this website

stckd.app sets no cookies and runs no analytics or third-party scripts. Fonts are served from this domain.

11. Changes

When this policy changes we update the date and version above and, for material changes, tell you in the app. Earlier versions are available on request.

12. Contact

support@stckd.app · Mário Otruba, Martina Hattalu 2973, Slovakia