Privacy Policy
Effective August 24, 2026
Summary
Stacks is a personal workout and nutrition tracker. The data recorded in the app is stored so that the app can display it back. It is never sold, never used for advertising, and never shared with third parties for marketing purposes. Stacks also collects anonymous, EU-hosted usage statistics in order to measure which features are used; they contain no personal or health data and can be disabled in the app. One feature relies on an outside AI provider: reading a restaurant receipt sends that photo to Google's Gemini API, and only once the notice describing it has been accepted. An optional subscription is billed by Apple through the App Store; payment details never reach Stacks.
Data controller
Stacks is operated by Aurélien Durier, an individual established in France, acting as data controller. Any request relating to personal data may be sent to the address at the bottom of this page.
Data collected
Creating an account and using Stacks involves storing:
- -Account: email address, hashed password, account creation date.
- -Profile: sex, year of birth, height, weight, activity level, fitness goal (cut/maintain/bulk).
- -Nutrition: recorded meals, food entries, recipes, daily targets.
- -Workouts: exercises, sets, reps, weights, workout templates, sessions.
- -Body composition: bodyweight entries recorded over time.
- -Technical: session tokens, which keep the account signed in, and standard web-server access logs (IP address, timestamp, requested route) kept by the hosting provider for security and abuse prevention.
- -Anonymous usage analytics, in the app: which features and screens are used, recorded as plain counters and flags (e.g. "a workout set was logged", "the weekly review was opened") tied to a random per-install identifier, never meal, food, exercise, or bodyweight values.
- -Audience measurement, on this website: the pages viewed and how long the visit lasts, the address of each page without its query string, the referring page, the campaign parameters and advertising click identifiers an incoming link carries (utm_*, gclid, fbclid and similar), and the browser, operating system, device type and screen size. No cookie and no local storage entry is kept, and the values typed into a form are never recorded. The IP address reaches the measurement provider, which uses it to compute an identifier that is regenerated every day, so a returning visitor is counted as a new one. Two named events record that the App Store badge was clicked and that the waitlist form was submitted, each carrying no information of its own beyond the page language.
- -AI features: the date on which the receipt scan notice was accepted, and a timestamped entry per scan performed, used to enforce a usage cap. The photo itself is not stored.
- -Subscription: the current subscription status (product, period, expiry, renewal state) and the related subscription events. Payment details (card numbers, billing address) never reach Stacks: Apple processes the payment.
The following are notcollected: contacts, location, photo library, microphone, or any health data from Apple Health or Google Fit. The camera is used in two cases, both user-initiated: barcode scanning, where the image stays on the device and is never transmitted, and receipt scan, where the photo is transmitted for reading as described under “Receipt scan” below and is not retained.
Purposes and legal bases
For account, profile, nutrition, workout, and body composition data, the legal basis is the performance of a contract(article 6.1.b): this data is necessary to operate the service that was signed up for. Profile data (sex, age, weight, height, activity level) is used solely to compute daily energy and macronutrient targets, and for no other purpose. The same basis covers the subscription status described under “Subscription” below, which is necessary to grant the features that were paid for.
For the anonymous usage analytics described above, the legal basis is the legitimate interest(article 6.1.f) in measuring how the app is used in order to improve it. That data being anonymous and limited to internal product measurement, it does not override the rights of the persons concerned, and in the app these analytics can be switched off at any time in Settings → Account & data.
Website audience measurement rests on the same legitimate interest(article 6.1.f): knowing how many people reach usestacks.app, where they arrive from, and whether they go on to the App Store. It is kept to what that purpose requires: nothing is stored on the visitor's device, the identifier is regenerated every day, no profile is built, and the data is never used for advertising nor shared with advertisers. A browser that sends the Do Not Track signal is not measured at all, and an objection may also be addressed to the contact address at the bottom of this page.
Cookies and similar technologies
This website sets two cookies. Both are first-party: they are set by usestacks.app itself and are readable by no one else. None of them serves advertising, audience measurement, or tracking from one site to another, and no third party sets a cookie here.
- -NEXT_LOCALE, on the public pages: records the display language, so that the pages that follow are served in the language chosen. It holds a language code and nothing else, and it lasts for the browsing session.
- -The session cookie, set after signing in: keeps the account signed in from one page to the next, so that credentials are not requested again on every request. It holds a session token. The session lasts 30 days and is extended each time it is used; signing out ends it.
Under article 5(3) of the ePrivacy Directive, transposed in France by article 82 of the Data Protection Act, consent is required before anything is stored on a visitor's device, unless what is stored is strictly necessary in order to provide an online service the user has expressly requested. Both fall within that exemption: keeping an account signed in is necessary to the account area itself, and the CNIL lists interface personalisation cookies, such as a language or display choice, among those exempt where that personalisation is an intrinsic and expected part of the service. That is what the language cookie does, holding a single preference and no identifier.
That exemption concerns the storing of the cookie; the GDPR applies to the personal data involved regardless. For the session cookie, the legal basis is the performance of a contract (article 6.1.b): it is what makes an account usable. The language cookie carries no identifier and no personal data, only a language code; to the extent the GDPR applies to it, the basis is the legitimate interest (article 6.1.f) in presenting the site in the language it was last read in.
No consent banner is shown, because nothing here requires consent: the two cookies above are exempt, the website audience measurement described above runs without a cookie and writes nothing to the browser's local or session storage, and no advertising or cross-site tracking technology is loaded at all. These cookies can still be deleted or blocked from the browser's settings; blocking them signs the account out and returns the display language to its default.
Waitlist
An email address entered on the website in order to be notified (for example about the Android version or product news) is stored together with the page language and the sign-up date, for the sole purpose of sending news about Stacks. The legal basis is consent (article 6.1.a), given when the form is submitted. The waitlist is separate from the app account: no account is required to join, and joining does not create one. The address is kept until its removal is requested, or until the purpose of the waitlist ends (for example once the Android app has shipped), after which it is deleted. These emails are sent through Resend (EU region) and every message carries a one-click unsubscribe link. Deletion may be requested at any time at the address at the bottom of this page.
Push notifications
Enabling reminders and allowing notifications causes the device to register a push token, stored with the account for the sole purpose of delivering the reminders that were enabled (meals, weekly review, weigh-in) at the chosen times. The legal basis is consent (article 6.1.a), given when notifications are allowed and a reminder is enabled; it can be withdrawn at any time by switching reminders off in Settings → Notifications or by revoking the notification permission. The reminder text is generic and contains no personal or health data. Delivery goes through Expo's push service, which relays it to Apple's notification service; Expo does not store the reminder text. The token is kept solely to deliver these reminders, and is removed on sign-out and on account deletion.
Receipt scan
Receipt scan is optional and requires prior consent, collected on a dedicated screen shown before the first photo. Nothing is transmitted until that consent is given.
When a receipt is scanned, the photo is transmitted to the Stacks server, then to Google's Gemini API, which identifies the item lines and estimates calories and macronutrients. The photo is not retained: it is processed in memory for the duration of that single request, then discarded. No email address, account identifier, profile data, or previously logged meal is transmitted with it.
The detected item names and the restaurant name are then sent to the same provider, which may run a Google Search, in order to refine the nutrition figures. The result is stored in a shared lookup table on the Stacks server, keyed by restaurant and item name only, with no link to any account.
The API is used on its paid tier, under which Google does not use prompts, images, or responses to improve its products, and acts as a data processor under its Data Processing Addendum. It logs them for a limited period in order to detect abuse of its own service. Processing may take place outside the European Union; Google LLC is certified under the EU-US Data Privacy Framework, which covers that transfer.
The legal basis is explicit consent (article 6.1.a, and article 9.2.a for information liable to reveal dietary habits). The date of acceptance and a timestamped entry per scan are recorded in order to enforce a usage cap. Ceasing to use the feature ends any further transmission; erasure of the consent record and of the scan history may be requested at the address at the bottom of this page, and both are deleted along with the account.
Subscription
Subscribing to Stacks Pro is optional. Payment is processed entirely by Apple through the App Store: card numbers and billing details never reach Stacks. For the payment itself, Apple acts as an independent controller, under its own privacy policy.
In order to know which account holds an active subscription, Stacks assigns the account a random purchase token, attaches it to the App Store purchase, and receives the subscription events (purchase, renewal, expiry, refund) directly from Apple's App Store server. No party other than Apple is involved, and these events carry only that token and the product details, never a name or an email address. The legal basis is the performance of a contract (article 6.1.b). These records are deleted with the account; Apple retains its own billing records under its own terms.
Recipients and subprocessors
Stacks relies on a limited number of third parties, strictly in order to operate the service. Most act as subprocessors, on Stacks's instructions. The identity providers below are the exception: they act as independent controllers for the sign-in they carry out.
- -Hosting: Hostinger (VPS, European Union). The Next.js application and the Postgres database run there.
- -Database backups: Cloudflare R2. A daily Postgres backup, encrypted at rest, retained for 30 days. International transfer covered by Cloudflare's Standard Contractual Clauses.
- -Transactional email: Resend, EU data region (Ireland). Used to send account and transactional emails. Processed in the European Union and covered by Resend's GDPR-compliant DPA.
- -Crash and error reporting (iOS app and server, never the website): Sentry (EU region, hosted in Frankfurt, Germany). From the app, receives stack traces, device model, OS and app version. From the server, receives stack traces and the failing route. Both SDKs are configured to drop IP addresses, request bodies, and user identifiers before sending, so meals, workouts, bodyweight, and receipt photos are never included. No reporter runs in the browser, so visiting this site sends nothing to Sentry.
- -Product analytics, iOS app only: PostHog (European Union region, eu.i.posthog.com). Receives anonymous usage events: feature and screen usage as counters and flags, plus device model, OS and app version. Its identify function is never called, so events are not linked to an account, and meal, food, exercise, and bodyweight values are never sent. Processed in the EU and covered by PostHog's GDPR-compliant DPA. Can be switched off in the app, under Settings → Account & data.
- -Audience measurement, website only: PostHog (European Union region, eu.i.posthog.com), loaded on the public pages of usestacks.app, never on the sign-in, account, or administration pages. It runs in cookieless mode: it keeps no cookie and no storage entry in the browser, and the visitor identifier is a hash computed on PostHog's side from the IP address and the browser, salted with a value that rotates every day. It receives the page addresses stripped of their query strings, the referring page, the campaign parameters, the browser and device characteristics, and the IP address. Its identify function is never called, no profile is created, and session recording is disabled. Processed in the EU and covered by PostHog's GDPR-compliant DPA. Enabling Do Not Track in the browser stops it. Events are kept for 12 months.
- -Food database lookup: Open Food Facts (French non-profit, EU-hosted). Queried when a barcode is scanned or a food is searched. The query and the IP address are visible to them; no account information is shared.
- -Push notifications: Expo (Expo Push service, operated by 650 Industries, Inc., United States) relays reminder notifications to Apple's notification service. It receives the device push token and the generic reminder text, which it does not store, and no personal or health data. 650 Industries self-certifies under the EU-US Data Privacy Framework, which covers the transfer to the United States.
- -Sign in with Apple: Apple (Apple Distribution International Ltd., Ireland, for the European Union). Involved only when that sign-in method is chosen. Apple confirms the identity and passes on an account identifier, plus, on the first sign-in only, the email address (or an Apple private relay address, if hiding it was chosen) and the name. Apple acts as an independent controller for the authentication itself.
- -Sign in with Google: Google (Google Ireland Ltd. for the European Union, Google LLC, United States). Involved only when that sign-in method is chosen. Google confirms the identity and passes on an account identifier, the email address, the name, and a profile picture URL that is discarded rather than stored. Google acts as an independent controller for the authentication itself. Google LLC is certified under the EU-US Data Privacy Framework, which covers the transfer outside the European Union.
- -AI receipt reading: Google (Gemini API, Google LLC, United States). Involved only when a receipt scan is run. Receives the photo of the receipt, then the detected item names and the restaurant name, and returns the estimated nutrition. No account identifier accompanies it. The paid tier is used, under which Google does not use this content to improve its products and acts as a data processor under its Data Processing Addendum, logging it briefly in order to detect abuse of its service. Google LLC is certified under the EU-US Data Privacy Framework, which covers the transfer outside the European Union.
No data is ever sold, and none is shared with advertisers or data brokers. Nothing recorded in the app is used to train AI models: the receipt scan described above runs on a paid API tier, under which the provider does not use the content it receives to improve its own products. The product analytics above is anonymous and used internally only, to improve Stacks.
Retention
Data is retained for as long as the account exists. Deleting the account from Settings → Account & data → Delete account permanently removes all associated data within 30 days, except the minimal records required by law (for example proof of consent), which are erased at the end of their statutory retention period.
Rights of the persons concerned
Under the GDPR, every user has the right to:
- -Access their data (Settings → Account & data → Download my data exports a JSON copy).
- -Rectify inaccurate data, which is directly editable in the app.
- -Erase the account and all related data (Settings → Account & data → Delete account).
- -Object to or restrict processing, including switching off anonymous usage analytics (Settings → Account & data).
- -Lodge a complaint with the CNIL (cnil.fr) should these rights not be respected.
These rights can be exercised directly in the app, or by writing to the address at the bottom of this page. Requests are answered within 30 days.
Security
Passwords are hashed and never stored in clear text. Traffic between the app and the server is encrypted (HTTPS). Database backups are encrypted at rest. Access to production data is restricted to the operator and logged.
Minors
Stacks is not intended for persons under 16. Should an account have been created by a minor, a message sent to the address at the bottom of this page will lead to its deletion.
Changes
Any amendment to this policy is reflected in the effective date shown at the top of this page. Material changes are notified in the app before they take effect.
For any question about this policy, write to adurier.pro@gmail.com.