Privacy Policy
Last updated: April 12, 2026
Effective date: April 12, 2026
The short version: stiff. does not collect personal data. Your stretch history, streak, and shrimp collection stay on your device. We use RevenueCat for subscription verification and Firebase for anonymous analytics and crash reporting — neither receives any personally identifiable information. This policy describes what we do, don't do, and your rights under applicable data protection laws.
This privacy policy applies to the stiff. mobile application ("the App") operated by Magnolia Labs Limited ("we," "us," or "our"). By using the App, you agree to the terms of this policy.
1. Information You Provide to Us
The App does not require an account, email, or any form of registration. You may optionally provide the following information, which is stored only on your device and never transmitted to us or any third party:
- A nickname for your shrimp mascot
- A first name for yourself
- A full name (optional, used only for the App's humor feature where the shrimp addresses you by full name)
- Stretch preferences (daily goal, reminder times)
- Apps you select to block via Apple's Family Controls framework
We never see, transmit, or store any of this information on our servers. It exists only in your device's local storage and is deleted when you uninstall the App.
2. Data We Process on Your Device
Camera Data
- The front camera may be used during stretch sessions to verify motion if you enable camera-based verification.
- Camera frames are processed in real time on-device using Apple's Vision framework for pose detection and frame differencing for motion detection.
- Camera data is never saved to disk, never transmitted to any server, and never retained beyond the active stretch session. Frames exist in device memory only during processing and are immediately discarded after each frame is analyzed.
- The App does not perform facial recognition, does not identify individuals, and does not retain any biometric data.
- Camera access can be revoked at any time in Settings → stiff. → Camera.
Motion Sensor Data
- In stealth mode (the default), accelerometer data from CoreMotion is sampled during stretch sessions to detect movement.
- Motion data is processed on-device only and is never stored, logged, or transmitted.
- Motion samples are discarded immediately after use.
- Motion sensor access can be revoked at any time in Settings → stiff. → Motion & Fitness.
Screen Time Data
- stiff. uses Apple's Family Controls and DeviceActivity frameworks to monitor screen usage and block selected apps.
- The App never sees which specific apps you select — Apple provides only opaque tokens that cannot be decoded or reversed to identify app names, publishers, or categories.
- We cannot identify, name, or track which apps you use, for how long, or when.
- Screen Time monitoring is handled entirely by Apple's system-level frameworks. stiff. only receives a signal when your configured usage threshold is exceeded.
- Screen Time permissions can be revoked at any time in Settings → Screen Time → Family Controls.
Locally Stored Data
The following data is stored on your device and never leaves your device:
- Stretch session history (start time, completion time, motion score)
- Streak count and longest streak
- XP total and unlocked shrimp collection
- Notification preferences and app settings
- Selected app tokens (opaque, Apple-managed)
- Subscription status (active or inactive)
- Your chosen shrimp name and your provided first/full name (if any)
- Daily goal setting and reminder times
- Trial start date
- A locally generated installation identifier used to distinguish anonymous analytics events (this identifier is not linked to your Apple ID, device ID, or any personally identifying information)
All locally stored data is protected by your device's built-in security, including iOS sandboxing, encryption at rest, and your device passcode, Face ID, or Touch ID.
3. Data We Collect Through Third-Party Services
stiff. uses exactly two third-party services. Both are configured to collect the minimum information necessary for their respective purposes.
RevenueCat — Subscription Management
- Purpose: Verifies your subscription status with Apple's App Store and manages subscription entitlements.
- Data processed: An anonymous identifier generated by RevenueCat, purchase receipts from Apple's StoreKit, device model, OS version, locale, and IP address (processed transiently for fraud prevention and not retained long-term in a form linked to your identity).
- Data NOT shared: Your name, email address, Apple ID, location beyond general region inferred from IP, app usage behavior, camera data, motion data, or any content from your device.
- Data retention: RevenueCat retains subscription records as required for accounting and audit purposes.
- RevenueCat's privacy policy: revenuecat.com/privacy
Firebase (Google) — Analytics and Crash Reporting
- Purpose: Helps us understand aggregate feature usage (e.g., which stretches are completed, when shields fire, trial conversion rates) and diagnose app crashes to improve stability.
- Data processed: Anonymous event data (stretch completions, shield triggers, onboarding progress, paywall views, draw actions), crash logs, device model, OS version, app version, and a Firebase instance ID.
- Data NOT shared: Your name, email, camera data, motion sensor data, Screen Time app selections, your shrimp name, any name you provided, or any content from your device.
- Event parameters are reviewed before each release to ensure they contain no personally identifiable information.
- Firebase instance IDs can be reset by uninstalling and reinstalling the App.
- Data retention: Firebase retains analytics data for up to 14 months per our configuration; crash logs are retained per Firebase's default retention policy.
- Firebase's privacy policy: firebase.google.com/support/privacy
- Google's privacy policy: policies.google.com/privacy
We do not use any advertising networks, tracking pixels, social media SDKs, marketing attribution services, or advertising identifiers (IDFA). The App does not request App Tracking Transparency permission because we do not track you across apps or websites owned by other companies.
4. Information We Do NOT Collect
To be explicit, stiff. does NOT collect, process, or transmit:
- Your real name, email address, phone number, or postal address
- Precise location data or coordinates
- Photos, videos, or audio recordings from the camera or microphone
- Your browsing history or specific app usage details
- Advertising identifiers (IDFA) or data used for cross-app tracking
- Contacts, calendar, health records, or files from other apps
- Biometric data, fingerprints, or facial recognition templates
- Any data that could be used to identify you personally
- Any data from children under 13
5. Legal Basis for Processing (GDPR and Similar Laws)
For users in the European Economic Area, United Kingdom, or other regions with comprehensive data protection laws, our legal bases for processing limited anonymous data through third-party services are:
- Legitimate interest: Anonymous analytics help us improve the App, fix bugs, and understand feature usage without identifying individuals.
- Contract performance: Subscription verification is necessary to provide the paid features you have purchased.
- Consent: By installing and using the App, you consent to the limited processing described in this policy.
You may object to processing based on legitimate interest by uninstalling the App, which removes all analytics data collection from your device.
6. Children's Privacy
stiff. is rated 12+ on the Apple App Store. We do not knowingly collect any personal information from children under 13 (or under 16 in jurisdictions where that is the applicable age of digital consent under GDPR or similar laws). The App does not require an account, does not collect personally identifiable information, and is age-gated through the Apple App Store.
If you are a parent or guardian and believe your child under 13 has used the App in a way that involved collection of personal information, please contact us at magnolia.labs.ai@gmail.com and we will take reasonable steps to verify and address the concern.
7. Data Retention and Deletion
All data is stored locally on your device. To delete all data associated with stiff., uninstall the App. This permanently removes all locally stored data including stretch history, preferences, and collection progress.
Data held by third parties is retained according to their respective policies:
- RevenueCat: Subscription records are retained as required for accounting and audit purposes.
- Firebase Analytics: Event data is retained for up to 14 months per our configuration.
- Firebase Crashlytics: Crash reports are retained per Firebase's default retention policy.
If you have an active subscription, uninstalling the App does not cancel your subscription. To cancel, go to Settings → Apple ID → Subscriptions on your iPhone or iPad.
8. Your Rights
Depending on your location, you may have the following rights under applicable data protection laws (including GDPR, UK GDPR, CCPA, and similar):
- Right to access: Because your data is stored locally, you can view it directly in the App.
- Right to deletion: Uninstall the App to permanently delete all local data.
- Right to rectification: Modify any data (shrimp name, user name, preferences) directly in the App.
- Right to data portability: Local data is not currently exportable in a machine-readable format; contact us if you need a specific export.
- Right to object: Uninstall the App to stop all data processing.
- Right to withdraw consent: Uninstall the App to withdraw consent.
- Right to lodge a complaint: If you believe we have violated your privacy rights, you may contact us or lodge a complaint with your local data protection authority.
To exercise any of these rights or ask questions, contact us at magnolia.labs.ai@gmail.com. We will respond within 30 days.
California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to delete personal information, and the right not to be discriminated against for exercising these rights. Because we do not sell personal information and do not collect personally identifiable information, most CCPA provisions do not materially apply, but we will honor valid requests made in good faith.
9. Security
All data remains on your device and is protected by your device's built-in security including:
- iOS application sandboxing
- Encryption at rest (enforced by iOS)
- Your device's passcode, Face ID, or Touch ID
- Secure transport (HTTPS) for all network communication with RevenueCat and Firebase
While we implement reasonable technical and organizational measures to protect data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
In the event of a data breach affecting any data we process through third-party services, we will notify affected users and relevant authorities as required by applicable law.
10. International Data Transfers
If you are located outside the United States, please note that data processed by RevenueCat and Firebase may be transferred to and processed in the United States and other countries where these services operate. These transfers are protected by:
- Standard contractual clauses approved by the European Commission (where applicable)
- Each service provider's own certification under frameworks such as the EU-US Data Privacy Framework (where applicable)
By using the App, you acknowledge that your limited anonymous data may be processed in countries outside your country of residence.
11. Third-Party Links and Services
The App may contain links to third-party websites (such as our support page, privacy policy, and terms of service). We are not responsible for the privacy practices of third-party websites. We encourage you to read the privacy policies of any third-party services you interact with.
12. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be reflected by:
- Updating the "Last updated" date at the top of this policy
- For significant changes, displaying an in-app notice on your next launch after the change takes effect
- Continuing to make the current policy available at the URL embedded in the App
Continued use of the App after changes take effect constitutes acceptance of the updated policy. If you do not agree to the changes, you should uninstall the App.
13. Contact Us
If you have questions, concerns, or requests regarding this privacy policy or your data, contact us at:
Email: magnolia.labs.ai@gmail.com
Response time: within 30 days
For urgent privacy concerns, please include "PRIVACY" in the subject line.
14. Disclaimer
stiff. is a wellness and productivity tool. It is not a medical device and does not provide medical advice. The stretch routines and Screen Time management features are for general wellbeing and productivity purposes only. Consult a qualified healthcare provider before beginning any new physical activity routine, especially if you have pre-existing conditions.
The App is designed for healthy adults engaging in light wellness activity. It is not designed for, and should not be used for, rehabilitation from injury, recovery from surgery, management of chronic pain conditions, or any therapeutic purpose. If you have any musculoskeletal condition, recent injury, or are recovering from medical procedures, do not use this App without explicit clearance from a qualified healthcare provider.
The brand voice of the App, including the shrimp mascot's commentary, is intended as humor. Any statements that may appear judgmental or critical are part of the App's comedic tone and are not intended as medical, psychological, or personal advice. The App is not a substitute for professional health, fitness, or mental health services.