Privacy Policy
Last updated: August 2, 2026
Overview
Stackr is a personal supplement and protocol tracking app developed by Alexander Hoogland. Your privacy is important to us. This policy explains what data we collect and how it is used.
Data Storage
All data you enter into Stackr (items, protocols, doses, wellness logs) is stored locally on your device using an on-device database. We do not collect or have access to this data by default.
Optional Account & Cloud Sync
If you choose to create an account and enable cloud sync, your stack data is stored on our servers (powered by Supabase) solely for the purpose of syncing across your devices. We do not sell, share, or use this data for any other purpose. Your data is protected by Row-Level Security, ensuring only you can access your own data.
Cloud sync is off unless you turn it on. If you never create an account, none of your stack data ever leaves your device and there is nothing for us to hold, disclose, or lose.
Where Your Data Is Processed
If you enable cloud sync, your data is stored on Supabase infrastructure in the West US (Oregon) region of the United States. Subscription records are handled by RevenueCat, also in the United States. Payments are handled entirely by Apple.
If you use Stackr from outside the United States — including the European Economic Area, the United Kingdom, or Australia — enabling cloud sync means your data is transferred to and stored in the US. We rely on our data processing agreement with Supabase, which incorporates the European Commission's Standard Contractual Clauses, as the safeguard for that transfer. You can avoid international transfer entirely by not enabling cloud sync.
Subscriptions & Purchases
Stackr Pro subscriptions are processed through Apple's App Store and managed by RevenueCat. We do not have access to your payment information. RevenueCat collects anonymous device identifiers and purchase history solely to manage your subscription status. See RevenueCat's privacy policy for details.
Notifications
Stackr may request permission to send local notifications for dose reminders, reorder alerts, and supply tracking. These notifications are generated entirely on your device. No notification data is sent to our servers.
Analytics & Tracking
Stackr does not use any third-party analytics, advertising, or tracking SDKs. We do not collect usage data, device information, IP addresses, or behavioral data.
Data You Provide
- Email address (optional): Only collected if you create an account for cloud sync. Used solely for authentication via magic link. Not shared with third parties.
- Stack data: Item names, quantities, dosing schedules, and notes. Stored locally and optionally synced to cloud.
- Wellness logs: Energy, mood, sleep, and recovery scores, plus any free-text notes you add. Stored locally, and synced to the cloud along with everything else if you enable cloud sync.
- Dose history and restock records: What you logged, when, and reorder history. Stored locally and synced if you enable cloud sync.
We recognise that what you record in Stackr — the substances you take, the doses, and how you say you feel — is health information, and is treated as sensitive data under the laws of the EEA, the UK, and Australia. We hold it to that standard regardless of where you live: it is stored on your device by default, never sold, never shared with advertisers, and never used to build a profile of you.
Why We Are Allowed To Hold It
For users in the EEA and the UK, the GDPR requires us to name a lawful basis for each thing we do with your data:
- Data kept only on your device: we are not processing it at all. We cannot read it, and it never reaches us.
- Your email address: processed to perform our contract with you (Article 6(1)(b)) — it is how we sign you in.
- Stack data synced to the cloud: this is health data, so we rely on your explicit consent (Article 9(2)(a)). Creating an account and enabling sync is that consent. You can withdraw it at any time by deleting your account, which erases the cloud copy.
- Subscription records: processed to perform our contract with you and to meet Apple's requirements for managing an auto-renewing subscription.
We do not use your data for automated decision-making or profiling.
How Long We Keep It
Cloud-synced data is kept until you delete it or delete your account — we do not impose our own expiry, because it is your record to keep. Deleting your account erases it immediately. Your authentication record (email only) may persist for up to 30 days afterwards, as described below. Subscription records are retained by RevenueCat and Apple under their own policies.
Data Deletion
You have full control over your data and can delete it at any time:
- Delete individual items: From the item detail screen within the app.
- Delete your account and all data: Go to Settings → tap "Delete account and all data". This permanently erases all your items, protocols, dose history, wellness logs, and cloud backup on Supabase. The action requires two confirmations and cannot be undone.
- Delete the app: Removes all local data from your device.
Signing out on its own does not delete anything — it only ends the session on that device. Use "Delete account and all data" if you want the cloud copy gone.
Your authentication record (email address only) may persist for up to 30 days after account deletion to prevent abuse. To request immediate removal of the authentication record, contact support@mystackrapp.com.
Your Rights Over Your Data
Wherever you live, you can do all of the following:
- See it: everything we hold is visible in the app. There is no hidden profile.
- Correct it: edit any item, dose, or log directly.
- Take it with you: Settings → Data → Export exports your dose history and inventory as a CSV. This is your right to data portability, and it does not require a request to us.
- Delete it: as described under Data Deletion above.
- Object or restrict: email us and we will stop the processing you object to, or explain why we cannot.
If you want to exercise a right you cannot complete in the app, email support@mystackrapp.com. We will respond within 30 days. We will not charge you, and we will not ask you to justify the request.
If You Are In The EEA Or The UK
Alexander Hoogland is the data controller for the data described in this policy. In addition to the rights above, you have the right to lodge a complaint with your local supervisory authority — for example the CNIL in France, or the Information Commissioner's Office in the UK. You do not have to contact us first, though we would rather you did, because we can usually fix it faster.
If You Are In Australia
We handle personal information in line with the Australian Privacy Principles. Because Stackr records health information, we treat it as sensitive information: we collect it only with your consent, and only for tracking your own protocol. As described under Where Your Data Is Processed, enabling cloud sync discloses your data to an overseas recipient in the United States. If you believe we have mishandled your information, contact us first at support@mystackrapp.com; if you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner.
If You Are In California
We do not sell or share your personal information, and we never have. We do not use it for cross-context behavioural advertising. There is no financial incentive attached to your data, so there is nothing to opt out of.
Children's Privacy
Stackr is not intended for use by anyone under 18. We do not knowingly collect data from minors.
Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by the "Last updated" date at the top.
Contact
Stackr is operated by Alexander Hoogland, who is the data controller for the purposes of the GDPR.
Questions about this Privacy Policy, or any request about your data? Contact us at support@mystackrapp.com