Privacy Policy
Last updated: August 2026
1. Introduction
StintBox ("we", "us") is developed by Kameli ApS, based in Denmark. This policy explains what data we collect, why, and how we protect it.
2. What We Collect
During license validation (each app open)
- License key
- Machine ID hash (anonymized hardware fingerprint; we do not collect or store individual hardware information)
- App version
- IP address
- Operating system name and version
When you create an account
- Email address
- Display name (optional)
- Password (hashed, never stored in plain text)
When you purchase a license
Payment is processed by Paddle.com (our merchant of record). We do not store credit card numbers or payment details directly. See Paddle's privacy policy.
When you use the mobile app
All telemetry and sensor data is stored locally on your device. It is never uploaded to our servers unless you explicitly choose to share or sync it (e.g., publishing a session recap to your profile).
- GPS / location data: recorded during sessions for telemetry overlay (speed, route, altitude, etc.)
- Sensor data: accelerometer, gyroscope, and barometer readings captured during recording
- OBD-II vehicle data: engine RPM, coolant temperature, and other diagnostics when an OBD adapter is connected
- Camera control metadata: connection status and settings for linked action cameras (GoPro, Insta360, DJI)
Crash reporting & diagnostics
We use Sentry (sentry.io) to collect anonymous crash reports and performance data across our desktop, web, and mobile apps. This helps us identify and fix bugs quickly. No personal information, telemetry data, filenames, or GPS data is included in crash reports. Crash reporting can be disabled in the app settings.
- Device type, operating system name and version
- App version and runtime environment
- Error messages and stack traces (code-level, no personal data)
- General performance metrics (app startup time, export duration)
Anonymous usage statistics (desktop + mobile)
On **desktop**, when your app checks for updates (every 4 hours), our update server counts the request. On **mobile**, when you open the app, it sends a single anonymous 'launch ping' to the same analytics endpoint. In both cases we use the counts to answer 'how many people are using StintBox?', 'which versions are in use?', and 'which countries are people using the app from?'. We do not set any identifier on your device: no tracking cookie, no install UUID, no advertising ID. A daily-rotating salt is used server-side to deduplicate IP subnets so we can approximate unique-device counts; the salt rotates every UTC midnight and your IP itself is discarded within the same request. Retention: 90 days for the anonymous hashed subnet; aggregate counters are kept for 13 months. Legal basis: legitimate interest (GDPR Article 6(1)(f)); on mobile the CNIL 'audience measurement' exemption (Sheet 16) also applies. To opt out on desktop, disable auto-update in Settings → Updates. On mobile, toggle off 'Anonymous usage statistics' in Settings → Privacy. Existing aggregate counts cannot be removed because they contain no identifier tied to you.
- App version and operating system (from the User-Agent header or launch ping)
- Country (derived from your IP address via an offline GeoIP database; your IP itself is never stored)
- Release channel (stable or beta)
- Platform type: desktop / mobile-ios / mobile-android
What we do NOT collect
- Your telemetry data is never uploaded without your explicit action
- Individual hardware serial numbers or specifications
- Browsing behavior outside of stintbox.app
- Continuous or background location tracking: GPS is only active during a recording session
When you upload a session or a video
Cloud sync uploads a session's GPS track, motion data, OBD readings, your heart rate if you recorded one, the times, the sport, and your phone model and OS. Privacy zones and anonymous GPS mode are applied before the upload, not after, and motion data is left out on the free tier. A video is uploaded only if you have a storage plan and press Back up on that session, and it moves only while the app is open in front of you.
When you send us diagnostics
A diagnostic report carries the app and phone version, the Bluetooth conversation with your camera, our debug log and a sensor snapshot. File paths, session ids and Wi-Fi network names are removed, any position is rounded to about a kilometre, and there is no video and no track in it. It does carry your phone identifier, so we can match it to the case you are writing about. The two troubleshooting wizards report the device model and whether it worked, never the name you gave the device, and both follow the same Settings, Privacy switch.
3. Cloud Storage (Optional)
StintBox may offer optional cloud storage for video and telemetry files. This is always opt-in: your data is never uploaded without your explicit action. Cloud-stored data is encrypted at rest and only accessible to your account. If your paid access ends, uploading stops, but nothing is locked: everything already in the cloud stays visible and downloadable for another 365 days, and you never have to pay to get it back. We email you during that window (weekly, then daily for the last three days) with the exact deletion date and what renewing would restore. Renewing at any point turns syncing back on with your data still in place. After the 365 days the cloud copies are permanently deleted; the copies on your own computer are untouched. You can also delete your cloud data yourself at any time. It stays recoverable for 30 days, then it is gone for good. Legal basis: performance of our agreement with you while your plan is active (GDPR Article 6(1)(b)); for the 365 days after it ends, our legitimate interest in giving you a fair chance to come back without losing your work (Article 6(1)(f)), which you can end at any time by deleting your cloud data.
4. Connected Services
You can link StintBox to services you already use. Today that means Strava. When you connect Strava, we ask for read access to your profile and activities, including activities you have marked private, because importing those is the point of the feature. StintBox reads activity data such as GPS position, speed, heart rate, power, cadence and altitude, and turns it into telemetry you can overlay on your video. In the desktop app your Strava tokens are encrypted and stored only on your own computer. If you connect from the website instead, they are encrypted and stored on our servers so the site can list your activities. Disconnecting inside StintBox revokes our access at Strava and deletes the stored tokens. Disconnecting from inside Strava has the same effect: Strava tells us, and we delete our copy. Legal basis: performance of our agreement with you (GDPR Article 6(1)(b)), for as long as the connection is active.
- Social platforms: link a YouTube, TikTok, Instagram, Facebook or X account and we hold the token that lets us post for you, until you unlink it. For Instagram, Facebook and X the video passes through our server on the way; for YouTube and TikTok it goes straight from your phone to the platform. Once it arrives it is on their terms, not ours.
- Your own cloud storage: connect Dropbox, OneDrive or Google Drive and your sessions and videos go into your account there, under that provider's terms. We hold the token until you disconnect. Deleting your account cancels every one of these connections at the provider as well as here.
5. Live Broadcasts
Going live is off until you start it. While a broadcast runs, your speed, lap times and position go out to a link once a second. Anyone who has that link can watch, and can pass it on. Inside a privacy zone your position is left out, and your heart rate is sent only if you switch that channel on, for that one broadcast. The video is not part of a broadcast: it stays on your phone unless you back it up yourself.
- We hold the last 30 seconds back before viewers see them, so a broadcast can be stopped before those seconds reach anyone. Up to 500 people can watch at once, and a broadcast that goes quiet for 120 seconds ends on its own.
- We keep a copy of the telemetry you broadcast for 30 days after it ends, so that we can investigate misuse of the service, for example if a broadcast is used to help commit an offence or to harass someone. The copy never contains your heart rate, and it never contains anything about the people who watched. It is kept for those 30 days whether or not you delete your account, and is then deleted automatically. There is no other copy.
- A copy that exists is a copy an authority can require us to hand over. That is true of any service that keeps anything, and it is why this one is small, short lived and has a single purpose. About the people who watch we know nothing except their IP address.
6. Other People in Your Recordings
A StintBox camera is pointed at you and your vehicle, which is what it is for. In practice someone in the paddock or on the road can end up in the background of a clip. They are never the subject, we do not identify anyone, and we do not search your footage. But if you upload, publish or broadcast something with other people in it, that decision is yours, and it is worth making the way you would want it made about you. On a group ride, remember that your position is roughly everyone else's too.
7. How We Use Your Data
- License validation: verify your license is active and within device limits
- Account management: login, password reset, subscription status
- Support: respond to your inquiries
- Product improvement: aggregate, anonymized statistics (e.g., "X% of users are on Windows"), never individual tracking
8. Data Sharing
We do not sell or share your personal data with third parties, except:
- Paddle.com: processes payments as merchant of record
- Backblaze B2 (EU region): stores the files you back up to the cloud, meaning your video, telemetry and project files. They hold the storage; only your account can retrieve them. Data processing agreement signed.
- Sentry (Functional Software, Inc.): receives anonymous crash reports and performance data to help us fix bugs. No personal data is shared. See Sentry's privacy policy at sentry.io/privacy
- SparkPost (EU region): delivers our email (sign-in links, account notices, and the newsletter if you asked for it). Data processing agreement signed.
- Hetzner (Falkenstein, Germany): hosts our servers and database. Your data does not leave the EU.
- Law enforcement: if legally required by Danish or EU law
- VersaTiles: serves the optional satellite map background. Every tile request tells them roughly where your track is, along with your IP address. The background stays off until you switch it on.
- Platforms you publish to, and cloud accounts you connect yourself: YouTube, TikTok, Instagram, Facebook, X, Dropbox, OneDrive, Google Drive. Nothing reaches any of them until you link the account and press publish or back up.
That's it. No ad networks, no data brokers.
9. Data Storage & Security
- Server located in Germany (Hetzner Cloud, Falkenstein)
- Data encrypted in transit (TLS 1.3) and at rest
- Passwords hashed with bcrypt
- Machine IDs stored as SHA-256 hashes only
- Database: PostgreSQL with regular backups
10. Your Rights (GDPR)
Under EU/GDPR, you have the right to:
- Access: request a copy of your data
- Correction: update inaccurate data
- Deletion: request complete deletion of your account and data
- Portability: receive your data in a standard format
- Objection: object to specific processing
To exercise any right: email [email protected]. We will respond within 30 days.
11. Cookies
stintbox.app uses minimal cookies:
- Session cookie: keeps you logged in (essential, no consent required)
- Referral attribution cookie: 30-day first-party cookie for referral tracking (legitimate interest)
We do NOT use third-party tracking cookies, Google Analytics, Facebook Pixel, or similar.
12. Children
StintBox is not directed at children under 16. We do not knowingly collect data from children.
13. Data Retention
- Account data: retained while your account is active. Deleted within 30 days of account deletion request.
- Cloud backups: kept until you delete them. There is no time limit while your plan is active.
- Cloud backups on the free quota: kept while your account is active, with no time limit. There is no lapse to count from, so nothing expires on its own. Deleting your account removes them on the same 30-day schedule as the rest of your data.
- After paid access ends: uploading stops, but everything already in the cloud stays visible and downloadable for another 365 days at no cost. We email you first (weekly, then daily for the last three days) with the exact deletion date. After 365 days the cloud copies are permanently deleted.
- Cloud data you delete yourself: kept for 30 days so you can undo a mistake, then permanently deleted. Deleting your account removes your cloud data on the same 30-day schedule.
- Storage capacity: in rare cases we may need to remove an exceptionally large project earlier than the periods above. We give at least 30 days' notice by email first (see our Terms).
- License validation logs: retained for 12 months, then automatically purged.
- Payment records: kept for five years after the end of the financial year they belong to, as Danish bookkeeping law requires.
- A payment made without an account: the whole record, including name, billing address, country and VAT number, kept for five years after the end of the financial year it arrived in, then deleted.
- Live broadcast telemetry: an administrative copy kept for 30 days after the broadcast ends, then deleted automatically. It never contains heart rate.
- Security and administration log: the event is kept, and the user id and the IP address on it are removed after two years.
14. Deleting Your Account
You delete your account in the app, under Settings, Account, Delete account. You are signed out everywhere at once, your profile stops being visible to anyone else, and we email you a link that puts it all back. After 30 days it is permanent, and we send one reminder first. At that point your sessions, videos, tracks, presets, settings, devices and login are deleted from our database and from our storage, and your connections to other platforms are cancelled at those platforms as well as deleted here.
- You choose what happens to what you shared with other users, such as a track outline, a preset or a PID definition: take it with you, or leave it for everyone else without your account attached. Leaving it does not make it anonymous, because a track is still a place and a preset is still a configuration. Anything you wrote in your own words, such as a review, is deleted either way.
- Your payment history goes with the account, apart from the bookkeeping record described under Data Retention. What survives is the amount, the currency, what the payment was for, the date and the payment reference, not your name, email address or billing address. If you paid us without ever creating an account, we keep that record whole, including name, billing address, country and VAT number, for its five years. That is wider than a bookkeeping voucher needs, and it is a deliberate decision: an unmatched payment has to stay reconcilable to the person who made it for as long as we hold it at all. Your invoices are held by Paddle under their own legal obligations, which we cannot shorten.
- What we cannot take back, because it was never only ours: what someone has already watched, a link someone saved, a post you published to another platform, a file you sent to your own Dropbox, OneDrive or Google Drive, and whatever our payment provider must keep. We can switch a broadcast off; we cannot unsee it for anyone.
15. Changes to This Policy
We will notify you of material changes via email at least 30 days in advance. Non-material changes are posted here with an updated date.
16. Contact
- General: [email protected]
- Privacy-specific: [email protected]
- Data Protection: Kameli ApS, Denmark