Privacy Policy
Last updated: March 2026
1. Introduction
StintBox ("we", "us") is developed by Kameli ApS, based in Denmark. This policy explains what data we collect, why, and how we protect it.
2. What We Collect
During license validation (each app open)
- License key
- Machine ID hash (anonymized hardware fingerprint — we do not collect or store individual hardware information)
- App version
- IP address
- Operating system name and version
When you create an account
- Email address
- Display name (optional)
- Password (hashed, never stored in plain text)
When you purchase a license
Payment is processed by Paddle.com (our merchant of record). We do not store credit card numbers or payment details directly. See Paddle's privacy policy.
When you use the mobile app
All telemetry and sensor data is stored locally on your device. It is never uploaded to our servers unless you explicitly choose to share or sync it (e.g., publishing a session recap to your profile).
- GPS / location data — recorded during sessions for telemetry overlay (speed, route, altitude, etc.)
- Sensor data — accelerometer, gyroscope, and barometer readings captured during recording
- OBD-II vehicle data — engine RPM, coolant temperature, and other diagnostics when an OBD adapter is connected
- Camera control metadata — connection status and settings for linked action cameras (GoPro, Insta360, DJI)
Crash reporting & diagnostics
We use Sentry (sentry.io) to collect anonymous crash reports and performance data across our desktop, web, and mobile apps. This helps us identify and fix bugs quickly. No personal information, telemetry data, filenames, or GPS data is included in crash reports. Crash reporting can be disabled in the app settings.
- Device type, operating system name and version
- App version and runtime environment
- Error messages and stack traces (code-level, no personal data)
- General performance metrics (app startup time, export duration)
Anonymous usage statistics (desktop + mobile)
On **desktop**, when your app checks for updates (every 4 hours), our update server counts the request. On **mobile**, when you open the app, it sends a single anonymous 'launch ping' to the same analytics endpoint. In both cases we use the counts to answer 'how many people are using StintBox?', 'which versions are in use?', and 'which countries are people using the app from?'. We do not set any identifier on your device — no tracking cookie, no install UUID, no advertising ID. A daily-rotating salt is used server-side to deduplicate IP subnets so we can approximate unique-device counts; the salt rotates every UTC midnight and your IP itself is discarded within the same request. Retention: 90 days for the anonymous hashed subnet; aggregate counters are kept for 13 months. Legal basis: legitimate interest (GDPR Article 6(1)(f)); on mobile the CNIL 'audience measurement' exemption (Sheet 16) also applies. To opt out on desktop, disable auto-update in Settings → Updates. On mobile, toggle off 'Anonymous usage statistics' in Settings → Privacy. Existing aggregate counts cannot be removed because they contain no identifier tied to you.
- App version and operating system (from the User-Agent header or launch ping)
- Country (derived from your IP address via an offline GeoIP database — your IP itself is never stored)
- Release channel (stable or beta)
- Platform type: desktop / mobile-ios / mobile-android
What we do NOT collect
- Your telemetry data is never uploaded without your explicit action
- Individual hardware serial numbers or specifications
- Browsing behavior outside of stintbox.app
- Continuous or background location tracking — GPS is only active during a recording session
3. Cloud Storage (Optional)
StintBox may offer optional cloud storage for video and telemetry files. This is always opt-in — your data is never uploaded without your explicit action. Cloud-stored data is encrypted at rest and only accessible to your account. If your paid access ends, uploading stops, but nothing is locked: everything already in the cloud stays visible and downloadable for another 365 days, and you never have to pay to get it back. We email you during that window — weekly, then daily for the last three days — with the exact deletion date and what renewing would restore. Renewing at any point turns syncing back on with your data still in place. After the 365 days the cloud copies are permanently deleted; the copies on your own computer are untouched. You can also delete your cloud data yourself at any time — it stays recoverable for 30 days, then it is gone for good. Legal basis: performance of our agreement with you while your plan is active (GDPR Article 6(1)(b)); for the 365 days after it ends, our legitimate interest in giving you a fair chance to come back without losing your work (Article 6(1)(f)) — which you can end at any time by deleting your cloud data.
4. How We Use Your Data
- License validation: verify your license is active and within device limits
- Account management: login, password reset, subscription status
- Support: respond to your inquiries
- Product improvement: aggregate, anonymized statistics (e.g., "X% of users are on Windows") — never individual tracking
5. Data Sharing
We do not sell or share your personal data with third parties, except:
- Paddle.com: processes payments as merchant of record
- Backblaze B2 (EU region): stores the files you back up to the cloud — your video, telemetry and project files. They hold the storage; only your account can retrieve them. Data processing agreement signed.
- Sentry (Functional Software, Inc.): receives anonymous crash reports and performance data to help us fix bugs. No personal data is shared. See Sentry's privacy policy at sentry.io/privacy
- SparkPost (EU region): delivers our email — sign-in links, account notices, and the newsletter if you asked for it. Data processing agreement signed.
- Hetzner (Falkenstein, Germany): hosts our servers and database. Your data does not leave the EU.
- Law enforcement: if legally required by Danish or EU law
That's it. No ad networks, no data brokers.
6. Data Storage & Security
- Server located in Germany (Hetzner Cloud, Falkenstein)
- Data encrypted in transit (TLS 1.3) and at rest
- Passwords hashed with bcrypt
- Machine IDs stored as SHA-256 hashes only
- Database: PostgreSQL with regular backups
7. Your Rights (GDPR)
Under EU/GDPR, you have the right to:
- Access: request a copy of your data
- Correction: update inaccurate data
- Deletion: request complete deletion of your account and data
- Portability: receive your data in a standard format
- Objection: object to specific processing
To exercise any right: email [email protected]. We will respond within 30 days.
8. Cookies
stintbox.app uses minimal cookies:
- Session cookie: keeps you logged in (essential, no consent required)
- Referral attribution cookie: 30-day first-party cookie for referral tracking (legitimate interest)
We do NOT use third-party tracking cookies, Google Analytics, Facebook Pixel, or similar.
9. Children
StintBox is not directed at children under 16. We do not knowingly collect data from children.
10. Data Retention
- Account data: retained while your account is active. Deleted within 30 days of account deletion request.
- Cloud backups: kept until you delete them — there is no time limit while your plan is active.
- Cloud backups on the free quota: kept while your account is active, with no time limit. There is no lapse to count from, so nothing expires on its own — deleting your account removes them on the same 30-day schedule as the rest of your data.
- After paid access ends: uploading stops, but everything already in the cloud stays visible and downloadable for another 365 days at no cost. We email you first — weekly, then daily for the last three days — with the exact deletion date. After 365 days the cloud copies are permanently deleted.
- Cloud data you delete yourself: kept for 30 days so you can undo a mistake, then permanently deleted. Deleting your account removes your cloud data on the same 30-day schedule.
- Storage capacity: in rare cases we may need to remove an exceptionally large project earlier than the periods above. We give at least 30 days' notice by email first — see our Terms.
- License validation logs: retained for 12 months, then automatically purged.
- Payment records: retained for 7 years (Danish tax law requirement).
11. Changes to This Policy
We will notify you of material changes via email at least 30 days in advance. Non-material changes are posted here with an updated date.
12. Contact
- General: [email protected]
- Privacy-specific: [email protected]
- Data Protection: Kameli ApS, Denmark