Guest mode and local recovery data
You can use Staplicht's free core experience as a guest. Check-ins, cravings, mood, triggers, notes and reflections are stored in a SQLCipher-encrypted local database. The personal plan, support contact and audio preferences stay in app-private local preferences.
Staplicht excludes both the recovery database and local preferences from Android cloud backup and device transfer. You control local export and deletion in Settings.
Optional account
If you create an account with email and password, Staplicht stores the email address, display name, a one-way password hash and hashed session records. The plain password is not stored.
Where email registration or password recovery is available, Staplicht uses short-lived, single-use codes and revokes existing sessions after a successful reset. Only hashes of active codes are stored. When an account email is sent, Resend receives the destination address and verification or recovery message solely to deliver it.
If Google sign-in is available and you choose it, Staplicht receives the Google account identifier, verified email address and display name needed to create and sign in to the account. Staplicht does not retain the Google profile image. Google sign-in is optional.
Google Play purchases
An account is required to securely link and restore a Google Play purchase. Staplicht stores the product, entitlement state, purchase status, expiry where applicable and a hash of the Google Play purchase token for verification and replay prevention.
When Staplicht receives a Google Play pending-refund notice for an account-linked purchase, it temporarily keeps the purchase token, order reference and any obfuscated account or profile identifiers encrypted at rest so an authorized operator can review the request within Google's review window. It also records the notification reason, event time, review status and outcome. The encrypted secrets are erased after a confirmed submission. When an unreviewed request expires, its configured erasure grace is capped at one hour and cleanup is scheduled at least hourly. Non-secret review and outcome metadata is retained for up to 400 days for dispute, audit and anti-fraud records.
Google Play processes the payment. Staplicht does not receive or store card numbers or Google payment credentials.
Optional product analytics
Product analytics is off unless you separately opt in. When enabled, Staplicht sends only an event name, broad duration category, app language, app version and experiment group. It never sends notes, recovery focus, craving or mood values, contacts, an advertising ID or a purchase receipt for analytics.
The app creates a random installation ID. The server immediately replaces it with a domain-separated keyed hash and never stores the raw ID. Raw analytics events are retained for no more than 90 days. Turning analytics off stops new events; Erase data clears the local queue and replaces the installation ID.
Disabled and future online features
Staplicht does not currently present community publishing or external AI reflection as generally available features. They are not active public data-collection routes, and the server keeps both capabilities disabled by default.
If either capability is introduced later, Staplicht will add an in-app opt-in disclosure and update this policy and the Google Play Data safety declaration before enabling it. A future community feature would need the chosen pseudonym and submitted post for publishing and moderation. A future external AI feature would require explicit consent and would explain which service provider receives the submitted text.
Security, retention and deletion
Staplicht uses encrypted transport, a SQLCipher-encrypted recovery database, app-private preferences excluded from backup, hashed session and purchase tokens, and Android Keystore-backed secrets. No system can promise absolute security.
To limit automated authentication abuse, Staplicht temporarily processes the request IP address and stores only a keyed one-way rate-limit identifier, time window and counter. This control does not store the raw IP address. Configured retention after a rate-limit window ends is capped at one day and cleanup is scheduled at least hourly.
Deleting local data does not by itself delete an online account. A confirmed account deletion revokes sessions, removes login credentials and direct profile identifiers, deletes linked report and block records, and deactivates entitlements. Pseudonymized billing records may remain while a purchase is restorable or financial, dispute and anti-fraud obligations apply. They retain a random account tombstone and transaction references but cannot be used to sign in. See the deletion page for both routes.
Contact
Privacy, access and deletion questions: support@staplicht.app.
Staplicht updates this policy and the Google Play Data safety declaration when its data practices change.