Privacy Policy
Last updated: 2026-10-01
1. Controller
The controller responsible for processing your personal data is:
Gabriel BattloggLegal form: Sole proprietorship
Seat: Austria
Email: hello@starpolar.app
Business website: gabriel-battlogg.com
The business address is published in the Legal Notice.
2. Scope
This Privacy Policy applies to starpolar.app, legacy domains that redirect to it, our contact and sign-up forms, our newsletter, our online shop and checkout, and the Starpolar app, including pre-release versions and the Starpolar Assistant.
To use the Starpolar app, you must accept the applicable Terms. This Privacy Policy provides information and is not blanket consent. Where a specific optional activity requires consent, we request it separately. You may withdraw that consent at any time for the future without deleting your account.
3. Data We Process
Depending on how you use Starpolar, we may process the following categories of data.
Website and forms
Name and email address
Platform preference and optional device information
Message content you submit in forms or surveys
App and account data processed on our servers
Account identifiers and account contact details such as email address, name, and a user identifier
Device related identifiers used for account security and app functionality
Subscription and entitlement information used to validate access to paid features
Firebase Device ID, in app User ID, and login timestamps for account security and abuse prevention
Nutrition and macro guideline data
Date of birth, weight, height, sex
Processed to calculate macro and guideline values
Stored in Firebase Firestore so your settings can currently be synchronized across your devices. You can disable this sync in the app settings and delete nutrition data there.
App content and files
Personal planning content such as schedules, routines, lists, settings, nutrition entries, and related app files may be stored on your device and in Firebase Firestore to support synchronization and app functionality. Data stored locally on your device is stored in encrypted form. App files may be synchronized across your devices through Filesync. Filesync is available only with Starpolar Plus. Filesync data is encrypted in transit and stored encrypted in Firebase Firestore. You may optionally set up end-to-end encryption; in that case, Filesync cloud data can only be decrypted by your trusted devices. In the app settings, you can delete nutrition data, remove or block Filesync devices, and remove all app files stored through the app, including Filesync cloud data. Complete deletion of account associated data requires account deletion.
Finance and recipe features
When using finance features (e.g. portfolio, price tracking), security identifiers such as ticker symbols and ISIN codes may be transmitted to external market data providers in order to retrieve current price and reference data.
When using recipe search, search queries and dietary preferences or food intolerances stored in your app profile may be transmitted to external recipe and translation services. Food intolerances may constitute health data within the meaning of Art. 9 GDPR. We transmit and process them for recipe personalization only after your separate, explicit consent under Art. 6(1)(a) and Art. 9(2)(a) GDPR. Active use of the feature or a device permission alone does not replace this consent.
When using barcode scanning and product search (e.g. food items), search queries and barcodes may be transmitted to external product databases.
Location and GPS data (cardio training)
When you use cardio training features with GPS tracking, your device location is accessed to record your route, distance, speed, and pace. The GPS data processed includes coordinates (latitude and longitude), speed, accuracy, and timestamps. This data is stored locally on your device in encrypted form as part of your training session logs. If you use Filesync, training session data including GPS route data may be synchronized to Firebase Firestore as part of your app files in encrypted form. GPS route data is not transmitted to the assistant backend or to external AI services.
Health data (steps, sleep, active energy)
If you connect Apple Health (iOS) or Health Connect (Android) in the training area, the app reads your step count, sleep duration, and active energy for the current day to display them directly in the training area. Without Cloud Sync enabled, this data stays only on your device. If you have Cloud Sync enabled, it is stored encrypted in Firebase Firestore like other app files so it can be synchronized across your devices; you can additionally set up end-to-end encryption for it, so that this data can only be decrypted by your trusted devices. We do not transmit this data to the assistant or to third parties. You can withdraw access at any time in the Apple Health or Health Connect settings and disable Cloud Sync in the app settings.
Assistant, voice, and interaction data
Text inputs you send to the Starpolar assistant
Images you deliberately attach to an assistant request, such as photos or screenshots of todo lists, schedules, meal plans, shopping lists, or training plans
Assistant generated replies, suggestions, preview, confirmation and discard states, and assistant actions that are executed for you
Reduced context data from your current assistant session, such as your last message, the last assistant reply, last action, date, and a compact structured item where needed to process your request
Assistant settings such as enablement status, context memory, confirmation mode, and your selection regarding optional use of redacted or pseudonymized assistant samples
Assistant feedback such as thumbs up or thumbs down ratings on individual assistant replies
Recent assistant history stored locally in encrypted form on your device to continue your session and show the current chat
Voice input and transcripts
If you use assistant voice input, your operating system or the speech recognition service available on your device processes microphone input to generate a transcript
We process the resulting transcript like a normal assistant text input
Persistent storage of raw microphone audio by Starpolar for normal assistant use is not intended, but platform or device providers may process speech or diagnostic data under their own terms and settings
Affiliate links, discount codes, and promotions
If you use an affiliate link, QR code, discount code, giveaway, or similar promotion, we process the data required to handle and secure that promotion. This may include your user ID or account identifier, the affiliate or campaign code, click or claim time, source URL or deep link where available, store and subscription events, product and purchase identifiers, attribution status, commission status, and technical security information. For affiliate claim logging and rate limiting, we use hashed identifiers such as hashed IP or device-risk signals where available; raw IP addresses are not intended to be stored in affiliate claim logs.
Technical and diagnostic data
Basic technical data needed to deliver and secure the website
Crash and performance diagnostics where available and enabled
Email delivery and unsubscribe events
Session storage entries used to remember temporary interface preferences during your current visit
Technical security headers and signals such as Firebase ID tokens and device risk signals where used to secure API requests
4. Purposes
We process personal data for the following purposes.
- Operate and secure the website and app
- Respond to inquiries and provide support
- Send newsletters and product updates when you subscribe
- Improve reliability, performance, and usability, including troubleshooting
- Validate subscriptions and feature access
- Process discount codes, affiliate links, giveaways, and related promotions, including attribution, abuse prevention, store purchase validation, commission calculation, and campaign reporting
- Provide Filesync for Starpolar Plus, including encrypted cloud synchronization, device management, and deletion of Filesync cloud data
- Track route, distance, speed, and pace during GPS-enabled cardio training sessions
- Display your step and sleep data from Apple Health or Health Connect in the training area and, if you enable Cloud Sync, synchronize it encrypted across your devices
- Account security and abuse prevention, including login and device logging
- Provide the Starpolar assistant, including analyzing your inputs, generating replies, showing previews, and executing requested actions
- Convert voluntarily started voice input into text for assistant use
- Optionally use redacted and reduced assistant samples to improve intent recognition and response quality where you explicitly enable this
5. Legal Bases
Where required under applicable law, we rely on one or more of the following legal bases.
Contract or steps prior to entering a contract
For example account services and support
Consent
For example newsletters or non essential product communications
Legitimate interests
For example security, fraud prevention, service improvement
Specific allocations
Nutrition, macro, food intolerance, and connected health data that reveal or may reveal health information: separate explicit consent under Art. 6(1)(a) and Art. 9(2)(a) GDPR
Providing nutrition and macro data is optional. You can use core planning features without entering this information. You can withdraw consent at any time with future effect.
If you withdraw consent, we stop using this data for calculations. In the app settings, you can disable synchronization and delete nutrition data. You can also delete all app files there, while complete deletion of account associated data requires account deletion.
Assistant functionality and assistant context processing: contract or steps prior to entering a contract and/or legitimate interests in providing a secure and functional service
Voluntary voice input: your active use of the voice feature and, where required, consent or the device permissions you grant
GPS location access for cardio training: your active use of the GPS tracking feature and the device location permissions you grant
Health data (steps, sleep, active energy): separate explicit consent under Art. 6(1)(a) and Art. 9(2)(a) GDPR. Apple Health or Health Connect permission is an additional technical control, not the sole legal basis. Cloud Sync includes this data only within the scope of that consent. You can withdraw consent in Starpolar and revoke device access at any time.
Optional use of redacted or pseudonymized assistant samples: consent
Login and security logs: legitimate interests
Affiliate attribution, discount-code security, promotion abuse prevention, and commission records: contract or steps prior to entering a contract where a promotion is used, legitimate interests in security and abuse prevention, and legal obligations where records are needed for accounting or tax purposes
Newsletter: consent
Where we rely on consent, you can withdraw it at any time with future effect.
6. Website Hosting and Delivery
Our website is hosted and delivered via Netlify. Netlify processes technical data necessary to deliver the website, maintain security, and ensure performance.
Website analytics, videos and local storage
Cloudflare Web Analytics loads only after you allow “Website analytics”. It measures page views, referrers, general device and country information and loading times without analytics cookies, fingerprinting or cross-site visitor profiles. The provider is Cloudflare, Inc. The legal basis is your consent (Art. 6(1)(a) GDPR). Analytics stays disabled without consent.
External YouTube videos load only after you allow “External videos”. The provider is Google Ireland Limited; connection data including your IP address may be transmitted to Google and information may be stored on your device. International transfers are possible; see section 12. The legal basis is your consent (Art. 6(1)(a) GDPR). The embedded player stays disabled without consent.
Your choices are stored in your browser’s local storage under starpolar_privacy_choices and used for up to 180 days. Expired entries are removed on your next website visit. We ask again after that period or when the choice version changes. Use “Cookie settings” in the footer to enable categories separately or withdraw consent at any time with future effect. Withdrawal does not undo earlier transfers. If your browser prevents storage, your choices apply only until your next page visit.
Necessary features including the cart, selected language and currency, security checks and storage of your privacy choices remain available. These use local or session storage and the website cache. A local cart preview stores product variants, quantities, images and prices and is used for previews for up to 30 minutes; it does not store customer names, addresses or payment details. The selected shop currency is also stored in the first-party cookie starpolar_shop_currency for up to one year. Language, cart ID and item count remain in local storage until replaced or removed. You can delete these entries through your browser’s website-data settings. Your choices control optional website analytics and embedded videos; they do not disable necessary hosting, security or order processing, or services in the external Fourthwall checkout.
External icon delivery
Our pages load icon resources from Font Awesome (Fonticons, Inc.) and Flaticon/UIcons (Freepik Company). These providers receive technically necessary connection data such as IP address, request time, requested resource, and browser or device information. The legal basis is our legitimate interest in consistent, secure website navigation and presentation (Art. 6(1)(f) GDPR).
6a. Online Shop and Fourthwall
Our online shop retrieves product information, prices, and availability from Fourthwall through our website infrastructure. Product images may load directly from Fourthwall domains and its CDN. Fourthwall then receives technically necessary connection data such as your IP address, request time, requested file, and browser or device information.
When you create a cart, we store its technical identifier and your selected currency in your browser's local storage. The cart identifier, product variants, and quantities are sent to the Fourthwall Storefront API through our shop endpoint. This keeps the cart available between visits. You can remove the locally stored information by clearing website data in your browser.
When you continue to checkout, you connect directly to Fourthwall. Fourthwall is the seller and merchant of record for Fourthwall catalog products and processes data including your name, contact details, billing and delivery address, order information, payment data, taxes, promotional codes, shipping data, and information about support cases, cancellations, withdrawal statements, returns, refunds, and complaints. An online withdrawal record may include the content of the statement and its submission date and time. Fourthwall uses this data to prepare, process, and fulfil the purchase and to meet its own legal obligations.
The legal bases are Art. 6(1)(b) GDPR for steps before entering a contract and contract performance, Art. 6(1)(c) GDPR for legal obligations, and Art. 6(1)(f) GDPR for secure and functional shop delivery. Depending on the processing activity, Fourthwall acts as an independent controller or as a service provider acting on our behalf. See the Fourthwall shop Privacy Policy for more information.
7. Forms and Contact Requests
When you contact us using our contact or feedback forms, we process the submitted name, email address, message, and related form fields to handle your request and communicate with you. Submissions may additionally be recorded through Netlify Forms and are transmitted through Resend for email delivery to Starpolar. Newsletter enrollment occurs only through a separate newsletter form and explicit consent.
Spam protection
Contact and feedback forms use a computational challenge that your browser solves in the background. The challenge is created and verified on our own website infrastructure. No form data is sent to an external captcha provider for this check. The legal basis is our legitimate interest in securing our forms and preventing abuse (Art. 6(1)(f) GDPR).
8. Newsletter and Email Delivery
If you subscribe to our newsletter, we process your email address and subscription status, including subscribe and unsubscribe events, and technical delivery information. We use Resend to manage contacts and send emails.
To document your consent, we record the consent wording and version, date and time, language, signup source, and email address. The checkbox is not preselected. Subscription becomes effective when you actively submit the form with consent.
Unsubscribe
You can unsubscribe at any time via the unsubscribe link in each newsletter email. After you unsubscribe, we retain newsletter data for 6 months and then delete it completely.
9. Assistant and AI-assisted processing
After you enable the Starpolar Assistant, your text or voice transcript and limited compact context needed for the current request are sent to Starpolar's Assistant backend and from there to Mistral AI. This allows the request to be interpreted, answered, and, where applicable, prepared as an app action or preview. Images and documents are transmitted only when you deliberately attach them. They can contain personal data such as tasks, appointments, nutrition, finance, shopping, or training details. The full local app database and unrelated local files are not attached to every Assistant request.
Data sent to the Assistant backend and Mistral AI may include your input, deliberately attached content, language settings, timestamps, reduced context, technical security information, and your choice regarding optional use of reduced Assistant samples. Ordinary Starpolar service logs store a request fingerprint, length, outcome, latency, and token usage rather than the full input text.
When you request a spoken answer, our backend sends the generated reply text, the German or English reply language currently selected by Starpolar, and your selected voice to Cartesia for text-to-speech generation. The resulting audio is available only to your authenticated session. Starpolar keeps its temporary server copy for up to one hour. This limit describes Starpolar's storage, not separate retention by Cartesia. Microphone input is first transcribed by the speech-recognition service available on your device. Starpolar then processes the transcript like typed Assistant input.
Assistant requests, including images, may be screened for abuse and safety violations. We may refuse processing where content appears to violate Starpolar's Terms or provider safety policies.
If you enable the optional training permission, redacted and reduced assistant samples as well as your positive or negative ratings on assistant replies may be used to improve intent quality and assistant performance. If this permission is disabled, we do not use your assistant content for that optional improvement purpose.
The in-app Assistant-improvement setting controls Starpolar's own reduced technical samples and related feedback. It does not change Mistral AI's provider controls. Under Mistral's paid commercial API terms, API content is not used for model training unless an applicable opt-in or other stated exception applies. Mistral may retain stateless API inputs and outputs for up to 30 rolling days for abuse monitoring unless Zero Data Retention is active. Starpolar therefore treats provider-side retention as up to 30 days unless Zero Data Retention is contractually confirmed.
Cartesia's public terms permit use of inputs, outputs, and service interactions to improve its models until an eligible training opt-out is processed; Cartesia also advertises optional Zero Data Retention. Starpolar therefore treats submitted reply text and generated audio as eligible for provider retention and model improvement unless and until Cartesia confirms the relevant opt-out or Zero Data Retention configuration. The in-app setting does not change that provider configuration.
9.1 Recipe sharing and moderation
Private recipes stay in the app storage and optional Filesync described above. Family recipes, including the required image, are end-to-end encrypted for the selected household; our server stores encrypted content and access metadata but cannot read the recipe or image. Public recipes are server-readable and include the recipe text, required image, stable recipe ID, internal owner account ID, versions, moderation status, timestamps, reports, appeals, favorites, aggregated impressions, and swipe reactions. Other users receive no owner or household identifier.
Before a public recipe appears, we check its text locally on our backend and send the recipe text and image to Mistral AI using the moderation service. We do not include your user or household ID in that moderation request. Mistral AI may process this content in the EEA or in other configured processing locations under its data-processing terms, applicable transfer safeguards, and subprocessor arrangements. A provider outage prevents a new public version from being published; the local recipe and any previously approved public version remain available as described in the app.
We use owner and access data to perform the contract, protect the service, prevent abuse, handle notices and appeals, and comply with legal obligations. Favorites and aggregated interaction signals support ranking and discovery. On account deletion public recipes are hidden during the 30-day restore period, then recipe data, favorite attribution, and images are deleted. Limited moderation event metadata is anonymised after no more than 180 days unless law or legal claims require otherwise.
10. Google Calendar and Google API Services (Limited Use)
Starpolar can optionally connect to your Google Calendar. If you enable this connection, Starpolar requests read-only access to your Google Calendar (Google OAuth scope "calendar.readonly"). Starpolar then receives your calendar list (calendar names and identifiers) and event data (such as event title, times and dates, duration, all-day and recurrence information) for the periods shown in the app.
This Google user data is retrieved directly from Google's servers to your device. It is used solely to display your Google Calendar events alongside your Starpolar schedule and to support user-facing scheduling features such as conflict-aware planning. Google Calendar data is cached temporarily on your device and is not stored on Starpolar servers; imported events are also not included in Starpolar's Filesync. Only if you edit an imported event in Starpolar is a separate Starpolar entry created from it, which is then treated like any other Starpolar entry (stored locally and, if you use Filesync, synced as described in this policy).
We do not sell Google user data. We do not use Google user data for advertising, for credit or lending decisions, or to develop, improve, or train generalized artificial intelligence or machine learning models. We do not share, transfer, or disclose Google user data to third parties, except in the following limited cases: if you actively use the Starpolar assistant and details of your schedule are part of your assistant conversation or its compact session context, those details may be processed by Starpolar's Assistant backend and by Mistral AI to answer your request, as described in Section 9; where disclosure is necessary for security investigations or abuse prevention; or where required to comply with applicable law. Human access to Google user data only takes place with your explicit consent, where necessary for security purposes or legal compliance, or where the data has been aggregated and anonymized.
Starpolar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Calendar at any time in the app's schedule settings, which removes the cached calendar data from your device. You can additionally revoke Starpolar's access in your Google account permissions.
11. Recipients and Processors
Netlify processes data for website hosting and form handling. With your consent, Cloudflare, Inc. processes aggregated, cookieless website analytics. Contact-form proof of work runs on our own website infrastructure. Resend processes newsletter delivery and transmits contact and feedback messages to Starpolar. Fonticons, Inc. (Font Awesome) and Freepik Company (Flaticon/UIcons) process technical connection data when their icon resources are loaded. Fourthwall, Inc. (United States) provides the product catalog, cart, and checkout and processes order, payment, shipping, tax, support, cancellation, withdrawal, return, refund, and complaint data for Fourthwall catalog products. Our production app APIs and assistant backend are operated on Hetzner servers located in Germany; test environments may currently use OCI servers. Firebase is used for authentication, synchronization, and crash or diagnostic services where enabled. Mistral AI processes Assistant inputs, deliberately attached content, and limited Assistant context for interpretation, moderation, and response generation. Mistral AI is a French provider and acts as a processor under its commercial Data Processing Addendum where applicable. Its terms allow subprocessors and safeguarded international transfers, including Standard Contractual Clauses where required. For the paid stateless API, provider retention is treated as up to 30 rolling days unless Zero Data Retention is confirmed; commercial API content is not used for training unless an applicable opt-in or stated exception applies. Cartesia AI, Inc. is a United States provider and processes generated Assistant text, reply language, voice selection, and generated audio when spoken output is requested. Until Cartesia confirms an eligible opt-out or Zero Data Retention configuration, its public terms permit provider-side retention and model improvement using inputs and outputs. Processing in the United States or by subprocessors requires the applicable data-processing terms and transfer safeguards. Apple and Google process App Store or Google Play purchases, offer codes, promo codes, billing, renewals, cancellations, and refunds under their own terms. Google processes data for Google Play testing and may also process speech or diagnostic data depending on your device and platform configuration. Affiliate partners generally receive only aggregated or pseudonymous campaign and commission information unless more detailed disclosure is legally required or separately agreed with appropriate safeguards. We use processors under appropriate data processing terms and safeguards where required, including data processing agreements where applicable. For recipe search, search queries and dietary preferences or food intolerances from your profile may be transmitted to Spoonacular (recipe API, USA); recipe queries may be translated via DeepL (translation API, Germany/EU); German recipes may be sourced through Gustar via RapidAPI (USA/Germany). For finance features, security identifiers (ticker symbols, ISINs) may be transmitted to Marketstack (market data API, USA) and OpenFIGI/Bloomberg (identifier mapping, USA). For product search and barcode scanning, search queries and barcodes may be transmitted to Open Food Facts (open product database, non-profit, France).
12. International Transfers
Recipients or subprocessors outside the EU or EEA may include Fourthwall, Cartesia, and processing locations used by Netlify, Cloudflare, Firebase/Google, Oracle, Resend, Font Awesome, RapidAPI, Marketstack, OpenFIGI/Bloomberg, Mistral, and their subprocessors. Where an EU adequacy decision applies, we rely on that decision, including the EU-US Data Privacy Framework only where the recipient's current certification covers the relevant processing. Otherwise, we use the European Commission's Standard Contractual Clauses, applicable data processing terms, and supplementary measures following a transfer assessment. You can request a copy or meaningful summary of the applicable safeguards at hello@starpolar.app. Locations and mechanisms may change with a provider's subprocessor list; material changes will be reflected here.
13. Retention
We retain personal data only as long as necessary for the purposes described.
Contact requests
We retain contact requests for 6 months. In specific cases, we may retain certain records for longer if they are reasonably necessary to establish, exercise, or defend legal claims, to investigate abuse, or to comply with legal obligations.
Newsletter
We retain newsletter data until you unsubscribe and for 6 months after unsubscribing. After that period, we delete it completely.
Health data (steps, sleep, active energy)
Without Cloud Sync enabled, we do not store this data on our servers; it is read directly from Apple Health or Health Connect each time and shown only on your device. If you enable Cloud Sync, it is stored encrypted in Firebase Firestore like other app files until you delete it or disable Cloud Sync.
Affiliate, discount-code, and commission records
Affiliate and promotion records are retained as long as reasonably necessary for attribution, abuse prevention, campaign reporting, commission calculation, accounting, tax documentation, and the establishment, exercise, or defense of legal claims. Claim-attempt and rate-limit logs are kept only for a limited period unless longer retention is necessary for abuse investigation, security, or legal defense.
Access logs
30 days.
Login and device logs
30 days.
Restricted or blocked accounts
A restriction does not itself delete account, local, or Filesync data. We retain the account status and the minimum security or abuse records needed to enforce the restriction, investigate incidents, handle review requests, meet legal duties, and defend claims. Ordinary security logs remain subject to the periods above unless a documented incident or legal reason requires limited longer retention. You may still request access or deletion by contacting us, subject to identity verification and lawful exceptions.
Local assistant history on your device
Recent assistant history is stored in encrypted form locally on your device and is retained by default only for short session continuity. The currently implemented local retention period is up to 2 hours unless you clear the chat earlier.
Assistant context and assistant replies on our systems
We retain assistant content on our systems only as long as necessary to provide the service, maintain security, troubleshoot issues, prevent abuse, and support the purposes described in this policy. If you have not enabled the optional training permission, we do not use assistant content for the optional quality improvement purpose based on redacted or pseudonymized samples.
Optionally permitted redacted or pseudonymized assistant samples and feedback
If you enable the relevant permission, redacted and reduced samples and your assistant feedback are currently generally retained for up to 90 days and may be used for quality improvement and evaluation. After that, we delete or anonymize the data unless a shorter period applies or limited longer retention is strictly necessary for security, abuse prevention, or legal reasons. After withdrawal, we stop using new content for that purpose.
Account deletion and restore grace period
If you delete your Starpolar account, we keep account associated data for 30 days to allow account restoration. After this 30 day period, the account can no longer be restored and a further technical deletion period of up to 30 days begins. Within no more than 60 days from the verified deletion request, we delete the remaining account data from our servers and synced Firebase storage, including subscription and entitlement information, unless limited retention is strictly necessary for legal obligations or the establishment, exercise, or defense of legal claims.
The 60 day maximum timeline starts when we receive a verified deletion request.
Filesync after Starpolar Plus expires
If Starpolar Plus ends, Filesync is blocked immediately. You can no longer upload, download, list, or delete Filesync cloud data. Local data in the app remains unchanged. Filesync cloud data is not deleted immediately. It is generally fully removed from Firebase Firestore 30 days after the known Plus expiry date, including active files, deletion markers, sync metadata, and the Filesync user root document. This period applies regardless of whether optional end-to-end encryption was enabled. Decryption is not required for deletion. Automatic deletion only applies where we know an actual Plus expiry date; for accounts without a known expiry date, this automatic deletion rule is not applied to avoid accidental deletion.
Deletion in app settings
In the app settings, you can disable synchronization, delete nutrition data, and remove all app files stored through the app. You can also delete Filesync cloud data through a trusted device and remove or block Filesync devices. These actions affect the relevant app data and synced copies, but they do not by themselves delete your Starpolar account. Complete deletion of account associated data requires account deletion.
Server-side security logs are deleted independently after 30 days, unless an exception applies for abuse investigation or legal defense.
Limited retention for legal protection and abuse prevention
In exceptional cases, we may retain a limited subset of information beyond the periods above where it is reasonably necessary to establish, exercise, or defend legal claims, to investigate fraud or abuse, or to comply with legal obligations. Where possible, we will minimize what is retained and restrict access.
14. Your Rights
You have the right to access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests. Where we rely on consent, you can withdraw consent at any time with future effect.
If you are located in Austria, your supervisory authority is the Austrian Data Protection Authority (Datenschutzbehörde).
15. Security
We use reasonable technical and organizational measures to protect personal data, including encryption in transit and access controls.
Filesync data is stored encrypted in Firebase Firestore. If you enable optional end-to-end encryption, we cannot decrypt your Filesync content. At least one trusted device must remain connected for that feature. If you lose or remove all trusted E2E devices, we cannot restore access to the encrypted Filesync data.
16. Contact
For privacy requests, contact hello@starpolar.app or use the contact form.
Company website: gabriel-battlogg.com
To withdraw consent, a short message to hello@starpolar.app is sufficient.
For deleting nutrition data, removing all app files, clearing assistant chat, or disabling synchronization, use the options in the app settings.
For Filesync, use the app settings to remove or block Filesync devices and to delete Filesync cloud data through a trusted device. If you no longer have access to a suitable device or your account, contact us at hello@starpolar.app. We may require verification of account ownership before providing support or deleting data.
To request account deletion, use the in-app deletion option where available. If you cannot access the app, email hello@starpolar.app from the email address linked to your account.
We may need to verify your identity before fulfilling deletion requests. If you no longer have access to the linked email address, we may require alternative proof of account ownership. If verification is not possible, we may be unable to fulfill the request.
17. Changes
We may update this Privacy Policy to reflect changes in features, providers, or legal requirements. The date at the top indicates the current version.