Legal · Privacy

Your data, in your file.

She remembers your color season and your travel budget — not so we can sell it. Here's exactly what Staitmint collects, how it's used, who sees it, and how to take it all back.

Effective June 8, 2026 · Version 1.1

Staitmint is an AI personal assistant built around four agents — Style, Travel, Fitness, and Lifestyle — that learn your preferences and connect to services like Spotify, Google Calendar, Amadeus, and Google Places to return real, actionable results. This Privacy Policy explains what personal information Staitmint, Inc. ("Staitmint," "we," "us," or "our") collects when you use the Staitmint mobile app or visit staitmint.io, how we use it, and the choices you have. It is designed to satisfy applicable privacy laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and the Apple App Store privacy guidelines.

01Overview — the short version.

Real talk, no dark patterns:

  • We don't sell your personal information. Ever. Not to advertisers, not to data brokers, not to anyone.
  • We don't use your chats, photos, or saved items to train AI models. Your conversations are yours.
  • Connected services use standard OAuth. We never see your Spotify, Google, or other passwords.
  • Conversations, photos, and saved facts are encrypted at rest and transmitted over TLS.
  • You can delete your account and all associated data in one tap from inside the app.

02Information we collect.

We collect only what we need to make the four agents useful for you. The categories below describe what is collected, how it's collected, and why.

Account informationProvided by you
Email address, display name, password hash (we never store your plaintext password), and any profile preferences (color season, sizes, dietary notes) you choose to add. Required to create and operate your account.
Conversation contentProvided by you
Messages you send to any of the four agents, plus the agent's replies. This includes any text, voice transcripts, or commands. Stored encrypted at rest and tied to your account so the assistant has context across sessions.
User photos & uploadsProvided by you
Photos you submit for color analysis, outfit rating, or wardrobe building. Other files you choose to upload. Photos are processed for the requested feature and stored encrypted in your private library; you can delete any item at any time.
Connected‑service dataProvided by you (OAuth)
When you connect Spotify, Google Calendar, or other services, we receive scoped tokens and the specific data those services return (e.g., your top tracks, your upcoming events). We never see your passwords. You can disconnect any service at any time.
Approximate locationWith your permission
If you ask for nearby studios, restaurants, or local recommendations, we use the device location you provide or your typed city. Precise location is requested only when needed and only for the duration of that task. You may deny or revoke this permission anytime in your device settings.
Device & usage dataCollected automatically
Device type, operating system version, app version, language, time zone, crash logs, performance metrics, and feature usage (e.g., which agent you opened). Used to keep the app stable and improve the experience. Identifiers are pseudonymous.
Diagnostics & logsCollected automatically
Error reports, latency measurements, and API call metadata. Used solely to diagnose problems and improve reliability. We do not collect IDFA for advertising.
Payment informationIf you subscribe
Subscriptions are processed by Apple (App Store) or Google (Play Store). Staitmint receives a subscription receipt and status — we never receive or store full card details.
Support communicationsIf you contact us
If you email or message us, we keep your messages and our replies so we can help and improve our service.
Sensitive data
Health, biometric, financial, or precise location data is not requested or used beyond what is strictly necessary to deliver a feature you've asked for (e.g., a fitness studio near you). We do not infer race, religion, sexual orientation, political opinions, or health conditions from your inputs, and we do not process biometric identifiers.

03How we use it.

We use the information described above only for these purposes:

  • Deliver the product. Run the four agents, route your messages, fetch live flights and hotels, surface studios near you, generate playlists, and remember your preferences across conversations.
  • Personalize results. Use the facts you've shared (your color season, your travel budget, your dietary notes) so answers actually fit you. You can view and edit every fact on your "About You" screen.
  • Operate connected services. Use scoped OAuth tokens to read or write to services you've connected — e.g., to create a Spotify playlist or check your Google Calendar availability.
  • Keep the app secure and reliable. Detect abuse, prevent fraud, debug crashes, and improve performance.
  • Communicate with you. Send transactional messages (sign-in, billing, security), respond to support, and — only with your consent — send product updates.
  • Comply with the law. Meet our legal, regulatory, and tax obligations.

05Third‑party services.

To return real results — actual flights, actual playlists, actual studios — Staitmint integrates with the services below. Each is governed by its own privacy policy. We share with each provider only the minimum data needed to deliver the feature you've requested.

S Spotify

Playlist creation, music search, top tracks. OAuth scopes you approve.

G Google Calendar & Places

Calendar sync, conflict detection, restaurant and studio search.

A Amadeus

Live flight and hotel pricing, availability, and booking links.

C ClassPass & Mindbody

Studio discovery and deep links to class booking.

AI AI model providers

We use enterprise AI APIs (e.g., OpenAI, Anthropic) under zero‑data‑retention or short‑retention agreements. Providers are contractually prohibited from training on your inputs.

C Cloud infrastructure

AWS / Google Cloud for hosting, storage, and database. Data encrypted at rest and in transit.

P Apple & Google (payments)

App Store and Play Store handle subscription billing. We receive subscription status, never card details.

D Diagnostics

Crash and performance monitoring (e.g., Sentry). Pseudonymous device and error data only.

You can disconnect any third‑party service from Settings → Connections at any time. Disconnecting revokes our access and removes related cached data.

06iOS permissions & tracking.

Staitmint requests system permissions only when a feature actually needs them, and only the minimum scope to deliver that feature. You may grant, deny, or revoke each permission anytime in iOS Settings → Staitmint. Denying a permission disables the specific feature that uses it but does not otherwise limit the app.

Photo libraryWhen you upload a photo
Used for color season analysis, outfit feedback, and wardrobe items. iOS prompt: "Upload photos for style analysis." We access only the photo you choose for the action.
CameraWhen you take a photo in‑app
Used for taking style photos directly in the app. iOS prompt: "Take photos for style analysis."
Location (when in use)For nearby search
Used to find studios, restaurants, and experiences near you. iOS prompt: "Find nearby studios and restaurants." We do not access location in the background and do not collect precise location persistently.
NotificationsFor reminders
Used to deliver reminders you create and important account messages (e.g., sign‑in alerts). You can disable any notification category in iOS Settings without affecting the rest of the app.
Calendar accessVia Google Calendar OAuth
When you connect Google Calendar, the Lifestyle agent reads upcoming events to check availability and surface conflicts. Granted via OAuth scope, not the system Calendar permission, so we never read your iOS Calendar app data.
App Tracking Transparency (ATT)
We do not present the ATT prompt because we do not track you across other companies' apps or websites. We do not collect the Identifier for Advertisers (IDFA). We do not share data with advertising networks, data brokers, or any party that operates cross‑app or cross‑site identifiers. Under Apple's definitions, no Staitmint data is "used to track you."

07Subscriptions & billing.

Staitmint offers a free tier and an optional Staitmint Pro subscription. Subscriptions are sold and processed by Apple (App Store) or Google (Play Store) — Staitmint never sees, stores, or transmits your full payment card details, billing address, or CVV.

  • Auto‑renewal. Subscriptions renew automatically at the end of each billing period at the then‑current price unless auto‑renewal is turned off at least 24 hours before the renewal date in your App Store or Play Store account settings.
  • Cancellation. Cancel anytime in your App Store or Play Store subscription settings. Your subscription remains active until the end of the paid period; we do not pro‑rate refunds for unused time, and we do not retain billing‑method access after cancellation.
  • Free trials. If a free trial is offered, it converts to a paid subscription at the end of the trial unless you cancel before the trial ends. The cancellation deadline is shown at purchase.
  • Refunds. All refund decisions are handled by Apple or Google under their respective policies. Staitmint can direct you to the right help article but cannot issue store refunds directly.
  • What Staitmint receives. A subscription receipt and an entitlement status (e.g., active, in trial, expired, billing retry). We do not receive the card number, expiry date, CVV, billing address, or any other payment instrument.
  • Price or term changes. We will notify you in‑app and by email before any price increase or material change to subscription terms takes effect, and you may cancel before the change applies.

08Sharing & disclosure.

We share personal information only in these specific cases:

  • With service providers who help us operate Staitmint, under written data‑protection agreements that prohibit using your data for any other purpose.
  • With services you've connected, but only as needed to fulfill the action you've asked for (e.g., creating a playlist in your Spotify account).
  • For legal reasons — to comply with applicable law, valid legal process, or enforceable government request, and to protect the rights, property, or safety of Staitmint, our users, or the public.
  • In a business transfer — if Staitmint is involved in a merger, acquisition, or asset sale, your data may be transferred subject to the protections in this policy. We will notify you of any change in ownership or material change in how your data is handled.
We do not sell your data
We do not sell or "share" personal information as those terms are defined under California, Virginia, Colorado, Connecticut, or other U.S. state privacy laws. We do not engage in cross‑context behavioral advertising.

09AI & model training.

Staitmint uses large language models and vision models to power the four agents. Here's how that works in plain language:

  • Your conversations and photos are not used to train our models or any third‑party model. We contractually require our AI providers not to retain or train on your inputs.
  • Personalization is not training. The facts the assistant remembers about you (your color season, your travel preferences) are stored in your account so future answers fit you. They are not used to modify any model.
  • Aggregate, anonymized analytics (e.g., "what percent of users open the Travel agent in a session") may be used to improve the product. These cannot identify you.

10Data retention.

We keep your personal information only as long as we need it for the purposes described above:

  • Account & conversation data — kept while your account is active. You may delete individual chats, individual saved facts, or your entire account at any time from inside the app.
  • Photos & uploads — kept while saved in your library. Deleted items are permanently removed from active systems within 30 days.
  • Connected‑service tokens — held until you disconnect the service, then revoked and deleted.
  • Diagnostics & logs — retained for up to 90 days, then deleted or fully anonymized.
  • Billing records — retained as required by tax and accounting law (typically up to 7 years).
  • Backups — deleted data may persist in encrypted backups for up to 35 days before being fully purged.

11Account & data deletion.

You can delete your Staitmint account and all associated personal data from inside the app at any time. This satisfies Apple's in‑app account deletion requirement for App Store apps.

In the app
Settings → Account → Delete Account → confirm. Deletion is permanent and cannot be undone.

When you delete your account, the following happens:

  • Conversations, saved facts, photos, wardrobe items, and reminders are queued for permanent deletion.
  • OAuth tokens for every connected service are revoked immediately. The connected providers (Spotify, Google, etc.) are signaled to drop our access.
  • Your account is deactivated immediately. You can no longer sign in, and your email is released for future re‑registration after a brief cooling‑off window.
  • Personal data is purged from active systems within 30 days. Encrypted backups containing the data are rotated out within 35 days.
  • Aggregated, fully anonymized analytics (which cannot identify you) and records we are legally required to keep (e.g., billing receipts for tax purposes) may be retained as described in Section 10.

Prefer not to delete from the app? Email privacy@staitmint.io from the address on your account. We will verify your identity and complete deletion within 30 days, in line with applicable law.

12Security.

We protect your data with the following safeguards:

  • Encryption in transit using TLS 1.2 or higher for every connection between the app and our servers.
  • Encryption at rest for conversations, photos, saved items, and OAuth tokens.
  • Scoped OAuth for every connected service — we never see or store your passwords for Spotify, Google, or other providers.
  • Least‑privilege access — only a small number of trained personnel can access production systems, and access is logged.
  • Regular reviews — periodic security audits, dependency scanning, and penetration testing.

No method of transmission or storage is 100% secure. If we become aware of a security incident affecting your data, we will notify you and the appropriate regulators in accordance with applicable law.

13Your rights — always.

Depending on where you live, you have the rights below. Staitmint honors these for all users regardless of jurisdiction.

AAccess

See exactly what facts the assistant holds about you on the "About You" screen, and request a copy of your account data.

EEdit / Correct

Edit any saved fact directly in the app, or contact us to correct inaccurate information.

DDelete

Delete individual chats, individual facts, your photo library, or your entire account in one tap.

PPortability

Export your conversations and saved data in a machine‑readable format on request.

RRestrict / Object

Ask us to limit or stop certain processing of your personal information.

WWithdraw consent

Disconnect any service or revoke any permission at any time. This won't affect prior lawful processing.

NNon‑discrimination

We will never charge a different price or downgrade your service because you exercised a privacy right.

CComplaint

EU/UK users may lodge a complaint with their local data protection authority. We'd prefer you reach out to us first so we can resolve it.

To exercise any right, use the in‑app controls or email privacy@staitmint.io. We will respond within 30 days (or the period required by applicable law).

14Apple App Store privacy disclosures.

Apple displays a Privacy card on every App Store listing that describes what data the app collects and whether it is used to track you. The categories below match exactly what Staitmint has submitted to Apple. If you ever notice a discrepancy between Apple's card and what is stated here, this Privacy Policy controls — please email privacy@staitmint.io and we will reconcile within 30 days.

Data used to track youApple category
None. Staitmint does not collect any data used to track you across other companies' apps or websites. We do not collect IDFA. We do not share data with advertising networks, data brokers, or any cross‑app or cross‑site identifier service.
Data linked to youApple category
  • Contact info — email address (account)
  • User content — chat messages, uploaded photos, saved facts, wardrobe items, reminders (operating the four agents)
  • Identifiers — pseudonymous user ID (account linking, fraud prevention)
  • Usage data — which agents you open, feature interactions (product improvement)
  • Diagnostics — crash logs, performance metrics (stability)
  • Purchases — subscription receipt and entitlement status (Pro feature gating)
  • Location — coarse location, only when you use a location‑aware feature (nearby search)
Data not linked to youApple category
Aggregate analytics. Fully anonymized counts of feature use across all users (e.g., "what percent of sessions open the Travel agent"). Cannot be linked back to any individual user.
Account deletion
Per App Store guideline 5.1.1(v), Staitmint provides an in‑app account deletion path at Settings → Account → Delete Account. See Section 11 for the full deletion timeline and what happens to your data.

15Children.

Staitmint is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided personal information to us, please contact privacy@staitmint.io and we will promptly delete it.

16International transfers.

Staitmint is operated from the United States. If you use the service from outside the U.S., your information will be transferred to, stored in, and processed in the U.S. and in other countries where our service providers operate. For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses and additional safeguards required by applicable law.

17Changes to this policy.

We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app and update the "Effective" date at the top of this page. Continued use of Staitmint after a change indicates your acceptance of the updated policy. A history of changes is available on request.

18Contact us.

Questions, requests, or feedback about privacy at Staitmint? We'd love to hear from you.

Staitmint, Inc.

Privacy & Data Protection

Response within 30 days