Effective 2026-08-18

Privacy policy

Who we are

Stresfri Ltd operates the Stresfri family calendar (web, iOS and Android). We are the controller of your personal data under UK GDPR and Nigeria NDPR.

Contact: privacy@stresfri.com

What we collect

  • Account: email, display name, avatar preferences.
  • Household: members you add (name, colour, emoji, birthday, role), the region and timezone you set.
  • Content you create: events, chores, habits, meals, lists, notes, photos on the wall display.
  • Loyalty ledger: points earned, converted, and settled in your household's own wallet.
  • Device data: push notification tokens (web and Expo), coarse network status, app version, crash reports.
  • Health integrations (opt in): only the metrics you explicitly authorise from Apple Health, Google Fit, Fitbit, Garmin or Oura.

We do not collect precise location, we do not sell your data to anyone, and we do not run third-party advertising in the app.

Children

Stresfri is designed for families. Adults create the account and add child members. Children under 13 must be added by a parent or guardian and their data is only visible to household members. Points and virtual wallet balances are not real money and never leave the app, settlement between family members happens offline.

How we use it

  • To deliver the service you signed up for.
  • To send reminders you asked for and product updates you opted into.
  • To keep the service secure, prevent abuse, and diagnose crashes.
  • To comply with legal obligations.

Where it lives

Your data is stored in Supabase (EU, Ireland) by default. All connections are TLS encrypted end to end. Push notifications are delivered via Firebase Cloud Messaging (Google, EU region) and Expo Push.

Subprocessors

We use the following third parties to deliver the service. The authoritative list, with contract terms, lives in the DPA. We give 14 days' notice before adding or replacing any subprocessor.

  • Supabase (Ireland / EU) โ€” primary database, auth, storage.
  • Cloudflare (global) โ€” Workers, CDN, DDoS protection.
  • Anthropic (United States) โ€” AI composer inference, under a zero retention data processing agreement. Your prompts and household rows are never used to train any model.
  • OpenAI (United States) โ€” Whisper audio transcription for the voice composer.
  • Resend (United States) โ€” transactional email delivery.
  • Sentry (United States) โ€” error monitoring, scrubbed of user PII.
  • Stripe (United States / Ireland) โ€” payment processing. We never see your card number.

Where transfers outside the EEA / UK are necessary (for example Anthropic in the US for AI inference), we rely on Standard Contractual Clauses and the UK IDTA, with supplementary measures per the EDPB Recommendations.

Your rights (GDPR / NDPR)

You have the right to:

  • Access a copy of your data (in app: Settings โ†’ Export my data).
  • Correct anything wrong.
  • Delete your account and all its data (in app: Settings โ†’ Delete my account).
  • Object to processing, restrict processing, or withdraw consent.
  • Lodge a complaint with the ICO (UK) or NITDA (Nigeria).

Deletion requests are processed within 30 days. Some records may be retained for legal or safeguarding reasons (e.g. Anti-fraud logs).

Cookies

We use a small number of first-party cookies for signing you in and remembering your theme. No third-party ad or tracking cookies.

Changes

When we update this policy we bump the effective date at the top and, for material changes, ask you to re-consent inside the app.