1. Who operates Stapla
Stapla is operated by Hawon Lee under the Stapla name. Hawon Lee is the person responsible for privacy inquiries and requests. You can contact us at privacy@stapla.stream.
2. Information we process
Account information. If you sign in with Apple, the account service receives your Apple account identifier, the email address Apple provides (which may be a private relay address), and the name you choose to share. The service uses authentication tokens to keep your account signed in. Refresh tokens are encrypted on the server; session tokens are stored as hashes.
Profile and body measurements. If you use profile features, Stapla processes your birth year, biological sex, height, weight, and any body measurements you choose to add, such as body-fat or skeletal-muscle measurements.
Food records. If you save food or meal entries, Stapla processes the food name, serving size, quantity, meal date, and nutrition values such as carbohydrates, protein, fat, and calories.
Photos and nutrition recognition. You may choose a food-label photo or use the camera to read nutrition information. Stapla uses Apple’s on-device text recognition for this task. The image is not sent to Stapla’s account server; only the food and nutrition details you choose to save are sent.
HealthKit and location. With your permission, Stapla can read workout records, workout routes, running or walking distance, heart rate, and active energy from Apple Health. While you record an outdoor run, the app can use your location to measure distance and create a route. Workout and route records created by Stapla are saved to Apple Health when you choose to save the workout. These HealthKit readings and route coordinates are processed on your Apple devices and are not uploaded to Stapla’s account server. They remain in Apple Health unless you remove them there.
Website request data. When you visit this website, its hosting provider may process your IP address, browser and device request information, timestamps, and security events to deliver and protect the site. The site does not ask for health information, does not use advertising or analytics trackers, and does not load third-party web fonts.
Messages to our privacy address. If you email us, we receive the sender and recipient email addresses, message, and any attachments you include. The address is routed by Cloudflare Email Routing to our designated inbox provider, which may process and store the message to deliver it. We use messages to respond and keep a record of the request.
3. Why we use information
- To create and secure your Stapla account and provide the features you request.
- To save and show your profile, food, and nutrition records.
- To connect with Apple Health only when you authorize access, and to record workouts you choose to save.
- To answer support and privacy requests, protect the service, and meet legal obligations.
We do not use health or fitness information for advertising, sell it, or use it to build advertising profiles.
4. When information is shared
Apple. Sign in with Apple is provided by Apple. Apple processes sign-in information under Apple’s own terms and privacy policy. HealthKit permissions and records are managed by Apple’s Health app and operating systems. Stapla does not send HealthKit readings to its account server.
Website hosting. The website is delivered through Cloudflare infrastructure. Cloudflare may process technical request and security information, including at network locations outside your country, to serve and protect the site.
Email routing. Messages sent to privacy@stapla.stream are forwarded by Cloudflare Email Routing to the inbox address designated by Hawon Lee. Cloudflare and the inbox provider may process message information to deliver and store correspondence.
Account hosting. Stapla’s production account server and database have not yet been deployed. Before the app becomes publicly available, this policy will identify the production hosting providers and processing countries, the information they process, and any cross-border transfer details or consent required by law.
We do not sell personal information. We may disclose information if required by law or necessary to protect a person’s safety, prevent fraud, or defend legal rights.
5. Retention and deletion
Account information, profile measurements, and food records are kept while your account is active. You can request account deletion in the app’s account settings after the service launches. Account deletion revokes the linked Apple refresh token and deletes the account and its server-stored records.
For an account-deletion retry, the service may keep a hash of the session token and the selected deletion reason for up to 24 hours. It retains daily, anonymous totals of account-deletion reasons for service improvement; these totals do not identify an account.
Deleting your Stapla account does not delete workout records already saved in Apple Health. You can remove those records in Apple Health. Local workout records stored by the app are removed when you delete your account through Stapla.
We keep privacy correspondence only as long as needed to respond, maintain an appropriate business record, or meet a legal obligation. Website security logs are handled by the hosting provider under its applicable retention practices.
6. Your choices and rights
You may request access to, correction of, or deletion of your account information, or ask us to restrict processing, by emailing privacy@stapla.stream. You may also withdraw HealthKit or location permission at any time in your Apple device settings. Revoking permission stops future access; it does not remove records already saved in Apple Health.
If you are in the Republic of Korea, you may exercise the rights available to you under the Personal Information Protection Act, including access, correction, deletion, suspension of processing, and withdrawal of consent. We will respond within the period required by applicable law.
7. Security
Stapla uses safeguards appropriate to the information it handles. The current account implementation stores refresh tokens encrypted and authentication session tokens as hashes. On Apple devices, the refresh token is kept in the system Keychain. No service can guarantee absolute security, so please protect access to your Apple account and device.
8. Children
Stapla is not designed for children to use independently. If a child needs to use the service, a parent or legal guardian must provide any consent required by applicable law and supervise the account.
9. Changes to this Policy
We will update this Policy when our information practices change. We will post the revised version here and update the effective date. Where required by law, we will give notice and obtain consent before a material change takes effect.
10. Contact
For privacy questions or requests, contact Hawon Lee at privacy@stapla.stream.