← Back to Stumbl

PRIVACY POLICY

Version 1.0 · Effective 20 April 2026

This policy describes how Stumbl collects, uses, stores, and protects your personal information when you use the Stumbl mobile application and the related website. If anything here isn't clear, email nick@stumbl.me and a human will reply.

1. Who we are

Stumbl is an unincorporated venture based in New South Wales, Australia, operated by Pete Reinke (founder) and Nick (Chief Financial Officer and Head of Support). Stumbl is currently in closed TestFlight beta, distributed only to users within Australia. No Australian Business Number has been registered at this stage.

For the purposes of the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), Stumbl is the entity that collects and holds your personal information.

  • Email: nick@stumbl.me
  • Post: 35 Wellington Street, Bondi Beach NSW 2026, Australia

2. What we collect

We only collect what's required to make the features you see work. Nothing is used for advertising. Nothing is sold. There is no third-party tracking.

2.1 Account information

  • Email address and password (passwords are hashed by Supabase Auth — we never see them in plaintext)
  • Display name and @username
  • Date of birth (used only to enforce the 13+ age gate and age-restricted experiences)
  • Avatar image (optional)

2.2 Optional profile information

Stored only if you fill them in: short bio, phone number, gender, marital status, home and work addresses, social-media handles (Instagram / Facebook / X / LinkedIn / YouTube / TikTok), emergency contact, and dietary preferences and food allergies.

Emergency-contact and allergy fields are held only in our database. They are never transmitted to any third party — including our AI provider — unless you explicitly send them by asking the AI assistant a question that references them (e.g. "what should I pack for someone with my allergies?").

2.3 Content you share in experiences

Inside an experience (a trip, festival, wedding, dinner, etc.) your crew sees what you share with them: photos, videos, chat messages, reactions, poll votes, schedule picks / RSVPs, expense amounts, comments, and any schedule items you create.

EXIF metadata is stripped from every photo on the server before storage — GPS tags, camera model, and original timestamps are removed so they're never exposed to other members.

2.4 Live location (opt-in, per-experience)

  • Raw GPS points broadcast to other members of that experience so the live map works.
  • Raw location points are automatically purged on a rolling 4-hour basis. Older points are deleted from our database.
  • You can turn off sharing per-experience at any time and the broadcast stops immediately.
  • "Incognito" mode hides your location from specific members while still letting you see theirs.

2.5 Fitness and health data (opt-in per integration)

  • Strava: we read activities you authorise via OAuth (distance, duration, type, route polyline). You can disconnect at any time in Settings.
  • Apple HealthKit: we read steps, distance, and workouts on-device. HealthKit data is read-only — we never write anything back to Health, and we never use Health data for advertising or any purpose other than displaying it in the app.

2.6 AI assistant messages

When you talk to Stumbl's AI assistant, your question and the relevant context (the experience you're in, schedule items, etc.) is sent to Anthropic's Claude APIto generate a reply. Anthropic's privacy policy is at anthropic.com/privacy.

We retain a copy of your AI conversation for up to 180 days for debugging and abuse prevention, after which it is automatically deleted. You can turn off AI features entirely in the Privacy Dashboard inside the app.

2.7 Voice dictation

If you tap the microphone in the AI bar, we use Apple's on-device Speech Recognition framework. Your voice does not leave your device. Only the resulting text is sent to our servers (and then to Anthropic, as above).

2.8 Push notifications

We store the push notification token issued to your device so we can deliver notifications. Tokens are passed to Expo's push delivery service to fan out notifications. Expo processes only the token and the notification payload.

2.9 Device and crash data

We collect limited device information for diagnostics: OS version, device model, app version, and crash reports. This is used internally to fix bugs. It is not linked to identifiers used by advertising networks.

2.10 Data Not Used to Track You

Stumbl does not ask you for App Tracking Transparency permission because Stumbl does not track you across other companies' apps or websites, does not share device identifiers with advertisers, and does not use any data to build advertising profiles. Stumbl qualifies for Apple's "Data Not Used to Track You" classification across every collected data category.

3. How we use your data

  1. Run the account, authentication, and experience-joining flows.
  2. Show your crew your photos, messages, location, schedule picks, and expenses — inside the experience you explicitly joined.
  3. Generate AI summaries, recaps, and assistant replies (when you ask for them).
  4. Send push notifications you've opted in to receive.
  5. Prevent abuse, enforce our Terms, and comply with law.
  6. Diagnose bugs and improve reliability.

We do not use your data for advertising. We do not sell it. We do not rank a feed algorithmically — your activity feed is purely reverse-chronological.

4. Who sees what

DataWho can see it
Your profile (display name, @username, avatar)Every member of an experience you join
Emergency contact, allergies, addresses, phoneOnly you (and, if you ask the AI, Anthropic)
Photos, videos, messages in an experienceMembers of that experience
Location (when sharing is on)Members of that experience, except those set to Incognito
Expense amounts and splitsMembers of the experience where the expense was added
AI conversation transcriptsOnly you, and Anthropic (for the generation call)
Fitness activitiesMembers of experiences where you chose to share them
Stumbl operators (Pete & Nick)Database-administrator access used only for support, debugging, and moderation enforcement. Access is logged.

5. Third parties we share data with

The full list of services Stumbl uses to run. Every other interaction with an external party is initiated by you (e.g. tapping a map to open directions in Apple Maps).

ProviderPurposeLocation
SupabasePrimary database, auth, file storage, realtime channels. Holds all account + experience data.Sydney, Australia
Anthropic (Claude API)AI assistant replies, recaps, summaries. Receives AI messages you send and their context.United States
ExpoPush notification delivery. Receives your push token and notification payload.United States
RailwayApplication server hosting. Transient request data passes through, not stored.United States
MapboxMap tile rendering. Receives approximate coordinates for tile lookup.United States
Strava (opt-in)Import fitness activities. OAuth token + activities you authorise.United States
Apple HealthKit (opt-in)Read steps + workouts on-device. Never sent to our servers without aggregation.On-device
Apple Speech RecognitionVoice-to-text for AI bar. Voice never leaves device.On-device
OpenWeatherWeather forecasts. Approximate coordinates only.United States
OpenStreetMap / NominatimReverse geocoding for place names. Approximate coordinates only.European Union
Google (Places, Calendar — opt-in)Place search + geocoding for locations; Google Calendar sync when you connect it. Receives place queries/coordinates and, for calendar sync, an OAuth token.United States
Postmark (opt-in)Inbound email forwarding — when you forward a booking to your Stumbl inbox, the message is received and parsed to add it to a trip.United States
Deezer, iTunes SearchPublic artist metadata for festival lineups. No user data.United States / France

We do not use Google Analytics, Facebook Pixel, Meta SDK, or any other third-party analytics, advertising, or tracking service.

6. International transfers

Your primary account data is stored on Supabase servers in Sydney, Australia. Some of the third parties in section 5 (notably Anthropic, Expo, Railway, and Mapbox) process data in the United States. OpenStreetMap reverse-geocoding occurs in the European Union. By using Stumbl you consent to these international transfers. Each provider is contractually bound (via their standard terms) to privacy protections broadly equivalent to the Australian Privacy Principles.

7. Children

Stumbl requires all account holders to be 13 years of age or older. We enforce this at three layers: a client-side date-of-birth check at signup, a server-side check in the account-creation trigger, and an age-gate on joining any experience with a minimum age set by its organiser.

We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has signed up, email nick@stumbl.me and we will delete the account and associated data without delay.

7.1 Managed Child Accounts (13–17)

An adult guardian may create a Managed Child Account for a teen aged 13–17. The guardian controls the child's profile, approves which experiences they can join, and can delete the child's account at any time via Settings → Delete Accountinside the app. The same data-collection rules apply to child accounts, and the same deletion flow cascades through all of the child's data.

8. Your rights

Under the Australian Privacy Act 1988 (and, where applicable, the EU GDPR or California CCPA if you access Stumbl from those jurisdictions) you have the right to:

  • Access the personal information we hold about you (Settings → Privacy → Export my data, or email us).
  • Correct any inaccurate or out-of-date information — directly in your profile or by emailing us.
  • Delete your account and all associated data (Settings → Privacy → Delete my account). Deletion is a hard delete across 40+ database tables and takes effect immediately; encrypted Supabase backups expire within 30 days.
  • Withdraw consent for AI features, location sharing, or fitness integrations at any time via the Privacy Dashboard.
  • Export your data in a portable (JSON) format via the Privacy Dashboard.
  • Complain to the Office of the Australian Information Commissioner at oaic.gov.au if you are unsatisfied with how we have handled your personal information.

9. Data retention

DataRetention
Raw live-location GPS pointsRolling 4 hours, then hard-deleted
Coarse check-ins in the activity feedUntil the experience is deleted or you delete your account
Photos, videos, messages, expensesUntil you delete them, leave the experience, or delete your account
AI conversation transcripts180 days, then hard-deleted
Account profileUntil you delete your account
Encrypted database backupsUp to 30 days (Supabase-managed)
Push notification tokensUntil the token expires or you uninstall the app

When you delete your account, the app runs a cascading hard delete across 40+ tables in the correct dependency order. There is no soft-delete flag that keeps your data around afterwards.

10. Security

  • All traffic between the app and our servers uses TLS.
  • Passwords are bcrypt-hashed by Supabase Auth. Nobody at Stumbl can read them.
  • All database tables use row-level security — a user can only read or write rows that belong to them or to experiences they are a member of, enforced by the database itself.
  • Database-administrator access is restricted to Pete and Nick. All access is logged.
  • Photos and videos are stored in a private Supabase bucket with per-row RLS; signed URLs are issued only when a member of the owning experience views them.

Chat messages are not end-to-end encrypted.This means the database operators (Pete & Nick) could, in principle, read them. We do not do this as a matter of routine — access is limited to support, debugging, and moderation enforcement — but you should be aware of this before sharing highly sensitive content.

10.1 Data breach notification

If a breach affecting your personal information occurs, we will notify you without undue delayby in-app banner and email, and notify the OAIC in accordance with Australia's Notifiable Data Breaches scheme.

11. AI features — opt-out

The Privacy Dashboard inside the app (Settings → Privacy) lets you:

  • Turn off AI assistant replies
  • Turn off AI recaps and summaries
  • Opt out of sponsor-campaign targeting (not currently active on TestFlight, but the toggle is in place for when it launches)

You can also delete any individual AI conversation from inside the chat view.

12. Changes to this policy

If we materially change how we handle your data, we will notify every account holder via in-app banner and email. Non-material clarifications may be made without notification, but the version number at the top of this page will always reflect the most recent update.

13. Contact and complaints

Stumbl

  • Email: nick@stumbl.me
  • Post: 35 Wellington Street, Bondi Beach NSW 2026, Australia

If you are unsatisfied with how we have handled a privacy issue, you can lodge a complaint directly with the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992 (within Australia).

Version 1.0 · Effective 20 April 2026

Stumbl

© 2026 Stumbl