Version 1.0 · Effective 20 April 2026
This policy describes how Stumbl collects, uses, stores, and protects your personal information when you use the Stumbl mobile application and the related website. If anything here isn't clear, email nick@stumbl.me and a human will reply.
Stumbl is an unincorporated venture based in New South Wales, Australia, operated by Pete Reinke (founder) and Nick (Chief Financial Officer and Head of Support). Stumbl is currently in closed TestFlight beta, distributed only to users within Australia. No Australian Business Number has been registered at this stage.
For the purposes of the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), Stumbl is the entity that collects and holds your personal information.
We only collect what's required to make the features you see work. Nothing is used for advertising. Nothing is sold. There is no third-party tracking.
Stored only if you fill them in: short bio, phone number, gender, marital status, home and work addresses, social-media handles (Instagram / Facebook / X / LinkedIn / YouTube / TikTok), emergency contact, and dietary preferences and food allergies.
Emergency-contact and allergy fields are held only in our database. They are never transmitted to any third party — including our AI provider — unless you explicitly send them by asking the AI assistant a question that references them (e.g. "what should I pack for someone with my allergies?").
Inside an experience (a trip, festival, wedding, dinner, etc.) your crew sees what you share with them: photos, videos, chat messages, reactions, poll votes, schedule picks / RSVPs, expense amounts, comments, and any schedule items you create.
EXIF metadata is stripped from every photo on the server before storage — GPS tags, camera model, and original timestamps are removed so they're never exposed to other members.
When you talk to Stumbl's AI assistant, your question and the relevant context (the experience you're in, schedule items, etc.) is sent to Anthropic's Claude APIto generate a reply. Anthropic's privacy policy is at anthropic.com/privacy.
We retain a copy of your AI conversation for up to 180 days for debugging and abuse prevention, after which it is automatically deleted. You can turn off AI features entirely in the Privacy Dashboard inside the app.
If you tap the microphone in the AI bar, we use Apple's on-device Speech Recognition framework. Your voice does not leave your device. Only the resulting text is sent to our servers (and then to Anthropic, as above).
We store the push notification token issued to your device so we can deliver notifications. Tokens are passed to Expo's push delivery service to fan out notifications. Expo processes only the token and the notification payload.
We collect limited device information for diagnostics: OS version, device model, app version, and crash reports. This is used internally to fix bugs. It is not linked to identifiers used by advertising networks.
Stumbl does not ask you for App Tracking Transparency permission because Stumbl does not track you across other companies' apps or websites, does not share device identifiers with advertisers, and does not use any data to build advertising profiles. Stumbl qualifies for Apple's "Data Not Used to Track You" classification across every collected data category.
We do not use your data for advertising. We do not sell it. We do not rank a feed algorithmically — your activity feed is purely reverse-chronological.
| Data | Who can see it |
|---|---|
| Your profile (display name, @username, avatar) | Every member of an experience you join |
| Emergency contact, allergies, addresses, phone | Only you (and, if you ask the AI, Anthropic) |
| Photos, videos, messages in an experience | Members of that experience |
| Location (when sharing is on) | Members of that experience, except those set to Incognito |
| Expense amounts and splits | Members of the experience where the expense was added |
| AI conversation transcripts | Only you, and Anthropic (for the generation call) |
| Fitness activities | Members of experiences where you chose to share them |
| Stumbl operators (Pete & Nick) | Database-administrator access used only for support, debugging, and moderation enforcement. Access is logged. |
The full list of services Stumbl uses to run. Every other interaction with an external party is initiated by you (e.g. tapping a map to open directions in Apple Maps).
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Primary database, auth, file storage, realtime channels. Holds all account + experience data. | Sydney, Australia |
| Anthropic (Claude API) | AI assistant replies, recaps, summaries. Receives AI messages you send and their context. | United States |
| Expo | Push notification delivery. Receives your push token and notification payload. | United States |
| Railway | Application server hosting. Transient request data passes through, not stored. | United States |
| Mapbox | Map tile rendering. Receives approximate coordinates for tile lookup. | United States |
| Strava (opt-in) | Import fitness activities. OAuth token + activities you authorise. | United States |
| Apple HealthKit (opt-in) | Read steps + workouts on-device. Never sent to our servers without aggregation. | On-device |
| Apple Speech Recognition | Voice-to-text for AI bar. Voice never leaves device. | On-device |
| OpenWeather | Weather forecasts. Approximate coordinates only. | United States |
| OpenStreetMap / Nominatim | Reverse geocoding for place names. Approximate coordinates only. | European Union |
| Google (Places, Calendar — opt-in) | Place search + geocoding for locations; Google Calendar sync when you connect it. Receives place queries/coordinates and, for calendar sync, an OAuth token. | United States |
| Postmark (opt-in) | Inbound email forwarding — when you forward a booking to your Stumbl inbox, the message is received and parsed to add it to a trip. | United States |
| Deezer, iTunes Search | Public artist metadata for festival lineups. No user data. | United States / France |
We do not use Google Analytics, Facebook Pixel, Meta SDK, or any other third-party analytics, advertising, or tracking service.
Your primary account data is stored on Supabase servers in Sydney, Australia. Some of the third parties in section 5 (notably Anthropic, Expo, Railway, and Mapbox) process data in the United States. OpenStreetMap reverse-geocoding occurs in the European Union. By using Stumbl you consent to these international transfers. Each provider is contractually bound (via their standard terms) to privacy protections broadly equivalent to the Australian Privacy Principles.
Stumbl requires all account holders to be 13 years of age or older. We enforce this at three layers: a client-side date-of-birth check at signup, a server-side check in the account-creation trigger, and an age-gate on joining any experience with a minimum age set by its organiser.
We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has signed up, email nick@stumbl.me and we will delete the account and associated data without delay.
An adult guardian may create a Managed Child Account for a teen aged 13–17. The guardian controls the child's profile, approves which experiences they can join, and can delete the child's account at any time via Settings → Delete Accountinside the app. The same data-collection rules apply to child accounts, and the same deletion flow cascades through all of the child's data.
Under the Australian Privacy Act 1988 (and, where applicable, the EU GDPR or California CCPA if you access Stumbl from those jurisdictions) you have the right to:
| Data | Retention |
|---|---|
| Raw live-location GPS points | Rolling 4 hours, then hard-deleted |
| Coarse check-ins in the activity feed | Until the experience is deleted or you delete your account |
| Photos, videos, messages, expenses | Until you delete them, leave the experience, or delete your account |
| AI conversation transcripts | 180 days, then hard-deleted |
| Account profile | Until you delete your account |
| Encrypted database backups | Up to 30 days (Supabase-managed) |
| Push notification tokens | Until the token expires or you uninstall the app |
When you delete your account, the app runs a cascading hard delete across 40+ tables in the correct dependency order. There is no soft-delete flag that keeps your data around afterwards.
Chat messages are not end-to-end encrypted.This means the database operators (Pete & Nick) could, in principle, read them. We do not do this as a matter of routine — access is limited to support, debugging, and moderation enforcement — but you should be aware of this before sharing highly sensitive content.
If a breach affecting your personal information occurs, we will notify you without undue delayby in-app banner and email, and notify the OAIC in accordance with Australia's Notifiable Data Breaches scheme.
The Privacy Dashboard inside the app (Settings → Privacy) lets you:
You can also delete any individual AI conversation from inside the chat view.
If we materially change how we handle your data, we will notify every account holder via in-app banner and email. Non-material clarifications may be made without notification, but the version number at the top of this page will always reflect the most recent update.
Stumbl
If you are unsatisfied with how we have handled a privacy issue, you can lodge a complaint directly with the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992 (within Australia).
Version 1.0 · Effective 20 April 2026
Stumbl
© 2026 Stumbl