Last updated: 30 July 2026
Privacy Policy
StillThere is a private family archive. This page explains what data the app collects, why, who it is shared with, and how you can delete it. We keep the policy short and honest because the product is designed to be a permanent home for your family's stories — not a data-harvesting service.
What we collect
The only data StillThere collects is the data you and your family put into the archive, plus a small amount of operational telemetry needed to keep the service running. We do not sell, rent, or share personal data with advertisers, data brokers, or third-party marketers. Tracking is disabled in the iOS privacy manifest.
Account data (linked to your identity, used for app functionality)
- Email address — used to sign you in and to send important account notifications (sign-in alerts, password resets, archival completion notices).
- Display name — shown to other members of your family archive so they can recognise who added a memory.
- User ID — a non-secret identifier used by the backend to route notifications and permission checks.
- Photos and videos — uploaded to your family's archive when you attach them to a person, memory, or comment.
- Audio recordings — voice stories you record inside the app, uploaded to your family's archive as memories.
Operational telemetry (unlinked, used for app functionality)
- Product interaction events — a fixed vocabulary of high-level funnel events (sign-in completed, memory saved, push delivered, etc.) used to understand feature adoption. No content is attached — only event name and numeric counts.
- Crash data — symbolicated native crash reports via Firebase Crashlytics, used to fix bugs. Crash reports never include the content of your memories.
- Performance data — aggregated app launch and screen-render timings, used to monitor release health.
What we never collect
- Location data, contacts, calendar, advertising identifiers, or device fingerprints for advertising purposes.
- The contents of your memories for any purpose other than displaying them back to your family and running the AI features you explicitly enable (biography drafts, Ask Legacy, timeline suggestions — disabled by default).
- Any data when the app is running in Developer Mock Mode with no Firebase project configured.
How we protect your data
- Firebase Authentication — industry-standard sign-in with email/password or Google Identity, recent-login checks before destructive actions.
- App Check — every backend request carries a device-attestation token. iOS uses App Attest (with DeviceCheck fallback), Android uses Play Integrity, web uses reCAPTCHA v3. Invalid tokens are rejected at the Firestore, Storage, and Cloud Functions layers.
- Firestore Security Rules + Storage Rules — only members of a family archive can read or write that archive's records and media.
- Encryption in transit and at rest — TLS for every request; Firebase encrypts data at rest by default.
Where your data lives
StillThere runs on Google Cloud / Firebase. Account and family
records live in the
besideus-f2ab9 Firebase project. Photos, videos,
and audio are stored in the project's default Storage bucket under
the families/{familyId}/ prefix; user avatars are
under avatars/{uid}/.
Who can see your data
Only the members of the family archive you belong to. StillThere staff cannot read the contents of your archive as part of normal operation. The only exception is an explicit, auditable support request you raise via /support, which is logged.
Children
StillThere is rated 4+ on the App Store and Everyone on Google Play. The service is not directed at children under 13 and does not knowingly collect personal data from children. Family archives may contain photos and audio of children uploaded by adult family members; that data is treated with the same protections as any other archive content.
Your rights
- Access — open the app's Profile section to see your account data and the archives you belong to.
- Export — contact support@stillthere.tunnxo.com to request a structured export of your data.
- Correct — edit your display name and contact info in Profile at any time.
- Delete — follow the in-app flow at /delete-account or visit Profile → Delete account in the app. Deletion is permanent and covers your account, profile, uploaded avatars, and any family archives where you are the sole member.
Changes to this policy
If we make a material change, we will surface an in-app notice and update the date at the top of this page. We will not silently broaden what we collect.
Contact
Questions, complaints, or data requests: support@stillthere.tunnxo.com. For the formal deletion flow, use /delete-account.
StillThere is operated by Tunnxo. "StillThere" and the legacy tree mark are trademarks of Tunnxo. Firebase, Crashlytics, and App Check are trademarks of Google LLC.