Welcome to Stamina Timer. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application and website (the "Service"). Please read this policy carefully. By using the Service, you consent to the practices described in this Privacy Policy.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address
- Name (if provided through OAuth)
- Profile picture (if provided through OAuth)
- Authentication provider information (Google, GitHub)
1.2 Training Data
When you use the Service, we collect:
- Session timing data (start time, end time, duration)
- Performance metrics (active duration, edge duration)
- Session outcomes and completion status
- Achievement progress and unlocked achievements
1.3 AI Coaching Data
When you use the AI coaching feature, we collect:
- Your questions and prompts to the AI
- AI-generated responses
- Interaction timestamps and frequency
AI prompts are processed through Google Gemini. Your prompts are sanitized before being sent to remove potential security risks. We do not store the full content of AI conversations long-term, but may log metadata for security and abuse prevention.
1.4 Technical Information
We automatically collect:
- IP address (hashed for anonymization)
- Browser type and version
- Device type and operating system
- Time zone and locale settings
- Pages visited and features used
- Error logs and performance data
1.5 Cookies and Local Storage
We use:
- Essential cookies: Required for authentication and security (CSRF tokens, session cookies)
- Local storage: Stores preferences, cached data, and offline session data
- Analytics cookies: Microsoft Clarity for usage analytics (with consent where required)
2. How We Use Your Information
We use collected information to:
- Provide the Service: Process your sessions, track progress, display analytics
- Maintain security: Rate limiting, fraud prevention, abuse detection
- Improve the Service: Analyze usage patterns, fix bugs, develop new features
- Communicate: Send service-related notifications and updates
- Legal compliance: Respond to legal requests and enforce our terms
3. Data Sharing and Disclosure
3.1 Third-Party Service Providers
We share data with trusted third parties who assist in operating the Service:
| Provider | Purpose | Data Shared |
|---|
| Supabase | Database and authentication | Account data, session data |
| Vercel | Hosting and deployment | Technical logs, IP addresses |
| Google Gemini | AI coaching feature | Sanitized user prompts |
| Upstash Redis | Rate limiting | Hashed identifiers, request counts |
| Microsoft Clarity | Analytics | Anonymized usage data |
3.2 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
3.3 Legal Requirements
We may disclose your information if required to:
- Comply with legal obligations or valid legal process
- Protect our rights, privacy, safety, or property
- Enforce our Terms of Service
- Respond to claims that content violates the rights of others
4. Data Security
We implement multiple layers of security to protect your data:
- Encryption: Data is encrypted in transit (TLS/HTTPS) and at rest
- Authentication: Secure OAuth 2.0 with trusted providers
- Access control: Row-level security ensures you can only access your own data
- CSRF protection: All state-changing requests require valid CSRF tokens
- Rate limiting: Protects against brute force and abuse attacks
- Input validation: All user input is validated and sanitized server-side
- Security headers: Strict CSP, HSTS, and other protective headers
While we take security seriously, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.
5. Data Retention
- Active accounts: Data retained while your account is active
- Deleted accounts: Data deleted within 30 days of account deletion
- Shared sessions: Automatically expire based on selected duration (1 hour to 30 days, or never)
- Analytics data: Anonymized analytics retained for up to 24 months
- Security logs: Retained for up to 90 days for abuse prevention
6. Your Rights and Choices
Depending on your location, you may have the following rights:
6.1 Access and Portability
- View your data through the dashboard and analytics pages
- Export your session data as PDF
- Request a copy of all your personal data
6.2 Correction and Deletion
- Update your account information in Settings
- Delete individual sessions from your history
- Delete your entire account and all associated data
6.3 Consent and Objection
- Withdraw consent for non-essential data processing
- Opt out of analytics tracking
- Object to processing based on legitimate interests
6.4 GDPR Rights (EU Users)
If you are in the European Union, you have additional rights under GDPR including:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with a supervisory authority
6.5 CCPA Rights (California Users)
If you are a California resident, you have the right to:
- Know what personal information is collected
- Know whether personal information is sold or disclosed
- Say no to the sale of personal information (we do not sell data)
- Request deletion of personal information
- Not be discriminated against for exercising your rights
7. Children's Privacy
The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected data from a minor, we will take steps to delete such information promptly.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by regulatory authorities
- Data processing agreements with our service providers
- Privacy Shield certifications where applicable
9. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party sites you visit.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on this page with a new effective date
- Sending an email notification for significant changes
- Displaying a notice within the Service
Your continued use of the Service after any changes indicates your acceptance of the updated policy.
11. Contact Information
For privacy-related questions, concerns, or to exercise your rights, please contact:
We will respond to your request within 30 days. For EU residents, you may also contact the data protection authority in your country if you have concerns about our data practices.
12. Legal Basis for Processing (GDPR)
We process personal data under the following legal bases:
- Contract: Processing necessary to provide the Service you requested
- Consent: Where you have given explicit consent (e.g., analytics)
- Legitimate interests: Security, fraud prevention, service improvement
- Legal obligation: Compliance with applicable laws