Release scope: Version 1.2.3 is awaiting App Review with optional iOS advertising measurement using Apple's separate tracking permission and Stillkeen Premium monthly, annual and lifetime options. These capabilities apply only where an installed version and its App Store checkout actually offer them; this page does not announce their release. This policy also covers consent-controlled Firebase diagnostics, Premium purchases and restore, deeper performance insights, encrypted iOS backup, and the optional Visual Memory Challenge current board.
1. Summary
- Your plans, attempts, results, settings, and personal bests are stored on your device.
- Stillkeen has no account, in-app advertising, or social feed. Its optional score ranking uses a generated display name and keeps only the current period's ranking rows.
- Local reminders are optional and scheduled by your operating system.
- Stillkeen Premium uses RevenueCat and the App Store for optional purchase, restore, offering, and entitlement state.
- iOS backup is optional, encrypted, and started by you through file export/import or app-private iCloud backup.
- Firebase analytics, crash-report transmission, performance monitoring, and optional Meta measurement stay off before the first-launch legal confirmation.
- In standard regions, accepting the User Agreement and Privacy Policy enables analytics, which can later be disabled in Settings. In the EEA, UK and Switzerland, a separate optional analytics switch is shown off by default. If the region is unresolved, analytics stays paused. In releases supporting deferred region checking, you can cancel the pending preference in Settings; automatic activation requires a confirmed standard region.
- iOS advertising tracking is a separate optional choice. Google and Meta advertising identifiers and cross-company measurement require both current analytics consent and permission in Apple's App Tracking Transparency prompt. Refusing tracking does not restrict training or purchases.
- Crashlytics automatic upload stays off. Current consent lets Stillkeen explicitly send eligible crash reports. Turning practice analytics off stops Dart error forwarding and performance collection, and asks Crashlytics to delete eligible reports that have not been uploaded. Local cohort bookkeeping remains on your device until Reset All Data, which also requests supported provider identity resets; neither control deletes providers' existing server records.
2. Data stored on your device
Stillkeen stores the minimum local state needed to provide the training routine:
- language, selected training goal, accessibility and feedback settings;
- daily-plan definitions, completion state, difficulty preferences, and instruction state;
- attempt summaries such as active duration, accuracy, errors, pause state, and exercise-specific result fields;
- derived personal bests, continuity, and weekly progress summaries;
- optional reminder preference, local reminder time, timezone, and permission-request state;
- analytics preference plus an app-generated local installation marker used only for coarse activation-day and plan-start bookkeeping;
- optional Premium plan, guided-program, analysis, purchase access, and backup state;
- badge collection acknowledgements and up to three display selections; badge eligibility is calculated from saved completed practice, and these preferences are included in encrypted backup and cleared by Reset All Data;
- for optional score ranking, a generated display name and a local random secret used to derive a separate participant ID for each ranking period.
Stillkeen does not provide an account and does not sell local training history. On iOS, you can choose to export an encrypted backup file or store one encrypted backup in Stillkeen's app-private iCloud container. The backup contains your local Stillkeen database in encrypted form; the backup key is kept in the iOS Keychain and may sync through your Apple account when iCloud Keychain is enabled.
3. App measurement, diagnostics, and practice analytics
Stillkeen uses Firebase Analytics, Firebase Crashlytics, and Firebase Performance Monitoring, and may use Meta app-event measurement in configured releases. Native analytics and performance collection, Crashlytics automatic upload, and consent defaults ship off before the first-launch legal decision. In standard regions, accepting the User Agreement and Privacy Policy enables measurement and diagnostic transmission, which can later be disabled in Settings. In the EEA, United Kingdom and Switzerland, a separate optional practice analytics switch is shown off by default. When the region cannot be resolved, collection stays off. Releases supporting deferred checking disclose a conditional regional default: after legal acceptance, the app may retry quietly while you are outside a practice session and enable analytics only after confirming that a separate opt-in is not required. You can cancel the pending preference in Settings. A strict result keeps analytics off unless you accept a separate optional analytics choice. Retries never override an existing refusal. After analytics is enabled, iOS may separately ask for tracking permission; you can refuse it. An older choice must be renewed before collection resumes. Training, reminders, progress, and sharing continue to work when analytics is off. Re-enabling analytics does not make Stillkeen app-author a backfill of prior behavior.
Firebase may use a resettable app-instance identifier and available platform measurement identifiers, collect standard app/session events, measure installs and campaigns, process ordinary app, device, platform, language, and network metadata, and derive approximate location such as country or city from connection data. On iOS, advertising storage and advertising user data are enabled only with current analytics consent and actual Apple tracking authorization. Google's ad-personalization consent remains denied; Android advertising consents remain denied. Google on-device conversion measurement can use de-identified, temporary app event data to measure eligible installs and in-app conversions without requiring an email or phone number. Google may process and store information on global infrastructure; the Analytics reporting location is not a data-residency guarantee. When practice analytics is enabled, Stillkeen also sends only these constrained custom-event categories:
| App context | App version, build number, platform, supported language, and consent-policy version. |
|---|---|
| Training context | Selected goal, plan type and program day, exercise key, rule/generator version, difficulty, accessibility variant, and attempt source. |
| Coarse result | Completed or abandoned status, pause boolean, duration/accuracy/error-count buckets, and constrained abandonment reason. Exact duration and reaction time are not sent. |
| Retention context | Whole-day activation age from 0 through 30 or 31_plus. Calendar date, timezone, and UTC offset are not sent. |
| Feature actions | Reminder offer, reminder open, permission result, Daily Board open, Arena open/run/submission/ranking actions, share preview/invocation with asset type and aspect ratio, and constrained settings changes. Reminder time, notification text, board date or seed, Arena participant ID, display name, signed token, answers, response intervals, score, rank, ranking size, shared content, and destination app are not sent to Firebase Analytics. |
| Premium actions | Offer view, purchase or restore start/result, entitlement state, Premium plan use, guided-program progress, and Premium performance-insight surface. App-authored events contain constrained product ID, environment, result, entry point, billing period, verified trial-offer visibility/days, and observed access phase; offer and checkout events may also include the displayed store price and currency. Trial or subscription access is not proof of a paid charge. These events omit receipts, order and transaction IDs, purchase tokens, CustomerInfo payloads, actual charged amounts, refund details, and store-account identifiers. Separate RevenueCat purchase reporting is described in section 4. |
Crashlytics automatic upload remains disabled. While this setting is enabled, Stillkeen explicitly sends eligible pending reports and newly recorded fatal Flutter-framework or uncaught asynchronous errors. A native process crash can be retained locally by Crashlytics and sent on a later launch only if consent remains current; when consent is off at launch, Stillkeen asks Crashlytics to delete it instead. Crash reports may include stack traces, exception and process context, and app/build, device, operating-system, and ordinary transport metadata. Performance Monitoring may collect standard app-startup, rendering, and supported network traces, including durations, network endpoints, response codes, payload sizes, and related app/device metadata. Stillkeen sets no Crashlytics user ID, custom key, explicit custom log, or app-authored non-fatal report, and adds no custom Performance trace, metric, or attribute. Firebase may attach enabled Analytics events, including Stillkeen's allowlisted events, to a crash report as Crashlytics breadcrumbs. Turning the setting off immediately stops Dart error forwarding, disables Performance collection, and requests deletion of eligible unsent crash reports, but does not delete provider records already received.
In iOS App Store privacy labels, these data flows map to Coarse Location, Device ID, Product Interaction, Other Usage Data, Crash Data, Performance Data, Other Diagnostic Data, and Purchase History. Advertising measurement can link device identifiers, app interactions, other coarse app-usage data, approximate location and purchases for tracking after your permission; being account-free does not make those records anonymous. Diagnostics and Arena functionality are not used as advertising signals. Releases that change provider data flows must keep their store privacy information accurate.
Stillkeen sets no Firebase user ID and never forwards its app-owned local installation marker. Its app-authored analytics events and diagnostic additions do not include names, email addresses, contacts, free text, board seeds or payloads, tap history, pointer locations, reminder time, medical data, or child data. Android Advertising ID collection is disabled; aggregate AdServices attribution may be available after analytics consent. Firebase may use iOS IDFV while analytics is enabled. In supporting iOS versions, Google and Meta may use IDFA only when analytics consent and App Tracking Transparency authorization are both present. Stillkeen has no in-app advertising or automatic Analytics screen reporting. SDKs may also process their own app/device identifiers and transport metadata such as IP address; the custom-event field restrictions do not describe the entire SDK payload. Optional score-ranking submissions go to the separate Arena service; Firebase receives only coarse Arena action labels and low-cardinality outcomes.
Meta receives installation/session activation and selected app-activity events: onboarding steps, practice starts/completions/exits, plan and course progress, challenge activity, reminder opens, sharing actions, Premium benefits/analysis views, paywall views/dismissals and checkout starts. Activity events carry only app/build/platform/language context; onboarding may also carry its flow version, step, variant and completion or skip status. Product, billing period, verified trial-offer visibility/days and displayed price/currency accompany only paywall-view and checkout-start events. SDK-generated device/network context may also be sent. On iOS, activation and event delivery follow current analytics consent, including when Apple tracking permission has not been granted. In that case, advertiser tracking and advertiser-ID collection stay off, and Stillkeen enables Meta's event-data-use restriction for analytics and conversion measurement. This setting is distinct from Meta's regional Limited Data Use (LDU) option. SKAdNetwork conversion updates are handled separately by Firebase, not by this Meta event-delivery setting. Advertiser-ID collection and the RevenueCat matching bridge additionally require actual ATT authorization. These signals support advertising measurement and optimization. Android retains its limited event-data-use posture. Meta automatic event and purchase logging remain disabled; RevenueCat alone reports subscription trials, purchases and renewals. This Meta event integration sends no scores or result ranges, accuracy, difficulty, exercise or course details, answers, local history export, settings values, email or phone number. Calibration progress is reported only as onboarding activity, not completed formal training. Expanding this event scope requires renewing the in-app analytics choice; previously recorded activities are not backfilled.
In configured releases from version 1.2.6, PostHog (US region) receives consent-controlled product analytics: named page views, onboarding steps, named exercise and difficulty selections, training starts/completions/exits, plan and course progress, feature actions, and Premium purchase-funnel outcomes. A provider-specific anonymous installation identifier links these actions across sessions; it is not linked to Firebase, Meta, RevenueCat, advertising identifiers, or an account. Requests include timestamps, app/build/platform/language context and ordinary network metadata. Stillkeen asks PostHog not to create person profiles or enrich events with IP-based location. The current KTI total (one decimal place) is also included and updated when the saved total changes, to analyze usage and conversion. Apart from that total, no component or individual exercise scores, accuracy ranges, answers, raw route identifiers, free text, screen recordings or automatic click capture are sent. This product analytics follows the current in-app analytics choice independently of ATT. Turning it off clears the app's pending PostHog queue; resetting local data also changes its anonymous identity. Neither action erases events already received. Purchase-funnel results describe the app's observed outcome, not verified payment or renewal revenue. Older analytics choices must be renewed before this integration starts. See PostHog's privacy policy for provider processing and retention.
4. Purchases and restore
Stillkeen Premium purchases, subscriptions and restore are handled by the App Store and RevenueCat. When the purchase feature is available, RevenueCat may process an anonymous app user identifier, offering and product information, trial eligibility and period, purchase or restore state, subscription expiry and renewal state, entitlement state, store environment, and platform transaction information needed to provide purchase functionality. Stillkeen does not create a Stillkeen account and does not pass a custom account user ID to RevenueCat.
Stillkeen disables RevenueCat automatic device-identifier collection and diagnostics. Only while current analytics consent remains valid, Stillkeen may sync Firebase's app-instance identifier to RevenueCat to associate purchase reporting; withdrawing consent requests removal of that saved attribution attribute. The active RevenueCat integration separately sends verified purchase events to Google Analytics, including product and platform transaction identifiers, purchase time, store environment, purchase value, and currency. Current production reporting uses gross purchase value in US dollars and excludes sandbox events and email addresses. These server-generated purchase events are separate from the app-authored event fields in section 3; Stillkeen does not provide local training history, exact scores, answers, or board content to RevenueCat for this purpose.
On supported iOS releases, Stillkeen enables Apple AdServices token collection only after valid analytics consent. RevenueCat can exchange this token with Apple for standard Apple Ads campaign attribution. This does not require Stillkeen to collect IDFA.
For supporting iOS versions, RevenueCat's Meta purchase integration requires authorized ATT and a permitted matching identifier. With both app analytics consent and ATT authorization, Stillkeen can send Meta's SDK-generated anonymous identifier to RevenueCat; RevenueCat then sends verified purchase events with product and transaction identifiers, purchase time, value, currency and provider matching context. RevenueCat automatic device-identifier collection remains off. Withdrawing app analytics consent requests removal of the Facebook matching attribute and synchronization; this does not retract previously delivered or already-processing events. Purchases are reported once through the server integration; restoring access is not a new sale. Google Analytics gross purchase revenue does not automatically subtract refunds, which require separate store/RevenueCat reconciliation. This integration does not include local training history or answers.
Where subscriptions are offered, the same consent-controlled provider integrations may also report verified trial starts, trial-to-paid conversions, renewals, cancellations and expirations according to their configuration. A free-trial entitlement is not reported by Stillkeen as billed revenue, and the app does not invent renewal events while closed. Actual payment and refund records remain with the store and RevenueCat. Subscription cancellation is managed with Apple, independently of analytics consent or local data reset; see Apple's cancellation instructions.
Internal tester builds may also connect to RevenueCat Test Store for non-production entitlements. Test Store purchases do not create real App Store charges.
5. Reminders and platform permissions
If you enable practice reminders, Stillkeen asks for notification permission in context and schedules future notifications locally through Android or iOS. Reminder time and notification content are not sent to Stillkeen analytics. You can disable reminders in Stillkeen or change notification access in system settings.
After app analytics consent, supporting iOS versions ask separately for Apple's tracking authorization. You can refuse, change the permission in iOS Settings, or use Advertising measurement in Stillkeen's Privacy and data settings. Stillkeen refreshes the OS choice on return to the app. Turning app analytics off stops new app-authored advertising measurement even if iOS still shows tracking authorized. Eligible aggregate SKAdNetwork and privacy-preserving Google measurement do not promise user-level attribution or complete advertising coverage.
6. Sharing
Stillkeen can render a result or Daily Board image on your device and open the operating system share sheet. Stillkeen does not receive the destination you choose. The temporary image is app-owned and is deleted after the share operation returns; stale app-owned exports are also cleaned up.
7. Optional score ranking
Free play stays on your device. You can view the public current-period ranking without sending a period participant ID or score. Starting a ranking run requests a signed seed from the Arena service. Completing a ranking run does not submit the result automatically.
Only when you choose Submit score does Stillkeen upload your current-period participant ID, generated display name, scene and parameter versions, seed and signed token, answer and response interval for each question, correct count, and total response time. The service uses the seed and answers to recalculate the score and perform basic validity checks. Other users can see the generated display name, rank, score, and response time; they do not receive your participant ID, token, seed, answers, IP address, or account identity. Stillkeen does not allow free-text ranking names.
The Arena service may process your IP address briefly for rate limiting and service protection. It does not store the IP address with ranking data or associate it with a score row. Current-period ranking rows and signed-run records are deleted after their UTC week ends, and Stillkeen does not provide historical ranking rows. You can delete your current submission from the app without deleting your local practice history.
Stillkeen may retain coarse anonymous score-distribution counts for service calibration for exactly 90 days after an aggregate bucket's last update. These aggregates exclude participant IDs, display names, seeds, answers, exact submission timestamps, and other fields that could reconstruct an individual submission.
8. Retention and deletion
Local data remains until you use Reset All Data, clear the app's storage, or uninstall the app, subject to operating-system behavior. Reset All Data disables analytics, cancels app-owned reminders, clears Stillkeen's local user tables and Arena presentation state, restores defaults, and returns to Today. It does not delete an active current-period Arena submission or the local Keychain secret used to derive rotating participant IDs; Delete current submission in Arena remains available for removing that server record after local presentation state has been reset. It also does not delete encrypted backup files you already exported or sent elsewhere. In-app iCloud backup controls can remove the managed Stillkeen iCloud backup when iCloud is available.
The provider-side retention period for Google Analytics user-level and event-level data is kept aligned with the current store privacy declarations and must be reviewed again before any future privacy-affecting submission. Google may retain aggregated reporting or security and service records under its applicable terms. Disabling practice analytics stops new Firebase Analytics transmission, Dart crash forwarding, Performance collection, Meta measurement, and app-authored analytics collection; asks Crashlytics to delete eligible reports not yet uploaded; and requests removal of saved RevenueCat attribution attributes. Local cohort bookkeeping remains on your device until Reset All Data, which also asks Firebase to reset its local analytics data and app-instance identifier. These controls do not delete events or diagnostics already delivered to providers or revoke store purchases. App Store and RevenueCat purchase records and events already being processed may remain subject to the providers' retention and processing rules. Contact us for privacy or data-deletion requests.
9. Children, health, and claims
Stillkeen is a general self-improvement utility and is not designed as medical diagnosis, treatment, or a substitute for professional care. The final store audience and age declarations remain subject to release review. Stillkeen does not intentionally request personal or child data through its analytics events.
10. Website hosting, analytics, and region policy
This website is delivered by Cloudflare Pages and uses Firebase Analytics for Firebase project stillkeen-2ba67 to understand website use. Firebase Analytics loads on public pages and may also record provider-generated first-visit, session and engagement events. Google Analytics may process the page URL and title, referral information, browser and device details, a browser analytics identifier, and network metadata such as IP address, from which approximate location may be derived. Google Analytics may use first-party analytics storage, including cookies.
Website measurement revision 1.2.3-web2 records only two website-authored events: web_page_view for a page visit and web_app_store_click for a click to the Stillkeen App Store listing. It no longer records a separate internal-navigation event and disables the default page-view event at initialization. These two events include only fixed page, language, link-location and destination categories, a website-origin label and the measurement revision; they do not send link text, custom full URLs, training results, a Firebase user ID or an app-owned visitor identifier. Google-generated events are separate from these two events and can be distinguished from App data by platform and data stream. A store click is not an installation or purchase. Shared Daily Board result pages and unknown routes do not initialize website analytics.
Advertising storage, advertising user data, and ad personalization consent are denied in the website integration. The website does not use advertising, session replay, forms, or third-party fonts. You can restrict or clear analytics storage through your browser settings; this does not delete events already delivered to Google. Cloudflare may separately process ordinary request and security metadata to deliver and protect the site.
A minimal endpoint uses Cloudflare’s request-country signal to return a strict or standard consent policy and, in updated responses, a flag indicating whether the region was resolved. Unavailable or unknown responses keep collection off. Supported app releases use a limited number of delayed foreground retries after the first-launch decision; they do not run a continuous background location service. Stillkeen does not store the country or IP in its app database.
11. Changes and contact
Material changes will update the date and content of this page. Privacy and data questions can be sent to muzil7734@gmail.com.