This Privacy Policy applies to every StackForge Studios game, app, website, account, and related service (the "Service"). JMB Assets LLC, doing business as StackForge Studios, is the controller of personal data described here unless a notice says otherwise.
Our baseline: we do not sell personal data, consumer health data, or HealthKit / Health Connect data. We do not use personal or health data for targeted advertising, cross-context behavioral advertising, insurance, credit, employment, or eligibility decisions.
PlateStack handles sensitive nutrition, fitness, body, and connected-health information. Read this policy together with our separate Consumer Health Data Privacy Policy, which explains additional rights and disclosures for consumer health data.
0. Product-specific data at a glance
Features and permissions vary by product. A check means the category may be processed when you use the corresponding feature; it does not mean every user must provide it.
| Data or feature | PlateStack | StackForge games |
|---|---|---|
| Account | Required | Optional |
| Nutrition / fitness data | Feature-based | No |
| HealthKit / Health Connect | Optional | No |
| Camera | Scan / photo | No |
| Microphone | Voice log | No |
| Progress photos | Optional | No |
| AI Coach and editable drafts | User-requested | No |
| Social features | Optional | Optional |
| Game progress | No | Feature-based |
| Optional product analytics | No | Opt-in only |
| Purchases | Optional | Optional |
| Precise location | No | No |
| Contacts | No | No |
| Third-party ad SDKs | No | No |
1. Personal data we process
1.1 Account, identity, and support data
- Account data: email address, display name, internal user identifier, authentication records, acceptance of legal notices, settings, and subscription entitlement.
- Third-party sign-in: a provider identifier and the name or email the provider makes available with your permission. Apple relay email remains an email address associated with your account.
- Support and communications: messages, attachments, contact details, and records needed to respond, investigate an issue, or handle a privacy request.
- Security records: limited logs, timestamps, IP address, device or session information, and events reasonably needed to authenticate users, prevent abuse, debug failures, and protect the Service.
1.2 PlateStack nutrition, fitness, and consumer health data
- Profile and goals: age or age range, height, weight, fitness goals, activity level, training preferences, dietary preferences, target calories and nutrients, and related settings you choose to provide.
- Nutrition and routine data: foods, meals, recipes, calories, macros, micros, nutrients, water, fasting, habits, reminders, and your edits or corrections.
- Fitness and activity data: workouts, exercises, sets, repetitions, weights, cardio, activity, personal records, progress, plans, and user-entered notes.
- Body and connected-record data: body weight, measurements, body-fat entries, progress photos, sleep, steps, active energy, workout history, resting heart rate, HRV, blood oxygen / SpO2, respiratory rate, blood pressure, VO2 max, and mindful minutes. PlateStack displays records and arithmetic trends; when a user chooses PlateStack Coach, a bounded snapshot of relevant values may also be included in that request as described below. Progress photos are not included in Coach requests. Historical recovery fields may remain until the user deletes them under this policy.
- Camera and image data: barcodes, food photos, nutrition-label photos, and progress photos only when you actively use the relevant feature. Food or label images submitted for AI analysis are sent for processing; progress photos are stored privately and are not used for food scanning.
- Voice data: audio you actively record for a voice log is transmitted for transcription. The resulting transcript may be used to prepare a draft log.
- User-requested AI data: selected food or label photos; voice or natural-language entries and transcripts; Coach prompts and responses; and generated logging estimates, workout or progress summaries, and editable meal or workout plan drafts. Depending on the feature selected, PlateStack may include limited age, goal, preference, food-log, workout and RIR, cardio, body-progress, saved-plan, habit, reminder, Coach-memory, and separately authorized connected-health context needed for that result. Connected-health context may include steps, active energy, sleep, resting heart rate, HRV, VO2 max, blood oxygen, and respiratory rate when available. We exclude full name, email address, and full date of birth from these AI requests. Do not submit information you do not want processed.
1.3 Apple Health / HealthKit and Android Health Connect
Connected-health access is optional and controlled through platform permission screens. PlateStack may request only the data types shown in the applicable permission flow and may read or write data when you enable the corresponding feature.
- Apple Health / HealthKit: may include steps, active energy, workouts, body weight, body fat, sleep, resting heart rate, HRV, blood oxygen, respiratory rate, blood pressure, VO2 max, mindful minutes, and nutrition data, plus user-requested workout or nutrition writes.
- Android Health Connect: may include steps, active calories, body weight, body fat, and sleep, plus user-requested workout, active-calorie, distance, weight, or nutrition writes.
We do not use connected-health data for advertising, marketing, data brokerage, unrelated profiling, or eligibility decisions. Revoking a platform permission stops future platform access but does not automatically delete data previously imported into your StackForge account.
1.4 Game, social, and product-usage data
- Game and puzzle data: save state, boards, runs, scores, streaks, achievements, rankings, settings, entitlements, and cloud-sync state.
- Social data: friend or squad relationships, invitations, user-chosen profile details, challenges, shared workouts or scores, messages, reactions, reports, and visibility settings.
- Functional events: actions needed to deliver a feature, maintain an entitlement, enforce a quota, sync state, prevent duplicate rewards, diagnose a failure, or secure the Service.
- Content-free AI service events: PlateStack records the requested AI mode, provider and model, app version, build, platform and runtime, provider token counts, duration, outcome, and bounded error code to measure service cost and determine whether supported app versions still depend on an AI mode. These server-only events contain no StackForge account or user identifier, prompt, response, image, audio, food log, workout log, health record, or Coach content. We describe them as content-free operational records, not as anonymous user analytics.
- Optional product analytics: only after a current affirmative opt-in and only in a build where the integration is configured, selected games may send event names, game and platform, gameplay or app-interaction properties, and a pseudonymous device or account identifier. Product analytics is off by default, can be withdrawn in settings, is not used for advertising, and does not include PlateStack health data, food logs, private messages, or One Good Thing private notes.
StackForge games do not request health, fitness, camera, microphone, contacts, or precise-location data unless a future product clearly discloses a new feature and obtains required permission before collection.
1.5 Website data
Our public websites do not currently use advertising pixels, behavioral analytics, or tracking cookies. Cloudflare and other infrastructure providers necessarily process request information such as IP address, browser type, requested URL, timestamp, and security signals to deliver and protect the site. We do not use those records to build advertising profiles.
1.6 Data we do not request
- Precise location or contacts: current products do not request GPS location or address-book access.
- Biometric templates: Face ID or fingerprint matching is performed by your operating system; we receive the success or failure result, not the underlying biometric template.
- Full payment credentials: Apple, Google, or Stripe processes payment-card or store credentials. We receive purchase and entitlement records.
- Advertising identifiers: we do not collect them for targeted advertising.
2. Sources of data
We receive data from:
- you, including entries, uploads, permissions, settings, messages, and corrections;
- your device and operating system when needed for a requested feature;
- Apple Health / HealthKit or Android Health Connect after platform permission;
- Apple, Google, Stripe, and RevenueCat for authentication, purchase, and entitlement information;
- friends or other users when they invite, share, message, report, or interact with you;
- food, barcode, and recipe sources used for searches or imports; and
- our service providers when they return a transcription, estimate, AI output, delivery result, security signal, or support record.
3. Why we process data
- Provide requested features: authenticate, store entries, sync devices, show progress, calculate estimates, process user-requested AI features, connect health platforms, deliver social interactions, and restore purchases.
- Personalize the user's own experience: apply settings, units, goals, themes, reminders, plans, and user-controlled context. We do not use this personalization for advertising.
- Maintain and secure the Service: prevent fraud and abuse, enforce quotas and entitlements, troubleshoot, back up systems, and protect accounts.
- Communicate: send transactional notices, requested push notifications, support responses, legal notices, and optional marketing messages.
- Comply with law: respond to valid legal process, protect rights and safety, maintain financial or consent records where required, and handle privacy or breach-notification duties.
- Improve products: use support reports, testing, deidentified or aggregated functional records, product feedback, PlateStack's content-free AI service events described in Section 1.4, and optional pseudonymous product analytics only when a user affirmatively enables it.
4. Consent and legal bases
Where applicable, we rely on performance of a contract to provide requested account and product features; legitimate interests in security, support, fraud prevention, and service improvement; compliance with legal obligations; and consent for optional permissions, marketing, sensitive processing, and disclosures that require it.
Health data and EEA / UK users: data concerning health is special-category data. Where required, we rely on your explicit, separate consent under Article 9(2)(a), together with an Article 6 basis. You may withdraw consent for future processing in settings or by contacting us. Withdrawal does not make earlier lawful processing unlawful, but an optional feature may stop working if its necessary data can no longer be processed.
AI and third parties: before personal data is first sent to a third-party AI provider, PlateStack presents a specific disclosure and records affirmative permission. Invoking an AI feature directs us to process the content and context described in that disclosure for the requested result. You can withdraw future permission; previously created logs or outputs remain until deleted.
Optional game analytics: product analytics is off by default and prior defaults do not count as current consent. Enabling the setting records a current affirmative choice; disabling it stops future optional analytics events from that game.
5. When data is disclosed
We disclose only data reasonably needed for the specified service, legal duty, or user-directed interaction. Providers may process data under contract and their applicable service terms.
- Supabase and AWS: authentication, database, storage, real-time features, edge functions, and infrastructure.
- OpenAI: user-requested image analysis, nutrition estimation, and voice transcription. OpenAI states API inputs and outputs are not used to train its models by default; provider security or abuse-monitoring retention may apply under our API terms.
- Anthropic: user-requested food-image classification, natural-language food-entry estimates, PlateStack Coach responses, workout or progress summaries, and editable meal or workout plan drafts. A Coach request may contain the limited logged-record and separately authorized connected-health context described in Section 1.2. Provider security or retention controls may apply under our API terms.
- FatSecret, USDA FoodData Central, and Open Food Facts: food, nutrient, and barcode lookup. Queries or barcodes and technical request metadata may be processed.
- Recipe-source websites: when you request an import, our server retrieves the public URL you submit. Do not submit private, authenticated, or token-bearing links.
- RevenueCat, Apple App Store, Google Play, and Stripe: purchases, subscription status, entitlement, fraud prevention, and payment support.
- Apple and Google: optional account sign-in and connected-health services that you enable.
- Expo: push-notification delivery and enabled app-update services.
- Resend or a replacement email-delivery provider: transactional emails, requested exports, and service notices.
- Cloudflare: website and service delivery, security, and abuse prevention.
- PostHog: optional pseudonymous game product analytics, only if the SDK and project key are configured and the user has made a current affirmative opt-in. PostHog is not used for targeted advertising and does not receive PlateStack consumer health data through this integration.
- Other users: only the profile, social, score, message, or workout information you intentionally make available through a social feature.
- Legal or safety recipients: when reasonably necessary to comply with valid law, enforce rights, prevent fraud, protect the Service, or address an imminent safety risk.
- Business transaction recipients: in a merger, financing, acquisition, bankruptcy, reorganization, or sale of assets, subject to confidentiality, notice, applicable law, and continued protection of consumer health data.
We do not sell personal data or consumer health data. We do not disclose personal or health data to advertising networks or data brokers. We do not permit AI providers to use submitted API content for targeted advertising or independent model training on our behalf.
6. Health-data restrictions
We do not use or disclose health, nutrition, fitness, body, recovery, HealthKit, or Health Connect data for targeted advertising, marketing profiles, data brokerage, credit, employment, insurance, housing, lending, or eligibility decisions. Access is restricted to people and processors that need it for the user-requested purpose, security, support, or law.
See the separate Consumer Health Data Privacy Policy for categories, sources, sharing, rights, withdrawal, deletion, and appeals.
7. Retention and deletion
- Account and product records: retained while the account is active and then deleted or deidentified when no longer needed, subject to the timelines below and lawful exceptions.
- User-deleted entries: removed from active systems within a commercially reasonable period; cached or backup copies age out under protected backup schedules.
- Account deletion: personal data is targeted for deletion or deidentification from active systems within 30 days after a verified request, except records we must retain for law, security, fraud prevention, disputes, or financial reporting.
- Consumer health data backups: where Washington's My Health My Data Act applies, deletion from archived or backup systems will be completed no later than six months after authentication of the request, and processors that received the data will be notified as required.
- AI inputs and outputs: food images and audio are not intentionally retained by StackForge after the requested analysis or transcription unless you save the resulting log. Coach transcripts are stored on the user's device; saved Coach memory notes, logs, and plan drafts remain with the account until the user deletes them. Provider security or abuse-monitoring retention may apply under provider terms.
- Content-free AI service events: retained for no more than 180 days, then deleted through the service's pruning process. These operational records are not linked to a StackForge account or user identifier and do not contain submitted or generated content.
- Optional product analytics: retained only while reasonably needed to understand product operation and usage, under the configured provider retention period, then deleted or aggregated. Withdrawing consent stops future optional collection but does not automatically erase earlier records; contact us to request deletion.
- Support, security, consent, and transaction records: retained only as long as reasonably needed for the request, legal limitation period, fraud prevention, tax, accounting, consent proof, or dispute.
8. Security
We use administrative, technical, and organizational safeguards designed for the nature and sensitivity of the data, including access controls, transport encryption, platform-secured authentication storage, database authorization policies, least-privilege practices, and contractual controls for processors. No system is perfectly secure, and we cannot guarantee that unauthorized access, loss, or disclosure will never occur.
If a security incident triggers notice obligations, we will notify affected users and regulators as required by applicable law, including the FTC Health Breach Notification Rule where it applies.
9. Your choices and privacy rights
- Access and portability: request a copy of personal data associated with your account.
- Correction: edit supported profile data or ask us to correct inaccurate information.
- Deletion: use Settings › Account › Delete Account where available, or submit a verified request.
- Consent and permissions: withdraw optional permission through the app, device settings, connected platform, or by contacting us.
- Product analytics: leave the setting off or turn it off at any time. Analytics remains off unless the current consent marker is present.
- Marketing: use the unsubscribe link in an optional marketing email.
- Appeal: if we deny a qualifying privacy request, reply with the subject "Privacy Appeal" and explain why you believe the decision should be reconsidered.
Submit requests to hello@stackforgestudios.com. We may verify your identity and authority. You do not need to create a new account to make a request. An authorized agent may submit a request where law permits, subject to proof of authority and identity verification.
9.1 California and other US state rights
Depending on where you live and whether a law applies to us, you may have rights to know, access, correct, delete, or obtain a portable copy of data; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive data; appeal a denial; and receive non-discriminatory service. We do not sell personal data or share it for cross-context behavioral advertising.
For a California request, use the subject "California Privacy Request." We will respond within the period required by applicable law. We do not provide a "Do Not Sell or Share" mechanism because we do not sell or share personal information for cross-context behavioral advertising.
9.2 EEA and United Kingdom rights
Users in the EEA or UK may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Data is processed in the United States and other locations used by our processors. Where required, we use approved transfer mechanisms such as Standard Contractual Clauses and supplementary safeguards.
We do not make decisions producing legal or similarly significant effects based solely on automated processing. Product scores, estimates, and AI outputs are not used to determine eligibility, insurance, credit, employment, or similar rights.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information. A parent or guardian who believes a child under 13 submitted data should contact us for prompt review and deletion. Products with health or body features are not intended for unsupervised use by minors.
11. Information is not health monitoring or advice
Personal data, estimates, arithmetic comparisons, game scores, user-created templates, imported records, and AI outputs processed by the Service are used to provide organizational, self-tracking, and entertainment features. They are not verified medical records, do not provide professional medical, health, wellness, nutrition, dietary, or fitness advice, and must not be used to monitor health or safety or make a clinical decision. See the Terms of Service for the complete safety and limitation disclosures.
12. Changes to this policy
We may update this policy as products, providers, or laws change. We will post the updated date and provide additional notice for material changes where required. We will obtain new consent before collecting, using, or disclosing consumer health data for materially new categories or purposes when law requires it.
13. Contact
Privacy questions, requests, appeals, or complaints:
hello@stackforgestudios.com
StackForge Studios · United States
Account deletion instructions · Consumer Health Data Privacy Policy