Privacy Policy
Last Updated: December 20, 2024
SitApp ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our desktop application and website (collectively, the "Service").
1. Information We Collect
1.1 Information You Provide
When you create an account or use our Service, you may provide:
- Account Information: Name and email address when you register
- Authentication Data: Login credentials or social login tokens (Google, GitHub, Apple)
- User Preferences: App settings and preferences you configure
- Communications: Information you provide when contacting us for support
1.2 Information Collected Automatically
When you use our Service, we may automatically collect:
- Usage Analytics: Which features you use and how often (anonymized)
- Technical Data: App version, operating system, device type
- Performance Data: App crashes and error reports (with your consent)
- Calibration Progress: Setup completion status (no images)
1.3 Webcam and Posture Data
Important: SitApp uses your webcam for posture detection. Here's how we handle this sensitive data:
- Local Processing Only: All webcam images are processed entirely on your device using on-device AI (TensorFlow.js)
- No Transmission: Webcam images, video, or detailed posture data are NEVER transmitted to our servers or any third party
- No Storage: We do not store webcam images or recordings
- Posture Metrics: Only anonymized, aggregated posture improvement statistics may be collected (e.g., "posture improved by X%"), never detailed body positions or images
1.4 Information NOT Collected
- Webcam images or video recordings
- Detailed body measurements or positions
- Location data
- Contacts or address book information
- Financial information (payments handled by third parties)
2. How We Use Your Information
We use the information we collect to:
- Provide and maintain the Service
- Create and manage your account
- Send you important notifications about the Service
- Respond to your inquiries and provide customer support
- Improve our Service and develop new features
- Detect, prevent, and address technical issues
- Analyze usage patterns to enhance user experience
- Comply with legal obligations
3. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we rely on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Performance of contract |
| Essential Service operation | Performance of contract |
| Analytics and improvement | Legitimate interests |
| Error reporting | Consent |
| Marketing communications | Consent |
You may withdraw your consent at any time by contacting us or adjusting your settings within the app.
4. Third-Party Services
We use the following third-party services:
4.1 Firebase (Google)
- Purpose: Authentication, database, and hosting
- Data Shared: Account information, user preferences
- Privacy Policy: firebase.google.com/support/privacy
4.2 Google Analytics
- Purpose: Website and app usage analytics
- Data Shared: Anonymized usage patterns, device information
- Privacy Policy: policies.google.com/privacy
4.3 Sentry (Error Reporting)
- Purpose: Error tracking and performance monitoring
- Data Shared: Error logs, device information (only with your consent)
- Privacy Policy: sentry.io/privacy
4.4 TensorFlow.js
- Purpose: On-device AI for posture detection
- Data Shared: None - all processing is local
5. Cookies and Tracking Technologies
Our website uses cookies and similar technologies. For detailed information, please see our Cookie Policy.
Types of cookies we use:
- Essential Cookies: Required for the website to function
- Analytics Cookies: Help us understand how visitors use our site (Google Analytics)
- Functionality Cookies: Remember your preferences
6. Data Storage and Security
6.1 Where We Store Your Data
Your data is stored on servers located in the United Kingdom and European Union via Firebase (Google Cloud Platform). By using our Service, you consent to this data storage.
6.2 Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest for stored data
- Secure authentication mechanisms
- Regular security assessments
- Limited access to personal data
6.3 Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion (immediately removed upon request) |
| Posture history | Until account deletion (immediately removed upon request) |
| Usage analytics | 26 months (anonymized) |
| Error reports | 90 days |
| Support communications | 3 years |
7. Your Rights Under GDPR
If you are in the European Economic Area (EEA) or United Kingdom, you have the following rights:
- Right of Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Request transfer of your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
- Right to Lodge a Complaint: File a complaint with a supervisory authority
We will respond to your request within one month. There is no charge for exercising these rights.
To exercise your rights, please contact us at privacy@sitapp.app.
8. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: What personal information is collected, used, shared, or sold
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt out of the sale of personal information
- Right to Non-Discrimination: Not be discriminated against for exercising your rights
To exercise your California privacy rights, contact us at privacy@sitapp.app.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
When we transfer data outside the EEA/UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Transfers to countries with an adequacy decision
- Other legally approved transfer mechanisms
10. Children's Privacy
SitApp is intended for users who are at least 18 years old. We do not knowingly collect personal information from children under 18.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@sitapp.app. We will take steps to delete such information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date
- Sending you an email notification (for significant changes)
We encourage you to review this Privacy Policy periodically.
12. How to Complain
If you have concerns about our use of your personal information, you can:
- Contact us directly at privacy@sitapp.app
- Lodge a complaint with the Information Commissioner's Office (ICO) if you are in the UK
ICO Contact Details:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Website: www.ico.org.uk
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: privacy@sitapp.app
General Inquiries: info@sitapp.app