Privacy Policy
This policy explains how Staily collects, uses, shares, retains, and protects information when you use the Staily app, website, and support services. Last updated 27 August 2026.
Who is responsible for your information
Staily is operated by Darko Smigic, Appenzellerstrasse 3/12, 6840 Götzis, Austria, who is the data controller responsible for the processing described in this policy. You can contact Staily at support@staily.app. This operator information is kept consistent with the Apple App Store and Google Play listings.
Information we collect
We collect account and authentication identifiers; settings and consent choices; photos, image metadata, preview instructions, generated previews, and saved content that you submit or create; subscription, entitlement, purchase-product, refund, and preview-credit records; support messages, voice notes, screenshots you choose to attach, and related device or route details; push-notification tokens and preferences; and limited security, reliability, and product-usage information. Apple and Google process your payment credentials; Staily does not receive or store full payment-card details.
Why we use information and our legal bases
We use information to create and store requested previews, authenticate accounts, provide subscriptions and credits, deliver notifications, restore purchases, provide support, prevent abuse, secure and debug the service, meet legal obligations, and establish or defend legal claims. Where laws such as the GDPR or UK GDPR apply, these activities rely as appropriate on performing our contract with you, complying with law, our legitimate interests in operating and protecting Staily, and your consent. Optional product analytics relies on consent and remains off until you enable it. You may withdraw that consent at any time without affecting earlier lawful processing.
Photos and AI processing
Photos and preview instructions you select are stored in Staily's Convex-backed service and sent to Venice AI only as needed to perform the image or voice-processing request you initiate. Photos may contain personal or sensitive information about you or other people. You must have permission to submit them. We do not use private photos, prompts, or generated images for optional product analytics, advertising, or sale. AI processing is automated, but Staily does not use it to make legal or similarly significant decisions about you.
Subscriptions and preview credits
Apple or Google processes store payments. RevenueCat receives a pseudonymous Staily account identifier plus store transaction, product, subscription, entitlement, refund, and virtual-currency information so Staily can provide purchases and restore access. Convex stores the corresponding entitlement state and an auditable preview-credit ledger. Billing and anti-fraud processing is necessary to provide paid features and does not depend on optional analytics consent.
Optional analytics and diagnostics
Optional PostHog product analytics are off by default. If you enable them, Staily may send a pseudonymous account identifier and allow-listed events such as onboarding progress, feature use, paywall placement, purchase or restore outcome, preview completion, platform, app version, and bounded performance or error codes. We do not send your name, email address, photos, image or file URLs, prompts, support content, notification tokens, or raw error messages to PostHog. Session replay is disabled unless this policy and the in-app consent are updated before it is introduced. Staily may separately process minimal reliability and security diagnostics through Expo/EAS and its infrastructure where necessary to operate and protect the service; these diagnostics must not include private photo content.
Service providers and disclosures
We disclose information only as needed to providers acting for us or to platforms that complete your request: Clerk for authentication; Convex for application data, functions, and file storage; Venice AI for requested AI image and voice processing; RevenueCat for purchases, entitlements, paywalls, and subscription analytics; PostHog for optional consented product analytics; Expo/EAS and Apple or Google for app delivery, diagnostics, notifications, and store transactions; and support, security, professional-adviser, or infrastructure providers where necessary. We may also disclose information when required by law, to protect users or the service, or in a merger, financing, acquisition, or sale subject to appropriate protections. We do not sell personal information or share it for cross-context behavioral advertising.
International transfers
Staily can be used internationally, and providers may process information in the European Economic Area, the United States, and other countries where they or their subprocessors operate. Those countries may have different data-protection laws. Where required, we use contractual and organizational safeguards such as data-processing agreements, the European Commission Standard Contractual Clauses, the UK transfer addendum, adequacy decisions, or another lawful transfer mechanism. You may contact us for information about applicable safeguards. Staily intends to use an EU-hosted PostHog production project; RevenueCat and some other providers process data in the United States under their published safeguards.
Retention and deletion
Account data, retained uploads, saved previews, billing state, and credit-ledger records are kept while your account is active and as needed to provide the service. Optional identifiable PostHog product events are retained for 12 months. Session replay is disabled; if introduced after renewed notice and consent, recordings will be retained for no more than 30 days. Raw server analytics are retained for 90 days, and genuinely de-identified aggregate statistics for 24 months. Security and authentication logs are normally retained for 12 months. Support communications are normally retained for 24 months after resolution; support screenshots are scheduled for deletion within 90 days. Account deletion requests removal of the RevenueCat customer record, Staily application data and stored files, optional analytics linked to the account where available, and the sign-in account; residual backups are overwritten or deleted within 90 days. Subscription records are normally retained for the account lifetime plus 24 months. Invoices, payment evidence, and tax or accounting records are retained for seven years from the end of the relevant calendar year, and longer only where required for an active legal or administrative proceeding. A stated period may be shortened when the information is no longer necessary or extended where law, fraud prevention, security, or a legal claim requires it. Store subscription records remain with Apple or Google under their policies, and deleting Staily does not itself cancel a store subscription.
Your privacy choices and rights
Settings lets you disable optional analytics and notifications, delete uploads and previews, and delete your account. Depending on where you live, you may also have rights to know or access information, correct it, receive a portable copy, delete it, restrict or object to processing, withdraw consent, appeal a refusal, and complain to a privacy regulator. We will not discriminate against you for exercising applicable rights. Send a request to support@staily.app; we may need to verify your identity and may decline or limit a request where the law permits. EEA residents may complain to the authority where they live or work; UK residents may contact the ICO; and residents elsewhere may contact their local regulator.
Children
Staily is an adult service, is not directed to children, and you must be at least 18 to create an account, use the service, or make a purchase. Staily does not offer a parental-consent route for minors. Do not upload images of children unless you are their parent or legal guardian, have all required permissions, and the use is lawful. Contact us if you believe a person under 18 created an account or provided information; we may suspend the account and delete the information, subject to legal retention duties.
Security and incidents
We use reasonable technical and organizational safeguards designed for the nature of the information, including authenticated access, server-side provider credentials, owner-scoped file access, and transport encryption supported by our providers. No service is completely secure. If a breach creates a legally reportable risk, we will notify affected people and authorities as required by applicable law.
Changes and contact
We may update this policy when Staily, its providers, or applicable laws change. We will post the revised date and provide additional notice or request renewed consent when required for a material new use. Questions, complaints, privacy requests, and requests for transfer-safeguard information can be sent to support@staily.app.