Privacy Policy
Last updated: 20 July 2026.
Who we are
Stasis is a hypnosis and meditation app. This policy explains what we collect, why, where it goes, and the choices you have. It is written to be honest about a design choice we care about: your most sensitive information never leaves your device.
The organisation responsible for your data (the data controller) is GrowthNodes ApS, Havneholmen 70, 2nd floor, 1561 Copenhagen V, Denmark (CVR 40196021). You can reach us about any privacy question or request at [email protected].
The short version
The app is local-first. The information that could reveal something about your health or state of mind stays on your device and is never uploaded to us. A small amount of account and app data does go to our servers so features like sign-in, subscriptions, and rewards can work across your devices. We do not sell your personal data.
What stays on your device
The following is stored only on your device. We never receive it, and it is removed from your device when you delete your account or the app:
- How you felt before or after a session, including moods and feelings you record.
- Your answers to the safety and contraindication check. This can include questions about pregnancy, epilepsy, psychosis, active thoughts of suicide, dissociation, and whether you have a pacemaker.
- Your listening history and which sessions you played.
- The goals you choose to work on.
This information exists so the app can personalise your sessions and keep you safe. Because it lives only on your device, we cannot read it, share it, or use it for advertising.
What we send to our servers
To make accounts, subscriptions, and rewards work, a limited set of data goes to our servers and service providers:
- Account email. Only if you create or upgrade to an account. You can use the app anonymously first, without an email.
- A random user id. A generated identifier (a UUID) that lets your data sync without using your name.
- Timezone. Used to schedule daily features and time-based rewards correctly.
- Sign-in identity. If you sign in with Google or Apple, the identity those services return so we can recognise you.
- The rewards economy. Your currency ledger, wallet, streaks, referrals, and chest rolls. The ledger includes short human-readable reason labels, such as the name of the feature or quest that earned a reward.
- Push token. A device notification token, only if you turn notifications on, so we can deliver reminders you asked for.
Analytics
We use PostHog to understand how the app is used so we can improve it. PostHog receives coarse in-app events (for example, that a screen was opened or a feature was used) tagged with a device-generated distinct id. By default it also receives the request IP address, which gives an approximate region. Event properties are designed to avoid personal content.
There is currently no in-app control to turn analytics off. We are adding a setting so you can opt out. In the meantime, you can contact us at [email protected] and we will honour a request to stop analytics for your device.
Why we are allowed to use your data (legal bases)
For people in the UK, the EU, and other regions with similar laws, the legal bases we rely on under GDPR Article 6 are:
- Contract. To provide the app, your account, subscriptions, and rewards.
- Legitimate interests. To keep the app secure, prevent abuse of the reward systems, and improve the product with coarse analytics.
- Consent. For notifications and, where required, for analytics. You can withdraw consent at any time.
The safety, mood, and goal information the app uses can count as special category (health-adjacent) data under GDPR Article 9. Where that applies, the basis is your explicit consent, given when you complete the safety check in the app. Because this data stays on your device and is never sent to us, we do not process it on our servers. You can withdraw consent at any time by clearing it in the app or deleting your account.
Who processes data for us (sub-processors)
We share the server-side data described above only with service providers that help us run the app, under contracts that limit how they may use it. We name them so you can see exactly who is involved and read their own policies:
- Supabase: database, authentication, and storage hosting. supabase.com/privacy
- PostHog (US): product analytics. posthog.com/privacy
- RevenueCat: subscription and purchase management. revenuecat.com/privacy
- Expo: push notification delivery. expo.dev/privacy
- Loops (US): lifecycle email for the early-access list and product updates. loops.so/privacy
- Resend (US): early-access and email delivery. resend.com/legal/privacy-policy
- Cloudflare (US): website hosting, the Turnstile bot check, and the early-access email form, which receives the email address you submit and your IP address. cloudflare.com/privacypolicy
The app stores (Apple App Store and Google Play) also process your subscription receipt and entitlement when you buy premium. We never receive your card number.
Where your data is processed (international transfers)
Some of our providers process data in the United States and other countries outside the UK and the EU. When data is transferred out of the UK or the EU, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the providers' own compliance measures.
How long we keep data
- On-device data (moods, safety answers, listening history, goals) stays until you delete it in the app or delete the app. We never hold a copy.
- Account and rewards data is kept while your account is active and is erased when you delete your account.
- Analytics events are retained for a limited period to spot trends, then removed or aggregated so they no longer identify a device.
- Records we must keep by law (for example, tax or transaction records tied to a purchase) are kept only for as long as the law requires.
Your rights and how to use them
Depending on where you live, you have rights over your personal data. Under GDPR and UK GDPR these include the right to access, correct, erase, and receive a portable copy of your data, to object to certain uses, and to withdraw consent. Under the CCPA and CPRA in California, these include the right to know, the right to delete, and the right to opt out of the sale of personal data. We do not sell your personal data.
To exercise any right, email us at [email protected]. We do not yet offer an automated export, so to receive a copy of your data please ask us and we will respond within 30 days.
Deleting your account
You can delete your account from inside the app at any time. Deleting your account runs a server routine that erases all of your server-side account data, including your account email, rewards ledger and wallet, streaks, referrals, and push token. Deleting the app or your account also removes the on-device data described above from your device. If you prefer, you can ask us to delete your account by contacting [email protected].
Children
Stasis is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has used the app, contact us at [email protected] and we will delete the data.
Changes to this policy
If we make material changes, we will update this page and change the "Last updated" date. Where appropriate, we will also let you know in the app.
How to contact us
For any privacy question or request, contact GrowthNodes ApS, Havneholmen 70, 2nd floor, 1561 Copenhagen V, Denmark (CVR 40196021) at [email protected].