Privacy Policy
This policy describes the launch version now being prepared, including optional Agent Card setup. Earlier TestFlight builds may not offer every setup or deletion control described below; contact us for help.
Last updated: September 12, 2026
The short version
Startr is made by Shop480, LLC. Habit tracking works without an email, password or online account setup, and your habit records stay on your device. We do not sell your data or use it for advertising. The launch version contains no ads or advertising SDK and does not request tracking permission.
Agent Cards are a separate, optional online service. Choosing to connect an agent creates an anonymous setup identity and device connection so the service can deliver your cards securely. “Anonymous” means we do not ask for your name, email or password; the random identifiers are still linked to your installation. Subscriptions also require limited purchase records to verify access.
What stays on your device
Your habits, entries, goals, notes, streaks, achievements, reminders, themes and selected habit artwork are stored locally. Apple Watch and widgets use local data through Apple's device/app communication facilities. Cross-device habit groups and CloudKit group sync are not enabled in this release.
Optional Apple Health integration reads or writes only supported, user-authorized types on device. Optional location verification checks a selected habit's location when you log it; the saved target and current check are not sent to Startr's servers. Apple's system photo picker lets you choose habit artwork; Startr does not upload those images or request your entire library. Apple's device backup and platform services are governed by Apple's policies.
Optional Agent Cards
Choosing Settings → Agent Cards → Connect an agent uses Supabase Auth to create an anonymous setup identity. The service stores its random ID and installation relationship. No name, email or password is required. Your compatible agent application is separate and may have its own account and terms.
Startr retains installation and agent IDs, the connection name you choose, credential hashes, ActivityKit/APNs delivery tokens, approval/revocation state, and bounded event/answer/delivery metadata. These authenticate connections, route the right card, enforce capacity, prevent abuse and diagnose delivery. They are not advertising identifiers or a habit-analytics feed.
Your agent supplies card title, status, progress, timing, milestones and other supported display fields. Content passes through Startr's Supabase-hosted relay and Apple Push Notification service. Startr's application tables do not store readable card text, question prompts or a card-history feed. They do store connection names and fixed Yes/No results with routing/timing metadata. An unanswered question is not treated as No. The selected agent can read its own fixed answers; an answer is not authorization for purchases or other consequential actions. Pairing does not give agents access to your habit, Health or location history.
Cards can appear on your Lock Screen, Dynamic Island, Apple Watch or other Apple surfaces enabled for your devices. Do not put passwords, access codes or confidential information on a card. Delivery uses HTTPS and Apple's push service; it is not end-to-end encrypted against the delivery providers.
Shared Cue cards
A host can invite a small audience to one expiring Cue card. Joining is explicit and read-only; a recipient needs no agent or command-line tool. Startr retains invite/member identifiers, hashed join credentials, recipient push tokens and delivery/lifecycle metadata. The host's agent supplies updates; Startr does not replay a stored readable card history to late joiners.
The host can stop new joins or end sharing. A follower can leave. Share invites only with intended recipients. Joining does not approve an agent to access the follower's other cards or habit records.
Subscriptions
Apple processes payments and refunds. Startr does not receive payment-card numbers, bank details, Apple Account passwords or Apple Account email addresses. We verify signed transactions and current subscription status to grant access.
We retain product/transaction identifiers, purchase/expiry/refund status and dates, an appAccountToken and installation associations. Restore Purchases can restore eligible paid access, but never restores, transfers or approves agent connections.
Service providers and operational logs
Apple supplies StoreKit, HealthKit, notifications, device communication and system services. Supabase hosts the optional connection, authentication, subscription-access records and card-delivery service. DreamHost hosts our website and a private server-to-server service that verifies Apple's signed purchase and subscription-notification records. That verifier processes purchase records in memory; our verifier code does not save those records or log request bodies or credentials. It does not receive your habits, card text or payment-card details. We use these providers to operate Startr, not to sell data or target advertising.
Authentication and delivery infrastructure can retain security/operational logs: identifiers, IP address, client information, timestamps, request/response metadata and diagnostic codes. Request content may be processed by delivery infrastructure separately from Startr's application tables. These records support service operation, fraud prevention and troubleshooting and are subject to provider and configured retention. No-cache headers do not erase provider logs. We do not operate a separate habit analytics or crash-reporting SDK.
Retention and deletion
- Local habit data remains until you delete it or remove the local app data. Export a backup first if you want to keep it.
- Active connection and routing records remain while needed for your chosen service. Revoke individual agents in Agent Cards settings.
- Card event metadata is scheduled for deletion after 7 days for Free or 30 days for Pro. Fixed-answer metadata follows the corresponding tier retention after question expiry. Daily cleanup can occur after the cutoff. Revoked/expired credentials and legacy connection records become eligible after 30 days.
- Delete connection and data in Agent Cards settings deletes this device's anonymous setup identity, installation relationship, agent credentials and routing data. End active hosted sharing first if requested. Local habits and separately followed shared cards are not erased by this action.
- A hash-only deletion completion receipt is kept for 30 days to confirm an interrupted response; it cannot authenticate another operation. Abandoned, unused anonymous setup identities become eligible for daily cleanup after 30 days; active enrolled identities are not swept by that rule.
- Limited purchase evidence is retained after connection deletion for subscription verification, restore, refunds and fraud prevention. It is not automatically purged with the connection; the deleted installation link is removed and the evidence cannot recreate agent credentials. Contact us about access/deletion requests and any records that must be retained.
Deleting Startr or its connection does not cancel an Apple subscription. Manage or cancel in your Apple Account subscription settings. Uninstalling alone is not a request to delete server records and may not clear iOS Keychain.
Website launch list and support
If you join the startrapp.com launch list, the website stores your email and basic submission details: timestamp, IP address, page/campaign information, referrer and browser user agent. We use these for Startr updates, spam prevention and signup-source measurement, not third-party advertising. The list is stored outside the public website directory. Unsubscribe or request removal by emailing hello@startrapp.com.
If you contact support, we use what you choose to send to respond. Do not send private connector credentials or sensitive card content. We may retain records needed to comply with law, resolve disputes or prevent fraud. We do not sell personal information or share it for cross-context advertising.
Your choices and contact
Use manual habit tracking without online setup or optional Health, location and notification permissions. Change permissions in iOS Settings, revoke an agent, leave a shared card, or delete the connection in-app. For access, correction or deletion questions, email hello@startrapp.com. Appropriate proof of control may be needed so we do not delete someone else's connection.
Startr is not directed to children under 13. If you believe a child provided personal information, contact us so we can investigate and remove it where appropriate. The App Store's age rating describes content, not a children's service.
We update this policy when practices change. Material new collection or sharing will be explained before it is enabled where required.
Provider information: Apple privacy, Supabase privacy, DreamHost privacy.