Privacy policy
Stiva website
Last updated: June 28, 2026
Welcome to Stiva ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and your rights when you visit our website (stiva.app) and join our waitlist.
1. Data Controller
The Data Controller responsible for your personal information is:
- Name: Dario Tordoni
- Contact Email: [email protected]
2. Information We Collect
We collect two types of information when you interact with our website:
- Information you provide: When you join our waitlist, we collect the email address you provide to us.
- Information collected automatically: When you visit our website, basic technical data such as your IP address, browser type, and operating system may be passively processed. This happens because our website is hosted on Cloudflare Pages and uses Google Fonts to display text properly.
- Anonymous analytics data: We use a privacy-friendly, cookieless analytics tool (Umami) to understand aggregate traffic, such as page views, referring sites, and approximate country, browser, and device type derived from your IP address. This data is anonymized and aggregated; it does not identify you personally and is never combined with your email address. When you join the waitlist, we also record an anonymous event noting which platform button you used, purely to measure interest.
- Legal Basis: Consent (for the waitlist) and Legitimate Interest (for analytics, security, and fonts).
3. How We Use Your Information (and Legal Basis)
We use your information solely for the following purposes:
- To manage the waitlist and send updates: We use your email to notify you when Stiva is ready for beta testing or public launch, and to send occasional, relevant updates. (Legal basis under GDPR: Your Consent).
- To ensure website security and functionality: Technical data (like your IP address) is processed by our hosting provider (Cloudflare) to defend against malicious traffic and by Google to serve fonts to your browser. (Legal basis under GDPR: Legitimate Interest).
- To understand and improve our website: We process anonymous, aggregated analytics (via Umami) to see which pages are popular and how visitors find us, so we can improve the site. This data cannot identify you. (Legal basis under GDPR: Legitimate Interest).
4. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties. We may share your data only with trusted third-party service providers strictly for the purposes outlined above:
- Email Marketing Platforms: To securely store your email and send you our communications.
- Infrastructure Providers: Such as Cloudflare (for secure hosting) and Google (for web fonts).
- Analytics Infrastructure: Our analytics tool (Umami) runs on a self-hosted instance provided by Vercel. Anonymous analytics data is processed on Vercel's servers, which may be located in the United States. We ensure appropriate safeguards are in place for such transfers.
5. Data Retention and Security
We will keep your email address only for as long as necessary to fulfill the purposes outlined in this policy (e.g., until the app is launched or you unsubscribe). We implement appropriate technical and organizational security measures to protect your information from unauthorized access or disclosure.
Local app/extension data remains on your device/browser until you delete it or uninstall the app.
All transmissions (e.g., to Dropbox or Google Drive) are encrypted via modern SSL/TLS (HTTPS) protocols.
6. Your Privacy Rights
Depending on your location (including the EU under the GDPR and California under the CCPA), you have specific rights regarding your data:
- Access, Correct, or Delete: You can request to access the personal information we hold about you, or ask us to update or delete it.
- Withdraw Consent (Unsubscribe): If you wish to be removed from our waitlist, you can easily do so at any time by clicking the "unsubscribe" link in our emails or by contacting us directly.
- Do Not Sell My Personal Information (CCPA): We explicitly confirm that we do not sell your personal data.
7. Contact Us
If you have questions, comments, or requests regarding this policy or your privacy, you may email us at: [email protected].
Stiva App
Last updated: May 28, 2026
Welcome to Stiva ("we," "our," or "us"). We have designed the Stiva mobile application with your privacy as a top priority. This Privacy Policy explains how we handle your data when you download and use the Stiva app. Unlike our website, the app operates primarily offline, keeping your sensitive personal data right on your device.
1. Data Controller
The Data Controller responsible for your privacy is:
- Name: Dario Tordoni
- Contact Email: [email protected]
2. User-Created Data (Saved Links, Articles, Tags)
Stiva is designed to work completely offline. All the content you create within the app is safely stored on your device:
- Local Storage: Your saved links, articles, tags, and reading progress are saved exclusively in a local database (SQLite) located directly on your device.
- No External Access: We do not have access to your saved links, reading lists, or tags. They are never transmitted to our servers or any third-party servers.
3. In-App Purchases and Payments
Stiva is offered as a one-time in-app purchase. When you buy the app you receive the version available at the time of purchase, together with any subsequent improvements and bug fixes released for that version. Future major releases, if any, may be offered as an optional, separately paid upgrade; they are never charged automatically.
- Processing: All financial transactions are processed securely by Apple (App Store) or Google (Google Play Store). We never have access to your payment information.
- RevenueCat: To verify your purchase and any optional paid upgrades, we use RevenueCat. It generates a random "App User ID" to confirm your entitlements. No identifiable personal information (name/email) is shared with them.
- Data Transfer: Transaction data is processed by RevenueCat on servers located in the United States. We ensure appropriate safeguards are in place for such transfers.
- Legal Basis: Performance of a contract.
4. Analytics and Usage Data
Tracking is disabled by default. If you opt-in via Settings, we use Firebase (Google) to collect anonymous usage data (e.g., features used, crash reports).
- International Transfers: This data is processed on servers located in the United States.
- Opt-out: You can disable this at any time in the app's Settings.
- Legal Basis: Consent.
5. Local Notifications
Notifications are triggered entirely locally by your device. No data is sent to external push notification servers.
6. Children's Privacy
Stiva is not intended for use by children under the age of 13. We do not knowingly collect personal data from children.
7. Your Privacy Rights and Data Deletion
Since Stiva requires no account, you have full control. You can delete all your data by:
- Deleting content within the app.
- Clearing app data/cache in your device settings.
- Uninstalling the app.
8. Contact Us
Questions? Contact us at: [email protected].
Stiva Extension
Last updated: May 22, 2026
The extension acts as a secure bridge between your browser and your personal cloud storage.
Information We Handle
- Authentication Data: When you connect Dropbox or Google Drive, the extension handles your email address and OAuth tokens. This data is stored locally in your browser's secure storage.
- Website Content (Clipping): When you click "Save to Stiva," the extension extracts the URL, title, and text content of the active tab using the Mozilla Readability library.
- Permissions: We use activeTab and scripting only when you interact with the extension to perform the clipping.
How We Use and Share Information
- Direct Transfer: Extracted content is sent directly from your browser to your cloud account via encrypted HTTPS. We do not operate any central server; your data never passes through our infrastructure.
- No Third-Party Sharing: We do not sell or trade your data. We do not use it for advertising or marketing.
Limited Use Disclosure
The Stiva Browser Extension complies with the Google Chrome Web Store User Data Policy (developers.google.com/chrome/web-store/program-policies#user-data), including the Limited Use requirements:
- Allowed Use: We only use data to provide the "save for later" functionality.
- No Transfers: We only transfer data to your chosen cloud provider (Dropbox/Google) to provide the service.
- No Ads: We never use your data for personalized or interest-based advertising.
- No Human Review: We do not allow any human to read your data.