Stompt
Effective 4 September 2026 · Last updated 22 September 2026
Stompt films your skating, and keeps a record of how your body moved. You tell it which trick you are working on and whether you landed it; the app does not work that out for you. Either way it handles video of you — and often of whoever else is at the spot. This page explains exactly what it keeps, where it goes, and how to get rid of it. No vague language, no hedging.
The short version. Stompt uses PostHog for app-lifecycle, product-use and subscription analytics. Screen recording, touch tracking, advertising and tracking across other apps or websites are off. Stompt does not sell your data. Your clips are private to your account. All the movement analysis happens on your phone — no video frame is ever sent anywhere to be analysed. Some data is uploaded to a private cloud account, and the sections below say precisely what. That upload is not a restore feature: Stompt cannot put your history back on a new or reset phone, and it does not sync between devices.
Stompt is made and operated by Robert Paul, a sole proprietor trading under his own name. When this policy says "we" or "us", that is one person.
Questions, requests or complaints: support@stompt.app, or the SEND FEEDBACK form under the YOU tab in the app. A message sent from the app is stored with your account so a reply can reach you; replies are sent by email to the address on your account.
You must be at least 13 years old to use Stompt. If the law where you live requires a higher minimum age or verified parental authorisation for an online service, that higher requirement applies. If you are under 18, you need a parent or guardian's permission first. Stompt does not ask for your date of birth and relies on the age representation you make when using the service. Stompt is not aimed at children under 13 and we do not knowingly keep data from them. If you believe a child under 13 has an account, email support@stompt.app and we will delete it.
You can sign in with Sign in with Apple, Google, or email and password. Email sign-in, confirmation and password recovery are handled by Supabase Auth. Passwords and authentication credentials are never sent to analytics.
…@privaterelay.appleid.com). The app never sees your real address in that case.Your separate Stompt profile record contains your user ID and your stance (regular or goofy) — that's it. It has no name, age, photo, avatar, email address or phone number. Authentication information lives in the sign-in system's own record described above.
The setup questions help personalize your introduction to Stompt. Your typed name stays in the local onboarding draft; it is not sent to analytics. Product analytics can record the choices you submit, changes to categorical selections, whether you provided a name, and whether you submitted a custom answer. It does not record typing or abandoned text. Custom working-on and blocker text is excluded from analytics while its separate disclosure, restricted access and automatic deletion controls are not enabled and verified. We will update this policy before enabling that text collection.
For each skate session Stompt stores an ID, your user ID, the start and end time, and a spot label. The spot label is free text you type; it defaults to "SESSION". Stompt does not read your location — but whatever you type in that box gets stored, so if you type a street address, that address is stored. Type whatever you're comfortable with.
For each attempt Stompt stores the trick label you declared, the timestamp, the verdict (make or bail) you confirmed, whether you kept it, a detection score, the version of the analyser used, the storage paths of any files, and a set of body measurements taken from the attempt:
What the detection score is, and what it is not. Stompt watches for the movement that means an attempt just happened, so it knows where to trim the clip. The score records how sure it was about that — nothing else. It is not a guess at which trick you did, and it is not a guess at whether you landed it. Those two facts come from you: you declare the trick before you film, and you confirm make or bail in review. Stompt does not identify tricks, does not decide makes, and does not count flips.
The pose record and measurements are used only to describe movement in your skate attempt. Stompt does not use them to identify or authenticate you, infer a diagnosis or injury, or make a medical assessment. They are not a faceprint, fingerprint or other biometric identifier.
When an attempt's footage is uploaded, three files go to your private cloud folder:
The most important sentence in this document: the analysis runs entirely on your phone, using Apple's on-device Vision framework. No video frame is ever sent anywhere to be analysed. What gets uploaded is the result — the pose record described above — which is stored in your private cloud folder. It is stored there; it is not something the app can give back to you on another phone.
Read this carefully, because the default is not "nothing":
The metadata row for an attempt — trick label, verdict, kept, detection score, analyser version and the five measurements — is uploaded for every attempt, including bails whose footage never leaves your phone.
Uploads run on Wi-Fi only by default. You can opt into cellular uploads in the YOU tab. Either way, Stompt honours iOS Low Data Mode and holds uploads while it is on.
Upload is not backup, and it is not sync. Uploading is how your footage gets somewhere private and durable — it is not a way to get your history back. Stompt only ever sends data up; it never reads it back down. In practice that means:
Your device's own iCloud or computer backup is what protects your local library. If you care about a clip, keep your own copy of it.
Verified absent from the app's code, not just absent from this list:
The app has four direct third-party dependencies: Supabase, RevenueCat, Google Sign-In and PostHog.
| Permission | Why |
|---|---|
| Camera | To film your attempts. Nothing records until you arm a session. |
| Microphone | Audio is captured as part of the video. Clips have sound. |
| Photos (add only) | To save your full session recording to your photo library. Stompt can add to the library but cannot read it. |
| Notifications | Only if you turn on skate reminders. Reminders are scheduled on your device. |
There are no other permission requests. You can revoke any of them at any time in iOS Settings, though the app cannot film without the camera.
Stompt uses information for the following purposes:
Your data is not used for advertising, is not sold, rented or traded, and is not shared with data brokers. Stompt does not use your data to train a machine-learning model or authorise a service provider to do so on Stompt's behalf.
The app uses four direct service providers, and the website and support channel use their own infrastructure providers. Stompt limits what it sends to the information needed for each service. Those providers also process information under their own terms, privacy notices and applicable data-processing commitments.
Supabase hosts the database and file storage. Your rows and clips live there. Client access is locked down with row-level security so one user account cannot read another user's rows or files. The clip bucket is private, and client access requires an authorised, time-limited link. Supabase infrastructure and authorised Stompt server operations may process the data when needed to host, secure, support or delete it.
RevenueCat manages the subscription. Stompt gives it your opaque Supabase user ID — a random-looking identifier — and a matching PostHog identifier used to associate subscription lifecycle analytics. Stompt does not give RevenueCat your email address, name, spot label, video, pose data, measurements or session history. RevenueCat also receives App Store transaction and receipt information from Apple so it can determine whether your subscription is active.
If you sign in with Google, Stompt uses Google's authentication service. Stompt does not send Google your video, pose data, measurements or session history. Google may independently process authentication, device, network, security and diagnostic information under Google's own privacy policy.
PostHog receives app lifecycle and selected product events, a randomly generated installation identifier, and — after sign-in — your opaque Supabase user ID. Product events describe onboarding and authentication outcomes without entered credentials, presented subscription offers and purchase/restore outcomes, tab and screen visits with active duration, film entry and readiness, requested and applied camera settings, recording and processing outcomes including recordings that produce no tries, and demo or own-video review and playback engagement. Events may include canonical declared trick IDs, manually confirmed verdicts, bounded counts/durations and opaque operation IDs. No video or movement samples accompany those events. RevenueCat may also send subscription lifecycle events associated with that same opaque ID. The installation identifier is kept in a minimal anonymous PostHog profile so pre-sign-in events can be found and deleted even if the sign-in-linking event is interrupted. Events include technical context such as app/build version, iOS and device type, app language, formatting locale, and region code. PostHog may also derive an approximate country or region from the network address that delivered an event. Stompt has disabled screen capture, automatic screen views, touch and element capture, session replay, surveys, automatic error capture, and push-notification capture. PostHog receives no email address, name, spot label, filename, raw error text, clip, audio, image, pose record, password, authentication token, keystrokes or raw onboarding write-in text from Stompt.
Stompt uses PostHog's US Cloud service. Analytics records are kept under Stompt's PostHog account so usage and retention can be compared over time. Deleting your Stompt account automatically requests deletion of the PostHog people, associated events, and any recordings linked to your opaque user and installation identifiers. Session replay is disabled.
Apple is also involved, but as the platform: Apple processes your payment and runs Sign in with Apple under Apple's own privacy policy.
Stompt's website host may process the technical request-log information described above to serve and protect the static site. If you email support, the email provider processes your email address, message headers, content and any attachment so the message can be delivered, secured and answered. Do not send footage or sensitive information unless it is needed for the request.
Stompt does not disclose personal information except in the situations described in this policy:
Stompt may use statistics that have been aggregated or de-identified so they no longer identify a person, for example to understand overall app reliability and use. Stompt does not try to re-identify that information.
Skate spots are public and they have other people in them. If someone is identifiable in your clip — on camera, or just their voice on the audio track — you are responsible for that. You are the one filming, so it is on you to have whatever permission the law where you skate requires, and to respect anyone who asks not to be filmed. If someone identifiable in your footage contacts us and asks for it to be removed, we may remove that footage.
Clips are private to your account. Stompt never publishes, shares or sells your footage. There is no feed, no public profile, no leaderboard.
The app does have a share button. If you tap it and send a clip to Messages, Instagram, AirDrop or anywhere else, that clip goes wherever you sent it and this policy no longer covers it — it is governed by whatever service you sent it to. You share it; the app does not.
Your data stays for as long as your account exists. There is no automatic expiry — the whole point is a training history that goes back.
In the app: YOU → Delete account. This deletes:
It works from your verified user ID and cryptographically bound installation identifiers, so another signed-in client cannot name an arbitrary analytics identity for deletion. Account, product database and file deletion starts immediately. A restricted deletion ledger retains opaque identifiers, encrypted Apple revocation material when available, and processing status only while automatic vendor and late-upload cleanup runs; completed ledger entries are removed after 30 days. PostHog and RevenueCat process some deletion asynchronously; Stompt removes this device's pending analytics queue and repeats analytics, RevenueCat and file cleanup over seven days as a safeguard for requests already in flight. Apple accounts created before Stompt began retaining an encrypted revocation token may still need authorization removed manually in Apple ID settings. Deletion is permanent and cannot be undone.
Two things account deletion does not do, stated plainly:
1. CLEAR deletes footage, not history. CLEAR applies only to bails — it never touches makes. On the bails it does clear, it deletes the video, the poster frame and the pose record: from your phone immediately, and from your private cloud folder too. If you are offline when you clear, the files go from your phone straight away and the cloud copies are removed the next time the app has a connection. What stays is the record of the attempt — the date, the verdict, the measurements — because that is your training history, not footage. Nothing about CLEAR can be undone.
2. It does not cancel your subscription. Apple owns your subscription, not us, and the app cannot cancel it. Cancel it yourself in iOS Settings → your name → Subscriptions, before or after deleting the account.
If you want specific clips removed from the cloud but want to keep your account, email support@stompt.app and we will do it by hand.
Deleted files may persist temporarily in a hosting provider's protected disaster-recovery backups until those backups roll over. They are not accessible through the app and are not restored except as necessary for disaster recovery.
Where privacy law requires a legal basis, Stompt relies on:
Account identity and the session information described above are needed to provide the signed-in service. Camera access is needed to film, and microphone access is needed to include sound. You can refuse those permissions, but the affected feature will not work.
Depending on where you live — California, the EU/UK, and other places — you may have the right to know or see the data held about you, correct it, delete it, receive a portable copy, restrict or object to certain processing, withdraw consent, or appeal a refused request. Stompt honours these requests from everyone, regardless of where you live, and will not discriminate against you for making one. Delete is available in the app; for anything else, email support@stompt.app. Stompt may need to verify that the request concerns your account and will respond within 30 days.
Stompt does not sell personal information and does not share it for cross-context behavioural advertising, as those terms are defined under California law. There is nothing to opt out of, because it does not happen.
To stop further collection: delete the app. To remove the account, uploaded skate data, and analytics associated with the account, delete your account in the app.
If you are in the European Economic Area or UK, you may also complain to your local data-protection supervisory authority. Please contact Stompt first if you can so there is an opportunity to resolve the concern.
Account, session and skate data is stored on Supabase's infrastructure. Product analytics is stored in PostHog US Cloud. If you use Stompt from outside the countries where those servers sit, data is transferred and stored there. Where applicable law requires safeguards for an international transfer, Stompt relies on the receiving provider's contractual and other legally recognised transfer safeguards. Email support@stompt.app to ask about the safeguards relevant to your data.
Data is encrypted in transit and at rest by our hosting provider. Access is restricted by row-level security so an account can only reach its own rows and its own files, and clip storage is a private bucket rather than a public one. If you use email sign-in, your password is handled by Supabase Auth, which stores it only as a one-way hash; Stompt's app tables and analytics never receive it. Apple and Google sign-in use no Stompt password at all.
No system is perfectly secure, and we won't pretend otherwise. If Stompt discovers a breach affecting your data, it will investigate and provide notice when applicable law requires it.
If this policy changes, the "last updated" date at the top changes with it. If a change is significant — new data collected, a new company involved, or a new use — Stompt will provide notice before the change takes effect and will ask for consent where applicable law requires it.
Robert Paul, sole proprietor
support@stompt.app