Privacy Policy — Stay at Zero

Last updated: 2026-08-14

Effective date: 2026-08-14

Controller: Paweł Graczyk

Contact: support@stayatzero.com

Product: Stay at Zero (web application for personal fasting tracking)

Keep this document in sync with Settings links and Connect-account copy.


1. What this policy covers

This policy describes how we process personal data when you use Stay at Zero, including:

  • guest / local-only use in your browser
  • connecting an account (sign-in via our identity provider)
  • syncing fasting history to our servers
  • optional import/export of backups

Stay at Zero is a personal fasting tracker. It is not a medical device and does not provide medical advice.


2. Data we process

2.1 On your device (even without an account)

Stored in your browser (including IndexedDB / local storage), for example:

  • fasting sessions (start/end times, planned duration/goal, optional names, sync/revision metadata)
  • offline change queue (outbox) and conflict-resolution state used for sync
  • UI preferences (theme, language, timer defaults, and similar settings)
  • OAuth tokens when you are signed in (stored in browser storage)

Device-local data stays on that browser until you clear it, sign out / clear device data, or the browser removes site data.

2.2 On our servers (when you connect an account)

If you connect an account, we store data needed to provide sync and account features, including:

CategoryExamples
Account identifiersInternal account id; identity-provider subject (sub); email if provided by the identity provider
PreferencesLanguage, country (if set), theme, timer defaults, related timestamps
Fasting historyFast records (times, goals, soft-delete / revision fields, client metadata used for sync)
Conflict recordsOverlap / conflict-resolution records tied to your account
Technical logsService logs and security signals (e.g. request metadata, error diagnostics) as needed to operate the service

We do not currently collect body measurements (weight, height), date of birth, sex, or real-name profile fields as product features. Do not describe those categories here unless you add them.

2.3 Identity provider (Zitadel or successor)

Sign-in is handled by our OIDC identity provider. That provider processes authentication data under its own terms and privacy policy. We receive tokens and claims needed to identify your Stay at Zero account (typically a stable sub, and email when available).

Important: Deleting your Stay at Zero account removes Stay at Zero server data for that account and then attempts to delete your identity-provider login (self-deletion). If identity-provider deletion fails (for example missing permission), Stay at Zero data may already be gone — retry delete or contact support. See §7.

2.4 Processors / hosting

We use service providers (processors) to host and operate Stay at Zero — for example cloud application hosting, managed databases, CDN / static hosting, and identity/authentication for sign-in. They process personal data only on our instructions and as needed to provide their services.

Where practicable we use infrastructure in the EU/EEA. If a transfer outside the EEA is required, we use safeguards required by law (such as Standard Contractual Clauses). Optional product analytics providers are described in §4.


PurposeLegal basis (typical)
Provide the app, local tracking, and (when connected) syncContract / steps prior to contract (Art. 6(1)(b)), or legitimate interests in operating a requested service for guests
Account security, abuse prevention, rate limitingLegitimate interests (Art. 6(1)(f))
Service reliability, debugging (logs / error reports)Legitimate interests (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c)) where applicable

Fasting history can be sensitive in context. We process it only to provide the tracking/sync features you request. We do not sell personal data.


4. Cookies and similar technologies

We use browser storage required for the product (preferences, offline data, auth tokens). We do not use third-party advertising cookies.

Product analytics (optional). If you turn on Product analytics in Settings (or accept an in-app prompt), we send anonymous usage events to PostHog (EU cloud, eu.i.posthog.com) so we can see which parts of the app work. Events may include route names, button/feature names, coarse duration buckets, and locale — not notes, labels, exact fast timestamps, or your email.

With the same opt-in, we may also record session replays (a reconstruction of what you see in the app: taps, scrolls, and screen layout) via PostHog so we can diagnose usability issues. Input fields are masked in recordings (including notes, labels, and time editors). Replays do not include your email or account password. Analytics and session replay are off by default. You can turn them off anytime in Settings → Legal; we then stop sending events and stop recording. When you connect an account with analytics on, we may link the anonymous analytics id to your opaque account id (not your email) so we can understand connected vs guest usage.

Marketing site (stayatzero.com). Google Analytics loads only after you choose Accept all on the cookie banner. Accepting can also enable anonymous product analytics in the web app via a same-site consent cookie and/or an ?analytics=1 handoff. You can withdraw that in app Settings. This handoff does not apply to native desktop/iOS shells.


5. Retention

DataRetention
Device-local dataUntil you clear device data / site data, or as retained by your browser
Server account + fastsUntil you delete the Stay at Zero account, or we close the service after notice
Backups / database historyPer our hosting provider’s backup and recovery windows
Security / operational logsTypically up to 90 days, unless needed longer for security incidents

After account deletion, server-side Stay at Zero account data and associated fasts/conflict records are removed from the primary database. Residual copies may persist until backup windows expire.


6. Sharing

We share personal data only with:

  • processors who host or operate the service for us
  • authorities when legally required
  • a successor if the service is transferred (you will be informed where required)

We do not sell your personal data.


7. Your rights and controls

Depending on applicable law (including GDPR if you are in the EEA/UK), you may have rights to access, rectify, erase, restrict, object, and data portability, and to lodge a complaint with a supervisory authority (the President of the Personal Data Protection Office (UODO) in Poland).

In-product controls today:

  • Export — download a Stay at Zero backup (when online with a connected account)
  • Import — restore from a Stay at Zero backup or supported Zero biodata.json fasting history
  • Clear data on this device — removes local browser data for this app; does not delete server data
  • Delete account — permanently deletes your Stay at Zero account and server fasting data, then deletes your identity-provider user (self-delete via Zitadel User API). Requires sign-in with a token that can call Zitadel APIs and self-delete permission on the identity provider.

For rights requests we cannot fulfill in-app, contact support@stayatzero.com.


8. International transfers

Where practicable we process data in the EU/EEA. If we process data outside your country or outside the EEA, we use appropriate safeguards required by law (for example Standard Contractual Clauses).


9. Children

Stay at Zero is not directed at children under 16 (EU digital-consent default; your country’s age of digital consent applies if higher). Do not use the service if you are under that age.


Stay at Zero stores self-reported fasting activity. It does not diagnose, treat, or monitor disease. Longer or medical-related fasting decisions belong with a qualified clinician. See also in-app safety information and the Terms of Service.


11. Changes

We may update this policy. We will change the “Last updated” date and, for material changes, provide additional notice where required (in-app or email if available).


12. Contact

Privacy questions and rights requests: support@stayatzero.com