Stoiq

Privacy

Stoiq privacy

Local first. Specific when it isn’t.

Effective August 13, 2026

Regulr AI, Inc., doing business as Stoiq, operates Stoiq and stoiq.ai. The Mac and iPhone apps keep the work itself on your devices first. When you are signed in, Stoiq can also keep an encrypted device snapshot for account sync. This policy names that and the other narrow cases where data reaches our services or the providers that help us run them.

The short version

  • Stoiq does not read keystrokes, screenshots, page content, messages, or general browser history.
  • Your to-dos, notes, focus history, and learned context are stored locally first; signed-in device sync uploads only a client-encrypted snapshot.
  • Purchases, account access, encrypted device sync, optional usage diagnostics, and a temporary live-session relay use Stoiq services.
  • Optional notifications and live-sync wakeups use an opaque Apple device token; live-sync wakeups contain no task content.
  • You can permanently delete your account and synced product data from Your account in the iPhone app, with a fresh email confirmation.
01

What stays on your devices

Stoiq stores your to-dos, steps, notes, due dates, check-ins, focus sessions, reflections, progress, protected domains, intervention outcomes, companion relationship state, and garden locally. Connected folders are scanned only for metadata such as names, paths, dates, sizes, and Git status; Stoiq does not read their file contents in this release.

During a focus session, Stoiq can observe the foreground app, a coarse idle state, and—when the Chrome companion is connected—the active domain. Those observations are held in a bounded in-memory buffer and discarded when the session ends or awareness is disabled. Stoiq does not collect URL paths, page titles, page content, search queries, form input, browser messages, keystrokes, screenshots, or general browsing history.

02

Chrome companion and Limited Use

The Stoiq Chrome extension uses the active tab URL only to normalize its domain and compare that domain with the websites you explicitly shield in the Stoiq Mac app. It keeps the current focus lease, shielded domains, short-lived allowances, bounded visit counts, intervention choices, and connection health locally in Chrome. It does not read page content, URL paths, page titles, form input, messages, search queries, keystrokes, or general browsing history.

The extension communicates with the Stoiq Mac app on the same computer through Chrome native messaging so it can receive the active focus context and return an intervention choice. This information is used only to provide Stoiq’s focus-shielding feature. Regulr AI, Inc. does not sell or transfer it to third parties, use it for purposes unrelated to that single purpose, or use it to determine creditworthiness or for lending.

The use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

03

Accounts, purchases, and licences

If you buy Stoiq or sign in, we process your email address, purchase plan and status, processor order or subscription identifiers, refund or cancellation status, licence claims, and the minimum security records needed to issue and refresh a signed licence. We use Supabase for account and entitlement storage, Stripe for direct checkout and billing, and Apple StoreKit for purchases made in the iPhone app. Stripe or Apple receives the payment and billing information you provide. Stoiq receives the resulting signed transaction, product, subscription, and refund status needed to deliver and restore access, but does not receive your full card number.

Purchase and entitlement records are kept as needed to deliver access, handle refunds and disputes, maintain accounting records, prevent fraud, and meet legal obligations. Licence links and codes are rate-limited and expire or become unusable after they are redeemed.

04

Encrypted device sync

When you are signed in, each Stoiq app periodically makes a versioned snapshot of its local product data and encrypts that snapshot on the device before uploading it. The sync API receives an opaque encrypted payload, a device identifier, format version, integrity digest, and update time; it does not receive separate plaintext fields for your to-dos, notes, check-ins, focus history, shields, garden, or relationship memory.

Supabase stores one encrypted snapshot per device under your verified Stoiq account. Other Stoiq apps presenting a current signed licence for that account can download the snapshots and merge them locally. Encryption material is carried in the signed licence and protected with the account records used to operate your account. Account sync does not depend on an iCloud account.

05

Live-session relay

When you are signed in and a focus session is running, Stoiq can relay its mode, start and end times, device identifier, and the title of the current to-do—capped at 200 characters—so another device on the same account can mirror it. No notes, steps, outcomes, browser context, or file data are included.

The relay row is readable only by the same account and is deleted when the session ends. Running rows expire after their finish line if the owner stops checking in; paused rows have a bounded twelve-hour recovery window. Apple push messages carry only a content-free wakeup, and each device then reads the authoritative relay row. Nothing is relayed when you are not signed in.

06

Diagnostics and website measurement

If product diagnostics are enabled, the apps send a closed set of event names, timestamps, anonymous device identifiers or a verified entitlement identifier, and bounded properties such as durations, outcomes, app version, and a protected domain when an intervention occurs. They do not send task notes, page content, file contents, screenshots, keystrokes, or general browsing history. You can turn diagnostics off in Settings.

Stoiq.ai uses Google Analytics to measure page visits and uses a first-party attribution cookie and browser storage when someone arrives through a creator link. Those records help us understand which page or creator led to a purchase. Stripe and Supabase also process technical and security data under their own policies. We do not sell personal information or use Stoiq activity to build advertising profiles for other companies.

07

Notifications

If you allow notifications on iPhone, Stoiq can schedule a small number of onboarding and first-focus reminders entirely on your device. Stoiq can also send account-scoped notifications for a closed set of product events, such as when Stoiq returns from an item journey, and limited re-engagement reminders based on account status and recent Stoiq activity. Notification payloads do not include task names, notes, browser activity, or other private work content.

To deliver remote notifications, Stoiq stores an opaque Apple Push Notification service token, a random app-install identifier, the token environment, notification authorization status, current timezone offset, and app version under your account. Apple receives the token, the closed notification payload, and technical delivery information needed to deliver it. Stoiq keeps bounded delivery and failure records without placing the raw token in those records. Signing out, deleting your account, an invalid token, or disabling notifications stops future delivery; you can also turn notifications off at any time in iOS Settings.

08

Your controls

Working Awareness, calendar access, connected folders, website shields, microphone access, notifications, and diagnostics are controlled in the app or the operating system. Delete all data in Stoiq removes its local records, learned context, diagnostics queue, bridge state, notifications, and listed preferences. Chrome keeps its own extension storage and permissions, so remove or reset the extension separately in Chrome.

You can export a JSON inventory of core local records in Settings. You can permanently delete your account and synced product data from Your account in the iPhone app; Stoiq sends a fresh confirmation link to the address on the account before it deletes anything. You can also request access to or correction of account data by emailing us from that address. Some transaction records may remain where law, fraud prevention, or an unresolved dispute requires them.

09

Children, security, and changes

Stoiq is not directed to children under 13 and we do not knowingly collect their personal information. We use access controls, signed licences, secret storage, rate limits, and encrypted HTTPS connections, but no service can promise perfect security.

We will update the effective date and this page when the policy changes materially. If a change affects how existing account data is used, we will provide notice appropriate to that change.

Privacy requests

Talk to a person.

Email hi@stoiq.ai from the address connected to your account.

Stoiq
© 2026 StoiqPrivacyTermsSupport