Your privacy

App Privacy Policy

Nobody, not even the Stotle team, can access your Stotles.

Stotle is a personal journal. Protecting the things you entrust to it is central to how the product is built.

Effective July 29, 2026Havre Labs AS
01

Overview

This Privacy Policy explains how Havre Labs AS, the company responsible for Stotle, collects and processes personal information when you use the Stotle app, its companion experiences, and related services.

Stotle lets you record or write journal entries, turn recordings into text, identify relevant patterns, and have conversations based on your own journal. You can begin as a guest without providing an email address.

The short version

We do not sell your personal information or use it for advertising. Your journal content is encrypted while stored and in transit. AI processing is provided through Google Cloud, and your content is not authorized for model training.

02

Information we collect

Content you choose to provide

This can include voice recordings, transcripts, written journal entries, photos or other attachments, conversations with Stotle, names and details about people, dates, locations, and any context you add to the service.

Location information

When you make a new Stotle, we collect the GPS position reported by your device. We use this location to connect your memories to the places where you recorded them.

Account and device information

Guest accounts do not require an email address. If you create or convert to a registered account, we collect your email address and any name you choose to provide. We also process account and session identifiers, language preferences, device type, IP address, and user agent information for login, security, abuse prevention, and service operation.

Usage and diagnostic information

We process technical events such as request status, feature usage, model and token counts, performance, and errors. The app uses Sentry for crash and error diagnostics. It is configured not to send default personal information, screenshots, or the app’s view hierarchy.

Connected services

If you choose to connect an external service, Stotle processes the connection details, credentials, and content needed to perform the actions you request. Connection credentials are encrypted while stored.

03

How Stotle uses AI

Stotle uses Google Cloud AI to transcribe recordings, create and analyze journal entries, identify relevant patterns, and respond in conversations. When you use these features, Stotle sends Google Cloud the audio, message, or journal content you provide, together with the journal context needed to complete your request.

  • AI processing is configured in Google Cloud’s EU locations.
  • Stotle does not authorize Google to use your content to train or fine-tune AI models.
  • Stotle does not enable Google Cloud request and response logging for model calls.
  • Google may temporarily cache input, output, and derived data in isolated server memory for up to 24 hours to improve service performance.
  • Depending on the Google Cloud agreement in effect, Google may process prompts for abuse monitoring and policy enforcement.

Google’s current details are available in its Vertex AI data retention documentation and Cloud Data Processing Addendum.

AI output can be incomplete or incorrect. Stotle is designed as a memory and reflection aid, not as professional medical, legal, financial, or safety advice.

04

How we protect your content

Stotle is not end-to-end encrypted because journal content must be processed on the server to provide the AI features you request. Your data is encrypted in transit and while stored, with two layers of key protection: Google Cloud Key Management Service and a key stored on your device.

Stored journal content cannot be decrypted from our database alone, and Stotle employees cannot browse it through administrative tools. An unlocked data key is held temporarily in server memory while processing actions you initiate. Media files, including recordings, are encrypted before being written to object storage.

No system is perfectly secure. You are responsible for protecting access to your device, email account, password, and recovery key. If you lose the key required to open a locked journal, Stotle may be unable to recover it.

05

How and why we use information

We process information to:

  • provide transcription, journaling, search, conversation, and memory features;
  • store, sync, and display your content across supported devices;
  • connect Stotles with the places where they were recorded;
  • secure accounts, maintain sessions, prevent abuse, and investigate incidents;
  • send login codes, service messages, and account notices;
  • understand reliability, performance, and aggregate service costs; and
  • comply with law and protect the rights and safety of users and others.

Where European data protection law applies, we rely on the performance of our contract to provide the service, your consent for third-party AI processing, our legitimate interests in operating and protecting Stotle, and legal obligations where applicable. You can withdraw AI processing consent by not using the service or by deleting your account.

06

Sharing and service providers

We do not sell your personal information. We share information only when needed to provide Stotle, when you direct us to, or when required by law. Our main service provider categories include:

Google CloudAI processing and key management, configured for EU locations
DigitalOceanApplication infrastructure and encrypted media storage in Frankfurt
MailgunTransactional email delivery through its EU service
SentryPrivacy-limited crash, performance, and error diagnostics through its EU service
CloudflareWebsite delivery, network security, and traffic protection

If you connect Stotle to another service, information is also sent to that service as needed to carry out your request. The connected service’s own privacy terms apply to its processing.

Some providers may process information outside Norway or the European Economic Area. Where required, we use recognized safeguards for those transfers, including adequacy decisions or standard contractual clauses.

07

Retention and deletion

We keep journal content while your account is active and as needed to provide the service. Entries you delete are removed from your active journal. Limited technical, security, and transaction records are kept only as long as reasonably needed for the purposes described in this policy.

You can delete your full account from Stotle’s settings. Full account deletion removes journal entries, recordings, photos, conversations, people, and connection details from active systems. It also destroys your encryption key, making any content remaining in old backups permanently unreadable. This cannot be undone.

We may retain anonymized AI usage statistics such as model, token, cost, duration, and feature category after account deletion. They no longer include your account identifier, request content, or response content.

08

Your choices and rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to the processing of your personal information. You may also withdraw consent and lodge a complaint with a data protection authority.

Many requests can be handled directly in the app. For anything else, email us. We may need to verify your identity before completing a request. In Norway, you can also contact Datatilsynet at datatilsynet.no.

Children

Stotle is not directed to children under 13. If you believe a child has provided personal information without the authorization required by local law, contact us so we can take appropriate action.

Website data

This marketing website does not use advertising cookies. Standard network logs may be processed by Cloudflare for delivery, security, and abuse prevention.

09

Changes and contact

We may update this policy as Stotle changes. We will update the effective date above and provide additional notice when a change materially affects your rights.

Data controllerHavre Labs AS

Norway

Privacy questionshello@getstotle.com