Version 1.0 · Effective 30 July 2026 · Registered particulars corrected 31 July 2026
This policy explains what personal information we collect through the STILL app and the stillsanctuary.app website, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it. It is written to meet the Protection of Personal Information Act, 2013 (POPIA) in South Africa and the EU and UK General Data Protection Regulation (GDPR) for visitors and users elsewhere.
The responsible party under POPIA, and the data controller under GDPR, is:
I-nspire Transformations CC
Registration number 2006/107940/23
274 Delphinus Street
Waterkloof Ridge
Pretoria, Gauteng, 0181
South Africa
Information Officer: Jacqueline Allschwang — jacque@i-nspire.co.za
I-nspire Transformations decides what personal information is collected and why, and is accountable for it. The app and website are built and maintained for us by Asan Digital, which acts as our operator (POPIA) / processor (GDPR) and works only on our instructions.
We collect only what the product actually needs. Here is all of it.
The request form on our home page asks for your name and email address. The form opens your own email program with the message pre-filled — you send it to us yourself, and it arrives in our mailbox at jacque@i-nspire.co.za. We use it to decide on and issue your invitation, and to reply to you.
To sign in to the beta or the web portal you enter your email address and we send you a one-time link. There is no password. We store your email address, the dates you signed up and last signed in, and whether your address is confirmed. This is what lets us check you are an invited tester and give you access.
Journal entries, reflections and Vault records are kept on your device by default. They are not sent to us, and removing the app removes them.
You can separately choose to save your Vault to your account so it is available on your other devices and through the web portal. Only if you switch that on are those records stored on our servers, linked to your sign-in. You can switch it off or delete the saved copy at any time. We do not read your entries, and we do not use them to build analytics.
On a shared library page you can leave a reaction or a short note. If you do, the optional first name and the text you write are stored and shown publicly to anyone who visits that page. Please do not put anything private or identifying in a note. You can ask us to remove one at any time.
Your reactions are also tied to a random identifier stored in your browser, so the same browser cannot react twice to the same item. It contains no personal information and is only set if you accept cookies.
If you accept the cookie notice, the website and the app record simple usage events — pages viewed, a track played, a feature opened, session counts — together with approximate location derived from your IP address, your device type and your browser. We use this to see what is used and what is broken. It is pseudonymous, we do not sell it, we do not use it for advertising, and it never includes the content of your journal, reflections or Vault. If you decline, nothing is recorded and the site works exactly the same.
If you install through Apple TestFlight or Google Play, that happens under your Apple or Google account and their terms, not ours. Those platforms give us aggregate crash and stability reports that do not identify you.
If you email us, we keep the message and your address so we can answer and keep a record of the request.
Under GDPR we need a lawful basis for each use. Under POPIA the equivalent justification is shown alongside.
| What | Ground |
|---|---|
| Beta request, sign-in, giving you access | Performance of a contract with you / necessary to provide the service you asked for |
| Analytics cookies | Your consent — you can withdraw it at any time |
| Saving your Vault online | Your consent — it is off unless you switch it on |
| Public reactions and notes | Your consent — given by choosing to post |
| Answering your emails | Legitimate interests — responding to people who contact us |
| Security, preventing abuse, keeping records | Legitimate interests and legal obligations |
Giving us your information is voluntary. If you do not give us an email address we cannot issue beta access or sign you in, because there would be no way to identify you as an invited tester.
We do not send marketing email. The only emails we send are the ones you ask for or need: your one-time sign-in link, your beta invitation, replies to your messages, and occasional notices about the beta itself, such as a new build or an important change to this policy. We do not sell, rent or share your address with anyone for marketing, and if we ever wanted to start a mailing list we would ask you to opt in first, as section 69 of POPIA requires. Every non-essential email we send will have an unsubscribe option.
We do not sell personal information. We use the following service providers, who process data only on our instructions and under contract:
| Provider | What they do | Where |
|---|---|---|
| Supabase | Sign-in, accounts, database for the online Vault and public notes, sending the sign-in email | United States |
| PostHog | Product and website analytics | United States |
| GitHub (GitHub Pages) | Hosting for stillsanctuary.app | United States |
| Apple | TestFlight beta distribution, App Store | United States and Ireland |
| Google Play distribution | United States and Ireland | |
| Asan Digital | Building and maintaining the app and site on our behalf | Belgium |
We may also disclose information if the law requires it, or to establish or defend a legal claim. If our business is ever transferred, personal information may transfer with it, and we would tell you first.
We are based in South Africa, and our servers are in the United States. This means your personal information is transferred out of South Africa, and out of the EU and UK, when you use STILL.
The United States does not have a general data protection law equivalent to POPIA or GDPR. We rely on the following safeguards, as section 72 of POPIA and Chapter V of GDPR require: our providers are bound by written contracts, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which oblige them to protect your information to a comparable standard and to restrict what they may do with it. You may request a copy of these terms from us.
| What | How long |
|---|---|
| Your account and email address | Until you ask us to delete it, or 12 months after the beta ends, whichever comes first |
| Vault records you chose to save online | Until you delete them or delete your account |
| Public reactions and notes | Until you ask us to remove them, or the page is retired |
| Analytics events | 12 months, then deleted |
| Emails between us | 24 months from the last message |
| Beta requests we did not take up | 12 months |
Journal entries, reflections and Vault records held on your device are kept until you delete them or remove the app. We never see them.
Whatever country you are in, you can ask us to:
Email jacque@i-nspire.co.za. We will answer within 30 days. We may ask you to confirm your identity first, so we do not hand your information to someone else. There is no charge, unless a request is repetitive or excessive. South African users may use the Information Regulator's prescribed forms, and our PAIA manual explains that route.
We do not use your information to make automated decisions that have a legal or similarly significant effect on you, and we do not profile you for advertising.
You can delete your account and everything attached to it at any time. See Delete your account for exactly what is removed, what is kept and for how long.
We keep the amount of personal information we hold small on purpose, which is the strongest protection there is. Beyond that: the site and all connections use HTTPS; sign-in is passwordless, so there are no passwords to steal; access to the database is restricted by row-level security so one user cannot read another's records; administrative access is limited to named people and checked on the server, not in the browser; and our providers encrypt data at rest and in transit.
No system is perfect. If a breach happens that puts your information at risk, we will notify you and the Information Regulator as POPIA section 22 requires, and the relevant supervisory authority within 72 hours as GDPR requires.
STILL is for adults. You must be 18 or older to request access, sign in, or post a note. We do not knowingly collect information from children. Under POPIA, personal information about a child may only be processed with the consent of a parent or guardian. If you believe a child has given us information, email us and we will delete it.
We use one strictly necessary sign-in token and, only if you accept, one analytics cookie. Nothing is set for advertising. Our Cookie Policy lists every cookie and storage item by name, what it does and how long it lasts, and lets you change your choice at any time.
Please raise it with us first at jacque@i-nspire.co.za — most things are quicker to fix directly. You also have the right to complain to a regulator.
South Africa — Information Regulator
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
complaints.IR@inforegulator.org.za
inforegulator.org.za
European Union — the data protection authority of the country you live or work in.
United Kingdom — the Information Commissioner's Office, ico.org.uk.
If we change this policy we will update the date at the top. If a change materially affects you — a new purpose, a new provider, a new category of information — we will tell you by email or in the app before it takes effect.
STILL is not a medical, clinical, diagnostic or emergency service, and nothing in it is a substitute for professional care. If you are in crisis, contact your local emergency service or the South African Depression and Anxiety Group on 0800 567 567.