Legal
Privacy Policy
Last updated: 30 April 2026
1. Who We Are
This Privacy Policy applies to Still Group Ltd, a company registered in England and Wales under Companies House number 17188025 (“Still”, “we”, “us”, or “our”).
We are the data controller for the personal data we collect and process through the Still™ platform, which includes the Still™ mobile application (iOS and Android), the Still™ desktop application (macOS, Windows, Linux), the Still™ web application, and any embeddable components or APIs we provide (collectively, the “Platform”).
Contact details:
Still Group Ltd
82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE
Email: [email protected]
Data Protection enquiries: [email protected]
We are registered with the Information Commissioner’s Office (ICO) under registration number ZC138808.
2. What This Policy Covers
This policy explains:
- What personal data we collect, and why
- The legal basis on which we process your data
- How we use your data, including our use of artificial intelligence
- Who we share your data with
- How long we keep your data
- Your rights under UK data protection law
- How to contact us or the ICO if you have a concern
This policy applies to all users of the Platform, including those on a free tier and premium subscription holders.
3. The Personal Data We Collect
3.1 Data You Provide Directly
| Category | Examples |
|---|---|
| Account information | Name, email address, password (hashed), account preferences |
| Voice input data | Audio streamed to the Still™ assistant; ephemeral — processed in real time via encrypted WebSocket and not stored |
| Text input data | Written messages or notes you type to the assistant |
| Note content | The notes, thoughts, feelings, reminders, and records captured by the assistant |
| Social data | Friends or contacts you connect with, notes you choose to share |
| Payment information | Billing address, payment method details (processed by our payment provider; we do not store full card details) |
| Support communications | Any messages you send to our support team |
3.2 Data Collected Automatically
| Category | Examples |
|---|---|
| Device information | Device type, operating system, app version, unique device identifiers |
| Usage data | Features accessed, session duration, frequency and patterns of use |
| Log data | IP address, timestamps, error logs, crash reports |
| Cookie and tracking data | See Section 10 (Cookies) below |
3.3 Data from Connected Services
If you use the MCP server integration to connect Still to third-party services (such as productivity tools or music platforms), we may receive data from those services as part of the integration. The data received will depend on the specific service and the permissions you grant. You remain in full control of which services you connect.
3.4 Special Category Data
The Still™ platform is designed to capture your thoughts, feelings, and personal reflections. Some users may incidentally disclose special category data (such as health information or data relating to beliefs) within their notes. We do not actively seek to collect such data. To the extent such data is processed, it is processed solely on the basis of your explicit consent through your voluntary use of the note-capture feature, pursuant to Article 9(2)(a) UK GDPR.
4. How We Use Your Data and Our Legal Bases
We process your personal data only where we have a lawful basis to do so under UK GDPR Article 6. The primary bases we rely on are:
4.1 Contract Performance (Article 6(1)(b))
We use your data to:
- Create and manage your account
- Provide the note-generation, organisation, and retrieval features of the Platform
- Process subscription payments and manage your billing
- Provide customer support
4.2 Legitimate Interests (Article 6(1)(f))
We use your data to:
- Improve the Platform through analysis of usage patterns and product analytics
- Detect and prevent fraud, abuse, or misuse of the Platform
- Maintain the security and integrity of the Platform
- Send transactional communications (e.g. service updates, billing notices)
In each case, we have conducted a Legitimate Interests Assessment (LIA) to confirm that our interests do not override your fundamental rights and freedoms.
4.3 Legal Obligation (Article 6(1)(c))
We may process your data to comply with legal obligations, including tax, regulatory, or law enforcement requirements.
4.4 Consent (Article 6(1)(a))
We rely on your consent where required by law, including:
- Non-essential cookies and analytics tracking (see Section 10)
- Marketing communications
- Processing of special category data voluntarily shared in notes (Article 9(2)(a))
You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
5. How Artificial Intelligence Processes Your Data
Still™ is an AI-native platform. Understanding how AI processes your data is central to your rights under UK GDPR and ICO guidance on AI and data protection.
5.1 How the AI Works
When you speak to or type to the Still™ assistant:
- Your voice or text input is transmitted securely to our AI processing servers
- The AI processes your input to generate a structured note, reminder, or response
- The resulting note is stored in your account and returned to you on your device
This process is designed to be transparent and user-controlled: every note generated by the AI is visible to you, and you can edit, delete, or share any note at any time.
5.2 AI-Generated Content
Notes may include dynamically generated images, background visuals, and embedded scripts produced by AI. These are generated in response to your specific requests and associated with your account. You retain the ability to delete any AI-generated content at any time.
5.3 Automated Decision-Making
Still™ uses automated processing to organise, categorise, and surface your notes. This processing does not produce legal or similarly significant effectson you within the meaning of UK GDPR Article 22 — it operates purely within the context of your personal note-management experience.
Where the Data (Use and Access) Act 2025 introduces updates to the UK GDPR framework for automated decision-making, we will ensure our practices remain compliant and will update this policy accordingly.
5.4 Model Training
We do not use the content of your personal notes to train AI models for general commercial purposes without your explicit, separate consent. Your voice recordings and note content are processed only to deliver your personalised experience of the Platform.
5.5 AI Transparency and ICO Compliance
We are committed to the ICO’s principles for AI and data protection, including:
- Data minimisation: We collect only the data necessary to operate the assistant and generate notes
- Purpose limitation: Your data is not repurposed beyond the functions described in this policy
- Transparency: This section and the policy as a whole provide meaningful information about how AI processes your data
- Security: Appropriate technical and organisational measures protect your data at every stage of AI processing
We monitor the forthcoming ICO Code of Practice on AI and Automated Decision-Making (SI 2026/425, effective 12 May 2026) and will align our practices with its requirements upon publication.
6. Voice Data
Because voice input is the primary interaction method on Still™, we draw specific attention to how voice data is handled:
- Voice audio is streamed in real time over an encrypted WebSocket connection directly to our transcription service — it is never written to disk or stored
- Voice data is ephemeral: audio exists only in transit and is discarded immediately once transcription is complete
- Processing converts your speech into structured text and notes
- Only the resulting transcription (text) is retained as part of your note — the underlying audio is not kept
- You may at any time review the notes generated from your voice input and delete any record
7. Sharing Your Data
We do not sell your personal data. We share data only in the following circumstances:
7.1 Service Providers and Sub-Processors
We engage trusted third-party service providers to operate the Platform, including:
- AI processing and cloud infrastructure providers (e.g. server hosting, model inference)
- Payment processing providers
- Analytics and crash reporting services
- Customer support platforms
All sub-processors are bound by data processing agreements requiring them to process data only on our instructions and in accordance with UK GDPR.
7.2 Social Features
When you use the social integration features to share a note with a connected friend, that note becomes visible to the friend you have designated. You are in full control of which notes you share. You can withdraw access to a shared note at any time by revoking sharing within the Platform.
7.3 MCP-Connected Services
When you authorise a connection to an external service via the MCP server integration, relevant note data and personal data may be transmitted to that service in accordance with the permissions you have granted. Each connection is subject to the privacy policy of the third-party service. We encourage you to review those policies before connecting any external service.
7.4 Legal Requirements
We may disclose your data where required by law, court order, or regulatory authority, or where necessary to protect the rights, property, or safety of Still Group Ltd, our users, or others.
7.5 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your personal data may be transferred to the acquiring entity, subject to equivalent data protection commitments.
8. International Data Transfers
Still Group Ltd is based in the United Kingdom. Some of our service providers and sub-processors operate outside the UK. Where we transfer personal data outside the UK, we ensure adequate protections are in place, including:
- Transferring to countries with a UK adequacy decision
- Using International Data Transfer Agreements (IDTAs) or equivalent safeguards approved by the ICO
- Applying additional contractual and technical safeguards where appropriate
You may request details of any international transfer safeguards by contacting us at [email protected].
9. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law:
| Data Type | Retention Period |
|---|---|
| Account information | For the duration of your account, plus 6 years after closure (for legal/tax purposes) |
| Note content | For the duration of your account, and deleted within 30 days of account closure |
| Voice recordings | Not retained — voice audio is ephemeral and discarded immediately after transcription; only the resulting text note is stored |
| Payment records | 7 years from the date of transaction (UK tax law) |
| Usage and log data | Up to 12 months, then anonymised or deleted |
| Support communications | 3 years from the date of last contact |
When your account is closed, we will delete or anonymise your personal data within 30 days, subject to any legal obligations to retain records.
10. Cookies and Tracking Technologies
The Still™ web application uses cookies and similar technologies. The following applies to our web platform:
Strictly necessary cookies— These are essential to the operation of the web application (e.g. maintaining your logged-in session). They do not require your consent under PECR.
Analytics cookies— We use analytics cookies to understand how users interact with the web platform and to improve our service. These require your opt-in consent before they are set.
Functional cookies— These cookies remember your preferences and settings. They require your consent.
Marketing cookies— We do not currently use cookies for advertising or behavioural targeting.
When you first visit the Still™ web application, you will be presented with a cookie consent banner. You may accept or reject non-essential cookies at any time, and you may change your preferences at any time via the Cookie Settings link in the footer of the website.
We comply with the Privacy and Electronic Communications Regulations 2003 (PECR) as amended by the Data (Use and Access) Act 2025.
11. Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
| Right | What It Means |
|---|---|
| Right to be informed | You have the right to receive clear information about how we use your data — this policy fulfils that obligation |
| Right of access | You may request a copy of the personal data we hold about you (a Subject Access Request or SAR) |
| Right to rectification | You may ask us to correct inaccurate or incomplete data |
| Right to erasure | You may ask us to delete your personal data (“right to be forgotten”), subject to certain limitations |
| Right to restriction | You may ask us to restrict how we process your data in certain circumstances |
| Right to data portability | You may request your data in a structured, machine-readable format |
| Right to object | You may object to processing based on legitimate interests |
| Rights in relation to automated decision-making | Where automated processing produces significant effects, you have the right to seek human review |
To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month of receiving your request. We will not charge a fee for exercising your rights in ordinary circumstances.
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:
- End-to-end encryption for data in transit
- Encryption of data at rest
- Role-based access controls limiting staff access to personal data
- Regular security audits and penetration testing
- Incident response procedures for detecting and reporting data breaches
- Data breach notification to the ICO within 72 hours where required by UK GDPR
13. Children’s Privacy
The Still™ Platform is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected] and we will promptly delete such data.
For users aged 13–17, parental consent may be required in certain circumstances. We apply the children’s higher protection matters duty introduced by the Data (Use and Access) Act 2025 when considering data protection by design for our Platform.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal obligations. When we make material changes, we will notify you by email or through a prominent notice in the Platform. The updated policy will take effect 30 days after notification, or immediately for new users.
The current version of this policy is always available at https://stillapp.io/privacy.
15. How to Complain
If you have a concern about how we handle your personal data, we encourage you to contact us first at [email protected]. We will investigate and respond promptly.
If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk