Stealward (“Stealward”, “we”, “us”) is an anti-theft tool. You activate it on a device you are leaving behind — a Mac, iPad, or iPhone — and that device watches your belongings and sends alerts to your phone if something looks wrong. This policy explains what data we collect, how we use it, who we share it with, and the choices you have.
We built Stealward to hold as little of your data as possible. We do not ask for your name, email address, or a password to create an account, and most of what the app records is end-to-end encrypted so that only your own devices can read it — not us, and not the companies whose infrastructure we run on.
1. Who we are and how to contact us
Stealward is the provider of the Stealward app and service. For any privacy question or request, contact us at [Email Loading Failed].
2. The short version
- We do not ask for your name, email, or a password to create an account. Your account is a random identifier plus cryptographic keys.
- Your recorded video and audio are end-to-end encrypted — only your devices can decrypt them.
- To detect threats, monitoring photos are analyzed by an AI provider during an active session, then encrypted so that afterward only your devices can open them. Our AI provider does not retain these images or use them to train models.
- We do not sell or share your personal data for advertising. Ever.
- Our website counts visits without cookies to improve the product. We and our infrastructure providers log IP addresses briefly to run and secure the service (app and website) — never to advertise, track, profile, or sell. For sensitive account actions, we keep a short-lived security log that is encrypted so that we can read it only when investigating a security incident or where the law requires (Sections 3 and 6).
- Recordings are kept for a limited time based on your plan, then deleted automatically. You can delete any session — or your whole account — yourself, in the app (Section 11).
3. Information we collect
Account and device information
- A randomly generated user ID and device ID. These are not derived from your name, email, phone number, or hardware serial.
- Cryptographic public keys used to authenticate your devices and to encrypt data to you.
- Your device’s name and model. On a Mac, the device name you have set may include your name (for example, “Robin’s MacBook Pro”). We store this encrypted — we cannot read it.
- Push notification tokens, so we can deliver alerts to your phone.
Approximate region, and IP address for security
- When you register, we read the approximate region (continent/country) that our network provider associates with your connection, so we can store your data in a datacenter close to you. We do not collect GPS or precise location.
- IP address. Like any internet service, we and our infrastructure providers can see the IP address your device connects from, and may log it for a limited time to operate and secure the service — both the app and this website — for example, to detect and investigate abuse, fraud, and attacks, and to apply rate limits. We do not use your IP address to advertise to you, track you across other sites, or build a profile, and we never sell it. When you take a sensitive account action — such as registering, signing in, linking a device, or starting or stopping a monitoring session — we keep a short-lived security log of the IP address and network information (network provider and approximate region) associated with that action. This log is stored encrypted so that it cannot be read in the normal course of operating the service; we decrypt it only when investigating a specific security incident or abuse, or where the law requires, and it is deleted automatically after up to 90 days.
- If available, we collect the name of the Wi-Fi network your monitoring device is on, and basic device status (battery level, charging state, connection type). This is encrypted so that only your devices can read it.
Media captured during a session
- Video and audio. While a session is active, the monitoring device records video and audio of its surroundings. Recordings, and the thumbnails generated from them, are end-to-end encrypted on the device before upload — we only ever store encrypted data and cannot watch or listen to your recordings.
- Monitoring photos. The monitoring device also takes still photos of the scene every couple of seconds so our AI can check on your belongings. See Section 4 for exactly how these are handled.
Detection and alert data
- Labels and descriptions our AI generates about the items it is watching, and the wording of the alerts we send you (for example, “Your backpack may have been moved”).
Subscription information
- If you subscribe, we store your Apple transaction identifier, the product purchased, and whether it was a production or test purchase, to manage your entitlement.
- Free-trial eligibility. New accounts can receive a short free trial without a purchase. To limit this to one trial per Apple Account, we keep a non-reversible eligibility record derived from your App Store record for this app. It tells us only whether a trial has already been used. It contains no name or email (we never receive your Apple ID details), cannot identify you outside Stealward, and is never used for advertising or tracking.
Support and feedback
- If you contact us from the app, your message and any attachments are encrypted before they leave your device, and our replies arrive in the app. You can choose to attach basic diagnostics to help us investigate.
- If you use the feedback form on our website, you can optionally include an email address so we can reply. Your message, attachments, and email address are encrypted the same way and are used only to respond to you.
Your settings and consents
- Your privacy choices (see Section 10) and a record of which version of this policy and our Terms you have agreed to, with the date.
Operational logs
- Our servers keep short operational logs to run and secure the service. These may include your user/device IDs, approximate region, push tokens, and IP address (handled as described above). They do not contain your recordings, and encrypted fields (such as your device name) remain unreadable to us.
4. How the AI monitoring works, and what it means for encryption
Threat detection requires our AI to actually see the scene, so this is the one place your imagery is briefly handled in unencrypted form:
- During an active session, each monitoring photo is sent to a third-party AI provider to check whether your belongings are safe. We have configured this provider for zero data retention: your photos are not stored by the provider and are not used to train any models.
- When the session ends, every monitoring photo is encrypted so that afterward only your own devices can open it. From that point on, we can no longer see them.
- Alerts. The wording of an alert is generated by Stealward from the AI’s analysis, so that text passes through our systems and Apple’s push service in readable form. The alert deliberately identifies your device using an encrypted name that only your devices can decrypt.
If you turn on “help improve detection” (off by default — see Section 10), an additional encrypted copy of your monitoring photos is made available to Stealward for the sole purpose of reviewing and improving our detection. You can turn this off at any time.
5. How we use your information
We use the information above to:
- provide the service — watch your belongings, record while a session is active, and detect possible threats;
- deliver real-time alerts to your chosen devices;
- store your data in a region close to you and let you play back your own recordings;
- manage subscriptions and entitlements;
- keep the service secure, prevent abuse, debug problems, and comply with law;
- with your consent, improve our detection and diagnose crashes (Section 10).
6. Website analytics and security logging
This section is about our public website (stealward.app). It explains how the site counts visits and keeps security logs. Your IP address is handled as described in Section 3 — logged only briefly, for security, and never for tracking, profiling, or advertising.
Our website handles two kinds of data at the edge, for two separate purposes. It uses no cookies and no client-side tracking script, and we do not use either purpose to advertise to you or to track you across other sites or apps.
Analytics — to improve the product. We count page views to understand our traffic: the page visited, the approximate region (country and city), the network your request came through, the site that referred you, and any campaign tags carried by the link you followed — these describe the link that brought you here, not you. To estimate unique visitors we derive a short-lived, daily-salted hash from your connection; we do not store your raw IP address for analytics, and the salt rotates every day so these hashes cannot be linked across days or reversed. The result is an aggregate trend only — we do not build a profile of you.
Security logs — to protect the site. To defend the website against abuse, fraud, and attacks, we keep short-lived server logs of requests to it. These include your IP address, browser user-agent, the page requested, the site that referred you, and approximate region — request metadata only, never the contents of anything you submit (for example, a message you send through our contact form is end-to-end encrypted and never appears in these logs). We keep these logs because we have a legitimate interest in keeping the service secure; we do not use them to advertise to you or build a profile, and they are automatically deleted after a short period (up to 90 days).
7. Recording others is your responsibility
Because Stealward records video and audio of the area around your device, it may capture other people. Laws on recording people — especially audio recording — vary by location and can require the consent of those recorded. You are solely responsible for using Stealward lawfully, including obtaining any consent required where you are. Do not use Stealward where recording is prohibited.
8. Who we share data with
We do not sell your personal data, and we do not share it for advertising. To operate the service, we rely on a small number of trusted service providers (“sub-processors”) that process data on our behalf and only on our instructions:
- Cloud infrastructure and storage providers — host our servers and store your data. Most of what we store, including your recordings, is encrypted, so these providers cannot access its contents.
- AI processing providers — a third-party AI service analyzes your monitoring photos during an active session to detect threats. These providers are configured for zero data retention: your photos are not stored by them and are not used to train any models.
- Apple — delivers push notifications to your devices. Apple receives your device’s push token and the alert text; your device name within the alert is encrypted.
We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, or property of our users or others.
9. How we protect your data
- End-to-end encryption. Your recorded video, audio, and thumbnails are encrypted on your device before they leave it, using keys that only your own devices hold. We store only encrypted data and cannot decrypt it. Your keys never touch our servers and are never synced to iCloud.
- Monitoring photos are handled as described in Section 4 — analyzed during a session, then encrypted so only your devices can open them.
- Data is transmitted over encrypted connections, and access to our systems is restricted.
- Some technical metadata about a session — such as timing, duration, and video resolution, and the belonging labels the AI produces — is not encrypted, so that we can operate and secure the service.
- No system is perfectly secure, and we cannot guarantee absolute security, but minimizing what we can see is central to how Stealward is built.
10. Your choices and consents
- Improve detection (off by default). Controls whether an encrypted copy of your monitoring photos may be made available to Stealward to review and improve detection (Section 4).
- Diagnostics (off by default). Controls whether we may collect crash reports and app logs to fix problems.
Both are off unless you turn them on, and you can change them at any time. Turning them off stops the associated use going forward.
11. Retention and deletion
Account and device information is kept for as long as your account is active. Recordings are kept for much less:
- Recordings expire automatically. A session’s video, audio, thumbnails, and monitoring photos are kept for a limited period after the session ends. How long depends on your plan — the app shows your plan’s retention period and the deletion date on each session. When a session reaches that date it disappears from your account, together with its alert history and details, and its data is permanently removed from our systems within a few days. A session’s retention period is fixed when the session takes place and can be extended — for example, when you upgrade your plan — but never shortened: a deletion date the app has shown you will never move earlier.
- You can delete a session at any time in the app. The session disappears from your account immediately, and its recordings, photos, and history are permanently removed from our systems within a few days. We may keep a minimal record of a deleted recording’s duration — never its content — for up to about two months, to meter plan usage.
- You can delete your account in the app. Deletion completes after a 7-day window: during those 7 days you can cancel the request from any of your devices, and new monitoring sessions cannot be started. When the window ends, your account and everything associated with it — devices, sessions, recordings, settings, subscription records, and support conversations — is permanently deleted. Apple keeps its own records of your App Store purchases under Apple’s policies. You can also ask us to delete your account by emailing [Email Loading Failed], and we will act within 7 business days of verifying your request.
Because your recordings are end-to-end encrypted, we cannot recover them for you if you lose access to your devices. Encrypted security logs (Section 3) are not deleted individually — including after account deletion — but expire automatically no more than 90 days after they were recorded. The free-trial eligibility record (Section 3) is kept after account deletion — with its link to the deleted account removed — solely so that deleting an account cannot reset the free trial; on its own it identifies no one. Some limited records may be retained where required by law.
12. International processing
Stealward runs on global cloud infrastructure. We store your data in the region closest to you, but data may be processed in other locations as part of operating the service. Service availability may vary by region.
13. Children
Stealward is not directed to, and is not intended for, anyone under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact [Email Loading Failed].
14. Changes to this policy
We may update this policy. When we make a material change, we will update the version and effective date above and, where appropriate, ask you to review the new version in the app. Your continued use after an update means you accept the revised policy.
15. Contact
Questions or requests: [Email Loading Failed].