StainFirstAid Privacy Policy

Effective date: August 27, 2026

This Privacy Policy describes how the StainFirstAid mobile application (the “Application”), operated by Sergey V. (the “Service Provider”), accesses, processes, and shares information. StainFirstAid helps users identify stains and obtain guidance for removing them.

Privacy summary: Photos of stains are handled locally on your device. StainFirstAid does not upload or store your photos on the Service Provider's servers. The Application does not use optical character recognition (OCR). Network data may be transmitted only through Yandex Mobile Ads SDK for advertising, Yandex AppMetrica for basic usage statistics, Firebase Crashlytics for crash diagnostics, and the Service Provider's minimal privacy-region endpoint for advertising-consent routing, within the scope described below.

1. Photos and Camera Access

StainFirstAid may request access to your device camera or allow you to select an image so that you can create or provide a photo of a stain for use within the Application.

You may deny or revoke camera permission in your device settings. Features that require taking a photo may not work without this permission, but other parts of the Application may remain available.

2. Information Collected by the Service Provider

The Service Provider does not require you to create an account and does not directly collect your name, email address, phone number, contacts, precise location, or stain photos through the Application. StainFirstAid does not operate a server that receives your photos.

The Application includes third-party SDKs that may automatically process limited device, application, advertising, network, session, and diagnostic information as described in Section 3. The Service Provider's privacy-region endpoint may process the network information inherent in an HTTPS request.

3. Third-Party Services and Network Data

StainFirstAid uses the following third-party services that may communicate over the internet:

Yandex Mobile Ads SDK

Yandex Mobile Ads SDK is used to display and measure advertisements. Depending on your device settings, consent choices, applicable law, and SDK configuration, Yandex may process information such as your IP address, advertising identifier, general device information, app interaction or ad event data, and an approximate location inferred from an IP address. The Application does not provide Yandex with your photos.

Where required, the Application will request consent before enabling personalized advertising or other non-essential processing. You can also limit ad personalization or reset/delete your advertising identifier through your device settings. Data transmitted by the SDK is encrypted in transit using HTTPS/TLS.

Firebase Crashlytics

Firebase Crashlytics is used to detect, diagnose, and fix crashes and stability problems. Crashlytics may automatically collect crash stack traces, relevant application state at the time of a crash, device and operating-system metadata, app version information, and installation identifiers used to associate crash reports with an app installation. Crash reports are not intended to include your photos.

Yandex AppMetrica

Yandex AppMetrica is used for basic automatic statistics about app launches and sessions. It may process technical information about the Application and device, operating system and app versions, session timing, network information, and SDK or installation identifiers. Usage analytics is enabled by default and can be turned off at any time in Settings. Turning it off stops future AppMetrica network transmission from the SDK; it does not delete information already processed by Yandex.

The Application configures AppMetrica not to collect the advertising identifier, precise location, Profile ID, purchase or revenue information, automatic deeplink/app-open data, custom product events, or AppMetrica crash reports. The Application does not send AppMetrica stain selections, searches, notes, or photos.

Service Provider privacy-region endpoint

The Application uses an unauthenticated HTTPS endpoint operated for the Service Provider only to determine whether the in-app advertising privacy choices are required for the current request. The endpoint returns a minimal region result, policy version, and expiry. Like any internet service, it may receive network information inherent in the request, such as an IP address and request metadata. It does not receive your photos, notes, stain selections, search terms, or the advertising-consent choice you save locally on your device. The Application does not use Google User Messaging Platform (UMP).

Advertising privacy choices depend on your region and applicable law. Where available, you may review or change them through the privacy options entry point in the Application. These choices are separate from the AppMetrica usage-analytics switch.

The privacy practices of these providers are governed by their own policies:

4. Purposes of Processing

Information processed through the third-party SDKs is used only for the following purposes:

5. Legal Bases and Consent

Where applicable data-protection law requires a legal basis, processing may be based on your consent, the Service Provider's legitimate interest in maintaining a secure and reliable Application, or the need to comply with legal obligations. Where processing is based on consent, you may withdraw that consent at any time through the privacy choices presented in the Application, the Usage analytics switch, or your device settings, as applicable. Withdrawal or opt-out does not affect processing carried out before it took effect.

6. Data Sharing and Disclosure

The Service Provider does not sell your photos or personal information. Information is shared only through Yandex Mobile Ads SDK, Yandex AppMetrica, Firebase Crashlytics, and the Service Provider's privacy-region endpoint for the purposes described in this Policy, or when disclosure is required by law, a valid legal process, or is reasonably necessary to protect users, the Service Provider, or the public from fraud, security threats, or harm.

7. Data Retention and Deletion

Because photos are handled locally and are not received by the Service Provider, the Service Provider does not retain or delete such data on a remote server. Temporary in-memory data used while working with a photo is discarded when it is no longer needed for the active operation or when the Application is closed, subject to normal operating-system behavior. A photo saved by you on your device remains under your control and can be deleted using your device's normal photo or file-management features.

Yandex and Firebase retain information according to their own retention policies and legal obligations. Firebase states that Crashlytics crash stack traces and associated identifiers are generally retained for 90 days before removal begins. Advertising, analytics, and consent-related data retention may vary according to the provider, data type, SDK configuration, consent status, and applicable law.

You can stop future AppMetrica transmission with Settings > Usage analytics, disable future Crashlytics collection with its separate switch, or uninstall the Application. Clearing all local Application data resets local preferences, including both switches, to their enabled defaults; you can turn them off again immediately. These actions do not delete reports already transmitted to a provider. You may also reset or delete the advertising identifier in your device settings and, where available, update advertising privacy choices inside the Application. To submit a privacy request concerning data controlled by the Service Provider, contact the email address below. Requests concerning data independently controlled by Yandex or Google/Firebase may need to be submitted directly to those providers.

8. International Data Transfers

Third-party service providers may process data in countries other than your country of residence. Where required by applicable law, transfers will be subject to appropriate safeguards provided by the relevant service provider, such as adequacy decisions, contractual safeguards, or another legally recognized transfer mechanism.

9. Security

The Service Provider uses reasonable technical and organizational measures appropriate to the nature of the Application. Local handling reduces the need to transmit stain photos. Network transmissions by the integrated SDKs use encrypted connections. However, no method of electronic processing or transmission is completely secure, and absolute security cannot be guaranteed.

10. Children's Privacy

StainFirstAid is not directed to children under 13, or a higher minimum age where required by local law. The Service Provider does not knowingly collect personal information directly from children. If you believe a child has provided personal information to the Service Provider, contact the Service Provider so that the matter can be investigated and appropriate action can be taken.

11. Your Privacy Rights

Depending on where you live, you may have rights concerning personal data, including rights to access, correct, delete, restrict, or object to certain processing, withdraw consent, or receive information about data sharing. You may also have the right to lodge a complaint with your local data-protection authority.

Because the Service Provider does not receive photos and does not provide user accounts, there may be no photo-related data held by the Service Provider to access or delete. To exercise an applicable right regarding information controlled by the Service Provider, use the contact details below.

12. California Privacy Notice

California residents may have rights to know, access, correct, or delete certain personal information and to opt out of certain forms of sale or sharing. The Service Provider does not sell personal information for monetary consideration. Advertising data processed by Yandex may constitute “sharing” or targeted advertising under some privacy laws, depending on configuration and use. Available privacy choices and device advertising settings can be used to limit such processing. The Service Provider will not discriminate against you for exercising applicable privacy rights.

13. Changes to This Policy

This Privacy Policy may be updated to reflect changes to the Application, SDKs, legal requirements, or data practices. The updated version will be posted with a revised effective date. Material changes will be communicated where required by law.

14. Contact Us

For questions or privacy requests related to StainFirstAid, contact the Service Provider at info[@]sedsoftware.com