Skip to content

Privacy Policy

Effective August 12, 2026 · Version 1.2

The short version

  • The calculators run on your phone, and your numbers stay there. Spans, loads, box fill, the dimensions of somebody’s deck — none of it is sent anywhere. There’s no account, no email signup, and nothing that asks who you are.
  • The free tier shows ads, and ads mean Google collects data. I’m not going to pretend otherwise. Google’s ad SDK reads your device’s advertising ID and roughly where you are, the same as it does in most free apps. Buying the Pro unlock turns the ads off.
  • Usage stats are off unless you switch them on. You’re asked once, and ignoring the question counts as no. If you do turn them on, I can see that somebody ran the beam calculator on a Pixel. I still can’t see the beam — your actual numbers never leave the phone.
  • I never see your card. Google handles the purchase end to end at the price shown in the Play Store. I get an order number and my cut.

That’s the whole shape of it. The rest of this page is the precise version — what each piece collects, who it goes to, how long it lasts, and what you can make me do about it.

Who this is

StorieDev is the trading name of Steven Storie, a sole proprietor in Pittsfield, Massachusetts, United States. I am the data controller for the products described here. There is no company behind me, no investor, and no data broker relationship — StorieDev is one person, which is worth knowing because it shapes what I can and can’t promise below.

Privacy questions and requests: privacy@storiedev.com.

The trade calculators

DeckSpec, RafterIQ, and ConduitCheck share one design and one data profile, so they share a section. Each is a calculator that works offline, cites the code section behind every answer, and has a free tier and a one-time paid unlock.

What stays on your device

These are stored in the app’s private storage on your phone using Android’s standard preferences mechanism. I never receive them, and they are not backed up to any server I control:

  • Your jurisdiction or state selection, and any code-edition override
  • Whether you’ve accepted the in-app disclaimer, so you’re only asked once
  • Whether you’ve bought the unlock
  • Any projects or configurations you save in the paid tier

Uninstalling the app, or clearing its data in Android settings, deletes all of it. Because it never leaves the device, there is nothing on my side to request a copy of or ask me to erase.

Advertising

The free tier is ad-supported through Google AdMob. This is the one place the apps genuinely collect data about you, so here it is without hedging.

To serve and measure ads, Google collects:

  • Your device’s advertising ID — a resettable identifier Android provides specifically for this purpose
  • Your IP address, which Google uses to work out approximately where you are
  • Device and operating system information
  • Which ads were shown, and whether you interacted with them

Google acts as an independent controller of that data under its own privacy policy, not as my processor. What Google does with it — including how long it keeps it — is governed by Google’s privacy policy and how Google uses data from apps that use its services. I can’t set retention periods on Google’s behalf and won’t claim to.

You have three ways out of this, in increasing order of finality:

  • Reset or delete your advertising ID in Android under Settings → Privacy → Ads. Deleting it stops apps from receiving a personalised identifier at all.
  • Refuse consent if you’re in the EEA, the UK, or Switzerland. The apps show Google’s consent prompt before the first ad request, and declining means you get non-personalised ads instead. Non-personalised ads still involve an ad request, but not profiling for targeting.
  • Buy the unlock. The Pro unlock removes advertising from the app entirely. The ad SDK stops making requests, so there is nothing left to collect.

Analytics

The apps can report usage data to PostHog, so I can see which calculators people actually use and which devices to test against.

It is off unless you turn it on. You are asked once, on first run, with Enable and Skip as the two options — and doing nothing counts as Skip. Until you opt in, the analytics client is never constructed at all, so an install that declined does not contain a running analytics SDK. That is a property of how the app is built, not a promise about how it is configured. You can change your mind at any time from the toggle in Settings, and turning it off calls PostHog’s opt-out and clears the local identifier.

What is collected, if you opt in

  • Event names — for example that a calculation ran, that a citation was tapped, that the unlock screen was viewed or purchased, that you chose a jurisdiction or changed a setting.
  • Non-identifying event properties — which calculator, which code section, whether the result passed or failed, and which feature area you were in. Where a number you entered is relevant, it is reduced to a coarse range before it can be reported: a 10.5 foot span leaves as “8–12”, never as 10.5.
  • An ephemeral install identifier — PostHog’s device identifier, which is regenerated when you reinstall the app or reset your advertising ID.
  • Platform information — Android version, app version, and device model, so I can tell which configurations to test against when something breaks.

What is never collected

Your name, email address, postal address, or phone number. Precise location, or any location beyond country level. Your contacts, photos, files, or messages. Health data, financial account details, or biometric data. The exact numbers you type into a calculator, and any free text.

There are no persistent user IDs, no cross-session tracking, and no cross-device linkage. Person profiles are disabled and you are never identified to PostHog. Uninstalling the app, or resetting your advertising ID, purges the local state that existed before.

A deliberate piece of precision here, because the distinction matters: I do not collect data that identifies you personally. I am not going to call this data “anonymised”, because the install identifier is technically pseudonymous rather than anonymous — it is not tied to your identity, but it is still an identifier for as long as it exists. Calling it anonymous would be the more comfortable word and the less accurate one.

Where it goes, and for how long

Analytics events are processed and stored by PostHog Cloud US, in Ashburn, Virginia. PostHog is my processor, not an independent controller: it holds the data on my instructions under a data processing agreement, and does not get to use it for its own purposes or sell it on. See PostHog’s privacy policy and PostHog’s data processing agreement.

Event data is retained for 90 days for product improvement purposes, and is deleted after that.

If you are in the EEA, the UK, or Switzerland, this is a transfer to the United States — see International data transfers for the safeguards it relies on.

Your choices

  • Opt out at any time from the toggle in the app’s Settings. It takes effect immediately, calls PostHog’s opt-out, and clears the local identifier. No explanation required and nothing about the app gets worse.
  • Request access or deletion by emailing privacy@storiedev.com. I forward deletion requests to PostHog’s data subject request tooling and confirm back to you when it is done.

Purchases

The Pro unlock is a one-time purchase processed by Google Play Billing. Google is the merchant of record: you transact with Google, Google handles your payment method, and your card details never touch my infrastructure because there is no infrastructure for them to touch.

What I receive is an order identifier, the product purchased, the country of purchase, and the amount, through the Play Console’s standard reporting. I keep those records for as long as tax and accounting rules require — seven years is the working assumption for US federal and Massachusetts purposes. Refunds are handled by Google under Google’s policies, not by me directly. See the Google Payments privacy notice.

What the calculators never do

  • No account, login, email capture, name, phone number, or postal address
  • No GPS or location permission request — the apps do not ask for location access
  • No access to contacts, photos, camera, microphone, or your files
  • No transmission of the values you enter into any calculator
  • No sale of personal information to anyone, for money, ever

RoseStorie

RoseStorie is a household dashboard with real user accounts and a subscription, which makes its data profile fundamentally different from the calculators: it has sign-in, it stores a household’s information on servers I operate, and it is not distributed through an app store. None of the Play or App Store declarations on this page apply to it.

A dedicated RoseStorie privacy policy covering accounts, household data, sensor and location features, and subscription billing is being written and will be published at rosestorie.com before RoseStorie is offered to anyone outside my own household. In the meantime, everything in Your rights below applies to RoseStorie account holders in full, and requests go to the same address: privacy@storiedev.com.

StorieBoard

StorieBoard is a virtual-closet app still in development. It has no public release, no store listing, and no users outside development, so there is currently no one whose data it could collect. Its data practices will be described here, and this policy updated, before its first public release — not after.

Pixie Papercraft

Pixie Papercraft is a custom-order planner storefront at pixiepapercraft.com. It was built under the working name PlannerBuilder, which survives in some infrastructure names but is not the product.

Because it sells a physical object, it collects what fulfilment requires — a name, a shipping address, and an order record — along with what the print and payment partners need. That is a materially different profile from anything else on this page, and it is not distributed through an app store, so none of the Play or App Store declarations on this page apply to it.

Those practices are described in full in Pixie Papercraft’s own privacy policy, which is the authoritative document for that storefront. Everything in Your rights below applies to Pixie Papercraft customers as well, and requests reach me at either address.

This website

storiedev.com is a static site served from a server I run. It sets no cookies, runs no analytics, embeds no tracking pixels, and loads no third-party scripts or fonts. There is no consent banner because there is nothing to consent to.

The web server keeps standard access logs — IP address, timestamp, requested URL, and user agent — which exist for security and debugging. They are not used to build a profile of you and are not combined with anything else. They rotate off the server within 30 days.

If I ever add analytics to this site, I will add a cookie and analytics notice here in the same change, and honour Global Privacy Control signals from browsers that send them.

Third parties, in full

Everyone who receives data connected to a StorieDev product, and what they get. There is nobody else.

WhoWhy they’re involvedWhat they receive
Google AdMob
policies.google.com/privacy
Advertising in the free tier of the trade calculatorsAdvertising ID, IP address, device and OS information, ad interaction events
PostHog (US Cloud — Ashburn, Virginia)
posthog.com/privacy
Product analytics, only if you opt in. Acts as my processor under a data processing agreementEvent names, non-identifying event properties, an ephemeral install identifier, and platform information (Android version, app version, device model)
Google Play Billing
Google Payments privacy notice
Processing the one-time Pro unlock. Google is the merchant of recordYour payment details, handled entirely by Google. I receive an order ID and a purchase receipt — never a card number
Virtualmin on a self-hosted serverServing storiedev.com. No third-party CDN or tag manager sits in front of itStandard web server access logs: IP address, timestamp, requested URL, user agent
Porkbun
porkbun.com/privacy
Domain registration and DNS for storiedev.comRegistrant details for the domain itself. No visitor data — DNS resolution does not identify you to me

I do not use a customer data platform, a CRM, an email marketing service, an attribution SDK, or an A/B testing service. If that list grows, this table grows with it.

If you are in the European Economic Area, the United Kingdom, or Switzerland, I rely on the following bases under Article 6:

What’s processedPurposeLawful basis
Advertising ID and ad request dataServing and measuring ads in the free tierConsent — Art. 6(1)(a), collected through Google’s consent prompt before the first ad request. Withdrawable at any time.
Analytics events and platform informationUnderstanding which features are used, and what to test againstConsent — Art. 6(1)(a), through a first-run opt-in prompt where taking no action means no. Withdrawable at any time from Settings, which also clears the identifier.
Purchase and order recordsDelivering the unlock you paid for and keeping tax recordsContract — Art. 6(1)(b), and legal obligation — Art. 6(1)(c) for the accounting retention.
Web server access logsKeeping the site up and secureLegitimate interests — Art. 6(1)(f), in operating a website securely.
Emails you send meAnswering your question or handling your requestLegitimate interests — Art. 6(1)(f), and legal obligation — Art. 6(1)(c) where the email is a data subject request I’m required to log.

On-device preferences are not in this table on purpose. They never reach me, so there is no processing by me to justify.

No decision affecting you is made by automated processing or profiling in the sense of Article 22. The apps compute framing and electrical numbers; they do not evaluate people.

International data transfers

I am in the United States, and so is every service the apps talk to. If you use the apps from the EEA, the UK, or Switzerland, the data described above is transferred to the United States. Concretely, that means two recipients:

  • PostHog, for analytics, if you opted in. Data is processed and stored in Ashburn, Virginia.
  • Google, for advertising in the free tier and for processing purchases.

Both transfers rely on the same two safeguards. Each recipient is certified under the EU–US Data Privacy Framework and its UK and Swiss extensions; and, for anything the Framework does not cover, on Standard Contractual Clauses in the underlying agreement — in PostHog’s case the data processing agreement between StorieDev and PostHog.

I hold no separate transfer mechanism of my own, because the apps send me no personal data directly that would need one.

Your rights

If you’re in the EEA, the UK, or Switzerland

Under the GDPR and UK GDPR you have the right to:

  • Access the personal data held about you, and get a copy
  • Rectify it if it’s wrong or incomplete
  • Erase it — the “right to be forgotten”
  • Restrict how it’s processed while a dispute is sorted out
  • Portability — receive it in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time, without affecting processing that already happened. For ads and analytics, this is the consent prompt — and deleting your advertising ID in Android settings enforces it at the device level.
  • Complain to a supervisory authority in your country of residence, work, or where you think something went wrong. You do not have to come to me first.

I will respond within one month, and will tell you if a genuinely complex request needs the two-month extension the GDPR allows.

One honest limitation: for the calculators I hold no identifier that links to you. If you ask me for a copy of your data, the truthful answer is usually that I have none to give, and I’ll say so and explain why rather than inventing a lookup. Data that Google collected as its own controller is subject to Google’s process, and I’ll point you at it.

If you’re a California resident

Under the CCPA as amended by the CPRA, and using the statute’s own category names, the personal information involved in the trade calculators breaks down as follows. All of it is collected from your device as you use the app, and none of it is collected from data brokers or other outside sources.

Statutory categoryWhat it is herePurposeDisclosed to
IdentifiersThe advertising ID, in the ad-supported free tier. Separately, an ephemeral install identifier if you opted into analytics.Advertising; analyticsGoogle; PostHog
Internet or other electronic network activityAd interactions, and — only if you opted in — in-app event names and non-identifying properties.Advertising; analyticsGoogle; PostHog
Geolocation dataCountry level only, derived by Google from your IP address for ad serving. No GPS or precise location is ever requested.AdvertisingGoogle
Commercial informationThat you bought the Pro unlock, and the order record.App functionality; tax recordsGoogle
Sensitive personal informationNone. No government identifiers, precise location, account credentials, contents of messages, health, biometric, or racial, religious, or union data is collected.

You have the right to:

  • Know what is collected, used, and disclosed, and to get a copy
  • Delete personal information I hold about you
  • Correct inaccurate personal information
  • Opt out of sale or sharing — see below
  • Limit the use of sensitive personal information. The apps collect none of the categories the CPRA treats as sensitive, so there is nothing here to limit.
  • Not be discriminated against for exercising any of this. The free tier stays exactly as functional if you opt out.

I will acknowledge a request within 10 business days and respond within 45 calendar days, extendable once by a further 45 days with notice. You may use an authorised agent.

Do Not Sell or Share My Personal Information

I do not sell your personal information for money. I never have, and there is no arrangement under which I could.

I do need to be straight about the second half of that heading, though. Under the CPRA, “sharing” has a specific meaning: disclosing personal information for cross-context behavioural advertising. When the free tier serves a personalised ad, the advertising ID goes to Google for exactly that purpose. Plenty of apps quietly take the view that this isn’t sharing. I think the honest reading is that it is, so I am treating it as sharing and giving you a real way out:

  • On your device, immediately: Android Settings → Privacy → Ads → Delete advertising ID. This stops the personalised identifier at the source, across every app, and doesn’t depend on me honouring anything.
  • By email: send “Do Not Sell or Share” to privacy@storiedev.com and I will confirm the request and pass an opt-out signal to Google for the app in question.
  • Permanently: the Pro unlock removes advertising, and with it the disclosure entirely.

Analytics is a separate switch, and it is already off. The PostHog analytics described above is opt-in, so unless you actively enabled it there is nothing to opt out of. If you did enable it, the Settings toggle turns it off immediately — that toggle is your opt-out for analytics, and no email to me is required to use it.

No personal information of anyone I know to be under 16 is sold or shared. See Children.

Other US states

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana — have broadly similar rights to access, correct, delete, and opt out of targeted advertising. Rather than reproduce each statute, I apply the same process to everyone: email privacy@storiedev.com and I will handle your request under whichever law gives you the stronger position. If your state gives you an appeal right after a refusal, say so and I will treat your reply as an appeal.

Children

The StorieDev trade calculators are professional tools for the building trades. They are not directed at children. They are rated and listed for a general adult audience, contain nothing aimed at children, and are not marketed to them.

Concretely, in the terms COPPA and the Play Families policy use:

  • The apps are declared as not primarily child-directed in the Google Play target audience settings.
  • Ad requests are tagged “not directed at children” — the ad SDK is configured with child-directed treatment set to false and no under-age-of-consent tag, because the audience is trades professionals.
  • I do not knowingly collect personal information from anyone under 13, and there is no mechanism by which a child could create an account, because there are no accounts.

If you believe a child under 13 has somehow provided personal information in connection with a StorieDev product, email privacy@storiedev.comand I will delete whatever exists and confirm that I have.

How long data is kept

WhatHeld byFor how long
On-device preferences and saved projectsYouUntil you uninstall the app or clear its data. I never receive them, so I cannot delete them for you — and cannot keep them either.
Advertising ID and ad request dataGoogleUnder Google’s own retention policy, not mine. I have no ability to shorten or extend it. See Google’s privacy policy.
Analytics events, if you opted inPostHog, in Ashburn, Virginia, as my processor90 days, then deleted. Withdrawing consent in Settings stops collection immediately and clears the local identifier; email privacy@storiedev.com to have events already collected deleted sooner.
Purchase and payment recordsGoogle, and me for order recordsGoogle under the Google Payments notice. My order records are kept 7 years for US federal and Massachusetts tax purposes.
Web server access logsMeRotated off the server within 30 days.
Emails you send to privacy@storiedev.comMeKept while I handle your request, then for 24 months as a record that I handled it — which the privacy laws above require me to be able to show.

Security

The honest version, because a one-person studio claiming enterprise security theatre would be worth less than the truth:

  • The calculators hold no server-side user data at all. This is the substantive security property here. There is no user database, so there is no user database to breach.
  • On-device data sits in the app’s private storage, isolated from other apps by Android, and covered by your device’s own encryption when you have a screen lock set.
  • Traffic between the apps and Google’s services, and all traffic to storiedev.com, is encrypted in transit over TLS.
  • Server access is restricted to key-based authentication over a private network, and the box is kept patched.

What I am not claiming: there is no SOC 2 report, no ISO 27001 certification, no formal information security management system, and no 24/7 security operations centre. If a claim like that matters to your purchasing decision, you should assume it does not exist unless it is written on this page.

If there is a data breach

If a breach of personal data occurs, I will notify the relevant supervisory authority within 72 hours of becoming aware of it where the GDPR requires, and notify affected individuals without undue delay where the risk to them is high. I will also comply with Massachusetts General Laws chapter 93H and the breach notification laws of other US states as they apply.

Given the architecture above, the realistic breach surface is my email and my server, not a store of your calculations — because that store does not exist.

Store disclosures

This section exists so the declarations in the app stores and this page cannot drift apart. The Google Play Data Safety form for DeckSpec, RafterIQ, and ConduitCheck is filled in from this table.

Data typeCollectedSharedPurpose
Device or other IDs — Advertising ID
Free tier only. The Pro unlock removes ads and the ad SDK stops requesting them.
Yes, by GoogleYes, with GoogleAdvertising
App activity — in-app actions
Which calculator ran, which code edition was selected, whether a result was in range. Goes to PostHog as my processor, so it is collected but not shared. Optional: off unless you turn it on.
Only if you opt inNoAnalytics
App info and performance — diagnostics
Device and OS class, so I know what to test against. Optional, same switch.
Only if you opt inNoAnalytics
Location — approximate
Country-level, derived by Google from your IP address for ad serving. The apps never request GPS or any location permission.
Yes, by GoogleYes, with GoogleAdvertising
Purchases — purchase history
Google processes the purchase. I see an order record, not payment details.
Yes, by GoogleNoApp functionality
Personal info — name, email, address, phone
There is no account and no sign-in. Nothing asks you who you are.
NoNo
Your calculator inputs — spans, loads, conductor counts
The precise numbers you type never leave the device. If you opt into analytics, a coarse range is reported instead — a 10.5 ft span leaves as “8–12”. If you do not opt in, nothing about your inputs leaves at all.
Exact values, neverNoAnalytics

Data is encrypted in transit. You can request deletion of data by emailing privacy@storiedev.com, subject to the limitation noted under Your rights that for the calculators I typically hold nothing that identifies you.

For Apple’s privacy labels, when these apps reach iOS, the same facts map as follows: the advertising ID is Data Used to Track You; usage data, diagnostics, and purchases are Data Not Linked to You; and there is no Data Linked to You, because nothing collected is tied to an identity I hold. Tracking will be gated behind Apple’s App Tracking Transparency prompt, and declining it will not reduce app functionality.

Governing law

This policy is governed by the laws of the Commonwealth of Massachusetts, United States, without regard to its conflict of laws provisions. Nothing here removes a mandatory protection you have under the law of your own country of residence — if you are in the EEA or the UK, your local data protection law and your right to complain to your own supervisory authority apply regardless of this clause.

Changes to this policy

When a StorieDev product changes what it collects, this page changes in the same release — not in a catch-up pass afterwards. Material changes will be reflected in the version number and the change log below, and where a change requires your consent, you will be asked again rather than opted in silently.

VersionDateWhat changed
1.2August 12, 2026Corrections of fact, with no change to what any product collects. Published the business postal address and named the registered trade name behind StorieDev. Replaced the PlannerBuilder section: that storefront has launched as Pixie Papercraft, and its own privacy policy is now the authoritative document for it. Removed a specific dollar figure for the Pro unlock in favour of the price shown in the store, so the policy does not go stale when the price changes.
1.1August 5, 2026Documented the opt-in PostHog analytics shipping in the trade calculators from day one: what is collected, the 90-day retention, US data residency in Ashburn, Virginia, and the consent basis and opt-out route. Corrected the data residency stated in 1.0, which had named the EU region.
1.0August 5, 2026First effective version, published for the initial Google Play release of the trade calculators. Replaced the outline that previously stood here.

Contact

For anything on this page — a request under any of the rights above, a question, or a correction — email privacy@storiedev.com. It reaches me directly.

StorieDev, a registered trade name of Steven Storie, a sole proprietor in Massachusetts
PO Box 118, Lenox, MA 01240, United States