StixBack to the sheet

Stix legal

Privacy Policy

This Policy explains what Stix processes, why it is needed, which providers assist us, and the controls available to you.

Effective date
July 29, 2026
Provider
Alef Labs, an independent app studio based in Tel Aviv, Israel
Contact
hello@aleflabs.io
On this page

01

Scope and operator

Alef Labs (“we,” “us,” or “our”) operates Stix. This Privacy Policy applies to the Stix mobile application, getstix.app, and related services. It does not govern a third-party service after you leave Stix or direct Stix to publish content there.

The public website does not use advertising, analytics, tracking cookies, accounts, or persistent browser storage in this release. Platform and hosting providers may process ordinary network information needed to deliver and protect the site.

02

Account and profile information

Stix uses Firebase Authentication and creates an anonymous identifier when you first use the app. If you register with Apple or Google, we receive the provider identifier and, depending on your choices and the provider response, your email address, display name, and profile image. We store a corresponding internal user identifier and may assign a public Stix handle.

We also process authentication tokens, account state, sheet and pack roles, blocked-user relationships, consent records, deletion requests, and support communications. We do not receive your Apple or Google password.

03

Prompts, images, stickers, and collaboration

We process the text prompts, style choices, photographs, camera captures, imported images, and generation parameters you submit. We store source photographs and images with the stickers created from them, generated and edited stickers, background-removed and intermediate images where operationally required, quality and safety results, preview images, sticker metadata, sheets, placements, packs, exports, and publishing state.

For shared sheets we process membership, roles, invitations, public handles, who added an item, edits, and other collaboration activity. We process content and user reports, report reasons, block relationships, and moderation outcomes to enforce our rules and protect users.

A public spatial hunt exposes an opaque hunt link and the associated sticker image. Precise coordinates and Cloud Anchor identifiers are not returned in the public hunt metadata.

04

AI processing

When you ask Stix to generate a sticker, we send your prompt and, when supplied, your input image to AI systems that enhance the request, create the image, remove its background, and evaluate quality and safety. Depending on current server configuration, processing may be performed by OpenRouter, fal.ai, or infrastructure operated for Alef Labs. Stix asks for versioned consent before your first generation request.

Do not submit sensitive personal information or an image you are not authorized to process. Provider handling, including retention and model-improvement practices, is governed by our provider arrangements and their applicable service terms. We do not use your content for advertising or sell it.

05

Camera, location, and spatial information

With your permission, Stix uses the camera to capture sticker inputs and power augmented-reality placement. Camera frames are processed on the device except for images you deliberately submit, spatial placement frames required to operate a hunt, and media you explicitly save or share.

Spatial features process precise latitude and longitude, location accuracy, altitude when available, physical sticker dimensions, Cloud Anchor identifiers, placement frames, resolve-session challenges, public hunt tokens, claim history, expiration state, and safety reports. Location access is foreground-only; Stix does not request background location.

Photo-library access is used when you choose an input. Media-library permission is used to save a placement video you request. You may deny or revoke these permissions in device settings, but the corresponding feature will not work.

06

Device, diagnostics, and notifications

We process platform and device information, app version, language, interaction and lifecycle events, generation performance, request and error status, and similar operational data. Production builds use Firebase Analytics and Firebase Crashlytics. Crash reports are scrubbed to avoid prompts and full URLs and may include short diagnostic attributes or a non-reversible hashed identifier.

If you enable notifications, we store an Expo push token and platform so we can notify you about generation or publishing jobs. You can disable notifications in system settings, and Stix deactivates or rotates tokens as needed.

07

Purchases and credits

Apple or Google processes your payment details; Stix does not receive your full card number. RevenueCat and Stix process store, product, offering, package, transaction and original-transaction identifiers, purchase environment and timestamps, refund state, entitlement-related metadata, and the Stix user identifier needed to credit the correct account.

We maintain a credit balance and transaction ledger recording grants, spending, refunds, reasons, references, and resulting balances for accounting, support, fraud prevention, and reliable job refunds.

08

How and why we use information

We use information to authenticate users; generate, edit, store, arrange, share, and publish stickers; operate sheets, packs, notifications, purchases, spatial hunts, reports, blocks, deletion, and support; prevent fraud and abuse; diagnose failures; improve reliability and safety; enforce our Terms; and comply with law.

Where applicable, our legal bases are performance of our contract with you, your consent for permissions and AI processing, our legitimate interests in operating and protecting Stix, and compliance with legal obligations. You may withdraw consent for future processing, but that does not invalidate processing already performed.

09

Service providers and disclosures

We disclose information only as needed to operate Stix, follow your instructions, protect users, complete a business transaction, or comply with law. Providers may include Cloudflare for Workers, databases, queues, and object delivery; Google and Firebase for authentication, remote configuration, analytics, crash reporting, maps, and ARCore; Apple for sign-in and store services; RevenueCat for purchases; Expo for push delivery; and OpenRouter, fal.ai, or Alef Labs-operated infrastructure for AI generation and evaluation.

If you choose Telegram or WhatsApp publishing or sharing, we send the selected content and required account or publishing information to that service. Collaborators and recipients see content and profile attribution according to the sharing feature you use.

We may disclose information to advisers, authorities, or counterparties where reasonably necessary for legal compliance, safety, claims, fraud prevention, financing, merger, acquisition, or transfer of Stix, subject to appropriate confidentiality and notice where required.

10

Public and shared information

Your handle, display name, avatar, sticker attribution, shared-sheet activity, or public spatial sticker may be visible to other people depending on the feature. People who receive content can copy or redistribute it outside our control. Use private or shared features accordingly and report misuse through the app or by email.

11

Retention and deletion

We keep account information and content while your account is active and as needed to provide Stix. Jobs, prompts, generated assets, sheet data, and operational metadata are retained with the related account or content unless removed earlier. Spatial placements expire, are claimed, recalled, moderated, or deleted according to their lifecycle, after which associated anchor and placement material is queued for cleanup.

When you request account deletion, access is disabled immediately while the request is reviewed. We target review within seven days. If approved, eligible personal information, owned content, memberships, tokens, prompts, and stored media are deleted or de-identified; if rejected, access is restored. Cleanup from active systems may continue for up to 30 days after approval, and limited encrypted backups may persist until overwritten. We may retain de-identified data and records required for tax, accounting, payment disputes, fraud prevention, security, enforcement, or legal claims for the applicable period.

12

Your choices and rights

You can edit profile information and sheet memberships in Stix; manage camera, photo, location, and notification access in device settings; withdraw future AI-processing consent in account settings; report content; block users; and delete your account in the app. Instructions and an email alternative are available at getstix.app/delete-account.

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, withdraw consent, and complain to a data-protection authority. Email hello@aleflabs.io to exercise a right. We may verify your identity and may deny or limit a request where the law permits.

We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We do not respond differently to browser “Do Not Track” signals because the website does not perform cross-site tracking.

13

International processing

Alef Labs is based in Israel and providers may process information in Israel, the United States, the European Economic Area, and other locations. Those places may have different privacy laws. Where required, we use contractual and other recognized safeguards for international transfers.

14

Security

We use reasonable technical and organizational safeguards, including authenticated API access, encrypted transport, access controls, scoped public links, secret management, and provider security controls. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

15

Children’s privacy

Stix is not directed to children under 13, and we do not knowingly collect their personal information. If local law requires a higher age for independent consent, a parent or guardian must authorize use. If you believe a child used Stix contrary to this section, contact us so we can investigate and delete the information.

16

Changes to this Policy

We may update this Policy as Stix, our providers, or legal requirements change. We will update the effective date and provide additional in-app notice or obtain consent when required for a material change.

17

Contact

For privacy questions, rights requests, account deletion, or complaints, contact Alef Labs at hello@aleflabs.io.