Last updated 14 September 2026 · StoneSmart is operated by Groklayer.
The short version. StoneSmart stores your health data on your own device, encrypted. We never sell it, never use it for advertising, and there is no advertising SDK in the app at all. You can export everything or delete everything from inside the app. Nothing is copied to the cloud unless you have a Premium subscription.
Everything below is created by you, in the app:
| Data | Why it exists |
|---|---|
| Fluid intake, in millilitres | Your daily hydration goal and reminders |
| Food entries — oxalate, sodium, protein and calcium | The four levers the dashboard tracks |
| Urine colour, pH and 24-hour panel results | Self-checks and the metabolic panel view |
| Stone and flare events | Days-since-last-stone and your history |
| Medications and doses | Medication reminders and adherence |
| Weight, climate, activity level and stone type | Computing your personal fluid goal |
Primarily on your device, in a database encrypted with SQLCipher using a 256-bit key held in the Android Keystore or the iOS Keychain. The app works fully offline and there is no account required to use it.
If the encryption key cannot be created or read on a particular device, StoneSmart records that fact and continues with an unencrypted local database rather than refusing to start — losing access to your own history would be worse than the device's own storage protection being the only layer.
Cloud backup (Firebase Firestore) is part of Premium. On a free account nothing you log is copied to our servers at all. With an active Premium subscription and a signed-in session, your entries sync automatically to a private area readable only by your own account — server-side rules enforce that, not just the app. Linking an email address is what makes that backup recoverable on a new device.
StoneSmart uses a small number of processors, and only for the purpose named:
| Service | What reaches it |
|---|---|
| Google Firebase (Auth, Firestore, Cloud Messaging, Crashlytics, Analytics, Remote Config) | Your anonymous or linked account id; your entries, only with a Premium subscription (see cloud backup below); crash reports; app-usage events that carry categories and counts only — never a milligram, millilitre, urine or stone value |
| Cloudflare Workers and R2 | Food lookups and meal-scan requests, so that API keys never sit on your device |
| Anthropic | A meal photo, only at the moment you scan one, to estimate what is on the plate |
| RevenueCat | Subscription status. No health data. |
When you scan a meal, the photo is sent to our Cloudflare Worker and on to Anthropic to produce an estimate. We do not store the photo. What we keep is the resulting estimate, for one hour, under a key derived from a fingerprint of the image, so that an immediate retry does not cost a second call. After that hour it is deleted. Meal-scan results are labelled as estimates in the app and are always editable.
Optional, off by default, and permission is asked per scope. Only water and weight are ever read or written. Oxalate, sodium, protein, calcium, urine values and stone events are never written to the platform health store — the app has no code path capable of it.
Every network request the app makes uses HTTPS/TLS.
StoneSmart is intended for adults managing their own kidney-stone risk and is not directed at children under 13.
If this policy changes materially we will update the date at the top and, where the change affects how your data is handled, tell you in the app.
Privacy questions, export requests or deletion requests: asimsafeer76@gmail.com.