✦ Stellart

Privacy Policy

Last updated 24 July 2026

Stellart is an art-history museum you explore in your browser and on your phone. It is local-first: the core museum works without an account, and most progress starts on your device. Some features still make network requests—for example to download the app or media, play narration, show a live tally, submit a vote, or provide optional account and community features. We do not show ads and we do not sell personal data.

Information kept on your device

Stellart uses local app or browser storage for information such as the artists and paintings you have studied, favourites, streaks and badges, quiz and “Take a Side” answers, puzzle results, optional birth month and day, language, sound preferences, and a cached copy of some cloud progress.

Stellart creates a cryptographically random device token when the app opens. It is not derived from device characteristics. The “Take a Side” feature sends the token with a vote and stores it with that vote's day so a device counts once per day. Ratings and product interaction records also use this token as described below. These requests do not include your name or email address.

Ratings and product interaction analytics

Stellart uses first-party analytics to understand which paintings, puzzles, and discoveries people use and whether they rate an experience positively or negatively. The records include a random device identifier, the relevant painting key or discovery name, the action and time, and the rating you choose. They do not include profile fields such as your name, email address, city, or country.

When you are signed in, these product interaction records may also include your internal account identifier. This lets Stellart understand interactions across signed-in sessions and may later help avoid asking people with negative recent experiences for a store rating. Stellart does not use third-party advertising or cross-app tracking services for these records.

If you create an account

Signing in is optional. Depending on the methods available in your build, you may sign in with email, Google, or Apple. We then process:

  • Account information: email address, an internal account identifier, and the name or avatar supplied by the provider. Apple may supply a private relay address if you use Hide My Email. Supabase manages authentication credentials; Stellart does not receive your Google or Apple password.
  • Your chosen profile: a display name and, if you add them, city and country.
  • Synced museum progress: visited and favourite items, scores, streaks, quiz or puzzle state, and related preferences used to continue on another device.
  • Community contributions: guide notes, stories, or corrections you submit; their moderation status; the related artist; and the public display name used if a contribution is approved.

Account data is stored in Supabase. Private rows are protected by access controls intended to limit them to your account and authorized Stellart operations. The public profile, leaderboard, or contribution information described below is deliberately visible to other visitors.

Public features

If you set a city or country and sign in, your chosen display name and Curator Score can appear on city and country leaderboards. Approved community contributions can appear with your chosen display name. Your email address and detailed progress are not intended to be public. Leave optional location fields blank and choose a non-identifying display name if you do not want those details shown.

These public profile, leaderboard, and community-contribution surfaces are website features and are not included in the Stellart app for iPhone and iPad at release.

Service and diagnostic information

Stellart and its hosting providers may receive ordinary technical information when the app communicates over the internet, such as internet protocol address, request time, requested resource, device and browser information, and error or security logs. We use this information to deliver and protect the service, diagnose failures, and prevent abuse—not for advertising or cross-app tracking.

Service providers

  • Supabase provides authentication, database storage, cloud sync, live tally data, and community submission storage.
  • Google processes authentication only when you choose Continue with Google; it can provide your email, name, and avatar.
  • Apple processes authentication only when you choose Continue with Apple; it can provide an account identifier, email or relay email, and your name on the first authorization.
  • Vercel hosts the public website and web service endpoints.
  • ElevenLabs helps generate spoken narration. Stellart sends prepared museum narration, not your profile or contribution text, for this purpose.
  • Wikipedia and Wikimedia Commonsprovide source/reference material and some artwork media. A media or source request may be served by their infrastructure or by Stellart's hosting.

These providers process information under their own terms and privacy policies. Apple and Google may also process App Store or authentication diagnostics according to your device and account settings.

Retention and deletion

  • Local information remains until you clear Stellart's site/app data or uninstall the app.
  • Account, profile, synced progress, and associated contribution rows remain until you delete the account, subject to limited security, backup, dispute, or legal retention where required.
  • Anonymous vote records and aggregate tallies are retained as needed to prevent duplicate votes and maintain the tally. They are not intentionally linked to an account.
  • Rating and product interaction records are retained as needed to evaluate and improve Stellart experiences. If you delete a linked account, Stellart removes the account identifier from these rows but keeps the random device identifier and anonymous, account-unlinked interaction history for aggregate analysis.
  • Infrastructure and provider logs follow operational, security, and provider retention schedules and may remain in restricted backups for a limited period.

Your choices

  • Use the core museum signed out and do not submit community content.
  • Leave optional profile location blank and use a non-identifying display name.
  • Delete your account in the app at More → Account → Delete account. This permanently removes the active account, profile, synced progress, and associated account rows. Rating and product interaction rows remain only as anonymous, account-unlinked history after their account identifier is removed. The local copy on the current device remains until you clear app or site data, or uninstall.
  • Revoke Google or Apple access from that provider's account settings in addition to deleting Stellart data where desired.
  • Ask for access, correction, or deletion help by emailing stellart.dev@gmail.com.

Children

Stellart is a general-audience museum and is not directed at children under 13. We do not knowingly collect personal information from children under 13. A parent or guardian who believes a child provided personal information can contact us to request review and deletion.

Community safety

The Community Guidelines explain what visitors may submit and how to report content. Approved contributions are public; do not include personal or confidential information in them.

Changes and contact

If this policy changes, we will update the date above. For questions or requests, email stellart.dev@gmail.com or visit the Support page.

← Back to the museum