Stableside Back to the site

Privacy

14 September 2026 · Stableside is in open testing on Google Play.

What this policy covers

The Stableside app for Android, the page your vet or farrier opens from a link you send them, and this website. Stableside is in open testing on Google Play: anybody can install it, it is a real app holding real records, and this policy covers it. It also runs in a browser at stableside.app/app, which is the same app and the same policy. There is no iPhone version on the App Store yet.

What the app collects, and why

Your name, your email address and your password. You type them when you make an account. The name is there so the record can say who did what: a groom reading “Given by Priya at 07:40” is the point of the app. Your password is stored as a cryptographic hash and nobody at Stableside can read it.

What you write about your horses. Their details, health entries, medication courses and doses, worming, vaccinations, farrier and dentist visits, appointments, tasks, weights, diets, costs, photographs and documents. This is the record. It is what you came for, and it is stored so that you and the people you invite can read it.

Who opened a shared link, and when. When you send your vet a link, the app records each time it is opened and whether anything was added. That is a feature rather than surveillance — you can see who has been in — and it records no IP address.

What the app does not collect

No location. No contacts. No calendar. There is no advertising inside the app — no banners, no sponsored entries, nothing for sale in the record. Nothing you write about a horse is ever used to target an advertisement, here or anywhere.

The advertising identifier, and the two companies that see it

This section is new, and it is a real change. Until now the app contained no third-party code at all. It now contains two pieces: Google Analytics for Firebase and Meta’s SDK. They are there for one purpose, and it is worth saying plainly what it is: we pay to advertise Stableside, and without them we cannot tell which advertisements led to somebody actually using the app rather than merely tapping it.

Both read your device’s advertising ID — a resettable number Android gives to apps for advertising, which is not your name and not tied to your account. Both are told that the app was installed, that it was opened, that an account was created, and that a first horse was added.

Both also record some things on their own, because that is how these libraries work rather than anything we added. Each learns basic facts about the device — its model, operating system, language and approximate region. Meta is told when the app is opened and closed. Google's library records when a session starts, how long you spend in the app, that the app's screen was shown, and when the app is updated or removed. That screen record names the app as a whole, not which part of it you were in: nothing in the app tells Google which screen you opened.

Google and Meta may join all of this to what they already know about the device, which is how they match an install back to an advertisement you saw. What they do with it afterwards is governed by their policies, not this one.

What they are never told: anything about a horse. No names, no health entries, no medication, no doses, no photographs, no documents, no notes, no email address, which screens you open, and nothing you have typed anywhere in the app.

To stop it: on Android, Settings → Google → Ads lets you delete the advertising ID outright, after which apps receive no identifier at all. That is a device-wide setting and it does not stop the app working.

What the app records about itself

We record which screens are opened, whether things finished, and how long they took, so that we can tell when the app is broken for somebody rather than waiting to be told. These records cannot contain anything you have written. Each one is a screen name from a fixed list, a handful of numbers, and — when something goes wrong — the type of the error and a code that groups it with others like it.

Error messages, and anything at all about your horses, never leave your phone. There is no crash reporter, and these records go to our own database, in London, alongside your own rather than to an analytics company. They are kept for as long as your account exists and go when it does. They are separate from, and are never sent to, the two advertising SDKs described above.

Who else sees it

Only the people you give access to. A stable, a groom, a sharer, a vet or a farrier sees a horse’s record because you decided they should, at the level you chose, and you can withdraw it in one tap. Nothing is sold. Nothing is shared with an advertiser. Nothing is used to train anything.

Anything your vet or farrier writes through a link carries their practice name and is locked from that moment, including from you. That is what makes the history worth showing an insurer, and it is why it cannot work any other way.

Where it is kept

On Supabase, in London. Photographs and documents sit in private storage that only an authorised request can reach. Everything travels over an encrypted connection.

Keeping it, and deleting it

Your record stays until you delete it. You can delete your account from inside the app under More → Settings → Deleting your account, or by writing to hello@stableside.app from the address on the account. The deletion page sets out exactly what goes and what stays — including the part that is not obvious, which is what happens to entries you wrote on somebody else’s horse.

Entries a vet practice signed are part of another party’s professional record. Tell us and we will explain precisely what is removed and what is not before anything happens.

The log of who opened a shared link is deleted automatically on a schedule, thirteen months after the access.

Children

Stableside is for adults. It is not directed at children and we do not knowingly collect anything from one.

Your rights

You can ask for a copy of everything held about you, ask for it to be corrected, or ask for it to be deleted: hello@stableside.app.

If you think your data has been handled wrongly you can complain to a supervisory authority. Stableside is established in Norway, so that is Datatilsynet, the Norwegian Data Protection Authority. If you are in the United Kingdom you may instead complain to the Information Commissioner’s Office.

Who we are

Stableside is run by Christian Mansfeldt, a sole trader established in Norway, who is the data controller for everything described above. Contact: hello@stableside.app.

Changes

If this policy changes in a way that matters, the app will say so rather than quietly updating this page.

The website, and the waitlist

The rest of this page is about stableside.app rather than the app, and the two are not the same. The site carries an advertising pixel; the app does not and never has.

The waitlist form collects the email address you type into it, if you type one. It is used to send you a message when there is something to open, and for nothing else. It is never sold and never shared.

Submitting the form also writes a one-way hash of your IP address, kept for one hour and then deleted. It exists so that a script cannot fill the list overnight, it cannot be turned back into your address, and it is the only thing besides the email that any submission leaves behind.

The feedback page

The page at /feedback collects what you type into it. That text is kept, read by us, and is the only reason the page exists. Nothing you write appears on the page unless somebody here reads it and decides to put it on the public list — and when that happens it is reworded by us, so your own sentence is never published.

The email box is optional and the page says so. If you leave an address it is used to answer you about what you wrote, and for nothing else: it is not added to the waitlist, never sold and never shared. Leave it blank and the message is anonymous — we keep no name, no account and no address against it.

Submitting the form also writes a one-way hash of your IP address, kept for one hour and then deleted, so that a script cannot fill the page overnight. It is held in a separate table from what you wrote, the two share no key, and it cannot be turned back into your address.

To have something you sent deleted, email the address at the bottom of this page and quote enough of it to find it.

Advertising, and the two trackers

Every page of this site carries the Meta pixel, so that the money spent advertising Stableside on Facebook and Instagram can be pointed at people who might actually want it. It is a third-party tracking pixel and it is worth being plain about what that means.

When a page loads, the pixel tells Meta that this browser opened this address. Meta receives the page URL, the page that referred you to it, your IP address and your browser's user-agent string, and it sets its own cookies in your browser under this domain, the main one named _fbp, to recognise the same browser on a later visit. If you are signed in to Facebook or Instagram, Meta can join that visit to your account. What Meta does with it afterwards is governed by Meta's own policy, not this one.

Your email address is never sent to Meta. The pixel reports page views and nothing else: no form contents, no typed text, no click-level record of what you did on the page.

To stop it: block trackers in your browser or use an extension that does, which stops the pixel loading at all; and separately, Facebook's Settings → Your activity off Meta technologies controls what Meta may do with what it has already received.

Every page of this site also carries the Google tag, which feeds Google Analytics, for the same reason and with the same honesty owed about it. When a page loads it tells Google that this browser opened this address, and Google receives the page URL, the referring page, your IP address and your browser's user-agent string. It sets its own cookies under this domain, named _ga and _ga_ followed by a code for this site, to recognise the same browser on a later visit. That property is linked to our Google Ads account, so what it records is used to measure and target advertising; if you are signed in to a Google account, Google can join the visit to it. What Google does with it afterwards is governed by Google's policy, not this one.

Your email address is never sent to Google either. The tag reports page views: no form contents, no typed text.

It is used for remarketing, and that is worth saying plainly. Because the analytics property is linked to our advertising account, opening this page can put your browser into an audience — which means you may later be shown an advertisement for Stableside somewhere else on the web, because you came here. Measured rather than assumed: loading this page makes a request to doubleclick.net and to Google's ads/ga-audiences endpoint.

To stop it: the same browser tracker-blocking as above stops it loading, and Google's own My Ad Center controls what Google may do with what it already has.

What the site still does not do

No session recording, no heat maps and no fingerprinting. Nothing on this site records what you type, and nothing follows your pointer. Beyond the four requests listed below, the page keeps no record of your visit.

What loads from elsewhere

Who receives something when you open this page, rather than how many requests it takes. This paragraph used to give a number, and the number was wrong twice: one tag can open several connections, and it opens more of them once it is doing its job. So here are the recipients instead.

Every image on the page is embedded in the page itself, so no image request leaves your browser.

The photographs

Most of the photographs on this site are generated images, made with Gemini 3 on 24 August 2026, rather than photographs of real yards. Three of them — the chestnut in the dark box, the grey's head, and the horse in the small round frame beside “Rowan” — are stock photographs from Unsplash.

None of the horses pictured is a customer's horse, no caption says otherwise, and no record shown beside one is a real horse's record.

Leaving the list

Reply to any email from the list, or use the leave link it carries, and the address is deleted.