Privacy
14 September 2026 · Stableside is in open testing on Google Play.
What this policy covers
The Stableside app for Android, the page your vet or farrier opens from a link
you send them, and this website. Stableside is in open testing on Google
Play: anybody can install it, it is a real app holding real records, and this
policy covers it. It also runs in a browser at stableside.app/app,
which is the same app and the same policy. There is no iPhone version on the
App Store yet.
What the app collects, and why
Your name, your email address and your password. You type them when
you make an account. The name is there so the record can say who did what:
a groom reading “Given by Priya at 07:40” is the point of the app.
Your password is stored as a cryptographic hash and nobody at Stableside can read
it.
What you write about your horses. Their details, health entries,
medication courses and doses, worming, vaccinations, farrier and dentist
visits, appointments, tasks, weights, diets, costs, photographs and documents.
This is the record. It is what you came for, and it is stored so that you and
the people you invite can read it.
Who opened a shared link, and when. When you send your vet a link,
the app records each time it is opened and whether anything was added. That is
a feature rather than surveillance — you can see who has been in —
and it records no IP address.
What the app does not collect
No location. No contacts. No calendar. There is no advertising inside the
app — no banners, no sponsored entries, nothing for sale in the
record. Nothing you write about a horse is ever used to target an
advertisement, here or anywhere.
The advertising identifier, and the two companies that see it
This section is new, and it is a real change. Until now the app contained no
third-party code at all. It now contains two pieces: Google Analytics for
Firebase and Meta’s SDK. They are there for one purpose, and
it is worth saying plainly what it is: we pay to advertise Stableside, and without
them we cannot tell which advertisements led to somebody actually using the app
rather than merely tapping it.
Both read your device’s advertising ID — a resettable
number Android gives to apps for advertising, which is not your name and not
tied to your account. Both are told that the app was installed, that it was
opened, that an account was created, and that a first horse was added.
Both also record some things on their own, because that is how these
libraries work rather than anything we added. Each learns basic facts about the
device — its model, operating system, language and approximate region.
Meta is told when the app is opened and closed. Google's library records when a
session starts, how long you spend in the app, that the app's screen was shown,
and when the app is updated or removed. That screen record names the app as a
whole, not which part of it you were in: nothing in the app tells Google
which screen you opened.
Google and Meta may join all of this to what they already know about the
device, which is how they match an install back to an advertisement you saw.
What they do with it afterwards is governed by their policies, not this one.
What they are never told: anything about a horse. No names, no health
entries, no medication, no doses, no photographs, no documents, no notes, no
email address, which screens you open, and nothing you have typed anywhere in
the app.
To stop it: on Android, Settings → Google → Ads
lets you delete the advertising ID outright, after which apps receive no
identifier at all. That is a device-wide setting and it does not stop the app
working.
What the app records about itself
We record which screens are opened, whether things finished, and how long
they took, so that we can tell when the app is broken for somebody rather than
waiting to be told. These records cannot contain anything you have
written. Each one is a screen name from a fixed list, a handful of numbers,
and — when something goes wrong — the type of the error and a code
that groups it with others like it.
Error messages, and anything at all about your horses, never leave your
phone. There is no crash reporter, and these records go to our own
database, in London, alongside your own rather than to an analytics company.
They are kept for as long as your account exists and go when it does. They are
separate from, and are never sent to, the two advertising SDKs described
above.
Who else sees it
Only the people you give access to. A stable, a groom, a sharer, a
vet or a farrier sees a horse’s record because you decided they should,
at the level you chose, and you can withdraw it in one tap. Nothing is sold.
Nothing is shared with an advertiser. Nothing is used to train anything.
Anything your vet or farrier writes through a link carries their practice
name and is locked from that moment, including from you. That is what
makes the history worth showing an insurer, and it is why it cannot work any
other way.
Where it is kept
On Supabase, in London. Photographs and documents sit in private storage
that only an authorised request can reach. Everything travels over an
encrypted connection.
Keeping it, and deleting it
Your record stays until you delete it. You can delete your account from
inside the app under More → Settings → Deleting your account,
or by writing to hello@stableside.app
from the address on the account. The deletion page
sets out exactly what goes and what stays — including the part that is
not obvious, which is what happens to entries you wrote on somebody
else’s horse.
Entries a vet practice signed are part of another party’s
professional record. Tell us and we will explain precisely what is removed and
what is not before anything happens.
The log of who opened a shared link is deleted automatically on a schedule,
thirteen months after the access.
Children
Stableside is for adults. It is not directed at children and we do not
knowingly collect anything from one.
Your rights
You can ask for a copy of everything held about you, ask for it to be
corrected, or ask for it to be deleted:
hello@stableside.app.
If you think your data has been handled wrongly you can complain to a
supervisory authority. Stableside is established in Norway, so that is
Datatilsynet, the Norwegian Data Protection Authority. If you are in
the United Kingdom you may instead complain to the Information
Commissioner’s Office.
Who we are
Stableside is run by Christian Mansfeldt, a sole trader established in
Norway, who is the data controller for everything described above. Contact:
hello@stableside.app.
Changes
If this policy changes in a way that matters, the app will say so rather
than quietly updating this page.
The website, and the waitlist
The rest of this page is about stableside.app rather than the app,
and the two are not the same. The site carries an advertising pixel; the app
does not and never has.
The waitlist form collects the email address you type into it, if you type
one. It is used to send you a message when there is something to open, and for
nothing else. It is never sold and never shared.
Submitting the form also writes a one-way hash of your IP address, kept for
one hour and then deleted. It exists so that a script cannot fill the list
overnight, it cannot be turned back into your address, and it is the only
thing besides the email that any submission leaves behind.
The feedback page
The page at /feedback collects what you type into it. That text is
kept, read by us, and is the only reason the page exists. Nothing you write
appears on the page unless somebody here reads it and decides to put it on the
public list — and when that happens it is reworded by us, so your own
sentence is never published.
The email box is optional and the page says so. If you leave an address it
is used to answer you about what you wrote, and for nothing else: it is not
added to the waitlist, never sold and never shared. Leave it blank and the
message is anonymous — we keep no name, no account and no address
against it.
Submitting the form also writes a one-way hash of your IP address, kept for
one hour and then deleted, so that a script cannot fill the page overnight. It
is held in a separate table from what you wrote, the two share no key, and it
cannot be turned back into your address.
To have something you sent deleted, email the address at the bottom of this
page and quote enough of it to find it.
Advertising, and the two trackers
Every page of this site carries the Meta pixel, so that the money spent
advertising Stableside on Facebook and Instagram can be pointed at people who
might actually want it. It is a third-party tracking pixel and it is worth
being plain about what that means.
When a page loads, the pixel tells Meta that this browser opened this
address. Meta receives the page URL, the page that referred you to it, your IP
address and your browser's user-agent string, and it sets its own cookies in
your browser under this domain, the main one named _fbp, to
recognise the same browser on a later visit. If you are signed in to Facebook
or Instagram, Meta can join that visit to your account. What Meta does with it
afterwards is governed by Meta's own policy, not this one.
Your email address is never sent to Meta. The pixel reports page views and
nothing else: no form contents, no typed text, no click-level record of what
you did on the page.
To stop it: block trackers in your browser or use an extension that does,
which stops the pixel loading at all; and separately, Facebook's
Settings → Your activity off Meta technologies controls what Meta may
do with what it has already received.
Every page of this site also carries the Google tag, which feeds
Google Analytics, for the same reason and with the same honesty owed about it.
When a page loads it tells Google that this browser opened this address, and
Google receives the page URL, the referring page, your IP address and your
browser's user-agent string. It sets its own cookies under this domain, named
_ga and _ga_ followed by a code for this site, to
recognise the same browser on a later visit. That property is linked to our
Google Ads account, so what it records is used to measure and target
advertising; if you are signed in to a Google account, Google can join the
visit to it. What Google does with it afterwards is governed by Google's
policy, not this one.
Your email address is never sent to Google either. The tag reports page
views: no form contents, no typed text.
It is used for remarketing, and that is worth saying plainly. Because
the analytics property is linked to our advertising account, opening this page
can put your browser into an audience — which means you may later be shown
an advertisement for Stableside somewhere else on the web, because you came here.
Measured rather than assumed: loading this page makes a request to
doubleclick.net and to Google's ads/ga-audiences
endpoint.
To stop it: the same browser tracker-blocking as above stops it loading, and
Google's own My Ad Center controls what Google may do with what it
already has.
What the site still does not do
No session recording, no heat maps and no fingerprinting. Nothing on this
site records what you type, and nothing follows your pointer. Beyond the four
requests listed below, the page keeps no record of your visit.
What loads from elsewhere
Who receives something when you open this page, rather than how many
requests it takes. This paragraph used to give a number, and the number was
wrong twice: one tag can open several connections, and it opens more of them
once it is doing its job. So here are the recipients instead.
- Meta — the pixel described above, which also fetches its own
settings for this site.
- Google, as three separate services and it is worth separating them.
Google Tag Manager serves the tag. Google Analytics receives
the page view. And Google's advertising network — the domains
doubleclick.net and google.com — receives a
request too, because the analytics property is linked to our advertising
account. That last one is what lets an advertisement be shown to somebody who
has been here before.
- Google Fonts — the two typefaces. Google's servers see what any
web server sees when a browser asks for a file: your IP address and the
request.
- The waitlist server, only when you submit the form. The feedback form
posts to this same site, which passes it on.
Every image on the page is embedded in the page itself, so no image request
leaves your browser.
The photographs
Most of the photographs on this site are generated images, made with
Gemini 3 on 24 August 2026, rather than photographs of real yards. Three of them
— the chestnut in the dark box, the grey's head, and the horse in the small
round frame beside “Rowan” — are stock photographs from
Unsplash.
None of the horses pictured is a customer's horse, no caption says
otherwise, and no record shown beside one is a real horse's record.
Leaving the list
Reply to any email from the list, or use the leave link it carries, and the
address is deleted.