Privacy Policy
Effective date: September 7, 2026 · Last updated: September 7, 2026
The short version. Pillar reads head position from your AirPods and analyses it on your iPhone. Raw motion data never leaves your device, there is no account, and there is no camera or photo of you anywhere in the product. We do send a small set of anonymous product analytics — session scores, which permissions were granted, and your calibration angles rounded to the nearest 5° — and Apple handles every payment. We never sell or share personal data.
This policy explains what Pillar (“Pillar”, “we”, “us”) does with data when you use the Pillar iPhone app. Pillar is developed and operated by Maksym Pustovit. You can reach us any time at glowdapp@gmail.com.
1. What we do not collect
- No user accounts. No name, email address, phone number or password is required or created.
- No camera and no photo library access. Pillar never asks for either, and there is no image of you anywhere in the product.
- No audio recording. The app plays sounds; it never listens.
- No raw motion data on our servers. The stream of head-angle readings is processed on your iPhone and is never transmitted.
- No GPS or precise location tracking.
- No advertising identifiers, ad networks, tracking pixels or cross-app tracking. We do not ask for App Tracking Transparency permission because we do not track you across apps or websites.
- No session recording or screen recording. Both are switched off in our analytics configuration.
- No Health app data. Pillar does not read from or write to Apple Health.
2. On-device processing
When you wear AirPods with motion sensors and start a session, Pillar receives head-orientation readings from iOS several times a second. All of the following happens locally on your iPhone:
- Head pitch (how far your head is tipped forward) is compared against the tall and slouched angles measured during your own calibration.
- The app decides when to nudge you, escalate, back off or stay quiet.
- Session score, tall time, nudges fired and nudges heeded are calculated and saved.
None of the underlying readings are uploaded. What leaves the device is only the summarised, anonymous analytics described in section 4.
3. What is stored on your device
- Session history — one record per session (start time, duration, score, tall and slumped time, nudge counts), in the app's local database.
- Your calibration — the tall, natural and slouched angles measured during setup.
- Your settings — sensitivity, sounds, quiet hours, Pomodoro lengths and so on.
- What you told the onboarding — your first name and your answers about desk hours, where the tension sits, age range and motivation. These are kept in local app storage so the app does not have to ask twice. They are not sent to us.
- A snapshot for the widgets and Live Activity — today's score and state, in a shared container that only Pillar and its own widget can read.
You can erase all of it from inside the app: You → Delete my data. Deleting the app removes it as well.
4. Analytics
We use PostHog to understand how the app is actually used, so we can fix what is broken and drop what nobody needs. Events are tied to a random identifier generated on your device, not to your identity. This is the complete list of what we send:
| Event | What it carries |
|---|---|
| App opened / became active / backgrounded | Nothing beyond the timestamp and the device properties below. |
| Session started | Open-ended or Pomodoro, planned number of cycles, whether motion permission is granted. |
| Session ended | Duration in minutes, score, share of time in poor posture, number of nudges and how many you heeded, longest tall stretch, which session number it was for you, how the session was ended. |
| Session blocked | The reason a session could not start (for example, AirPods not connected). |
| Permission result | Whether Motion & Fitness and notifications were granted or denied. |
| Calibration completed | Your tall angle, slouched angle and the spread between them, each rounded to the nearest 5° — never the exact measurement. |
| Streak milestone | The number of days reached. |
| Setting changed | Which setting, and its new value. |
| Device properties, attached to all of the above | Device model, iOS version, app version, locale and time zone, an anonymous app-install identifier, and your IP address — which PostHog uses to derive an approximate region and does not expose to us as a precise location. |
This website
The pages on pillar.glowd.tech send the same PostHog project three events, and
nothing else: site_page_viewed (which page, and the domain you arrived from — not
the full referring address), site_cta_clicked (which App Store button you pressed and
where on the page it sat) and site_faq_opened (which question you expanded). Your IP
address reaches PostHog with them, as it does with any web request.
The site sets no cookies and writes nothing to your browser's storage: web analytics here is kept in memory for the length of the page visit and then discarded, so you are not recognised on a later visit or followed to another site. That is also why there is no cookie banner to dismiss. If your browser sends a Do Not Track signal, nothing is sent at all. Session and screen recording are switched off.
We deliberately report body angles only in 5° buckets. Precise measurements of somebody's neck are the kind of data that should not be collected without a reason, and the questions we need answered do not require them.
PostHog's own privacy policy is at posthog.com/privacy.
5. Purchases and subscriptions
If you subscribe, the payment is processed entirely by Apple through the App Store. We never receive or store your card number, billing address or Apple Account credentials.
We use RevenueCat to check whether a subscription is active. RevenueCat receives a randomly generated app user ID, your purchase receipts from Apple and your subscription status. It receives no payment card details and no posture data. Its privacy policy is at revenuecat.com/privacy.
6. Notifications
If you allow notifications, Pillar can post a nudge as a local notification when it cannot reach you any other way. These are composed and scheduled on your device — there is no push server, and no device token is sent to us. You can revoke the permission at any time in Settings → Pillar → Notifications.
7. Third parties we rely on
| Service | Purpose | What it receives |
|---|---|---|
| Apple (App Store, iOS) | Distribution, payments, motion sensor access, notifications | Apple handles all payment data. Head-orientation readings are provided by iOS to the app on your device. |
| PostHog | Anonymous product and website analytics | See section 4. |
| RevenueCat | Subscription status | See section 5. |
None of them receive your raw motion data, your name or your onboarding answers.
8. Retention
Data on your device stays until you delete it, in the app or by removing the app. Anonymous analytics events are retained according to PostHog's standard retention policy. Subscription records are retained by Apple and RevenueCat according to their own policies and applicable tax rules.
9. International transfers
All posture analysis happens on your device. The anonymous analytics events in section 4 may be transferred to and stored on servers operated by PostHog, and subscription records by RevenueCat, including in the United States, under those providers' own terms and safeguards.
10. Your rights
Because Pillar has no accounts, we generally cannot connect any data to a named individual, which limits what we can look up on request. What you can do:
- Erase everything we hold on your device — You → Delete my data, or delete the app.
- Ask us about the analytics — write to glowdapp@gmail.com. If you can give us the anonymous identifier from your install, we will delete the matching events.
- Revoke any permission — Motion & Fitness, notifications and Live Activities are all controlled in Settings → Pillar.
If you are in the European Economic Area or the United Kingdom, you have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR. Our lawful basis for the analytics in section 4 is legitimate interest in maintaining and improving the app; for processing your purchase, performance of a contract. If you are in California, we confirm that we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not offer financial incentives for personal information.
11. Children
Pillar is not directed at children under 13, and we do not knowingly collect data from them. The onboarding asks for an age range only to phrase its own copy; that answer stays on your device.
12. Security
Everything the app stores lives in your iPhone's own protected app container, covered by iOS device encryption. Data in transit to PostHog and RevenueCat is encrypted with TLS. No system is perfect, and we cannot guarantee absolute security.
13. Changes to this policy
If we make material changes, we will update the “Last updated” date above and, where practicable, say so in the app. Continuing to use Pillar after a change takes effect means you accept the updated policy.
14. Contact
Questions about this policy or about your data: glowdapp@gmail.com. We answer in English or Ukrainian.