Sill app icon — a die-cut sticker of a potted plant

Sill

Privacy Policy

Effective July 2, 2026

Sill is a paper journal for the things you find: you photograph an object, Sill lifts it into a sticker, and it lives in a journal on your device. This policy explains what data Sill handles, where it goes, and the choices you have. The short version:

What stays on your device

Your captures, stickers, journal, boards, collections, and search labels are stored locally on your iPhone. Sill's subject detection and content labeling run on-device using Apple's frameworks — camera frames are not sent to us. When "Save originals to Photos" is on (the default), each capture's full-resolution original is saved to your own Photos library, not to our servers. Deleting the app deletes Sill's local data.

Permissions Sill asks for

Your account (optional)

Magic Polish uses cloud AI, so it needs an account and credits. If you sign up, we store your email address and a random account identifier (authentication is handled by Supabase), your credit balance and its history, and records of your Magic Polish jobs. Passwords are handled by Supabase Auth; our server never sees them.

Magic Polish (cloud AI)

When you polish a sticker, the app uploads the sticker image — and, when available, the original photo it came from, including that photo's embedded metadata — to our server's private storage (Cloudflare R2). The image is processed by Google's Gemini API to produce the cleaned-up result, which is stored privately so the app can download it. We use your images only to provide this feature: we don't use them to train AI models, and they are never made public. Images and results are retained while you have an account and are deleted when you delete your account.

Windowsill (community icon votes)

Windowsill is opt-in: if you submit a sticker as an app-icon candidate, that image is reviewed by us and — if approved — becomes publicly visible to other Sill users, credited either anonymously or with the username you chose. Embedded photo metadata (like location) is stripped before a submission is stored. Your votes and any reports you file are recorded against your account. Submissions are removed when you delete your account.

Analytics and crash reports

To understand what's working and fix what's broken, Sill collects usage analytics with PostHog (for example: a capture happened, a sticker was shared, a polish succeeded) tied to a random identifier — and to your email once you sign in — plus crash and error reports with Sentry. This data is used for product quality only: no advertising, no data sales, no tracking across other companies' apps or websites.

Sharing and exports

Sharing a sticker, card, or board uses the standard iOS share sheet. What you share, and where, is entirely your action — Sill just prepares the image file.

Service providers

Sill relies on: Supabase (sign-in and database), Railway (server hosting), Cloudflare R2 (private image storage), Google Gemini API (Magic Polish image processing), PostHog (analytics), Sentry (crash reporting), and Apple (geocoding, on-device frameworks). Each receives only what's needed for its job.

Deleting your data

In the app: Settings → Delete account permanently removes your sign-in, credits, Magic Polish images and history, and Windowsill submissions and votes from our servers. Your on-device stickers are yours and are unaffected. Local data: delete the app (originals saved to your Photos library remain in your Photos, under your control). You can also email us (below) to request deletion.

Security

Traffic to our servers uses HTTPS. Images live in a private storage bucket accessed through short-lived signed URLs. Your session token is stored in the iOS Keychain.

Children

Sill is not directed at children under 13, and we don't knowingly collect data from them.

Changes

If this policy changes materially, we'll update this page and the effective date above.

Contact

Questions or requests: [email protected]