Privacy Policy

Stillbook LLC · version draft-3 · Last updated August 19, 2026 (working draft)

This is a working draft provided so the product can be used end to end. The final, binding text is provided by counsel and replaces this before public launch.

How Stillbook LLC handles your information — and your clients'.

The short version

Stillbook is built for solo massage therapists, and protecting your clients' information is the whole point. We do not sell or rent your data or your clients' data to anyone, and we never will.

We do not place advertising or analytics trackers on any page that touches client information — not your provider dashboard, not your booking page, not the links your clients use. Third-party analytics live only on our public marketing pages (this site), and they are privacy-respecting and cookieless.

Information we collect

Account information you give us: your business name, email address, password (stored only as a salted hash), and time zone.

Practice data you create: your services, hours, availability, appointments, client records, charting notes, and intake responses. This may include Protected Health Information (PHI), which we handle under the Business Associate Agreement you accept at signup.

Operational metadata: log and audit records of who accessed which record and when (kept free of PHI by design), and basic device/usage information needed to run and secure the service.

How we use it

We use your information solely to provide Stillbook: to run your scheduling, charting, payments, reminders, and client management, to keep the service secure, and to support you.

We send your clients only the transactional messages your practice triggers — booking confirmations, reminders, and the links to manage their appointments. We do not market to your clients.

Clients who are minors

Stillbook is a tool for your practice; we do not knowingly collect information directly from children. If your practice serves clients who are minors, you are responsible for obtaining any parental or guardian consent your jurisdiction requires before entering their information.

Text messages (SMS)

If a client chooses to receive texts, Stillbook sends transactional appointment messages on your practice's behalf — booking confirmations, appointment reminders, reschedule and cancellation notices, and intake-form reminders — along with replies that let a client confirm or cancel an appointment. Stillbook LLC is the registered sender, and your practice is named in each message. We never send marketing or promotional texts.

Clients opt in on your practice's booking page through a separate checkbox that is not required to book — SMS consent is never a condition of booking or of any purchase. Message frequency varies with appointment activity, and message and data rates may apply. A client can reply STOP to any message to unsubscribe from all texts — or opt out by any other reasonable method, such as replying UNSUBSCRIBE, CANCEL, END, or QUIT, or contacting support — or reply HELP for help (we point them to support@stillbook.app).

Mobile phone numbers and SMS opt-in (consent) information are never shared with or sold to third parties or affiliates for marketing or promotional purposes. We share them only with the messaging subprocessors that deliver the texts your practice triggers, and only the minimum information needed to send each message.

Google Calendar sync

If you choose to connect your Google Calendar, Stillbook asks Google for a single permission — access to your calendar events — and uses it for exactly one feature: two-way availability sync between your calendar and your Stillbook schedule.

What we read and keep: we read your calendar events only to learn when you are busy, and we store only the busy time intervals (start and end times) so booked and blocked times can't be double-booked. We deliberately do not store event titles, descriptions, attendees, locations, or any other event content.

What we write: when an appointment is booked in Stillbook, we create a matching event on your Google Calendar. That event contains at most a client's initials and the service name — or simply "Busy", if you choose that setting — never a client's full name, contact details, notes, or any health information.

How this data is used, shared, and protected: Google user data is used solely to provide the calendar-sync feature described here. It is never sold, never shared with third parties, never used for advertising, and never used to develop, improve, or train artificial-intelligence or machine-learning models. Access credentials and synced data are encrypted in transit and at rest and protected by the same security controls as the rest of the service.

Retention and deletion: you can disconnect Google Calendar at any time from Settings → Sync — we ask Google to revoke our access and immediately delete the stored connection, its credentials, and every busy interval we synced. You can also revoke Stillbook's access from your Google Account's security settings at any time. Stored calendar data is likewise removed when you close your account.

Stillbook's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing & subprocessors

We do not sell or rent your data or your clients' data — to anyone, ever. Beyond that, we share data in only three situations.

Subprocessors: we share data with the vetted infrastructure subprocessors needed to run the service (for example, our cloud host and our messaging providers, and Stripe — the payments platform on which each practice holds its own account and is the merchant of record for client payments), each under a contract and, where applicable, a Business Associate Agreement. Every outbound message to a subprocessor carries only the minimum information required — never your full client records. We publish the current subprocessor list on our Security page.

When the law requires it: we may disclose information if we are required to by a valid subpoena, court order, or other legal process, or where disclosure is necessary to protect the rights, safety, or property of our users, the public, or Stillbook. Where the information is PHI, any such disclosure is handled as the Business Associate Agreement and HIPAA allow; where the law permits, we will tell the affected practice before we disclose.

If Stillbook changes hands: if Stillbook LLC is ever part of a merger, acquisition, financing, or sale of assets, practice and client data may transfer to the successor — but only under the promises in this policy, and we will notify you before your data becomes subject to a different privacy policy. A business transfer is not, and will never be, a sale of your data to a data broker or advertiser.

Tracking, cookies & Do Not Track

We use only the essential first-party cookies needed to sign you in and keep the service secure (session and security cookies). We set no advertising or cross-site tracking cookies anywhere.

Our marketing pages use a cookieless, privacy-respecting analytics service; every page that touches client information has no third-party analytics at all. Because we do not track anyone across other websites or over time, there is nothing for a Do Not Track (DNT) or Global Privacy Control (GPC) signal to turn off — our practices already match what those signals request, so our sites do not change behavior in response to them. No other parties collect personal information about your online activities over time and across different websites through our service.

Security

We encrypt data in transit and at rest, isolate each practice's data from every other practice, require strong authentication, and keep record-level audit logs. See the Security page for details.

We process and store your data on infrastructure located in the United States.

If there's a data breach

If client or account information is ever exposed in a security incident, we investigate promptly and notify the affected practice(s) without undue delay, along with any individuals or regulators the law requires us to inform.

Where we act as your Business Associate, we follow the breach-notification duties set out in the Business Associate Agreement. In all cases we follow the federal and state breach-notification laws that apply.

How long we keep your data

We keep your practice data for as long as your account is active so you can run your practice. When you delete a client record, it leaves your active workspace immediately and is permanently purged from our systems within 30 days. Clinical records may be subject to retention periods under your state's laws — you are responsible for exporting or retaining what your license requires before deleting.

When you close your account, we return or securely destroy the practice data we hold within 30 days — except for the limited records we must keep to meet a legal, tax, or security obligation. Backups are encrypted and cycle out on a rolling schedule.

Your choices & data rights

You can export your practice's data at any time, and delete individual client records or your whole account from within the app.

Questions about privacy, or want to exercise a data right? Email support@stillbook.app.

State privacy rights

Depending on where you and your clients live, state laws may grant additional rights over personal and health-related information — for example, Washington's My Health My Data Act, California's CMIA and CCPA/CPRA, and the Texas Data Privacy and Security Act. These can include rights to access, correct, or delete information, and the right not to have health data sold or shared. We do not sell or share it.

Stillbook usually handles client information as a service provider acting on your practice's behalf, so a client's request is generally directed to your practice — the business that collected the information — and we help you respond. For information we hold about you as our customer, email support@stillbook.app to make a request.

Who we are & how to reach us

Stillbook is operated by Stillbook LLC, a limited liability company formed in Utah, USA, which is the entity responsible for the information described in this policy.

Privacy questions or requests: email support@stillbook.app or call (801) 923-8008. Mailing address: Stillbook LLC, 7533 S Center View Ct, Ste N, West Jordan, UT 84084.

We may update this policy from time to time. We post changes here and, for material changes, notify you.

Are you a client looking to book?

Your therapist will have texted or emailed you a personal link — check there to book or change your appointment.