Privacy Policy
App: StockMvt (Android package com.jllbstudio.stockmvt) ·
Publisher: JLLB Studio
Version 1.0 — Last updated: 4 August 2026 ·
Version française
1. Who we are
StockMvt is an Android inventory management app published by JLLB Studio, represented by Jean-Louis LIKULA BASOMBOLI, its developer and creator. We are the data controller for the processing described below. Contact: privacy@jllbstudio.com.
2. Summary
- StockMvt can be used entirely without an account. In that mode, no data ever leaves your device.
- We show no ads and include no analytics or advertising trackers.
- We never sell, rent or trade your data.
- We do not collect location, contacts, SMS, call logs, microphone input or your list of installed apps.
- Camera frames are processed on-device and are never stored or transmitted.
- You can delete your account and all associated data at any time — in the app, or via this page.
3. Two usage modes
Without an account (fully local). If you choose “Continue without an account”, a local profile is created on your device only. Every piece of data — company, products, categories, locations, movements, alerts, photos — is stored in the device's internal database (IndexedDB) and local storage. We receive nothing at all, and the AI assistant is disabled. Uninstalling the app or clearing its data permanently erases everything, and we cannot restore it.
With a Google account. Signing in creates an account on our infrastructure so your data can be backed up to the cloud, restored on other devices, and shared with your team. This is the mode that involves the processing described below. If you later sign in from the local mode, your existing local data is migrated to your new account; this is triggered explicitly by you.
4. Data we process
| Category | Specific data | Source | Where stored |
|---|---|---|---|
| Identity & account | Display name, email address, profile photo, technical account ID | Provided by Google Sign-In | Our servers (Supabase) + local copy |
| Company | Name, description, currency, colour theme, logo, lock status | Entered by you | Our servers + local copy |
| Inventory content | Products, codes and barcodes, categories, locations, quantities, min/max thresholds, purchase and sale prices, notes, product photos | Entered or captured by you | Our servers + local copy |
| Stock movements | Type (in, out, stocktake), reason, quantity, location, stock before/after, note, author, date and time | Generated by your use of the app | Our servers + local copy |
| Team & roles | Company member list, role assigned to each, invitation tokens | Generated by administrators | Our servers + local copy |
| Notifications | Firebase Cloud Messaging registration token and device platform | Generated by Google services if you allow notifications | Our servers + Google (Firebase) |
| AI assistant | Your question, the last ten turns of the conversation, an extract of your inventory data needed to answer, your language and current screen | Only when you send a message | Sent to our AI inference provider for the duration of the request; not retained by us |
| Technical logs | Timestamps of server calls, response codes, technical error messages | Generated automatically | Our servers (limited retention) |
Free-text fields (product names, notes, location names, company description) are intended for business information. Please do not enter sensitive data, health data, payment card details, or personal information about third parties. You are responsible for the content you store.
5. Why we process it
- Create your account, authenticate you and identify you within a company — performance of our contract (Terms of Use).
- Store, display, sync and back up your inventory data — performance of our contract.
- Assign roles and manage access rights within a team — performance of our contract.
- Send stock alert notifications (out of stock, low stock, overstock) — your consent, revocable at any time in Android settings.
- Answer your questions via the AI assistant — your consent, given by sending a message.
- Ensure security, prevent fraud and abuse, diagnose failures — legitimate interest.
- Respond to your support or deletion requests — performance of our contract and legal obligation.
6. Android permissions
| Permission | Purpose | Can you deny it? |
|---|---|---|
INTERNET | Sync your data, receive notifications, talk to the assistant. Unused in no-account mode. | No (normal permission) |
CAMERA | Scan a product barcode, scan an invitation QR code, take a product photo. Analysis happens on-device; the video stream is never stored or transmitted. | Yes — the rest of the app keeps working |
POST_NOTIFICATIONS | Display stock alerts on your screen. | Yes — alerts remain visible in the Notifications screen |
READ_EXTERNAL_STORAGE (Android 12 and below) | Import an image from your gallery: product photo or a screenshot of an invitation QR code. | Yes — use the camera instead |
WRITE_EXTERNAL_STORAGE (Android 10 and below) | Save a PDF report or a barcode label into your Documents folder. | Yes — you can share the file without saving it |
The app also declares intent queries so it can offer the correct “open with” and
“share” options when exporting a PDF. That list is neither collected nor transmitted.
7. AI assistant
The app includes a conversational assistant that answers questions about your inventory. It runs only when you send a message; it does not listen, read or monitor anything continuously. When you send a message, our server assembles your question, the last ten turns of the current conversation, and the extract of your inventory data needed to answer, and sends it to Groq Inc., our inference provider, which runs an open Llama-family language model and returns the answer.
We keep no conversation history on our servers — the visible history lives only in the app's memory and disappears when you close it. We do not train any model on your data. The assistant is unavailable offline and in no-account mode.
Like any generative system, the assistant may produce inaccurate, incomplete or unsuitable answers. Its output is decision support only and is not accounting, financial, tax, legal or medical advice. Always verify important figures in the app's own screens before acting. If the assistant produces inappropriate, offensive or clearly incorrect content, please report it to support@jllbstudio.com; we review such reports and adjust the system instructions accordingly.
8. Processors and recipients
| Provider | Role | Data involved | Their policy |
|---|---|---|---|
| Supabase Inc. | Database hosting, authentication, image storage, server functions | All account, company and inventory data | supabase.com/privacy |
| Google LLC (Google Sign-In, Firebase Cloud Messaging) | Sign-in with your Google account, notification delivery | Google account identity, device notification token | policies.google.com/privacy |
| Groq Inc. | Runs the AI assistant's language model | Your question and the inventory extract needed to answer | groq.com/privacy-policy |
| Cloudflare, Inc. | Hosting and delivery of this website | Technical browsing data (IP address, headers) | cloudflare.com/privacypolicy |
| Web3Forms | Delivers this site's contact and deletion forms to our inbox by email | Information you voluntarily type into a form | web3forms.com/privacy |
We may also disclose data where required by law, upon a valid request from a competent authority, or to assert our legal rights. In the event of a business transfer or merger, your data may be transferred to the acquirer; you would be informed beforehand through an update to this policy.
9. International transfers
Our providers operate infrastructure located in the United States and the European Union, among others, so your data may be processed outside your country of residence. Such transfers rely on the contractual mechanisms offered by the providers concerned, including the European Commission's Standard Contractual Clauses where applicable.
10. Retention
- Account and inventory data: kept for as long as your account exists; erased after a deletion request.
- Notification tokens: deleted on sign-out, or automatically once they become invalid.
- Invitation tokens: deleted after use or expiry.
- AI conversations: not retained server-side.
- Technical logs: up to 90 days, for security and troubleshooting.
- Local device data: until you uninstall the app, clear its data in Android settings, or sign out.
- Support emails: up to 24 months, as a record of your request.
11. Security
Traffic between the app and our servers is encrypted in transit (HTTPS/TLS), and data stored on our infrastructure is encrypted at rest by our host. Access is isolated per company at the database level through row-level security policies, so a user can only read data belonging to companies they are a member of, within the limits of their role. Third-party API keys are never shipped inside the app; they are held server-side.
No system is infallible. If a security incident materially affected your data, we would inform you promptly and notify the competent authorities where legally required. On your side, please protect access to your Google account and your device, and grant the administrator role only to people you trust.
12. Your rights
Depending on your country of residence, you may have the right to:
- Access a copy of the data we hold about you;
- Rectify inaccurate data — most of your data is directly editable in the app;
- Erase your account and data (see section 13);
- Restrict a contested processing operation;
- Port your data in a machine-readable format — you can already export PDF reports from the app;
- Object to processing based on our legitimate interest;
- Withdraw consent — disable notifications in Android settings, or stop using the AI assistant, at any time and without affecting the rest of the service;
- Complain to your national data protection authority.
To exercise a right, email privacy@jllbstudio.com from the address linked to your account. We respond within 30 days at the latest. We may ask you to confirm your identity before acting, to prevent someone else from acting on your behalf.
13. Deleting your account and data
In the app: open StockMvt, then Menu → Delete account, and confirm.
On the web, without the app: use the form on our dedicated page Account and data deletion. It sets out exactly what is deleted, what may be retained, and within what timeframes.
In no-account mode, no data exists on our side: simply uninstall the app or clear its data in Android settings to erase everything.
14. Children
StockMvt is a professional tool for adults running a business. It is not designed, marketed or directed to anyone under 18, and contains no content appealing to children. We do not knowingly collect data from minors. If you believe a minor created an account, email privacy@jllbstudio.com and we will delete the account and associated data.
15. What we do not do
- No advertising and no ad networks.
- No advertising identifier and no cross-app or cross-site tracking.
- No behavioural analytics or audience measurement SDK inside the app.
- We never sell or rent your data.
- We do not collect location, contacts, SMS, call logs, microphone input, or your list of installed apps.
- We never record your camera feed.
16. This website
stockmvt.jllbstudio.com is a static site hosted on Cloudflare Pages. It sets no advertising or analytics cookies. Only one item is stored in your browser's local storage: your light/dark theme preference, which never leaves your device. Our contact and deletion forms are delivered to our inbox by Web3Forms and feed no database. Like any host, Cloudflare processes technical connection data (IP address, browser type) for security and availability. Fonts are loaded from Google Fonts.
17. Changes to this policy
We may update this policy to reflect changes in features, providers or legal obligations. The last-updated date appears at the top of this page. For material changes affecting your rights, we will notify you in the app or by email before they take effect. Continuing to use StockMvt after that date constitutes acceptance of the current version.
18. Contact
JLLB Studio — Publisher of StockMvt
Represented by: Jean-Louis LIKULA BASOMBOLI
Privacy and rights requests: privacy@jllbstudio.com
General support: support@jllbstudio.com
Website: stockmvt.jllbstudio.com