How to choose the best posture app for privacy in 2026

Pointing a camera at yourself for eight hours a day is a real trust decision, not a small one. Every vendor says a version of the same thing — that your video is never uploaded — and mostly you are asked to believe it. This guide shows you how to check instead.

Where each promise is written

Every vendor here makes a version of the same promise on its marketing page — that the camera feed stays on your device, or that what it captures is never uploaded.[1][2][3][4][5] What differs is which document that promise sits in — a marketing page, a store listing, or the binding privacy policy and terms you actually agree to. The tables below report what each vendor publishes and nothing more, with the source for every cell; verify each one yourself using the method above.

What can leave the device according to each vendor’s legal documents, at a glance

Four things that can leave a device, against each vendor’s own published documents, read on 31 July 2026, and — for SitSense’s privacy policy, which SitSense replaced on 13 August 2026 — on 15 August 2026. Open a column header for what that category covers, and any cell for the sentence its entry rests on. Where a vendor has only said something outside its legal documents — in a store listing, say — the entry says so and the open cell names where it comes from.
App
Whether the posture analysis happens in a browser tab or in a native app you install. It decides how easy the rest of that vendor’s row is to check for yourself.
Pictures or video frames of you: the camera feed itself.
The numeric landmark positions derived from the picture — where a shoulder or an ear sits — and every figure computed from them: an angle, a distance, a posture score, a daily summary. Numbers describing your body, not pictures of it. Both halves count, because a vendor can keep every landmark on the machine and still send the measurements taken from them.
Data collected about you or your machine while you use the app: analytics, advertising identifiers, third-party trackers, device and usage data, and IP addresses logged in the ordinary course. What you knowingly hand over — a name, an email, the settings you choose — is a different question, answered under "What an account requires" below; the licence call has its own column to the right.
The call an app makes to check whether you are entitled to use it — for a free-tier limit or a subscription.
UpSensei
Open your browser’s developer tools (F12) and watch the Network tab while a session runs: every request the page makes is listed there, and a continuous video upload cannot hide in it. That check needs nothing installed, though reading the list takes some patience — this guide walks through it under "How to verify it yourself".
UpSensei’s privacy policy[33] and §2 of its terms of use[34] both state that no image, video frame or recording is transmitted, uploaded or stored.
Only UpSensei Pro’s optional Cloud mode uploads abstract posture coordinates — numeric landmark positions, never pictures. Guests and free accounts upload none.[1]
UpSensei loads no analytics, no advertising identifiers and no third-party trackers, and its published documents describe no device or usage data gathered while you work.[1] Two things sit outside this column by its definition, and are worth naming here rather than leaving you to find them: an optional account’s sign-in details, which Hanko holds as UpSensei’s Art. 28 processor, and the settings you choose, which sync to that account. Both are data you enter, not data collected about you — see "What an account requires" below.[28] The licence call is the next column.
Every UpSensei session starts by asking our server for a licence — unless you are offline and the last one is still valid, in which case it is reused and there is no ask at all. Like any web request that ask carries your IP address, so even a guest session is not literally zero contact with us. For a guest or free account that start-of-session ask is the only one, because the licence lasts an hour and its expiry ends the session rather than renewing it; a Pro licence lasts to the end of the billing period and is renewed by one further ask only if a session is still running when it lapses. The server counts those asks pseudonymously: rather than your browser’s identifier it keeps a fingerprint of it that cannot be turned back into you, plus how many sessions it has allowed or refused, and when. That is what enforces the free-session limit. Because the count cannot be traced back to you, we cannot look it up and delete it on request either (Art. 11 GDPR); it is deleted automatically 90 days after your last session.[28]
SitApp
A native app does not list its requests for you the way a browser does. Reading them means routing its traffic through a proxy you control — extra software, and a certificate you install — and an app may pin its certificate, which is sound security practice and also stops such a proxy working. Short of that you are left watching your machine’s overall traffic with a firewall or a network monitor, which shows whether data is leaving but not what it contains — harder to check than a browser app, which is not the same as less trustworthy.
SitApp’s privacy policy §1.3[6] and its terms of service §3[7] both state webcam images and video are never transmitted: "Webcam images and video are NEVER transmitted to our servers or any third party."[7]
SitApp splits this by granularity, and its own documents describe both halves. The fine-grained readings stay put: "The time-series database … stays on the machine that recorded it. Readings are never uploaded."[17] The figures computed from them do not — the same table lists "Daily & monthly summaries" as "Per-account", "Synced to the cloud. Your posture score, total duration, and session count are the same on every machine you sign in to."[17] SitApp’s privacy policy says where they land: data is stored "on servers located in the United Kingdom and European Union via Firebase (Google Cloud Platform)", and its retention table keeps "Posture history" until account deletion.[16] A posture score is a figure computed from landmarks, so it belongs in this column.
SitApp’s own App Store privacy label declares, under "Data Linked to You" and for the purposes "Developer’s Advertising or Marketing" and "Analytics", these categories: "Identifiers" ("User ID", "Device ID"), "Usage Data" ("Product Interaction") and "Diagnostics" ("Crash Data", "Performance Data", "Other Diagnostic Data"). Apple publishes a rider with it: "This information has not been verified by Apple."[35] SitApp’s privacy policy sets a retention period for the same kind of data — its retention table lists "Usage analytics 26 months (anonymized)"[16]. Two things are deliberately not counted here: the posture figures on SitApp’s servers, which are under Body measurements so one upload is not reported twice, and the account details and preferences you enter yourself, which this column excludes for every vendor including us.
Neither of SitApp’s published legal documents describes a licence or entitlement check: its terms of service set out paid access in §8 "Subscription Plans and Payment" without describing one[30], and the Firebase, storage and retention sections of its privacy policy describe no such call[16].
SitSense
Open your browser’s developer tools (F12) and watch the Network tab while a session runs: every request the page makes is listed there, and a continuous video upload cannot hide in it. That check needs nothing installed, though reading the list takes some patience — this guide walks through it under "How to verify it yourself".
SitSense’s privacy policy §2.A states "No video, images, camera frames, or body landmarks ever leave your device.", and the policy opens on the same promise: "Pose estimation runs in your browser. No video, image, or camera frame is ever stored, transmitted, or seen by our servers."[18] Its terms and conditions address images too, but cover storage only, not transmission[13].
SitSense’s privacy policy §2.A states "Your camera feed is analysed in your browser. From it we store numerical posture measurements:" and names them — "neck angle", "craniovertebral angle", "trunk angle", "head-forward distance", "head tilt", "shoulder slope" and "neck rotation" — with "a posture rating (good, fair, or poor)" and measurement metadata stored alongside each reading. The same section states "No video, images, camera frames, or body landmarks ever leave your device."[18] So it is figures computed from the landmarks that reach SitSense’s servers, not the landmark positions themselves. §4 adds that on a paid plan "a numerical summary of your posture history" is sent to OpenAI to write the in-app replies[36], and SitSense’s FAQ describes that feedback as generated by a large language model[15].
SitSense’s privacy policy §2.D states "We record your sessions and in-app activity, linked to your account, so your history and progress work.", and names PostHog as the analytics provider for page views, crash reports and in-app feedback. Where analytics cookies are accepted, that section says PostHog "links your visit history to your account (by an internal ID, never your email) and may record your screen on the sign-up, sign-in, and app pages", adding "Anything you type is always masked in these recordings."; where they are declined, there is "no recording, no cookie, and no cross-visit identity".[19]
SitSense’s published documents do not describe a licence check.[8][13]
Slouch Sniper
A native app does not list its requests for you the way a browser does. Reading them means routing its traffic through a proxy you control — extra software, and a certificate you install — and an app may pin its certificate, which is sound security practice and also stops such a proxy working. Short of that you are left watching your machine’s overall traffic with a firewall or a network monitor, which shows whether data is leaving but not what it contains — harder to check than a browser app, which is not the same as less trustworthy.
Slouch Sniper’s terms of service list "optional images …" among the information Slouch Sniper says it collects, in the same "Data & Privacy" clause as email, IP and usage data — information a vendor collects is information that reached it. The clause states a purpose for those images, elided above only because this page does not print the word it uses: troubleshooting, and improving the service. Nothing in those documents says such an image is a webcam frame. The sentence after that list states "We may train AI models on collected data".[9]
Slouch Sniper’s privacy policy §3 "Information We Collect" says it collects "information you provide and information generated when you use our services", and lists among it "posture-related, biometric and wellness signals when features require them".[10] Neither that policy[10] nor Slouch Sniper’s terms of service[9] uses the word "coordinates" or "landmarks" anywhere, so the vendor does not say which figures those signals are — but a signal a vendor states it collects is a figure about your body that reached it, which is what this column asks. The qualifier "when features require them" is theirs and is quoted rather than dropped.
IP address, device and usage data and analytics, per the "Data & Privacy" clause of Slouch Sniper’s terms of service — which lists an email address in the same sentence.[9]
Slouch Sniper’s published documents do not describe a licence check.[9][10]
Posture Reminder AI
A native app does not list its requests for you the way a browser does. Reading them means routing its traffic through a proxy you control — extra software, and a certificate you install — and an app may pin its certificate, which is sound security practice and also stops such a proxy working. Short of that you are left watching your machine’s overall traffic with a firewall or a network monitor, which shows whether data is leaving but not what it contains — harder to check than a browser app, which is not the same as less trustworthy.
Posture Reminder AI makes the promise in its App Store description — "No images are stored, uploaded, or shared"[14] — and in no legal document: its privacy policy never mentions images at all[12], and its terms of service carry no data clause[25].
Posture Reminder AI’s privacy policy states "Your posture data is never collected and remains only on your device."[12]
Posture Reminder AI answers this on its App Store listing and nowhere else: the listing’s App Privacy label reads "Data Not Collected — The developer does not collect any data from this app.", published with Apple’s rider "This information has not been verified by Apple."[11] Neither legal document addresses what the app itself transmits: its privacy policy does not[12], and its terms of service address account details, but for the purchase rather than for the app — they state "Direct-download customer accounts are created after a successful payment." and that the transaction is "securely processed by Stripe".[25]
Posture Reminder AI’s App Store description states "A brief internet connection is only used at launch to verify subscription status"[14] — the only network use by the app itself that any Posture Reminder AI document discloses. Its terms of service disclose network use of another kind: direct-download purchases are "securely processed by Stripe" and delivered "through your account dashboard".[25]

Jurisdiction, accounts and what you can check yourself

Questions four to six of the checklist, against each vendor’s own published documents, read on 31 July 2026, and — for SitSense’s privacy policy, which SitSense replaced on 13 August 2026 — on 15 August 2026. Open a column header for what it covers, and any cell for the sentence its answer rests on. "Not stated" records that a vendor’s documents are silent on the question — never an answer inferred from how its app behaves. The last column carries no source because it is not a vendor claim: it follows from whether an app runs in a browser tab or as a native process.
App
Which country’s law a vendor has written into its own documents, where it says the data it does collect is stored, and whose law can reach that data — which is not only a question of where the racks sit. US law such as the CLOUD Act can require a US-based company to produce data it controls, including data held in Europe, so a provider’s home country counts as much as its data centre’s. It also decides which regulator you can turn to if a promise is not kept.
The identifying details a vendor’s published documents say you hand over to hold an account — an email address, a name, a payment identity, or none of them.
How much of a vendor’s row a reader can confirm without installing anything. A browser app lists every request it makes in the browser’s own Network tab; reading a native app’s requests means routing its traffic through a proxy you control, and an app may pin its certificate, which is sound security practice and also stops such a proxy working. Harder to check is not the same as less trustworthy — the method, and the patience it takes, is under "How to verify it yourself" on this page.
UpSensei
UpSensei is operated by a sole trader with a German postal address, published in its Impressum[27], so the authority to complain to is a German one. Posture data in Cloud mode lives at Scaleway, a French company with data centres only in the EU.[26] The same US-law point applies to UpSensei in one place, and its own privacy policy says so: sign-in runs through Hanko, whose sub-processor AWS has its data centre in Frankfurt while its parent company is US-based.[29] That reach covers sign-in data, not posture data.
An UpSensei account is optional and passkey-based: its privacy policy states you can hold one with no email address at all, and UpSensei’s own server stores an opaque identifier rather than a name or an email.[28] Paying is the exception worth being plain about — UpSensei Pro is sold by Creem (Armitage Labs OÜ, Estonia) as merchant of record, and the name, email and billing address entered at Creem’s checkout link a payment identity to the account reference in Creem’s own records.[28]
UpSensei runs in a browser tab, so every request it makes is listed in the browser’s own developer tools and a continuous video upload cannot hide there. That check needs nothing installed, though reading the list takes some patience — this guide walks through it under "How to verify it yourself".
SitApp
SitApp is operated by "Aston Smith Ltd, trading as SitApp", whose terms of service state: "These Terms of Use are governed by and interpreted following the laws of the United Kingdom." The same clause continues: "If your habitual residence is in the EU, and you are a consumer, you additionally possess the protection provided to you by obligatory provisions of the law of your country of residence."[21] SitApp’s privacy policy states: "Your data is stored on servers located in the United Kingdom and European Union via Firebase (Google Cloud Platform)."[16] Firebase is Google Cloud Platform, operated by a US company, and US law such as the CLOUD Act can require a US-based provider to produce data it controls, including data held in Europe. That is a property of the statute and of the provider SitApp itself names, not a statement about SitApp’s conduct.
SitApp’s privacy policy §1.1 lists what you provide on registering: "Account Information: Name and email address when you register" and "Authentication Data: Login credentials or social login tokens (Google, GitHub, Apple)".[20]
SitApp is a native desktop app, so it does not list its requests for you. Reading them would mean routing its traffic through a proxy the user controls — extra software, and a certificate they install — and a native app may pin its certificate, which is sound security practice and also stops such a proxy working. Short of that a user is left watching the machine’s overall traffic with a firewall or a network monitor, which shows whether data is leaving but not what it contains — harder to check than a browser app, which is not the same as less trustworthy.
SitSense
No SitSense legal document names a country: its terms and conditions carry no governing-law clause[13], and its privacy policy gives no server location and no postal address — §12 "Contact" is an email address and nothing else.[23] That policy does name the services SitSense runs on, "Vercel (hosting) and Supabase (database)" among them, without a country or a region for any of them[36]. The EU, UK and California rights listed in §9 "Your rights" of that policy follow the reader’s location, not SitSense’s own.[31]
SitSense’s privacy policy §2.B "Account information" lists an email address, a "Password (hashed) or OAuth identity", a display name, and subscription and billing status.[22]
SitSense runs in the browser, so every request it makes is listed in the browser’s own developer tools and a continuous video upload cannot hide there. That check needs nothing installed, though reading the list takes some patience — this guide walks through it under "How to verify it yourself".
Slouch Sniper
Slouch Sniper’s privacy policy §11 "International Transfers" says only "Information may be stored and processed in countries outside your own." and promises "appropriate safeguards (such as standard contractual clauses or equivalent measures)", without naming a country, a provider or a data-centre region[10] — which leaves the question unanswerable from the published documents rather than answered, since neither a jurisdiction nor a provider’s home country can be identified from them; Slouch Sniper’s terms of service carry no governing-law clause[9].
Slouch Sniper’s terms of service state "You must be at least 18 years old to use Slouch Sniper and provide accurate account information."[24], and its "Data & Privacy" clause opens "We collect information such as email, IP address, device and usage data, analytics"[9].
Slouch Sniper is a native desktop app, so it does not list its requests for you. Reading them would mean routing its traffic through a proxy the user controls — extra software, and a certificate they install — and a native app may pin its certificate, which is sound security practice and also stops such a proxy working. Short of that a user is left watching the machine’s overall traffic with a firewall or a network monitor, which shows whether data is leaving but not what it contains — harder to check than a browser app, which is not the same as less trustworthy.
Posture Reminder AI
Posture Reminder AI names no operating company, no country and no server location in the two legal documents it publishes itself: its privacy policy of 27 June 2021 promises only to protect stored data "within commercially acceptable means"[12], and its terms of service carry no governing-law clause[25]. A third document does carry one, and its own Mac App Store listing names it: the listing gives Apple’s standard licence agreement as the app’s "Terms of Use"[14]. That agreement’s governing-law clause opens "Except to the extent expressly provided in the following paragraph, this Agreement and the relationship between you and Apple shall be governed by the laws of the State of California" — and the following paragraph reads "If you are a citizen of any European Union country or Switzerland, Norway or Iceland, the governing law and forum shall be the laws and courts of your usual place of residence."[32] So for a reader in the EU that agreement names their own law and courts, not California’s.
Posture Reminder AI’s terms of service state "Direct-download customer accounts are created after a successful payment." and make you "responsible … for using the same checkout email address when setting your password and accessing your downloads"; those terms state that checkout is "securely processed by Stripe".[25]
Posture Reminder AI is a native desktop app, so it does not list its requests for you. Reading them would mean routing its traffic through a proxy the user controls — extra software, and a certificate they install — and a native app may pin its certificate, which is sound security practice and also stops such a proxy working. Short of that a user is left watching the machine’s overall traffic with a firewall or a network monitor, which shows whether data is leaving but not what it contains — harder to check than a browser app, which is not the same as less trustworthy.
What each vendor promises on its marketing page, set against what its own binding documents — its published privacy policy and terms of service — say, read on 31 July 2026, and — for SitSense’s privacy policy, which SitSense replaced on 13 August 2026 — on 15 August 2026. Rows are grouped by what those documents do to the promise, and the grouping is the whole of the ranking: first the one whose own published documents state something the marketing page rules out, then the one whose promise has no binding document behind it at all, then the three that say the same thing in both places. Within a group the order carries no meaning. Open a cell for the quotes and the sources they come from. The cells report what those documents say, not how any vendor behaves — and what each app can send at all is the four-way matrix that opens this section.
AppMarketing vs legal
Slouch Sniper
Slouch Sniper’s site states at a glance that the camera feed is "never recorded, stored, or uploaded", while the privacy answer further down that same page reads "never recorded, stored, or transmitted anywhere without your permission"[4]. Slouch Sniper’s terms of service list "optional images …" among the information collected, for a purpose the clause names as troubleshooting and improving the service[9]. The site’s own qualifier and the terms’ word "optional" describe a condition the headline sentence does not.
Posture Reminder AI
Posture Reminder AI’s site[5] and App Store listing[11] promise what no legal document of its own states: its privacy policy carries no camera, image, video, upload or server wording[12], and its terms of service contain no data clause[25]. That listing’s privacy label reads "Data Not Collected — The developer does not collect any data from this app.", and Apple publishes a rider with it: "This information has not been verified by Apple."[11]
SitSense
SitSense’s homepage answers the privacy question in one paragraph, and the whole answer matters: "SitSense processes all video analysis locally on your device—no video or images are ever stored or transmitted. Only numerical posture metrics are saved to help track your progress over time. … all video processing happens in your browser without external network calls."[3] Its extension page, for a product the same page marks "No account needed", states "No video or data is ever sent to any server."[3] SitSense’s privacy policy of 13 August 2026 states the same in §2.A — "No video, images, camera frames, or body landmarks ever leave your device."[18] — and covers the extension expressly in §7: "The SitSense extension runs entirely on your device. It has no account, no analytics, and it sends nothing to our servers."[37] Until that policy replaced the previous one, this guide reported the extension page as promising more than the policy, because the policy it replaced did not mention the extension at all. The homepage’s sentence about what is saved is about what the camera feed produces; what else that policy records is answered under "Usage data".
SitApp
SitApp’s site states "Your webcam feed never leaves your computer" and "No recordings, no uploads, no exceptions.", and separately describes an on-device AI model.[2] The same no-transmission promise sits in both of SitApp’s binding documents — its privacy policy[6] and its terms of service[7].
UpSensei
UpSensei’s privacy policy[33] and §2 of its terms of use[34] both state that no image, video frame or recording is transmitted, uploaded or stored — the same commitment in both binding documents, and since 31 July 2026 in the contract you agree to, not only in the policy.

What a webcam posture app can technically see

To coach your posture, an app needs a live camera stream — there is no way around that. The design question is not whether it sees you, but what leaves the device: the raw video, some derived data such as pose coordinates or metrics, or nothing at all. Those are very different privacy positions that can look identical on a marketing page.

The six questions to ask

The first five questions are answered by the vendor — the third of them by its documents rather than its marketing, which is why it is worth reading them. The sixth is the one you can answer without taking anyone’s word for it, so it is worth spending the most time on.

How to verify it yourself

For a browser-based app, you have a built-in inspector. Open your browser’s developer tools (F12, or right-click → Inspect) and select the Network tab, then let the coach run for a minute or two. Every request the page makes shows up there — its destination, its size, and its payload.

A continuous video upload cannot hide in that list. Sort by size and watch for a large, steady stream of outbound data; switch to the WS filter to see any WebSocket, click a request to read its payload. Small, periodic requests of a few kilobytes are consistent with coordinates or statistics; a fat, sustained upload is video. You are looking at the actual bytes, not a promise about them.

For a desktop app there is no inspector already in front of you — but its requests can still be read. Route its traffic through a proxy you control (mitmproxy, Charles or Fiddler) with a certificate you install so the proxy can open TLS, and you get the same list. Two caveats, and they are the whole difference. It is software to install and configure rather than a key to press; and an app may pin its certificate, which is sound security practice and also stops the proxy working, after which only patching or instrumenting the binary would produce the list — more than a buying decision should ask of anyone. Failing that, watch the machine’s overall traffic with your operating system’s firewall or a network monitor, which tells you whether data is leaving but not what it contains. That is a weaker check, and it is worth knowing the difference before you install.

What GDPR jurisdiction changes

Where an operator is based decides who it answers to. An EU operator is accountable to EU regulators, and your data-subject rights under GDPR — access, correction, deletion — are enforceable against it in your own market. That is not a claim about any one vendor’s honesty; it is about which authority you can turn to if a promise is not kept.

This is not a reason to fear vendors based elsewhere — many are careful and transparent. It is simply worth knowing which rules apply to whom. For the record: UpSensei is developed in Germany, and its data stays in the EU.

The one upload of ours worth spelling out

Our own row in the matrix says "Optional" for body measurements, and that single word is carrying a lot, so here it is in full: UpSensei Pro adds an optional Cloud mode that uploads abstract posture coordinates — never images or video — to sync sessions across devices and keep full-density replays. That is a real upload, it is off unless you turn it on, and it is the only way posture data reaches us. To see the difference for yourself, open the Network tab on a guest session: you should see the licensing call and no stream of posture data at all, which is a stronger thing to check for than "no video".

UpSensei is a wellness tool, not a medical device. The point of this guide is not that one architecture is always right — it is that you should be able to check, not just believe. Open the Network tab on any browser posture app, including ours, and confirm for yourself.

Sources

  1. UpSensei — homepage and privacy information — retrieved 2026-07-31
  2. SitApp — official website, homepage — retrieved 2026-07-31
  3. SitSense — official website, homepage and /extension page — retrieved 2026-07-31
  4. Slouch Sniper — official website, homepage — retrieved 2026-07-31
  5. Posture Reminder AI — official website, homepage — retrieved 2026-07-31
  6. SitApp — Privacy Policy, §1.3 "Webcam and Posture Data" — retrieved 2026-07-31
  7. SitApp — Terms of Service (the document’s own text calls itself "Terms of Use"), §3 "Description of Service" — retrieved 2026-07-31
  8. SitSense — Privacy Policy, §6 "Security" — retrieved 2026-08-15
  9. Slouch Sniper — Terms of Service, "Data & Privacy" section — retrieved 2026-07-31
  10. Slouch Sniper — Privacy Policy — retrieved 2026-07-31
  11. Posture Reminder AI — Apple App Store listing, "App Privacy" label — retrieved 2026-07-31
  12. Posture Reminder AI — Privacy Policy (effective 27 June 2021) — retrieved 2026-07-31
  13. SitSense — Terms & Conditions (whole document); §5 "Data & Content": "No video or images are stored; only posture metrics are saved." — retrieved 2026-07-31
  14. Posture Reminder AI — Apple App Store listing, app description — retrieved 2026-07-31
  15. SitSense — FAQ, "How does the AI feedback work?" — retrieved 2026-07-31
  16. SitApp — Privacy Policy, §4.1 "Firebase (Google)", §6.1 "Where We Store Your Data" and §6.3 "Data Retention" — retrieved 2026-07-31
  17. SitApp — "Local API & Automation" documentation, "Multi-Device Setups" — retrieved 2026-07-31
  18. SitSense — Privacy Policy, §2.A "Posture data", and the policy’s opening summary — retrieved 2026-08-15
  19. SitSense — Privacy Policy, §2.D "Usage data" — retrieved 2026-08-15
  20. SitApp — Privacy Policy, §1.1 "Information You Provide" — retrieved 2026-07-31
  21. SitApp — Terms of Service, opening paragraph and §16 "Governing Law" — retrieved 2026-07-31
  22. SitSense — Privacy Policy, §2.B "Account information" — retrieved 2026-08-15
  23. SitSense — Privacy Policy, §12 "Contact" — retrieved 2026-08-15
  24. Slouch Sniper — Terms of Service, "Accounts & Eligibility" section — retrieved 2026-07-31
  25. Posture Reminder AI — Terms of Service, whole document; the "Accounts and Access" and "Payments and Fulfilment" sections are the ones quoted here — retrieved 2026-07-31
  26. UpSensei — trust page, "Everything is hosted in the EU" — retrieved 2026-07-31
  27. UpSensei — Impressum (operator name, postal address and country) — retrieved 2026-07-31
  28. UpSensei — Privacy Policy, account and payment sections — retrieved 2026-07-31
  29. UpSensei — Privacy Policy, processor table and its footnote (AWS listed as Hanko’s sub-processor) — retrieved 2026-07-31
  30. SitApp — Terms of Service, §8 "Subscription Plans and Payment" — retrieved 2026-07-31
  31. SitSense — Privacy Policy, §9 "Your rights" — retrieved 2026-08-15
  32. Apple — Licensed Application End User License Agreement, the "Terms of Use" named by Posture Reminder AI’s Mac App Store listing — retrieved 2026-07-31
  33. UpSensei — Privacy Policy, the pose-data and Cloud-mode sections — retrieved 2026-08-01
  34. UpSensei — Terms of Use, §2 "The service" — retrieved 2026-08-01
  35. SitApp — Mac App Store listing, "App Privacy" label — retrieved 2026-07-31
  36. SitSense — Privacy Policy, §4 "Third-party services" — retrieved 2026-08-15
  37. SitSense — Privacy Policy, §7 "The browser extension" — retrieved 2026-08-15