Privacy Policy
Summary of the July 4, 2026 update: Stepsy now uses Mixpanel, a third-party product analytics service, to understand how the App is used so we can improve it. Section 5 describes exactly what Mixpanel receives — and what it never receives (your health data, step counts, or the identity of the apps you shield). No other changes were made to our data practices.
EFN Group LLC ("we", "our", or "us") operates the Stepsy mobile application ("Stepsy" or the "App"). This Privacy Policy explains what information Stepsy collects, how we use it, who we share it with, and the rights you have over your data. By installing or using Stepsy, you agree to this Privacy Policy.
If you have any questions about anything below, contact us at app@stepsy.fit.
01Scope and Principles
Stepsy is built around a local-first principle: the core experience — tracking your steps, earning screen time, and blocking apps on your device — works entirely on your device with no account required. Cloud features (friends, leaderboards, friend requests, nudges and cheers) are optional and only activate if you choose to sign in with your Apple ID.
If you never sign in, the data described in Section 3 ("Cloud Data") is never collected from you.
02Information We Collect — Local Only
The following data is stored only on your device, in iOS UserDefaults inside an App Group container shared between Stepsy and its extensions (widgets, the shield extensions, and the device-activity monitor). It is never transmitted to our servers unless you opt into social features (Section 3).
Health data
- Stepsy reads your daily step count from Apple HealthKit. We do not read any other HealthKit data type. We do not request write access (see your iOS Settings > Privacy & Security > Health > Stepsy at any time to revoke access).
- Step counts are used solely to calculate your earned screen time and to display your progress, weekly chart, and streak inside the App.
- We do not store or transmit raw HealthKit samples. We do not use HealthKit data for advertising or share HealthKit data with any third party for advertising or data brokerage. This is required by Apple's HealthKit guidelines and we comply with it.
Screen Time and Family Controls data
- Stepsy uses Apple's FamilyControls, ManagedSettings, and DeviceActivity frameworks to block and unblock the apps you choose. The set of apps you select is represented by opaque tokens that Apple provides to the app — we never see the underlying app names or bundle identifiers. The selection, the time you spend in those apps, and the shield state are processed locally on your device by the system frameworks. None of this information is transmitted to our servers or to any third party.
- The Screen Time selection is stored locally in your App Group container. Deleting Stepsy removes it.
Settings, preferences, and earned-time wallet
Your daily step goal, conversion rate (steps per minute), accent color, appearance mode, custom shield message, streak count, earned-minute wallet balance, and similar preferences are stored locally on your device.
Name and email (when present)
- If you provide your name during onboarding, it is stored locally on your device.
- If you sign in with Apple, your full name and email address (or Apple's private relay address) may be stored locally on your device for display in the Account section of Settings. See Section 3 for cloud storage of this information.
Notifications
Stepsy schedules local notifications (UNUserNotificationCenter) for goal reminders, streak protection, unlock celebrations, and incoming social interactions. Stepsy does not use Apple Push Notification service (APNs). No notification content is transmitted off-device.
03Information We Collect — Cloud (Social Features, Opt-In)
If you tap "Sign in with Apple" inside Stepsy to enable the Friends tab, leaderboards, friend requests, or nudges and cheers, we collect and store the following information on our backend (Supabase, see Section 5):
Account identifiers
- Your Apple-issued user identifier (a stable, opaque UUID) — required for authentication.
- Your email address as delivered by Sign in with Apple. Apple delivers either your real email address or a private relay address (e.g. abc123@privaterelay.appleid.com) depending on the choice you made when you first signed in. We use it only to identify your account and to display it in the Account section of Settings. We do not send marketing email, and we never sell your email or share it with third parties for their own use; it is processed only by the service providers listed in Section 5 (Supabase for authentication and storage, Mixpanel for analytics) acting on our behalf.
- Your full name as delivered by Sign in with Apple on your first sign-in. Used to seed your initial display name. Apple only delivers name once, on the first sign-in.
Profile data
- Your display name (initially seeded from Apple, then editable by you in Settings).
- A unique friend code in the format STP-XXXXXX, generated when your profile is created, so other users can add you as a friend.
- Your avatar emoji and accent color preference.
- Your subscription tier (free or Pro) — synced from your in-app subscription state.
Activity data (synced from your device approximately every 15 minutes while the App is in the foreground)
- Your daily step count total (an integer number — never raw HealthKit samples).
- Your current step goal.
- Your current streak length.
- A daily summary record per calendar day containing: the date, total steps, whether you met your goal, and earned minutes. This powers the weekly leaderboard.
Social data
- Your friendships (the list of users you have accepted as friends).
- Pending friend requests sent to or from you.
- Nudges and cheers exchanged with friends, including a timestamp and (for cheers) an optional pre-defined message.
What we DO NOT collect to the cloud, even when you are signed in
- Your raw HealthKit samples.
- The names or identifiers of apps you have shielded.
- The amount of time you spend in any specific app.
- Your earned-minute wallet balance.
- Your location, contacts, calendar, photos, microphone, or camera (Stepsy never asks for these permissions).
- Free-form messages between users (cheers and nudges use pre-defined templates only — there is no chat).
You can use the entire core experience of Stepsy — step tracking, app shielding, streaks, widgets, notifications, the paywall — without ever signing in. If you do not sign in, none of the data in this Section 3 is collected.
04Subscription Data
If you subscribe to Stepsy Pro, your purchase is processed by Apple through the App Store. Apple does not share your name, email address, or payment information with us.
We use RevenueCat to verify your subscription state and to keep it consistent across your Apple devices. When you sign in with Apple, we send your Supabase user identifier to RevenueCat so it can associate your subscription with your account. RevenueCat additionally collects, automatically through its SDK, technical information including:
- An anonymous device identifier (IDFV) and the App User ID we provide
- Your country, your iOS and app version, and your device model
- Subscription and purchase events (such as purchase, renewal, refund, or cancellation)
RevenueCat acts as a data processor on our behalf for the purpose of subscription management and fraud prevention. RevenueCat's privacy policy is available at revenuecat.com/privacy.
We never receive or store your credit card number, billing address, or other payment information. All billing is handled by Apple.
05Third Parties That Process Your Data
We share information only with the third parties listed below, only as necessary to operate the features you use. We do not sell, rent, or trade your personal information.
- Apple — Sign in with Apple, HealthKit, FamilyControls, DeviceActivity, ManagedSettings, App Store. Apple Push Notification service is NOT used. Apple's privacy policy: apple.com/legal/privacy
- Supabase, Inc. — Provides our backend authentication, PostgreSQL database, and row-level security infrastructure for the social features described in Section 3. Supabase processes only the data listed in Section 3 and only when you have signed in. Supabase is hosted in the United States. Privacy: supabase.com/privacy
- RevenueCat, Inc. — Manages in-app subscriptions and entitlements as described in Section 4. Privacy: revenuecat.com/privacy
- Mixpanel, Inc. — Provides product analytics that help us understand how Stepsy is used so we can improve it. Mixpanel acts as a data processor on our behalf and is hosted in the United States. Privacy: mixpanel.com/legal/privacy-policy
What Mixpanel receives
- Usage events describing actions taken inside the App — for example completing an onboarding step, viewing the paywall, subscribing, meeting your daily goal, unlocking an achievement, or sending a friend request or cheer. These events happen whether or not you are signed in.
- Your current streak length (a count of consecutive days, attached to the goal-met event).
- If you sign in with Apple: your account identifier (the same UUID used by Supabase) and your email address (or Apple private relay address), used to associate your usage events with your account.
- Technical information collected automatically by the Mixpanel SDK: an anonymous per-vendor device identifier (IDFV), device model, iOS and app version, language, and country.
What Mixpanel NEVER receives
- Your step counts or any other value read from HealthKit or the motion sensors.
- The identity of the apps you have shielded or the time you spend in them.
- Your display name, friend code, friends list, or the content of nudges and cheers.
- The advertising identifier (IDFA) — Stepsy does not request it and does not track you across other companies' apps or websites.
We do not use any advertising, attribution, or marketing SDKs. If we add or change an analytics provider in the future, we will update this Privacy Policy and disclose the provider, the categories of events tracked, and the identifiers shared.
06How We Use Your Information
We use the information described above for the following purposes:
- To operate the core walk-to-earn loop on your device (calculating earned screen time, applying and removing shields, displaying progress, sending local notifications).
- To authenticate your account when you sign in with Apple.
- To power the social features (display the friends list, leaderboards, and friend requests; deliver nudges and cheers).
- To verify and synchronize your Stepsy Pro subscription across your devices via RevenueCat.
- To understand how Stepsy is used in aggregate (which features are used, where onboarding is abandoned, how the paywall performs) via the product analytics described in Section 5, so we can improve the App.
- To diagnose and fix bugs based on logs that remain on your device, unless you choose to email us a description of an issue.
- To comply with our legal obligations and to enforce our Terms of Service.
We do not use your information for advertising. We do not profile you for behavioral advertising. We do not sell your information.
Legal bases under GDPR (for users in the European Economic Area, the United Kingdom, and Switzerland): we process your data on the basis of (a) your consent (HealthKit access, Sign in with Apple, social features), (b) the performance of a contract you have entered into by accepting our Terms (subscription management), and (c) our legitimate interests in operating and improving the App, where those interests are not overridden by your rights.
07International Data Transfers
EFN Group LLC is based in the United States. Our backend infrastructure (Supabase), our subscription processor (RevenueCat), and our analytics provider (Mixpanel) are also located in the United States. If you use Stepsy from outside the United States, including from the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred to and processed in the United States. By using Stepsy and enabling cloud features, you consent to this transfer.
08Data Retention
Local data persists on your device until you delete the App, reset its data through iOS Settings, or sign out of your account.
Cloud data persists on our backend until you delete your account. When you delete your account from inside the App (Settings > Account > Delete Account), we permanently delete the following within 30 days: your profile, friend code, friendships, pending friend requests, daily statistics, and all nudges and cheers you have sent or received. Your record in Supabase auth.users is also deleted, which revokes your authentication tokens and removes your email and Apple identifier from our systems.
We retain transactional records related to your subscription (purchase events) only for as long as required by Apple, RevenueCat, and applicable accounting and tax law.
If you only sign out without deleting your account, your cloud data remains until you sign back in or delete your account. Deleting Stepsy from your device alone does not automatically delete your cloud data.
09Your Rights
You have the following rights regarding your personal information:
- Access — You can see your current cloud profile inside the App at any time on the Friends tab and in the Account section of Settings.
- Correction — You can edit your display name in the Account section of Settings. To correct any other personal information, contact us at app@stepsy.fit.
- Deletion — You can delete your account and all associated cloud data from inside the App at Settings > Account > Delete Account. If for any reason you cannot use the in-app option, you may also email us at app@stepsy.fit and we will delete your data within 30 days.
- Portability — On request, we will provide you with a machine-readable copy of the cloud data we hold about you. Email app@stepsy.fit with the subject "Data Export Request".
- Withdrawal of consent — You can disable HealthKit access at any time in iOS Settings > Privacy & Security > Health > Stepsy. You can disable Family Controls authorization at any time in iOS Settings > Screen Time. You can sign out at any time from Settings inside the App. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us at app@stepsy.fit. We will respond within 30 days. We will not discriminate against you for exercising any of these rights.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with your local data protection supervisory authority.
If you are a California resident, you have additional rights under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"). These include the right to know what categories of personal information we collect, the right to delete the personal information we hold about you, the right to correct inaccurate information, and the right to limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising. We have not done so in the preceding 12 months and have no plans to do so.
To cancel your subscription, manage it through your Apple ID account settings on your device. Cancellation cannot be processed by us.
10Security
We use industry-standard practices to protect your data:
- All cloud data is transmitted over HTTPS (TLS 1.2 or higher).
- Cloud data at rest is protected by Supabase's PostgreSQL encryption and access controls.
- Access to social data is restricted by row-level security policies so that you can only read or modify your own records and the limited profile fields your friends have chosen to share.
- API secrets are injected at build time from a private configuration file and are never committed to source control.
No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security breach affecting your information, we will notify you and the relevant authorities as required by applicable law.
11Children's Privacy
Stepsy is not directed at children under the age of 13 and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and you believe a child under 13 has provided us with personal information, please contact us at app@stepsy.fit and we will delete it.
Stepsy's social features (friend requests, leaderboards, nudges and cheers) are intended for users aged 17 and over. Younger teenagers may use the core walk-to-earn experience but should not enable cloud-backed social features without parental supervision.
12Do Not Track
Stepsy is a native iOS application. We do not use cookies and we do not track your activity across other apps or websites. Stepsy does not integrate with the App Tracking Transparency framework because we do not track you. Some browsers transmit a "Do Not Track" signal — this signal does not apply to native iOS apps.
13Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated Privacy Policy at stepsy.fit/privacy-policy and updating the "Last updated" date above. Changes that expand the categories of data we collect will be highlighted at the top of the policy for at least 30 days. Your continued use of Stepsy after the updated policy takes effect constitutes acceptance of the updated policy.
14Contact Us
If you have questions about this Privacy Policy, want to exercise your privacy rights, or want to request account deletion, contact us at:
EFN Group LLC
Email: app@stepsy.fit
Website: stepsy.fit