StepMates
← stepmates home

StepMates Privacy Policy

Effective date: June 10, 2026  ·  Last updated: June 10, 2026

StepMates ("the App") is operated by SH Software, a sole proprietorship (enkeltmandsvirksomhed) registered in Denmark ("we", "us"). We are the data controller for the personal data described in this policy.

Contact: ibrahim@shsoftwaresol.com

StepMates is a step-counting app for two partners. Steps sync automatically from your phone's health app; whoever walks less does one small, free household kindness. We built it to collect as little data as possible, and we never sell data or show ads.

1. The short version

2. What we collect and why

DataSourceWhy (purpose)Lawful basis (GDPR)
Anonymous account IDCreated automatically (Supabase Auth)To operate your account and pairingArt. 6(1)(b) — contract
Display name (the first name you type)YouShown to your partnerArt. 6(1)(b) — contract
Profile photo (optional)YouShown to your partnerArt. 6(1)(a) — consent
Daily step totals (date, total, source)Read-only from Apple Health / Health Connect, with your OS-level permissionComparing steps between the two of youArt. 6(1)(a) and Art. 9(2)(a) — your explicit consent
Couple pairing data (invite code, membership)YouConnecting you and your partnerArt. 6(1)(b) — contract
Daily kindness status (open / completed / forgiven), task choice, reroll requestsYouThe core featureArt. 6(1)(b) — contract
Short nudge messages (max 60 characters)YouSending an encouragement to your partnerArt. 6(1)(b) — contract
Purchase records — Skip Pass / Point Boost / Premium (date, store transaction id)Apple App Store / Google PlayApplying the skip or boost; support and refund lookupsArt. 6(1)(b) — contract

Stored only on your device (never sent to us): your onboarding/consent flags and local notification schedule (the evening reminder).

We do not collect: email, phone number, contacts, precise location, GPS routes, heart rate, workouts, or any health data other than the daily step total. We do not use tracking or analytics SDKs in this version of the App.

Purchases: the optional Skip Pass, Point Boost and Premium unlock are processed entirely by Apple or Google as merchant of record — we never see your card or bank details. We store only the store's transaction id, the date, and your anonymous account id, and we show your partner that a pass was used (that visibility is part of the feature). Purchase records are deleted with your account.

3. Health data — special protections

Step counts are treated as health-related data. We:

This follows Apple's App Store Guideline 5.1.3 and Google Play's Health Connect permissions policy.

4. A note on profile photos

Profile photos are optional. They are stored in a storage bucket addressed by a long, unguessable URL. The App only ever shows your photo to your paired partner, but anyone who obtained the exact URL could view the image, so please don't upload a photo you wouldn't want seen. You can replace it anytime, and it is deleted with your account.

5. Who can see your data

Only you and your one paired partner. This is enforced server-side with PostgreSQL Row Level Security — another user (or anyone without your couple's keys) cannot read or write your couple's rows. There are no public profiles, feeds, or leaderboards. The "Share our week" feature only shares text you explicitly choose to send through your phone's share sheet.

6. Processors (who stores it for us)

We use Supabase (database, authentication, storage, realtime) as our processor, hosted in the European Union. Supabase's infrastructure provider is Amazon Web Services (EU region). We have accepted Supabase's Data Processing Addendum. We do not use any other processor for your personal data, and we have no access to your data beyond what is needed to run and support the App.

7. International transfers

Your data is stored and processed in the EU/EEA. We do not transfer it to third countries.

8. Retention and deletion

9. Your rights (GDPR / UK GDPR)

You have the right to access, rectify, erase, restrict, object to processing of, and port your personal data, and to withdraw consent at any time (withdrawing consent doesn't affect prior lawful processing). To exercise any right, use the in-app controls or email ibrahim@shsoftwaresol.com. Because accounts are anonymous, we may ask you to make the request from inside the App (or provide your invite code/account ID) so we can locate your data.

You can complain to a supervisory authority — in Denmark, Datatilsynet (www.datatilsynet.dk), or your local EU authority, or the UK ICO (ico.org.uk).

10. California (CCPA/CPRA) and other US state rights

We do not sell or share personal information, and we do not use it for cross-context behavioral advertising. California residents (and residents of other US states with similar laws) have rights to know, delete, correct, and to non-discrimination. Use the in-app deletion or email us to exercise them. We do not collect data categories that would require an opt-out.

11. Age limit

StepMates is for adults — you must be 18 or older. We do not knowingly collect data from anyone under 18; if we learn we have, we will delete it. The App includes an age confirmation at sign-up.

12. Security

Row Level Security on every table, TLS in transit, encryption at rest (via our processor), least-privilege keys (the App ships only a publishable client key; administrative keys are kept server-side only), and account deletion that removes data at the source.

13. Data breaches

If a breach is likely to put your rights at risk, we will notify the supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33) and inform affected users without undue delay (Art. 34), including in-app or via our website.

14. Changes to this policy

We'll post any changes here with a new "Last updated" date, and for material changes we'll tell you in the App before they take effect.

15. Contact

SH Software (enkeltmandsvirksomhed, Denmark)
Email: ibrahim@shsoftwaresol.com