StepMates Privacy Policy
Effective date: June 10, 2026 · Last updated: June 10, 2026
StepMates ("the App") is operated by SH Software, a sole proprietorship (enkeltmandsvirksomhed) registered in Denmark ("we", "us"). We are the data controller for the personal data described in this policy.
Contact: ibrahim@shsoftwaresol.com
StepMates is a step-counting app for two partners. Steps sync automatically from your phone's health app; whoever walks less does one small, free household kindness. We built it to collect as little data as possible, and we never sell data or show ads.
1. The short version
- We use anonymous accounts — no email, password, phone number, or real name required.
- We read your daily step total only (read-only) from Apple Health or Android Health Connect, with your permission.
- Your data is visible only to you and your paired partner, enforced by database-level security (Row Level Security).
- Everything is stored in the EU (Supabase, EU region). We do not transfer your data outside the EU/EEA.
- No ads, no analytics, no data sale, no sharing of health data with anyone — ever.
- You can delete your account and all your data from inside the app (Settings → Delete my account & data), or by emailing us.
2. What we collect and why
| Data | Source | Why (purpose) | Lawful basis (GDPR) |
|---|---|---|---|
| Anonymous account ID | Created automatically (Supabase Auth) | To operate your account and pairing | Art. 6(1)(b) — contract |
| Display name (the first name you type) | You | Shown to your partner | Art. 6(1)(b) — contract |
| Profile photo (optional) | You | Shown to your partner | Art. 6(1)(a) — consent |
| Daily step totals (date, total, source) | Read-only from Apple Health / Health Connect, with your OS-level permission | Comparing steps between the two of you | Art. 6(1)(a) and Art. 9(2)(a) — your explicit consent |
| Couple pairing data (invite code, membership) | You | Connecting you and your partner | Art. 6(1)(b) — contract |
| Daily kindness status (open / completed / forgiven), task choice, reroll requests | You | The core feature | Art. 6(1)(b) — contract |
| Short nudge messages (max 60 characters) | You | Sending an encouragement to your partner | Art. 6(1)(b) — contract |
| Purchase records — Skip Pass / Point Boost / Premium (date, store transaction id) | Apple App Store / Google Play | Applying the skip or boost; support and refund lookups | Art. 6(1)(b) — contract |
Stored only on your device (never sent to us): your onboarding/consent flags and local notification schedule (the evening reminder).
We do not collect: email, phone number, contacts, precise location, GPS routes, heart rate, workouts, or any health data other than the daily step total. We do not use tracking or analytics SDKs in this version of the App.
Purchases: the optional Skip Pass, Point Boost and Premium unlock are processed entirely by Apple or Google as merchant of record — we never see your card or bank details. We store only the store's transaction id, the date, and your anonymous account id, and we show your partner that a pass was used (that visibility is part of the feature). Purchase records are deleted with your account.
3. Health data — special protections
Step counts are treated as health-related data. We:
- read only the daily step total, read-only — the App never writes to Apple Health or Health Connect;
- ask for your explicit consent in the App before requesting OS permission;
- never use health data for advertising, marketing, or "use-based data mining";
- never disclose health data to third parties or brokers — it is visible only to you and your one paired partner;
- do not store health data in iCloud.
This follows Apple's App Store Guideline 5.1.3 and Google Play's Health Connect permissions policy.
4. A note on profile photos
Profile photos are optional. They are stored in a storage bucket addressed by a long, unguessable URL. The App only ever shows your photo to your paired partner, but anyone who obtained the exact URL could view the image, so please don't upload a photo you wouldn't want seen. You can replace it anytime, and it is deleted with your account.
5. Who can see your data
Only you and your one paired partner. This is enforced server-side with PostgreSQL Row Level Security — another user (or anyone without your couple's keys) cannot read or write your couple's rows. There are no public profiles, feeds, or leaderboards. The "Share our week" feature only shares text you explicitly choose to send through your phone's share sheet.
6. Processors (who stores it for us)
We use Supabase (database, authentication, storage, realtime) as our processor, hosted in the European Union. Supabase's infrastructure provider is Amazon Web Services (EU region). We have accepted Supabase's Data Processing Addendum. We do not use any other processor for your personal data, and we have no access to your data beyond what is needed to run and support the App.
7. International transfers
Your data is stored and processed in the EU/EEA. We do not transfer it to third countries.
8. Retention and deletion
- Your data is kept while your account exists.
- Delete in-app: Settings → Delete my account & data removes your profile, step history, couple membership, nudges, your photo, and your account itself. Because couple data is shared, deleting your account also dissolves the couple and deletes the shared records (forfeits, nudges, the pairing); your partner's own account and their step history remain theirs.
- Delete by request: email ibrahim@shsoftwaresol.com, or use the deletion page on our website, and we will delete your data within 30 days.
- Backups are rotated automatically by our processor and expire within ~30 days.
9. Your rights (GDPR / UK GDPR)
You have the right to access, rectify, erase, restrict, object to processing of, and port your personal data, and to withdraw consent at any time (withdrawing consent doesn't affect prior lawful processing). To exercise any right, use the in-app controls or email ibrahim@shsoftwaresol.com. Because accounts are anonymous, we may ask you to make the request from inside the App (or provide your invite code/account ID) so we can locate your data.
You can complain to a supervisory authority — in Denmark, Datatilsynet (www.datatilsynet.dk), or your local EU authority, or the UK ICO (ico.org.uk).
10. California (CCPA/CPRA) and other US state rights
We do not sell or share personal information, and we do not use it for cross-context behavioral advertising. California residents (and residents of other US states with similar laws) have rights to know, delete, correct, and to non-discrimination. Use the in-app deletion or email us to exercise them. We do not collect data categories that would require an opt-out.
11. Age limit
StepMates is for adults — you must be 18 or older. We do not knowingly collect data from anyone under 18; if we learn we have, we will delete it. The App includes an age confirmation at sign-up.
12. Security
Row Level Security on every table, TLS in transit, encryption at rest (via our processor), least-privilege keys (the App ships only a publishable client key; administrative keys are kept server-side only), and account deletion that removes data at the source.
13. Data breaches
If a breach is likely to put your rights at risk, we will notify the supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33) and inform affected users without undue delay (Art. 34), including in-app or via our website.
14. Changes to this policy
We'll post any changes here with a new "Last updated" date, and for material changes we'll tell you in the App before they take effect.
15. Contact
SH Software (enkeltmandsvirksomhed, Denmark)
Email: ibrahim@shsoftwaresol.com