Privacy Policy
Last updated August 4, 2026
Steppy is built around a simple rule: your Apple Health data stays under your control. Steppy never sells your information, serves targeted ads, or uses your data to track you across apps.
Information Steppy uses
- Apple Health step count, with read-only permission you can revoke in Settings.
- Your first name, friend code, optional profile picture or emoji avatar, and Steppy friend relationships.
- Derived step totals, weekly average, goal, lifetime total, time zone, and update timestamps when step sharing is enabled.
- Friend requests, blocked-profile IDs, nudge delivery status, and fixed-category safety reports needed for social features and abuse prevention.
Apple Health
Steppy reads step count only after you approve Apple Health access. Raw HealthKit samples are not uploaded. Your phone calculates step totals, and only derived totals are shared with Firebase when step sharing is enabled. Steppy does not use HealthKit data for advertising, data brokerage, or medical decisions.
Friends and leaderboards
Accepted friends can see your shared step summary and shared daily totals. The authenticated Global Top 5 can show your first name, avatar, friend code, current-day total, and freshness information. Turning step sharing off clears current shared totals and prevents friends and global leaderboard readers from accessing shared history under Steppy’s database rules.
Storage and processors
Steppy uses Firebase Authentication and Cloud Firestore, services provided by Google, for accounts, profiles, friends, and leaderboards. Widget snapshots, app preferences, and pending sync data are stored locally in Steppy’s App Group container. This version records MetricKit crash and hang counts only in the device’s local system log.
Retention and deletion
Shared data is retained while your Steppy social profile exists. You can choose Delete Account and Cloud Data in Steppy Settings. Steppy immediately stops new uploads and removes your profile, friend code, friendships, requests, nudges, shared daily totals, and leaderboard entries. It then deletes the anonymous Firebase sign-in record. If Firebase requires a recent credential that an anonymous account cannot provide, the empty sign-in record is queued for administrator deletion and processed within 30 days.
Your choices
You can disable step sharing in Steppy, revoke Apple Health or camera access in iOS Settings, remove or block profiles, report inappropriate public profile content, change your profile, or delete your account in the app. Deleting Steppy data does not delete records stored by Apple Health. Safety reports may be retained as needed to investigate abuse and protect users.
Children
Steppy is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes and questions
This policy may be updated when Steppy’s features or providers change. The revision date above will identify the current version. For help or privacy questions, visit the Steppy Support page.