Stepi
Stepi Privacy Policy
Effective: July 28, 2026
Stepi stores all of your data — habits, todos, notes, journal entries, and settings — locally on your device.
- No accounts. Stepi has no sign-up and no servers.
- Your content never leaves your device. Habit names, todo titles, notes, and journal entries are never collected, transmitted, sold, or shared — see “Analytics, crash reporting, and tracking” below for the limited, content-free data Stepi does collect, and how to turn it off.
- Your exports are yours. Backups and CSV exports are created only when you tap Export, and go only where you send them via the iOS share sheet.
- App lock. If you enable the app lock, your PIN is stored in the device Keychain and never leaves your device. Face ID is handled entirely by iOS; Stepi never sees biometric data.
- Notifications. Reminders are scheduled locally on your device.
Analytics, crash reporting, and tracking
Zero-content principle. Whatever Stepi sends off-device is limited to anonymous event names, counts, and buckets (for example: “a habit was checked in, current streak bucket 4–7 days”). Habit names, note and journal text, and todo titles are never included — this is enforced in code by a typed event catalog, not just policy.
Processors:
- Google Firebase (Analytics + Crashlytics) — active from Stepi’s first release. Firebase Analytics collects anonymous usage events scoped to a per-app-instance identifier (not your name, email, or account — Stepi has none). Firebase Crashlytics collects crash and diagnostic data to help us fix bugs. See Firebase’s privacy and security overview and Firebase’s Data Processing and Security Terms.
- TikTok for Business — not active in this release. Stepi’s TikTok integration is dormant until a future app update (“activation”), used solely to measure which ad campaign led to an install and whether that install went on to use the app. Once active, see TikTok for Business’s Privacy Policy for how it processes data on our behalf; this section and our App Store privacy label will be updated in the same release that activates it.
App Tracking Transparency (ATT). Once TikTok is active, iOS will ask your permission before Stepi is allowed to track you across other companies’ apps and websites for ad measurement. Stepi shows a short explanation first, then the system prompt, after your first meaningful action in the app — never during the calm intro. You can review or change your answer anytime in iOS Settings → Privacy & Security → Tracking. Declining is final — Stepi never asks again — and never limits any feature.
Turning analytics off. Settings → Analytics (default on) stops all analytics event sends — Firebase now, and TikTok once active — immediately. Crash reporting (Crashlytics) is kept separate from this toggle, since crash reports carry no usage or content data and help us keep the app reliable.
Retention. Stepi does not run its own analytics servers or retention schedule — data sent to Firebase and (once active) TikTok is retained per each processor’s own privacy policy, linked above.
Deleting the app deletes your local data (export a backup first if you want to keep it). Questions: cashcall.it@gmail.com.