Privacy Policy
1. General Provisions & Data Controller Identity
This Privacy Policy governs the processing of personal data within the StepMe mobile application and the official website (stepme.app), hereinafter referred to collectively as the "Service" or "Application".
The Data Controller of your personal data is MS Digits Spółka z Ograniczoną Odpowiedzialnością (alternatively abbreviated as MS Digits Sp. z o.o.), with its registered office in Poland (hereinafter referred to as "we", "us", "our", or the "Controller"). Users can communicate with the Controller regarding data isolation and security questions through the following endpoints:
2. Legal Basis and Scope of Data Processing
We process personal data in strict compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") as well as applicable Polish data protection enactments. Data processing loops are limited to the following categories:
A. Native Health and Fitness Subsystems (Strict Isolation)
- Data Fields Collected: Native steps taken, estimated distance metrics, active metabolic burn, and activity timestamps.
- Source Elements: Apple HealthKit (on iOS devices) and Google Health Connect (on Android devices).
- Legal Basis: Explicit user consent (Art. 6(1)(a) GDPR).
- Protection Guarantee: Fitness metrics are used strictly within the Service to populate competitive public leaderboards, evaluate insights, track daily milestones, and calculate virtual tier awards. Under no circumstances is health or fitness data shared, bundled, or sold to marketing platforms, third-party data brokers, or advertising networks.
B. Personally Identifiable Information (PII) & Authentication
- Data Fields Collected: User name, account avatar image, email address, unique registration keys, and localized identifiers.
- Source Elements: Collected and parsed securely via our authentication partners, including Firebase Authentication and Facebook Authentication platforms.
- Legal Basis: Performance of a contract to which the user is party (Art. 6(1)(b) GDPR).
C. Financial Transactions & Economy Audit Trails
- Data Fields Collected: Subscription tier active state logs (StepMe Pro), transactional receipt token strings, histories of in-app consumable microtransactions, and current balances or transactional records for Sparks (our virtual rewards token).
- Legal Basis: Performance of a contract (Art. 6(1)(b) GDPR) and fulfillment of corporate accounting obligations under Polish tax law (Art. 6(1)(c) GDPR).
D. System Integrity & Anti-Cheat Telemetry
- Data Fields Collected: Step sequence logs, packet synchronization timestamps, device integrity attestation flags, and hardware-derived validation events. Please note: The Service does not collect, track, or record your physical GPS location data.
- Legal Basis: Legitimate interest of the Controller (Art. 6(1)(f) GDPR) to eliminate fair-play violations, protect the platform economy, and prevent leaderboard exploitation.
E. Diagnostic Architecture Logs
- Data Fields Collected: Masked IP logs, device hardware configurations, operating system release versions, app state tracking metrics, and raw diagnostic crash reports.
- Legal Basis: Legitimate interest of the Controller (Art. 6(1)(f) GDPR) to isolate system errors, guarantee application stability, and safeguard backend availability.
3. Third-Party Service Providers (Subprocessors)
To deliver a highly responsive, stable mobile fitness network, the Service transfers specific personal data profiles (excluding health metrics) to external technical processors. These services act under strict compliance with GDPR requirements, governed by Standard Contractual Clauses (SCCs):
- Google Cloud & Firebase Infrastructure: Used to manage secure data pipelines, user databases, app state remote variables, and system chronologies. Detailed data handling terms are governed by the Google Firebase Data Processing Terms.
- Google Analytics & Firebase Analytics Services: Used to compute structural application parameters, usage demographics, and interactive app flows. Regulated under the Google Analytics for Firebase Terms.
- Firebase Crashlytics Diagnostics: Handles real-time system failure parsing. Regulated under the Firebase Crashlytics Terms.
- Google AdMob Monetization: Used to serve advertisements to tiers utilizing the free version of the Application. AdMob evaluates non-sensitive device telemetry to contextually focus promotional items. Regulated under the AdMob Privacy Guide.
- Apple Media Services & Google Play Commerce: Used to clear, authorize, and track transactional subscriptions and microtransactions. Regulated under the Apple Privacy Policy and Google Privacy Policy respectively.
4. Data Retention Frameworks
The Controller preserves your personal metrics solely for the duration required to satisfy operational or legal mandates:
- Operational profile logs, step tracking balances, leaderboard states, and Sparks records remain active until you trigger account closure.
- Anonymized system diagnostic data or Crashlytics logs are overwritten routinely on short-term technical lifecycles.
- Financial receipts and ledger information are retained for extended statutory archiving periods required under Polish tax and accounting regulations.
5. Your Rights Under GDPR
As a data subject located within the European Economic Area (EEA), you retain comprehensive protections under GDPR rules:
- Right of Access & Rectification: The right to demand a clear copy of your records or correct erroneous entries.
- Right to Erasure & Portability: The right to request absolute profile removal, or download your data in a structured, electronic format.
- Right to Object & Restrict: The right to halt metrics evaluation driven by direct marketing loops or legitimate interests.
- Right to File a Complaint: The right to register formal claims with an official data authority. In Poland, the competent body is the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych - UODO), located at ul. Stawki 2, 00-193 Warsaw.
6. User-Controlled Account & Data Erasure Protocol
In accordance with platform requirements and privacy principles, you can self-initiate complete data destruction from within the interface at any time.
Deletion Process: Navigate inside the app to: Profile -> Account Settings -> Delete Account.
Consequences of Action: Upon activation, your account profile, your unique Firebase Auth authentication mappings, all compiled historical step metrics, and your accumulated balance of Sparks are immediately and irreversibly purged from our live database records. Offline architectural data backups automatically turn over and completely eliminate this information within a maximum frame of 30 days. Required accounting records are kept independently to fulfill legal tax requirements.
7. Children's Privacy Shield
The Service is explicitly not intended for, marketed to, or structured to attract minor children under the chronological age of 13. We do not deliberately retain information from individuals below this threshold. If you are a parent or guardian and become aware that a child has bypassed checks and registered an account, notify us at support@stepme.app. We will purge the associated data arrays instantly.
8. Document Alterations
We reserve the right to revise this Privacy Policy to align with new application capabilities or changing international laws. We will notify you of text updates by updating the live text on this portal, posting an alert in the application dashboard, or dispatching a system notification push event.