Privacy Policy

Effective Date: July 6, 2026 | Last Updated: July 6, 2026

1. General Provisions & Data Controller Identity

This Privacy Policy governs the processing of personal data within the StepMe mobile application and the official website (stepme.app), hereinafter referred to collectively as the "Service" or "Application".

The Data Controller of your personal data is MS Digits Spółka z Ograniczoną Odpowiedzialnością (alternatively abbreviated as MS Digits Sp. z o.o.), with its registered office in Poland (hereinafter referred to as "we", "us", "our", or the "Controller"). Users can communicate with the Controller regarding data isolation and security questions through the following endpoints:

2. Legal Basis and Scope of Data Processing

We process personal data in strict compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") as well as applicable Polish data protection enactments. Data processing loops are limited to the following categories:

A. Native Health and Fitness Subsystems (Strict Isolation)

B. Personally Identifiable Information (PII) & Authentication

C. Financial Transactions & Economy Audit Trails

D. System Integrity & Anti-Cheat Telemetry

E. Diagnostic Architecture Logs

3. Third-Party Service Providers (Subprocessors)

To deliver a highly responsive, stable mobile fitness network, the Service transfers specific personal data profiles (excluding health metrics) to external technical processors. These services act under strict compliance with GDPR requirements, governed by Standard Contractual Clauses (SCCs):

4. Data Retention Frameworks

The Controller preserves your personal metrics solely for the duration required to satisfy operational or legal mandates:

5. Your Rights Under GDPR

As a data subject located within the European Economic Area (EEA), you retain comprehensive protections under GDPR rules:

6. User-Controlled Account & Data Erasure Protocol

In accordance with platform requirements and privacy principles, you can self-initiate complete data destruction from within the interface at any time.

Deletion Process: Navigate inside the app to: Profile -> Account Settings -> Delete Account.

Consequences of Action: Upon activation, your account profile, your unique Firebase Auth authentication mappings, all compiled historical step metrics, and your accumulated balance of Sparks are immediately and irreversibly purged from our live database records. Offline architectural data backups automatically turn over and completely eliminate this information within a maximum frame of 30 days. Required accounting records are kept independently to fulfill legal tax requirements.

7. Children's Privacy Shield

The Service is explicitly not intended for, marketed to, or structured to attract minor children under the chronological age of 13. We do not deliberately retain information from individuals below this threshold. If you are a parent or guardian and become aware that a child has bypassed checks and registered an account, notify us at support@stepme.app. We will purge the associated data arrays instantly.

8. Document Alterations

We reserve the right to revise this Privacy Policy to align with new application capabilities or changing international laws. We will notify you of text updates by updating the live text on this portal, posting an alert in the application dashboard, or dispatching a system notification push event.