Legal

StepsApp Privacy Policy

Version 1.5 Last updated: 2026-03-02

This Privacy Policy explains how StepsApp GmbH handles personal data in accordance with the General Data Protection Regulation (EU 2016/679) (GDPR) and applicable national data protection laws.

1. Who We Are

Company: StepsApp GmbH

Address: Schuberstraße 6a, 8010 Graz, Austria

Email: [email protected]

Website: https://steps.app

Support: /fr/support/pedometer/ios

We are the controller responsible for your personal data when you use our apps and services.

2. What Data We Process

We process the categories of personal data set out below. What we process depends on which features you use and your settings.

Data Category Examples
Step dataSteps, distance, goals, basic profile attributes used for step calculations (age, sex, height)
Extended health dataWeight, activity time, heartrate, sleep, menstrual cycle data & symptoms
Workout dataExercise details (type, duration, calories burned, intensity)
Nutrition dataNutrition details (consumed kcal/food intake)
Device and app infoDevice model, operating system, app version, locale, time zone, language
IdentifiersApple Identifier for Vendors (IDFV), Installation ID, Apple Identifier for Advertisers (IDFA) (where enabled)
Profile infoUsername, avatar (auto-generated or user-uploaded), social links
CommunicationsMessages, group details, media content shared in community features
Purchase dataAnonymized receipts, subscription status, purchase history necessary to manage purchases
Usage dataCrash reports, screen views, user interactions, timestamps
Notification contentNotification payloads, debug logs (encrypted)
Contact dataEmail address (account identification, newsletter)

3. Why We Process Your Data

We process your data for the purposes below. We thereby rely on the legal bases identified for each purpose.

Purpose Data Categories Description Legal Basis Is Data Provision Required?
Core app functionalityStep data; device and app info; profile infoEnabling step tracking, activity goals, user profile featuresPerformance of a contractRequired to use the app. Without this data, the core features of the app cannot function properly.
Optional health insightsExtended health data; workout data; nutrition dataProvide broader fitness/health insights by combining activity and health metricsPerformance of a contract; consent where legally requiredOptional. If provided, you receive more detailed insights about your overall fitness/health.
User communications and social interactionProfile info; communicationsEnable user-to-user interactions and community moderationPerformance of a contract; legitimate interest (Enable social interactions)Optional. Not providing data means chat or group features won't work.
Analytics & error reportingUsage data; device and app infoUnderstand usage patterns, detect crashes, improve app performanceLegitimate interest (Improve app reliability)Optional. You can disable this in the app. If not provided, our ability to fix bugs may be reduced.
NotificationsNotification content; contact dataSending reminders, motivational messagesLegitimate interest (Improve user engagement)Optional. You can disable notifications. Without this data, you won't receive updates or reminders.
AdvertisingIdentifiersServing personalized and non-personalized adsLegitimate interest (Provide targeted advertising)Optional. You can disable personalized advertising. Ads may still be shown but will be less relevant.
PurchasesPurchase dataProcessing in-app purchases and subscriptionsPerformance of a contractRequired for purchases. Without this data, purchases and subscriptions cannot be processed.
Community featuresStep data; profile infoProviding leaderboards, challenges and rankingsPerformance of a contractOptional. If you don't provide data, you can't take part in community rankings or challenges.
NewsletterContact dataSending you marketing emails if you opt inConsentOptional. You can use the app without subscribing to the newsletter.
Account identification & supportContact dataIdentifying your account for login, support cases, and account managementPerformance of a contractRequired if you create an account. Optional for account creation if using Apple Sign-In with Hide My Email.

4. With Whom We Share Your Data

We share your date with the following categories of recipients. If your data is processed by our service providers (processors), we ensure that they only process your data within the scope of our instructions and for the respective purposes stated above.

Some recipients are located outside the European Economic Area (EEA), including in the United States. Where we transfer your data internationally, we use legally required safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, participation in the EU-US Data Privacy Framework.

For more detailed information on this, or to obtain a copy of the standard contractual clauses agreed with the recipients, please contact us using the contact details in point 1 above.

5. How Long We Keep Your Data

Data Category Retention Period
Step data3 years after last step sync
Workout data3 years after last sync
Nutrition data3 years after last sync
Extended health data3 years after last sync
Device and app info[Please add]
IdentifiersUntil disabled or account deleted
Profile info3 years after last sync
Communications3 years after last sync
Purchase data7 years after account closure
Usage dataRaw: 15 days; Aggregated: 3 years
Notification content15 days
Contact data (Newsletter email)Until you withdraw your consent or account deletion
Contact data (Account email)30 days after account deletion

6. Your Rights

You have the following rights under GDPR:

To exercise your rights, contact us at [email protected] or via in-app settings.

7. Profiling & Automated processing

In accordance with Art. 22 GDPR, we do not use automated decision-making to make decisions about the establishment and implementation of a business relationship with you. No profiling is carried out when using our services.

We may use your data to:

These features are part of our service and do not involve automated decisions with legal or similar effects.

You may disable:

8. Is Providing Personal Data Required?

Some data (e.g., steps, goals, and purchases) is required by contract. Without it, we cannot offer our core services.

Other data (e.g., chat features, analytics, advertising preferences) is voluntary, and you may disable or avoid providing it without any legal or contractual consequences. However, not providing it may limit certain features or result in less optimized performance.

If you have questions about what is required vs optional, contact us at [email protected].

9. Contact Information

We do not currently appoint a Data Protection Officer, as not legally required.

For any privacy concerns or questions, contact:

StepsApp GmbH

Email: [email protected]

Website: https://steps.app

10. Website & Cookies

This section applies to visits to our websites (for example, steps.app and related pages).

10.1 Why we use cookies and similar technologies

Cookies are small text files stored by your browser. We may also use similar technologies such as local storage or SDK-based identifiers where relevant.

10.2 Analytics tools

For website analytics, we may use providers such as Google Analytics to evaluate site usage, compile aggregate reports, and improve our services. Where configured, IP anonymization is applied before further processing.

Google may process data outside the EEA. Where required, transfers are protected using appropriate safeguards such as the Standard Contractual Clauses.

More information: Google Analytics Terms and Google Privacy Policy.

10.3 How to manage cookies

Legal basis: required cookies are processed on the basis of our legitimate interests (Art. 6(1)(f) GDPR); non-essential measurement cookies are processed based on consent where legally required (Art. 6(1)(a) GDPR).

11. Changes to This Policy

Version: 1.5

Last Updated: 2026-03-02

Significant changes will be communicated in the app and on our website.

You can request previous versions at [email protected].