StepUp is a step-tracking and walking app for iPhone. This policy explains what the app collects, what it deliberately does not collect, who it shares data with, and the choices you have.
The app is published by Dheeraj Kumar Sharma, an individual based in India (“we”, “us”). For privacy purposes we are the data controller.
- Email: dheerajsh.codes@gmail.com
1. The short version
Your health data never leaves your iPhone.
Your steps, distance, calories, flights climbed, walking speed, step length, walking heart rate, gait measurements, streaks, and everything StepUp calculates from them, including your metrics, your walking plan and your daily targets, are read from Apple Health on your device, used on your device, and stored on your device. None of it is uploaded to our servers, included in analytics, put in a notification, or written to a log.
What we do store on our servers is your account and the things you typed in yourself: your name, your email address, your goals, your preferences.
We show no ads, we use no advertising identifier, we do not track you across other companies’ apps or websites, and we never sell your data.
2. Health and fitness data (stays on your device)
With your permission, StepUp reads the following from Apple Health:
- Step count
- Walking + running distance
- Flights climbed
- Active energy burned
- Walking speed
- Walking step length
- Walking asymmetry percentage
- Walking double support percentage
- Walking heart rate average
- Walking workouts
StepUp uses these to draw your dashboard, your calendar, your nine walking metrics (Momentum, Trend, Tempo, Climb, Effort, Routine, Pace, Evenness and Fitness), your widgets, your share cards, your streaks and your walking plan.
How this data is handled:
- It is read only. StepUp never writes to Apple Health and never modifies or deletes anything in it.
- It is processed entirely on your iPhone. It is never transmitted to us or to any third party.
- It is not included in analytics events, push notification payloads, crash logs, or any request to our backend.
- Your walking plan is generated on your device from this data and stored on your device.
- Your reminder and nudge notifications are composed on your device. Our servers cannot write “you’re 1,240 steps away” because our servers are never told your step count.
You grant this access through Apple’s own Health permission screen, and you can review or revoke it at any time in Settings → Health → Data Access & Devices → StepUp, or in Settings → Privacy & Security → Health. Apple does not tell us which permissions you granted or denied; if you deny access, StepUp simply has nothing to show.
Deleting the StepUp app removes the copy of this data that StepUp held on your device. Your data in Apple Health itself belongs to you and is unaffected.
3. Information we do collect
3.1 Account information
When you sign in with Apple or with Google, we receive and store:
- Your email address from that provider. If you use Sign in with Apple and choose “Hide My Email”, we only ever receive Apple’s private relay address, never your real one.
- Your display name, which you can edit or clear in the app.
- A user identifier used to link your account to your data.
We do not receive or store your password. Authentication is handled by Apple and Google.
3.2 Information you enter yourself
Stored against your account so that it follows you to a new device:
- Your fitness goal, weight goal, current weight, target weight and target timeline
- Your self-described fitness level and how often you walk
- Your daily step goal
- Your unit system (kg/lb), preferred start of week, language, time zone and haptic feedback preference
- Your notification preferences, including your reminder time and days
- Your progress through onboarding: which step you are on, when you reached it, and the app version you were using
Weight is a number you type in, not a HealthKit reading. We store it because your goals depend on it. It is never shared with anyone.
3.3 Product analytics
StepUp collects anonymous product analytics at all times. There is no in-app setting to turn this off. We are telling you here because the app does not ask you, so please read this section rather than skim it.
We use Google Firebase Analytics to understand which parts of the app are used and where people get stuck. The app records a small, fixed set of events:
| Event | What it carries |
|---|---|
| Sign-in started / completed | Which provider (Apple or Google), and whether it succeeded |
| Screen viewed | A screen name from a fixed list |
| Onboarding step | A step name from a fixed list |
| Notification permission / opened | A category label |
| Walking plan generated | Nothing beyond the event name |
These events contain no free text, no step counts, no distances, no weights, no health readings and no plan data. The app is built so that a health value cannot be placed inside an analytics event even by mistake.
Firebase additionally collects its own standard data: an app instance identifier, your device model, your OS version, app version and an approximate region derived from your IP address. Firebase does not receive your name, your email address or any health data from us.
This is analytics, not tracking. We do not use the Advertising Identifier (IDFA), we do not build advertising profiles, and we do not share this data with data brokers. That is why StepUp never shows you an App Tracking Transparency prompt.
3.4 Push notification registration
If you opt in to product announcements, we store a push token for your device along with your installation identifier, locale, time zone, app version and OS version, so that a message can be delivered and so we can stop sending to devices that no longer exist.
Remote messages are generic product announcements only. They are never about your activity, because our servers do not know your activity.
Your daily and weekly walking nudges and reminders are local notifications, scheduled by the app on your device. They do not involve our servers at all.
3.5 Purchases
StepUp Pro is sold through Apple’s In-App Purchase system and managed with RevenueCat. Apple processes the payment; we never see your card details, your billing address or your Apple Account credentials.
RevenueCat receives an anonymised account identifier (never your email address, never a device identifier) together with the purchase, renewal, cancellation and refund events Apple reports. We keep a record of which plan is active on your account so we can support you. No health data, plan data or receipt contents are stored there.
3.6 Camera
If you choose to add your own photo to a share card, StepUp asks for camera access. The photo is used to compose that card on your device. It is not uploaded to us, not stored in your account, and not shared with anyone unless you yourself share the finished card.
3.7 What we never collect
Location, contacts, your photo library, microphone, browsing history, the Advertising Identifier, health readings of any kind, your weight as recorded in Apple Health, your walking-plan targets or adherence, or your Health authorisation status.
4. How we use your information
- To run the app: sign you in, restore your settings and goals on a new device, and keep your preferences consistent.
- To personalise your experience: your goals and preferences shape your targets, your plan and your reminders. This personalisation happens on your device.
- To deliver notifications you asked for.
- To operate StepUp Pro, including restoring purchases and handling refunds.
- To improve the app, using the anonymous analytics described above.
- To answer you when you contact support.
- To meet legal obligations and to protect against fraud and abuse.
We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not use it for advertising.
5. Legal bases (EEA and UK users)
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Creating and running your account | Performance of a contract (Art. 6(1)(b)) |
| Storing your goals and preferences | Performance of a contract (Art. 6(1)(b)) |
| Reading Apple Health data on your device | Your explicit consent (Art. 9(2)(a)), given through Apple’s permission prompt |
| Product analytics | Our legitimate interest in improving the app (Art. 6(1)(f)) |
| Push announcements | Your consent (Art. 6(1)(a)) |
| Purchases and support | Performance of a contract (Art. 6(1)(b)) |
| Fraud prevention and legal compliance | Legal obligation / legitimate interest (Art. 6(1)(c), (f)) |
Because health data never reaches our servers, no special-category data under Article 9 is processed by us. It is processed only locally on your own device, under the consent you gave Apple Health.
You may object to analytics processing at any time by emailing dheerajsh.codes@gmail.com, and we will exclude your account.
6. Who we share data with
We do not sell your personal data and we do not share it for advertising. We use a small number of service providers, each acting on our instructions:
| Provider | What it receives | Purpose | Where |
|---|---|---|---|
| Supabase | Account, profile, preferences, goals, notification settings, push tokens | Database and authentication | Mumbai, India (ap-south-1) |
| Google Firebase | Anonymous analytics events, app instance ID, device and OS details, push delivery | Product analytics and push delivery | Google infrastructure |
| Apple | Sign-in, payments, subscription status | Authentication and In-App Purchase | Apple infrastructure |
| Google Sign-In | Sign-in details, if you choose Google | Authentication | Google infrastructure |
| RevenueCat | Anonymised account ID, purchase events | Subscription management | RevenueCat infrastructure |
None of these providers receives your health data, because your health data never leaves your iPhone.
We may also disclose information if required by law, court order or a valid government request, or to establish or defend legal claims. If StepUp is ever sold or merged, we may also disclose it to the acquirer, under this same policy.
7. International transfers
Our database is hosted in India. Our analytics, push and purchase providers operate globally and may process data in the United States and elsewhere. Where data from the EEA or the UK is transferred outside those regions, it is done under the European Commission’s Standard Contractual Clauses (and the UK Addendum) as incorporated into our agreements with those providers.
8. How long we keep data
- Account, profile, goal and preference data: for as long as your account exists, and deleted when you delete your account.
- Onboarding history: kept with your account; older records are pruned automatically.
- Push tokens: removed when you turn off announcements, when Apple or Firebase reports the token is dead, or when you delete your account.
- Analytics: retained according to the retention period configured in Firebase, after which Google deletes it. Analytics data is not linked to your name or email.
- Purchase records: retained as long as required for support, tax and accounting obligations.
- Health data: not applicable, because we never hold it.
9. Your rights and choices
In the app
- Delete your account. Profile → Delete Account removes your account and its data from our servers, clears the local cache, and erases your walking-plan history on the device. If you signed in with Apple, we also revoke StepUp’s Apple sign-in token. This cannot be undone.
- Edit your data. Your name, goals, step goal, units, week start, language, haptics and notification settings are all editable in Profile.
- Turn off notifications, in the app or in iOS Settings.
- Revoke Health access, in iOS Settings, at any time.
By request
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data; to restrict or object to processing; to withdraw consent; and to complain to a supervisory authority.
If you are in the EEA or UK (GDPR / UK GDPR), you have all of the above, including the right to data portability and the right to lodge a complaint with your national data protection authority or the UK ICO.
If you are in California (CCPA/CPRA), you have the right to know, delete and correct your personal information, and the right to opt out of sale or sharing, though we do not sell or share personal information as those terms are defined, and we do not offer financial incentives. We will not discriminate against you for exercising any right.
If you are in India (DPDP Act, 2023), you have the right to access a summary of your personal data and our processing, to correct or erase it, to nominate another person to exercise your rights in the event of your death or incapacity, and to grievance redressal. Our Grievance Officer is Dheeraj Kumar Sharma, at dheerajsh.codes@gmail.com.
Email dheerajsh.codes@gmail.com to exercise any of these. We will verify your request against your account email and respond within 30 days.
10. Security
Data in transit is encrypted with TLS. Data in our database is encrypted at rest, and every table carrying user data is protected by row-level security, so one account cannot read another’s rows. Our backend tables for notifications and purchases are unreachable from any client. The app holds no server secrets.
Your health data is protected by iOS itself, in Apple’s Health store, under the device passcode and encryption.
No system is perfectly secure, but we design to keep the amount of data worth attacking as small as possible.
11. Children
StepUp is not directed at children and is not intended for anyone under 13 (or under 16 in the EEA and UK, where local law sets that threshold). We do not knowingly collect personal data from children. If you believe a child has provided us data, email dheerajsh.codes@gmail.com and we will delete it.
12. Changes to this policy
If we change this policy we will update the date at the top and post the new version on this page. If the change is significant, such as a new category of data or a new purpose, we will tell you in the app or by email before it takes effect.
13. Contact
Dheeraj Kumar Sharma
Email: dheerajsh.codes@gmail.com
For privacy questions and for grievance redressal under India’s DPDP Act, use the same address.