Privacy Policy
Effective date:
This Privacy Policy explains what information Steply ("we", "us") collects through the Steply mobile app and this website, how we use it, who we share it with, and the choices and rights you have. It applies to everyone who creates a Steply account or uses the Steply app.
We wrote this policy to describe what the app actually does today, not a generic template — if a feature described here doesn't sound familiar, or you have questions about any part of it, contact us using the details at the bottom of this page.
Information we collect
Account information: your name, email address, and — if you sign up with email and password — a securely hashed version of your password (we never store your actual password). If you sign in with Google, we receive your name, email address, and a stable account identifier from Google instead of a password.
Profile and app settings: an optional avatar image, your timezone, distance-unit preference, app theme, and which optional reminders (daily goal, streaks, challenges, inactivity) you've turned on or off.
Walking goals and activity: your daily step goal, and the step count, distance, and estimated calories you sync from your device for each day. We receive these as daily totals your device already calculated — not a continuous stream of raw sensor or location data.
Routes: routes you generate or save, including the route's name, distance, estimated duration, difficulty, and the path geometry returned by our mapping provider. See "Location data" below for how a route's starting point is used.
Challenges and achievements: which challenges you've joined, your progress toward them, and which achievements you've unlocked.
Authentication and session data: a securely hashed session identifier while you're logged in, and a securely hashed, single-use, time-limited token if you request a password reset. Raw tokens are never stored — only a cryptographic hash that can't be reversed back into a usable token.
Technical data: standard request metadata (like IP address) is processed transiently to enforce rate limits against abuse (for example, limiting how many login attempts can be made in a short period) and is not retained as part of your profile.
Location data
Steply is a route-planning app, not a fitness tracker that continuously records your GPS position. Location is only used at the moment you ask the app to generate a walking route: your starting coordinates (either your current location or a point you choose) are sent to our mapping provider, Mapbox, to calculate walkable directions and points of interest near that starting point.
We do not run continuous background GPS tracking, and we do not store a history of everywhere you've been. What we do store, if you save a generated route, is the route itself — its start/end coordinates and the walking path Mapbox returned for it — the same way any map or navigation app stores a route you've saved, not a log of your real-time movement while walking it.
Your daily step count and distance (see "Information we collect" above) come from your device's own activity/health tracking and are sent to us only as a daily total — they are separate from, and do not include, GPS location history.
How we use your information
To operate the app's core features: authenticating you, tracking your goals and daily activity, generating and saving walking routes, calculating streaks, and running challenges and achievements.
To communicate with you about your account — for example, sending a password-reset email when you request one.
To maintain the security and reliability of the service, including rate-limiting abusive requests and investigating misuse.
We do not use your information for third-party advertising, and we do not sell your personal data.
Third-party services we use
We rely on a small number of service providers to run Steply. Each one only receives the specific data it needs to do its job:
- Mapbox (routing) — receives the coordinates needed to generate a walking route (your chosen or current starting point, and route waypoints) so it can return real-street directions and route geometry. See Mapbox's own privacy policy for how they handle this data.
- Google Sign-In (authentication) — if you choose to sign in with Google, Google shares your verified name, email, and account identifier with us; we never see or store your Google password.
- Resend (email delivery) — sends transactional emails on our behalf, such as password-reset emails. Resend processes the recipient email address and message content needed to deliver that email.
- Neon (database hosting) — our PostgreSQL database, where your account and app data described above is stored, runs on Neon's infrastructure.
- Redis Cloud (caching and rate limiting) — used for short-lived data only: rate-limit counters and temporary cached results. It is not used to store your profile, activity, or route data long-term.
- Vercel (application hosting) — hosts and serves the app's backend and this website, and processes requests as part of standard web hosting.
Cookies (website only)
The Steply mobile app does not use cookies — it authenticates using a session token stored securely on your device instead.
This website and admin dashboard use a small number of strictly functional cookies: one to keep an administrator signed in, one as a security measure (CSRF protection) for the admin dashboard, and one to remember your language preference on this site. None of these are advertising or third-party tracking cookies.
Data retention
We keep your account and app data for as long as your account is active, so the app can continue working the way you expect. Password-reset tokens expire automatically after a short window (30 minutes by default) and can only ever be used once. If you request deletion of your account (see below), we delete your account data rather than keeping it indefinitely.
Security
Passwords are never stored in plain text — we use Argon2id, a modern password-hashing algorithm designed to resist offline cracking attempts. Session tokens and password-reset tokens are likewise never stored in a usable raw form, only as a cryptographic hash. All traffic to our servers is encrypted in transit (HTTPS/TLS).
No method of transmission or storage is perfectly secure, and we can't guarantee absolute security — but we've designed the system so that a database compromise alone does not expose usable passwords or session tokens.
Your rights
Depending on where you live, applicable privacy law may give you some or all of the following rights over your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data (you can also update most of this yourself in the app's account settings).
- Deletion — ask us to delete your account and associated data (see "Account and data deletion" below).
- Restriction or objection — ask us to limit how we use your data, or object to certain uses, in the circumstances the law provides for.
- Portability — request your data in a portable format, where applicable.
- Withdraw consent — where we rely on your consent for a particular use of your data, withdraw that consent at any time.
- Complain to a regulator — if you're in the European Economic Area, the UK, or another jurisdiction with a data protection authority, you have the right to lodge a complaint with that authority.
Account and data deletion
The app does not yet have an automatic, self-service "delete my account" button — we want to be upfront about that rather than claim a feature that doesn't exist yet.
To request deletion of your account and associated data today, email us at support@steply.app from the email address on your account, with the subject "Account deletion request". We will verify the request and delete your account data within a reasonable time, except where we're required to retain certain records by law.
Children's privacy
Steply is not directed at children, and we do not knowingly collect personal data from children under 13 (or the minimum age required by your local law, if higher). If you believe a child has provided us with personal data, contact us at support@steply.app and we will take appropriate steps to delete it.
International users
Our infrastructure providers (see "Third-party services" above) currently process and store data in the United States. If you use Steply from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your home country.
Changes to this policy
We may update this Privacy Policy from time to time — for example, as the app gains new features or our providers change. We'll update the effective date above when we do. If a change is material, we'll make reasonable efforts to let you know (such as an in-app notice) before it takes effect.
Contact
Questions, requests, or concerns about this policy or your data can be sent to support@steply.app.