Daily Steps

Privacy Notice

Version · In effect since 8 October 2026

Daily Steps is a small, invite-only app that reminds you to go for a walk and lets you keep track of your steps, weight and streaks. This notice explains, in plain language, what data the app stores, why, for how long, and what you can do about it.

In Short

  • We only store what the app needs to work: your account, your settings and the entries you type in.
  • Your height and weight are health data. We only process them with your explicit consent.
  • No analytics, no ads, no tracking, no social logins, no profiling. We never sell your data.
  • Notifications never show your weight or BMI.
  • You can download all your data or delete your account at any time in Settings. Deletion is immediate and permanent.
  • Only strictly necessary cookies are used, so there is no cookie banner. See the Cookie Overview.

Who Is Responsible for Your Data

The controller (the party responsible for your personal data under the General Data Protection Regulation, “GDPR”) is:

[Operator name]
[Postal address or city, the Netherlands]
E-mail: [contact e-mail]

Daily Steps is a private, non-commercial hobby project. Because it is small, there is no separate data protection officer; you can contact the operator directly at the address above about anything in this notice.

What Data We Collect

We only collect the data below. You give us most of it yourself; the rest is created when you use the app.

Personal data stored by the app
DataDetails
AccountUsername, e-mail address, password (stored only as an Argon2id hash, never in readable form), sign-up date and time, the date your e-mail address was confirmed, and your time zone (for example “Europe/Amsterdam”, detected by your browser so reminders and days follow your local time).
Health dataYour height and the weight entries you log (one per day, together with your height at that moment). Your BMI is calculated from these when it is shown; it is not stored separately.
Step entriesThe number of steps you type in per day, and your step goal on that day (so changing your goal later does not rewrite past days). The app does not read step counts from your phone’s sensors or health apps.
SettingsStep goal, units (kg or lb, cm or feet and inches), whether weight tracking is on, reminder settings (on or off, reminder times, walk window and interval, snooze lengths) and whether you finished the introduction.
Notification devicesFor each device on which you turn on notifications: the push address your browser gives us (an “endpoint” URL at your browser maker’s push service), two encryption keys, a coarse label such as “iPhone · Safari”, the date it was added and when a notification was last delivered. No device identifiers or fingerprinting data.
Reminder bookkeepingWhen each type of reminder was last sent to you, and until when you postponed it (“Remind me later”).
Consent recordsWhen you confirmed you are 16 or older, and when you accepted which version of this Privacy Notice and of the Terms of Use.
SessionsFor each device where you are logged in: a hash of the session token in your cookie, when the session started, when it was last used and when it expires.
One-time linksHashes of the one-time codes in e-mail links (confirming your e-mail, resetting your password, changing your e-mail), their expiry time, and, when you change your e-mail, the new address until it is confirmed.
InviteInvite codes are stored only as hashes. When you sign up, the invite you used is marked as used and linked to your account. That link is removed when you delete your account.

Technical Data

Like every website, the app’s servers receive your IP address and basic browser information with each request. We use your IP address only briefly, to limit how often requests can be made (rate limiting), to slow down password guessing and to block abuse. The rate-limit store only keeps a one-way hash of your IP address or e-mail address, never the address itself, and these counters expire automatically after minutes to at most two days. Our hosting provider may also keep IP addresses in short-lived server logs (see How Long We Keep Data).

We do not collect your real name, your location, contacts, photos or anything from other apps.

Why We Use Your Data and on What Legal Basis

Purposes and legal bases
PurposeData usedLegal basis
Providing the app: your account, logging in, saving entries, calendar, charts and streaksAccount, step entries, settings, sessionsPerformance of our agreement with you (Art. 6(1)(b) GDPR)
Recording your height and weight and showing your BMIHealth dataYour explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), given when you sign up. See Your Health Data.
Sending the reminders you switched onSettings, time zone, notification devices, reminder bookkeeping, whether you logged todayPerformance of our agreement with you (Art. 6(1)(b) GDPR)
Service e-mails: confirming your address, password reset, security notices and the confirmation that your account was deletedE-mail address, username, one-time linksPerformance of our agreement with you (Art. 6(1)(b) GDPR); security notices also on our legitimate interest in protecting your account (Art. 6(1)(f) GDPR)
Security and abuse prevention: rate limiting, login lockouts, bot checks, checking new passwords against known data breachesIP address (hashed in the rate-limit store), hashed e-mail address, password at the moment you set itOur legitimate interest in keeping the app and your account safe (Art. 6(1)(f) GDPR)
Proving that you accepted this notice and the Terms of UseConsent recordsLegal obligation to be able to demonstrate consent (Art. 6(1)(c) and Art. 7(1) GDPR)

We do not use your data for any other purpose. There are no marketing e-mails and no newsletters, and we do not make automated decisions about you or build profiles of you.

Your Health Data

Your height, your weight entries and the BMI calculated from them are “special category” data under Article 9 of the GDPR, because they say something about your health. We therefore only process them with your explicit consent, which you give by ticking the box when you sign up (or when you accept an updated version of this notice).

BMI is a rough general indicator, not a diagnosis. Daily Steps does not give medical advice; see the Terms of Use.

How Long We Keep Data

Retention periods
DataHow long
Account, health data, entries, settings, consent records, reminder bookkeepingUntil you delete your account. Deletion is immediate and permanent; there is no “soft delete” or waiting period. You can also remove single entries at any time.
Accounts whose e-mail address was never confirmedAutomatically deleted 7 days after sign-up.
Sessions (being logged in)End after 30 days without use, and at the latest 90 days after you logged in, or earlier when you log out. Ended sessions are removed by a daily clean-up.
One-time e-mail linksPassword reset links work for 1 hour; links to confirm or change your e-mail address work for 24 hours. Used and expired links are removed by a daily clean-up.
Notification devicesUntil you turn notifications off, remove the device in Settings, log out on that device, delete your account, or the push service tells us the address no longer works.
Rate-limit and login-protection counters (hashed)Expire automatically after a few minutes to at most 48 hours.
Hosting logs (may include IP addresses)[Fill in: log retention of the hosting provider, for example “up to 30 days”]
E-mail delivery logs at our e-mail provider[Fill in: log retention of the e-mail provider, for example “up to 30 days”]
Database backups[Fill in: backup or point-in-time-recovery window of the database provider, for example “7 days”]. Data you delete disappears from backups when this period has passed.

Who Receives Your Data

We do not sell, rent or share your data with anyone for their own purposes. To run the app we use the technical service providers below. They act as our processors: they may only process your data on our instructions and under a data processing agreement, and only for the task listed.

Service providers (processors)
ProviderTaskData involved
Vercel Inc.Hosting the website; server functions run in Frankfurt, Germany (EU)All data passing through the app, IP addresses in server logs
[Database provider, e.g. Neon or Supabase]Database hosting [region: fill in, an EU region is recommended]All stored data listed above
Upstash, Inc.Rate-limit counters [region: fill in, an EU region is recommended]Hashed IP addresses and hashed e-mail addresses only
ResendSending service e-mailsYour e-mail address and the content of the e-mail
Cloudflare, Inc. (Turnstile)Bot protection on the sign-up and forgot-password forms, and on the login form after repeated failed attemptsIP address and technical browser signals during the security check

Push Services

When you turn on notifications, your browser chooses its own push service to deliver them: Apple for Safari, Google for Chrome and most Android browsers, Mozilla for Firefox, or Microsoft for Edge. We send each notification to the address your browser gave us. The content is end-to-end encrypted, so the push service can only see that a message is sent to that address, not what it says. These services are operated by your browser maker under their own privacy terms.

Breached-Password Check

When you choose a password, our server checks whether it appears in known data breaches using the “Pwned Passwords” service (api.pwnedpasswords.com). Only the first 5 characters of a one-way hash of the password are sent; your password, e-mail address and IP address are never sent. This is not personal data.

We may also disclose data if we are legally required to, for example by a court order, and only to the extent required.

International Transfers

We choose providers and regions within the European Economic Area (EEA) where possible. Some providers above are based in the United States or may access data from outside the EEA, for example for support or e-mail delivery. In those cases the transfer is protected by the EU–US Data Privacy Framework where the provider is certified, or otherwise by the European Commission’s Standard Contractual Clauses, together with additional safeguards such as encryption in transit. You can ask us for a copy of the relevant safeguards.

Cookies and Local Storage

The app only uses cookies and browser storage that are strictly necessary: one to keep you logged in, one to remember your light or dark theme, and a few items for installing the app and working offline. Because nothing is used for tracking, no cookie banner is needed. See the Cookie Overview for the full list.

What We Never Do

Your Rights

Under the GDPR you have the following rights. Most of them you can use directly in the app.

Your rights and how to use them
RightHow
Access and data portabilitySettings → Your Data: “Download All Data (JSON)” gives your account details, consents, settings, all entries (with BMI), devices and sessions; “Download Entries (CSV)” gives your entries as a spreadsheet. Security values such as your password hash and device encryption keys are left out because they are of no use to you. For a full overview of everything, e-mail us.
Rectification (correcting data)Settings → Account (username, e-mail address, password), Body & Units (height, units), Time Zone, and the Log page for any entry.
Erasure (deleting data)Settings → Delete Account deletes your account and all related data immediately and permanently. You get a confirmation e-mail. You can also remove single entries on the Log page and notification devices in Settings.
Withdrawing consentDelete your account, or turn off weight tracking and remove your weight entries. See Your Health Data.
Restriction and objectionE-mail us. You can also switch off notifications or weight tracking at any time in Settings.

You can also exercise any of these rights by e-mailing [contact e-mail]. We answer within one month. We may ask you to confirm the request from the e-mail address of your account, so we know it is really you.

If you are unhappy with how we handle your data, please tell us first so we can try to fix it. You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the supervisory authority in the EU country where you live.

Age Requirement

You must be 16 or older to use Daily Steps. We ask you to confirm this when you sign up. If we learn that an account belongs to someone younger, we delete it.

How We Protect Your Data

Changes to This Notice

The version and date at the top show when this notice last changed. If we change it in a way that matters for you, for example new data or a new purpose, the app asks you to read and accept the new version the next time you open it. Small corrections, such as fixing a typo, do not need your new acceptance. You can see which version you accepted in Settings → Weight & Privacy.

Contact

Questions about this notice or your data? E-mail [contact e-mail]. Please write from, or mention, the e-mail address of your account, so we can find it.