Privacy Notice
Version · In effect since 8 October 2026
Daily Steps is a small, invite-only app that reminds you to go for a walk and lets you keep track of your steps, weight and streaks. This notice explains, in plain language, what data the app stores, why, for how long, and what you can do about it.
In Short
- We only store what the app needs to work: your account, your settings and the entries you type in.
- Your height and weight are health data. We only process them with your explicit consent.
- No analytics, no ads, no tracking, no social logins, no profiling. We never sell your data.
- Notifications never show your weight or BMI.
- You can download all your data or delete your account at any time in Settings. Deletion is immediate and permanent.
- Only strictly necessary cookies are used, so there is no cookie banner. See the Cookie Overview.
Who Is Responsible for Your Data
The controller (the party responsible for your personal data under the General Data Protection Regulation, “GDPR”) is:
[Operator name]
[Postal address or city, the Netherlands]
E-mail: [contact e-mail]
Daily Steps is a private, non-commercial hobby project. Because it is small, there is no separate data protection officer; you can contact the operator directly at the address above about anything in this notice.
What Data We Collect
We only collect the data below. You give us most of it yourself; the rest is created when you use the app.
| Data | Details |
|---|---|
| Account | Username, e-mail address, password (stored only as an Argon2id hash, never in readable form), sign-up date and time, the date your e-mail address was confirmed, and your time zone (for example “Europe/Amsterdam”, detected by your browser so reminders and days follow your local time). |
| Health data | Your height and the weight entries you log (one per day, together with your height at that moment). Your BMI is calculated from these when it is shown; it is not stored separately. |
| Step entries | The number of steps you type in per day, and your step goal on that day (so changing your goal later does not rewrite past days). The app does not read step counts from your phone’s sensors or health apps. |
| Settings | Step goal, units (kg or lb, cm or feet and inches), whether weight tracking is on, reminder settings (on or off, reminder times, walk window and interval, snooze lengths) and whether you finished the introduction. |
| Notification devices | For each device on which you turn on notifications: the push address your browser gives us (an “endpoint” URL at your browser maker’s push service), two encryption keys, a coarse label such as “iPhone · Safari”, the date it was added and when a notification was last delivered. No device identifiers or fingerprinting data. |
| Reminder bookkeeping | When each type of reminder was last sent to you, and until when you postponed it (“Remind me later”). |
| Consent records | When you confirmed you are 16 or older, and when you accepted which version of this Privacy Notice and of the Terms of Use. |
| Sessions | For each device where you are logged in: a hash of the session token in your cookie, when the session started, when it was last used and when it expires. |
| One-time links | Hashes of the one-time codes in e-mail links (confirming your e-mail, resetting your password, changing your e-mail), their expiry time, and, when you change your e-mail, the new address until it is confirmed. |
| Invite | Invite codes are stored only as hashes. When you sign up, the invite you used is marked as used and linked to your account. That link is removed when you delete your account. |
Technical Data
Like every website, the app’s servers receive your IP address and basic browser information with each request. We use your IP address only briefly, to limit how often requests can be made (rate limiting), to slow down password guessing and to block abuse. The rate-limit store only keeps a one-way hash of your IP address or e-mail address, never the address itself, and these counters expire automatically after minutes to at most two days. Our hosting provider may also keep IP addresses in short-lived server logs (see How Long We Keep Data).
We do not collect your real name, your location, contacts, photos or anything from other apps.
Why We Use Your Data and on What Legal Basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the app: your account, logging in, saving entries, calendar, charts and streaks | Account, step entries, settings, sessions | Performance of our agreement with you (Art. 6(1)(b) GDPR) |
| Recording your height and weight and showing your BMI | Health data | Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), given when you sign up. See Your Health Data. |
| Sending the reminders you switched on | Settings, time zone, notification devices, reminder bookkeeping, whether you logged today | Performance of our agreement with you (Art. 6(1)(b) GDPR) |
| Service e-mails: confirming your address, password reset, security notices and the confirmation that your account was deleted | E-mail address, username, one-time links | Performance of our agreement with you (Art. 6(1)(b) GDPR); security notices also on our legitimate interest in protecting your account (Art. 6(1)(f) GDPR) |
| Security and abuse prevention: rate limiting, login lockouts, bot checks, checking new passwords against known data breaches | IP address (hashed in the rate-limit store), hashed e-mail address, password at the moment you set it | Our legitimate interest in keeping the app and your account safe (Art. 6(1)(f) GDPR) |
| Proving that you accepted this notice and the Terms of Use | Consent records | Legal obligation to be able to demonstrate consent (Art. 6(1)(c) and Art. 7(1) GDPR) |
We do not use your data for any other purpose. There are no marketing e-mails and no newsletters, and we do not make automated decisions about you or build profiles of you.
Your Health Data
Your height, your weight entries and the BMI calculated from them are “special category” data under Article 9 of the GDPR, because they say something about your health. We therefore only process them with your explicit consent, which you give by ticking the box when you sign up (or when you accept an updated version of this notice).
- We use this data only to show it back to you: your entries, charts and BMI.
- Notifications never contain your weight, BMI or other sensitive values, because they can appear on a locked screen. They only contain neutral text such as “Time for a walk?”.
- We never share it with anyone except the technical service providers that host the app (listed below).
- Weight tracking is optional. In Settings → Weight & Privacy you can turn it off; weight and BMI are then hidden and the weight reminder stops. Past entries are kept until you remove them (on the Log page) or delete your account.
- You can withdraw your consent at any time. Because the app is built around this data, the way to withdraw it completely is to delete your account, which removes all your health data immediately. Withdrawing consent does not affect processing that happened before.
BMI is a rough general indicator, not a diagnosis. Daily Steps does not give medical advice; see the Terms of Use.
How Long We Keep Data
| Data | How long |
|---|---|
| Account, health data, entries, settings, consent records, reminder bookkeeping | Until you delete your account. Deletion is immediate and permanent; there is no “soft delete” or waiting period. You can also remove single entries at any time. |
| Accounts whose e-mail address was never confirmed | Automatically deleted 7 days after sign-up. |
| Sessions (being logged in) | End after 30 days without use, and at the latest 90 days after you logged in, or earlier when you log out. Ended sessions are removed by a daily clean-up. |
| One-time e-mail links | Password reset links work for 1 hour; links to confirm or change your e-mail address work for 24 hours. Used and expired links are removed by a daily clean-up. |
| Notification devices | Until you turn notifications off, remove the device in Settings, log out on that device, delete your account, or the push service tells us the address no longer works. |
| Rate-limit and login-protection counters (hashed) | Expire automatically after a few minutes to at most 48 hours. |
| Hosting logs (may include IP addresses) | [Fill in: log retention of the hosting provider, for example “up to 30 days”] |
| E-mail delivery logs at our e-mail provider | [Fill in: log retention of the e-mail provider, for example “up to 30 days”] |
| Database backups | [Fill in: backup or point-in-time-recovery window of the database provider, for example “7 days”]. Data you delete disappears from backups when this period has passed. |
Who Receives Your Data
We do not sell, rent or share your data with anyone for their own purposes. To run the app we use the technical service providers below. They act as our processors: they may only process your data on our instructions and under a data processing agreement, and only for the task listed.
| Provider | Task | Data involved |
|---|---|---|
| Vercel Inc. | Hosting the website; server functions run in Frankfurt, Germany (EU) | All data passing through the app, IP addresses in server logs |
| [Database provider, e.g. Neon or Supabase] | Database hosting [region: fill in, an EU region is recommended] | All stored data listed above |
| Upstash, Inc. | Rate-limit counters [region: fill in, an EU region is recommended] | Hashed IP addresses and hashed e-mail addresses only |
| Resend | Sending service e-mails | Your e-mail address and the content of the e-mail |
| Cloudflare, Inc. (Turnstile) | Bot protection on the sign-up and forgot-password forms, and on the login form after repeated failed attempts | IP address and technical browser signals during the security check |
Push Services
When you turn on notifications, your browser chooses its own push service to deliver them: Apple for Safari, Google for Chrome and most Android browsers, Mozilla for Firefox, or Microsoft for Edge. We send each notification to the address your browser gave us. The content is end-to-end encrypted, so the push service can only see that a message is sent to that address, not what it says. These services are operated by your browser maker under their own privacy terms.
Breached-Password Check
When you choose a password, our server checks whether it appears in known data breaches using the “Pwned Passwords” service (api.pwnedpasswords.com). Only the first 5 characters of a one-way hash of the password are sent; your password, e-mail address and IP address are never sent. This is not personal data.
We may also disclose data if we are legally required to, for example by a court order, and only to the extent required.
International Transfers
We choose providers and regions within the European Economic Area (EEA) where possible. Some providers above are based in the United States or may access data from outside the EEA, for example for support or e-mail delivery. In those cases the transfer is protected by the EU–US Data Privacy Framework where the provider is certified, or otherwise by the European Commission’s Standard Contractual Clauses, together with additional safeguards such as encryption in transit. You can ask us for a copy of the relevant safeguards.
Cookies and Local Storage
The app only uses cookies and browser storage that are strictly necessary: one to keep you logged in, one to remember your light or dark theme, and a few items for installing the app and working offline. Because nothing is used for tracking, no cookie banner is needed. See the Cookie Overview for the full list.
What We Never Do
- No analytics or statistics tools, no advertising, no tracking pixels.
- No social logins and no social media buttons or embeds.
- No third-party fonts or other scripts, apart from the bot check described above.
- No profiling and no automated decision-making with legal or similarly significant effects.
- No selling or renting of your data.
Your Rights
Under the GDPR you have the following rights. Most of them you can use directly in the app.
| Right | How |
|---|---|
| Access and data portability | Settings → Your Data: “Download All Data (JSON)” gives your account details, consents, settings, all entries (with BMI), devices and sessions; “Download Entries (CSV)” gives your entries as a spreadsheet. Security values such as your password hash and device encryption keys are left out because they are of no use to you. For a full overview of everything, e-mail us. |
| Rectification (correcting data) | Settings → Account (username, e-mail address, password), Body & Units (height, units), Time Zone, and the Log page for any entry. |
| Erasure (deleting data) | Settings → Delete Account deletes your account and all related data immediately and permanently. You get a confirmation e-mail. You can also remove single entries on the Log page and notification devices in Settings. |
| Withdrawing consent | Delete your account, or turn off weight tracking and remove your weight entries. See Your Health Data. |
| Restriction and objection | E-mail us. You can also switch off notifications or weight tracking at any time in Settings. |
You can also exercise any of these rights by e-mailing [contact e-mail]. We answer within one month. We may ask you to confirm the request from the e-mail address of your account, so we know it is really you.
If you are unhappy with how we handle your data, please tell us first so we can try to fix it. You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the supervisory authority in the EU country where you live.
Age Requirement
You must be 16 or older to use Daily Steps. We ask you to confirm this when you sign up. If we learn that an account belongs to someone younger, we delete it.
How We Protect Your Data
- Passwords are hashed with Argon2id; nobody, including the operator, can read them.
- All connections use HTTPS. Session cookies are HttpOnly and Secure, and only a hash of the session token is stored, so a database leak alone does not let anyone log in as you.
- E-mail links contain single-use codes that expire, and only their hashes are stored.
- Rate limiting, login lockouts, a bot check and a breached-password check protect against attacks.
- A strict Content Security Policy and other security headers protect against malicious scripts.
- You can log out on all devices at once in Settings, for example after losing your phone.
- Changing your password logs you out on other devices, and we e-mail you about password and e-mail address changes.
- Access to the production systems is limited to the operator. If a data breach happens, we follow a documented procedure, including notifying the Autoriteit Persoonsgegevens and you where required.
Changes to This Notice
The version and date at the top show when this notice last changed. If we change it in a way that matters for you, for example new data or a new purpose, the app asks you to read and accept the new version the next time you open it. Small corrections, such as fixing a typo, do not need your new acceptance. You can see which version you accepted in Settings → Weight & Privacy.
Contact
Questions about this notice or your data? E-mail [contact e-mail]. Please write from, or mention, the e-mail address of your account, so we can find it.