StepLink Privacy Policy

Last updated: 22 August 2026

StepLink is a step-counting app with shared group leaderboards. This policy explains what it collects, why, who else sees it, and how to get rid of it.

Health data is the most sensitive thing StepLink handles, so the short version first: your step data is never sold, never used for advertising, and never shared with anyone outside the groups you personally join.

1. Who is responsible

Jaanus Tilk
Estonia

Questions, requests or complaints: privacy@steplink.net

We are the data controller for the information described below.

2. What StepLink collects

Account information

Created when you sign in with Google or Apple. StepLink never sees or stores your Google or Apple password — sign-in is handled by Firebase Authentication.

DataSourceWhy
User IDFirebaseIdentifies your account
Display nameGoogle/Apple, editable in-appShown on leaderboards
Email addressGoogle/AppleAccount identity; cannot be changed in-app
Profile photo URLGoogle/AppleShown on leaderboards
Account creation dateStepLinkAccount management

Health and fitness data

DataWhy
Daily step count, per calendar dayThe entire purpose of the app
Which app or device each day's steps came fromPrevents double-counting between sources
Your daily and monthly step goalsProgress display

StepLink reads step counts only. It does not read or store heart rate, sleep, location, GPS routes, workouts, body measurements, calories, or any other health metric — even where the connected service offers them.

Group data

Groups you create or join, your membership dates, group start dates, and the trophy days your group has earned.

App preferences

Your chosen walker style and accent colour, and whether you have seen the welcome screen.

Subscription status

Trial start date, subscription date and expiry date, where applicable.

Diagnostic data

What StepLink does not collect

No advertising identifiers. No location or GPS data. No behavioural analytics or tracking. No contacts. No third-party advertising or marketing SDKs of any kind.

3. Where step data comes from

You choose one source. StepLink reads from it and nothing else.

On your device — you grant permission in the platform's own dialog, and can revoke it there at any time:

From a connected account — you authorise StepLink through the provider's own consent screen, and your steps sync without your phone being involved:

For connected accounts, StepLink stores an access credential so it can keep reading your steps. These credentials are encrypted before storage. StepLink never receives or stores your password for these services.

Apple HealthKit disclosure: data read from HealthKit is used solely to display and compare your step counts within StepLink. It is never used for advertising, marketing or data mining, and is never disclosed to third parties for those purposes.

Google API Services disclosure: StepLink's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google Health is used only to provide the step-tracking features described here, is not transferred to others except as required to provide those features, is never used for advertising, and is never sold.

4. Who else can see your data

Members of groups you join

This is the one place your data is visible to other people, and it is the point of the app. Anyone in a group with you can see:

If you do not want someone to see your step counts, do not join a group with them. Leaving a group stops your future steps appearing on its leaderboard.

Service providers

ProviderWhat they processWhy
Google Firebase (Authentication, Crashlytics)User ID, email, crash reportsSign-in and crash diagnostics
Hetzner Online GmbH, FinlandAll app dataRuns the API and database

Nobody else

StepLink does not sell your data. It does not share it with advertisers, data brokers, analytics companies or insurers. There is no advertising in the app.

We disclose data otherwise only where legally compelled to, and only what is compelled.

5. Legal basis (GDPR)

Health data is a special category of personal data under Article 9 GDPR. StepLink processes it on the basis of your explicit consent (Article 9(2)(a)), given when you grant health permissions or connect a provider account. You may withdraw that consent at any time by revoking the permission, disconnecting the provider, or deleting your account.

Account and group data are processed to perform the service you asked for (Article 6(1)(b)).

6. How long it is kept

Your data is kept while your account exists. When you delete your account it is removed immediately — see below. Crash reports are retained by Firebase Crashlytics according to Google's own retention schedule (currently 90 days).

7. Deleting your account

Settings → Delete Account.

This is a hard delete, not a deactivation. There is no archived copy and no recovery period. It removes:

Groups you created are transferred to another member, or removed if you were the only member.

Your access grants at connected providers (Google Health, Garmin) are revoked as part of deletion. If a provider is unreachable at that moment, deletion still proceeds — you can also revoke access directly in your Google or Garmin account settings.

One exception, stated plainly: the Samsung Health permission is held by the Samsung Health app on your device, not by StepLink. Deleting your StepLink account does not remove it. Clear it yourself in Samsung Health's own permission settings.

8. Your rights

Under GDPR you have the right to access, correct, delete, export, restrict or object to the processing of your personal data, and to withdraw consent at any time.

Deletion and correction of your display name are available directly in the app. For anything else, contact privacy@steplink.net and we will respond within one month.

You may also complain to your national data protection authority. In Estonia this is the Andmekaitse Inspektsioon (aki.ee).

9. Security

No system is perfectly secure, and we do not claim otherwise.

10. Children

StepLink is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

11. International transfers

StepLink's servers and database are hosted by Hetzner Online GmbH in the European Union (Finland). Your step history and account data stay within the EU.

Firebase Authentication and Crashlytics are operated by Google and may process data outside the EEA under Standard Contractual Clauses. This affects your user ID, email address and crash reports — not your step history, which never leaves our EU servers.

12. Changes

Material changes will be announced in the app before taking effect. The date at the top shows the current version.

13. Contact

Jaanus Tilk
privacy@steplink.net