StepScroll Privacy Policy
The short version
- Your step count never leaves your iPhone, and neither does anything worked out from it: your earned minutes, your balance, your average.
- Apple's Screen Time data never leaves your iPhone. StepScroll can't see which apps you use or for how long, and the apps you lock are stored as tokens that only Apple can read.
- The app does send some data to outside services: usage analytics to Mixpanel, paywall and purchase data to Superwall, crash reports to Sentry, and a random user ID, remote settings and, if you sign in, a backup of your plan to Google Firebase. Each one is described below, with what it gets and what it never gets.
- An account is optional. If you make one, you can delete it in the app, and the plan backup goes with it.
- No ads inside the app. We never sell your data, never ask to track you, and never read your device's advertising identifier.
What stays on your iPhone
StepScroll turns your steps into screen time for apps you choose to lock. It uses three Apple frameworks, and what they give the app stays on the phone:
- HealthKit (read-only, step count only). StepScroll reads your step count, including about the last 30 days, to set up your plan and to count what your walking has earned. It asks for no other Health data and never writes to Health.
- Motion & Fitness. StepScroll also reads your iPhone's own step counter, so steps you just took count before the Health app catches up. Same rules as HealthKit.
- Screen Time (Family Controls, Managed Settings, Device Activity). You pick the apps to lock in Apple's own picker. Apple gives StepScroll opaque tokens, not app names, and they only work on the phone that made them. StepScroll uses them to lock and unlock those apps. The screen-time chart in setup is drawn by Apple in a sandbox the app itself can't read.
None of this is sent anywhere: not your step counts, not anything computed from them (earned minutes, your balance, your average), not your Screen Time usage, not which apps or categories you locked or how many, and nothing about what happens on a locked app's lock screen beyond the once-a-day count described under Usage analytics. It is never used for advertising or marketing. You can turn off Health, Motion & Fitness or Screen Time access at any time in iOS Settings; the parts of the app that need them stop working, and nothing else happens, because we never had that data.
The app also keeps these on your phone: your rate and mode, your day-by-day spend history, the app selection tokens, your notification settings, and your answers to the setup questions. Some of them also leave the phone, as described below: your rate, mode, setup answers and whether notifications are on go to Mixpanel, your setup answers go to Superwall, a once-a-day count of your unlocks goes to Mixpanel, and if you sign in, your rate, mode, setup answers and day-by-day counts are backed up (see Plan backup). The app selection tokens never leave the phone.
Usage analytics (Mixpanel)
StepScroll uses Mixpanel to see how people move through setup and use the app, so the parts where people get stuck can be found and fixed. Mixpanel receives:
- Events for taps and screens in StepScroll's own app, with the time they happened: for example "setup screen reached", "Health connected", "deal locked in", "spent 10 minutes", "pass used", "signed in", "notification opened". Mixpanel's automatic events are on, so it also records first open, app updates and how long sessions last.
- Your answers to the setup questions, as the option you tapped: for example how many hours you think you scroll, which apps you named, how you heard about StepScroll, and your age range and gender if you answered those. The only thing you type that is sent is the name you enter if you answer the optional "Did a creator send you?" question.
- Your settings in StepScroll: your rate (5, 10 or 15 minutes of locked-app time per 1,000 steps), your mode (Easy or Hard), whether you picked any apps to lock (not which, not how many), and whether notifications are on.
- A once-a-day summary of StepScroll's own record of your previous day: how many 10-minute unlocks you spent, borrowed and repaid, and how many passes you used, plus how many times a StepScroll extension failed that day. It says nothing about which apps, and nothing finer than the day.
- IDs and device details: a random ID Mixpanel makes for the install, the Firebase user ID described below, your device model, iOS version, app version and screen size.
- Approximate location: Mixpanel works out your city, region and country from your internet (IP) address. It does not get your precise location, and StepScroll never asks for location access.
Mixpanel never receives your step count or anything computed from it, your Screen Time usage, which apps you locked, your email or your name.
Paywall and purchases (Superwall and Apple)
StepScroll requires a subscription. Superwall shows the subscription screen at the end of setup, and again if your subscription ends, and handles the purchase through Apple. Apple processes the payment; StepScroll and Superwall never see your card or your Apple Account password. Superwall receives:
- What happens on the subscription screen (opened, closed, purchased, restored) and your subscription status and purchase history from the App Store. These paywall events are also forwarded to Mixpanel.
- Your setup answers, the same ones Mixpanel gets, including the optional creator name, so the right subscription screen can be shown.
- The Firebase user ID, a random ID Superwall makes, and your device's vendor ID (an ID Apple gives each developer, the same across this developer's apps on your phone, not the advertising identifier).
- Device details: model, iOS and app version, language, region setting, time zone, screen size, connection type and whether Low Power Mode is on. From your IP address it works out your approximate location (country, region and city).
- A one-time install check. The first time the app opens, Superwall's code sends one request with the device details above, the install date and your IP address, which Superwall uses to tell whether the install followed a link that Superwall tracks. StepScroll has not turned on any of Superwall's ad-network integrations, so nothing about you goes from Superwall to an ad network. Superwall may also ask Apple whether the install came from an Apple Search Ads ad; Apple answers with campaign details only, never who you are.
Your user ID, sign-in and remote settings (Google Firebase)
Random user ID. The first time StepScroll opens, Google's Firebase Authentication gives the install a random user ID. Nothing is shown and nothing is asked. The ID carries no name, email or password. Mixpanel, Superwall and Sentry records are filed under it, so one person's records stay together.
Optional sign-in. After you subscribe you can sign in with Apple or Google, or skip. If you sign in, Firebase stores the email address (or Apple's private relay address) and the name your provider shares, under the same user ID. StepScroll uses them only for your account. They are never sent to Mixpanel, Superwall or Sentry.
Remote settings (from version 1.5). The app downloads its settings from Firebase Remote Config, so we can switch a feature off or show an update notice without a new app version. To do that, the app sends a Firebase installation ID, the app version, iOS version, language, region setting and time zone. Nothing is used to target you.
Plan backup (Cloud Firestore, signed-in accounts only)
If you sign in with Apple or Google, StepScroll keeps a copy of your plan in Google's Cloud Firestore, under your user ID, so signing in on a new phone brings it back. If you never sign in, nothing is copied. The copy holds:
- Your deal: how many minutes 1,000 steps buy, and your mode (Easy or Hard).
- Your answers to the setup questions and the date you signed the commitment (not the signature itself).
- A change you queued for tomorrow, if there is one.
- One line per day: how many 10-minute unlocks you spent, whether you borrowed or repaid one, how many passes you used, and the rate in force that day. These are counts of your own taps in StepScroll.
It holds no step counts or anything computed from them, no Health data, no Screen Time usage, and not which apps you lock (a new phone picks them again). Only you, signed in, can read or write your copy. Signing out stops the backup on that phone. Deleting your account deletes the copy.
Crash and error reports (Sentry, from version 1.5)
When StepScroll crashes or something fails (a purchase check, a sync, a permission request), the app sends a report to Sentry so we can fix it. A report holds the error and where in the code it happened, your device model, iOS and app version, memory and storage state, your user ID, error codes, and the names of the screens and steps leading up to it.
A report never holds a screenshot, your step count or anything computed from it, Screen Time data, which apps you lock, your email, your name, or anything you typed.
Ads and attribution
StepScroll has no ads inside the app. We do advertise StepScroll on other apps and websites, and work with creators who post about it. To see which of those bring people in, StepScroll uses only Apple's own tools:
- Apple's ad attribution (SKAdNetwork and AdAttributionKit). If you installed StepScroll after tapping an ad, Apple may tell the ad network, after a random delay and with no ID for you or your device, that the ad led to an install. From version 1.5, StepScroll gives Apple a small number to include that says how far setup got and whether a subscription started. Nothing from your steps, your Screen Time data or your answers goes into it.
- Creator links. A creator's StepScroll link (step-scroll.vercel.app/c/name) opens a page that records the tap in Mixpanel (which creator, and whether the link was opened in TikTok, Instagram, Snapchat, YouTube or another app, read from the browser) without looking up your location, then sends you to the App Store with that creator's campaign tag. Vercel, which hosts this website, may also count the page view, without cookies. Apple reports installs per tag to us only as totals.
- Your own answer. Setup asks how you heard about StepScroll, and optionally which creator sent you.
StepScroll does not use the advertising identifier (IDFA), does not show Apple's App Tracking Transparency prompt, has no ad-network or attribution SDK in the app, and does not combine what it collects with data from other companies' apps or websites to target ads or measure them.
Notifications
From version 1.5, StepScroll can remind you when your walking has earned more minutes. These are written and shown on the phone; their content is not sent anywhere. Mixpanel records whether you allowed notifications and when you open one.
Your internet address and where data is kept
Every service above sees your phone's IP address when the app talks to it, the same way a website does. Only Mixpanel and Superwall use it to work out an approximate location, as described above. Mixpanel, Superwall, Google and Sentry are US companies. StepScroll's Mixpanel project, its Sentry account and the plan backup are stored in the United States (the plan backup in Google's US multi-region). If you use StepScroll outside the US, your data is transferred to the United States.
Each of these services processes data only to provide its service to StepScroll, under its own terms and privacy policy, and gives it the same or equal protection as this policy: Mixpanel, Superwall, Google Firebase, Sentry and Apple.
How long data is kept
- On your phone: until you delete the app, except the user ID and sign-in that iOS keeps in the phone's keychain (see Deleting your data).
- Account and plan backup (Firebase): until you delete your account in the app. Signing out keeps them, so you can sign in again.
- The random user ID (Firebase): until you ask us to delete it.
- Usage analytics (Mixpanel) and paywall records (Superwall): for as long as StepScroll uses those services, unless you ask us to delete yours sooner.
- Crash reports (Sentry): deleted automatically within 90 days.
- Purchase records: Apple and Superwall keep them as long as billing, refunds, fraud prevention and the law require, even after you delete your account.
Deleting your data
- Your account and plan backup: in the app, go to Settings > Account > Delete account. It asks you to sign in once more, then deletes the sign-in, its email and name, and the plan backup. Your subscription is billed by Apple and keeps renewing until you cancel it in your Apple Account settings.
- Analytics, paywall and crash records: email us from Settings > Contact Support in the app and ask. From version 1.5 that email includes a Support ID, which is how we find your records, whether or not you signed in. On an older version, update the app first. You can also write to ryankrane@me.com from the email on your account, if you signed in.
- Everything on the phone: delete the app. One thing survives that: iOS keeps StepScroll's user ID, and your sign-in if you made one, in the phone's keychain. A reinstall picks them back up, so a signed-in plan can come back without signing in again. To remove the sign-in, delete your account (or sign out) in Settings > Account before you delete the app. Deleting the app alone also leaves the plan backup with your account.
- Uninstalling the app stops all further collection.
Your rights
Depending on where you live (for example under the GDPR in Europe and the UK, or the CCPA/CPRA in California), you can ask to see, correct, export or delete the personal data we hold about you, and to object to or restrict how it is used. Email ryankrane@me.com and we will answer within 30 days. We don't sell your personal information and don't share it for cross-context behavioral advertising. We use it only to run StepScroll, fix it and improve it, and to measure which ads and creators bring people in (Apple's ad attribution, creator links and your answer about how you heard of StepScroll, as described under Ads and attribution), based on providing the service you asked for and our interest in keeping the app working and knowing what brings people to it. For health data under Washington, Nevada and similar laws, see our Consumer Health Data Privacy Policy.
Children
StepScroll is for people managing their own screen time and is not directed at children under 13. We don't knowingly collect data from children under 13. If you think a child has used StepScroll, email us and we will delete their records.
Older versions
This page describes version 1.5. How earlier versions differ:
- Versions 1.4 and earlier also send Mixpanel your minutes balance with the in-app spend event, and how many apps and categories you picked (a number, never which ones). Version 1.5 stops both.
- Versions 1.4 and earlier have no plan backup, crash reports, remote settings, notifications, creator question or daily summary. Version 1.4 and earlier also have no Firebase user ID or sign-in; their records are filed under Mixpanel's and Superwall's random IDs.
Changes to this policy
If we change what StepScroll collects, we update this page and the date at the top.
Contact
Questions about privacy in StepScroll: Ryan Krane, ryankrane@me.com.