Privacy Policy

Effective June 20, 2025

Overview

SteadyChip is built with privacy as a core principle. By default, all your data stays on your device. Cloud sync is strictly opt-in. We do not sell your data, run ads, or share your information with third parties for marketing purposes.

Data We Collect

Local-only (no account): Your check-in logs, streak, savings goal name and amount, and app settings are stored solely in your browser's local storage or device storage. Nothing is transmitted to our servers. With cloud sync (optional): If you sign in, we store your email address, your data logs, and basic account metadata (display name, sign-in timestamps) on our servers to enable cross-device sync. Data is encrypted in transit (TLS) between your device and our servers.

How We Use Your Data

We use your data only to provide the service you've requested: syncing your sobriety logs across your devices. We do not use your data for advertising, analytics sold to third parties, profiling, or any purpose other than delivering the app's core functionality.

Email Address

We use your email only to send you a one-time sign-in code and, if enabled, transactional account emails. We do not send newsletters or marketing messages. Your email address is never shared with third parties.

Third-Party Services

We use the following third-party services to operate the app: • Resend — for delivering sign-in code emails. Only your email address is shared with Resend for delivery purposes. • RevenueCat — for managing subscriptions on iOS and Android. RevenueCat may process your Apple/Google account identifier and purchase receipt data. We do not use any advertising SDKs, behavioral analytics platforms, or social media tracking pixels.

Data Retention

Local data persists until you reset it from Settings or clear your browser/app storage. Cloud sync data is retained for as long as your account is active. You may request deletion of your account and all associated data at any time by emailing [email protected].

GDPR Rights (EU/EEA Users)

If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR): • Right of access — you may request a copy of the data we hold about you. • Right to rectification — you may correct inaccurate data. • Right to erasure ("right to be forgotten") — you may request deletion of all your personal data. • Right to portability — you may request your data in a machine-readable format. • Right to object — you may object to certain processing activities. • Right to restrict processing — you may ask us to limit how we use your data. To exercise any of these rights, email [email protected]. We will respond within 30 days.

CCPA Rights (California Users)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA): • Right to know — you may request disclosure of the categories and specific pieces of personal information we have collected about you. • Right to delete — you may request deletion of your personal information, subject to certain exceptions. • Right to opt out of sale — we do not sell personal information, so this right is not applicable, but you may contact us to confirm. • Right to non-discrimination — we will not discriminate against you for exercising your CCPA rights. To submit a request, email [email protected].

Data Security

All data transmitted to our servers is encrypted in transit using TLS. We apply industry-standard security measures to protect your data from unauthorized access or disclosure. However, no method of transmission over the internet is 100% secure.

Children's Privacy

SteadyChip is not directed at anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from someone under 18, please contact us immediately at [email protected] so we can delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. We will note the effective date at the top of this document. Continued use of SteadyChip after any changes constitutes acceptance of the updated policy.

FTC Health Breach Notification

SteadyChip collects identifiable health information (your email address linked to sobriety log data) and is subject to the FTC Health Breach Notification Rule (16 C.F.R. Part 318). In the event of a data breach involving unauthorized access to, acquisition of, or disclosure of your health information, SteadyChip will: • Notify you individually by email describing what data was affected, when the incident occurred, and what steps you should take. • File a report with the Federal Trade Commission within the timeframes required by law (within 60 calendar days for incidents affecting fewer than 500 users; within 10 business days for incidents affecting 500 or more users). • Notify prominent media outlets in your state, if required by law. You have the right to receive this notification. If you believe your data has been improperly accessed, contact us at [email protected].

Contact

Privacy questions or requests: [email protected]

Questions? Email [email protected]