StepTrove Support

Your data

Privacy

Last updated August 16, 2026

StepTrove is designed around activity data that you choose to provide. This page explains the categories we handle and the controls available to you.

Your account

StepTrove works without an email address. When you tap Get started, the app creates an account for your phone. The account holds a random account identifier, a generated name such as BraveOtter42, your timezone, and the activity you record. There is no sign-up form and no password.

We do not collect your real name. If you later link an Apple or Google account so your progress can move to a new phone, we request only your email address, and discard the name those providers offer. Linking adds an email to the account you already have. Nothing is moved or deleted when you link. Linking cannot be undone.

Other people never see your email address. Mutually accepted friends see exact step totals for today and this week, your generated name or nickname, your profile photo if you added one, whether you have Pro, and the date you became friends. A recorded zero is shown as zero; if no total has synced for that period, the app shows a dash. Club members see exact step totals on the club's board and member details. A recorded Club zero is shown as zero; if no total has synced for a Club period, the app shows a dash. If you turn on Being listed, that name and an approximate step count appear on the shared pace boards. My pace normally shows one count rounded to the nearest 500 for today and this week. Counts below 500 and counts near legal activity ceilings are shown as a dash; unlike a Friends or Club missing-data dash, it does not mean that no total synced or say whether you walked during that period. Current app screens do not show personal step ranges. You still see your own exact total, and exact server totals still determine rank and order. Once either person accepts a friend request, exact friend totals are shared; joining a club shares exact Club totals, while turning on Being listed shares a rounded count. Removing the friend, leaving the club, or saving Being listed as off stops that sharing on subsequent live board reads. Nobody is shown your workout routes or where you walked.

StepTrove is for people aged 13 and over. The App Store applies that through the app’s age rating, so we do not use an in-app age gate. The app does not ask for your age, sex, weight, or height. If you connect Apple Health, StepTrove reads those details from your Health profile to set your heart-rate zones and show them on your Profile page. They stay on your phone and are never sent to our servers. Details you entered in an earlier version of the app, including a birth year, remain on your account, are not used for age checks, social features, rankings, or analytics, and are erased when you delete your account.

Data we handle

How data is used

We use this data to calculate progress, show workout and health insights, restore your data, operate optional social features, prevent abuse, and troubleshoot the service. Health data is not used for advertising or sold to data brokers.

The dates your account was used are kept for up to 400 days. If an account is never used to record any activity, has no linked email, and has no purchases, we automatically delete it 180 days after it was created.

Daily Check-ins

We use Daily Check-ins data only to let you record, sync, read, edit, delete, and export your check-ins. Each check-in is private to your StepTrove account and is not shown to other members. StepTrove’s service providers process it only as needed to store and synchronize the feature.

A live check-in is kept until you delete that entry or delete your account. When you delete an entry, its mood and note content are removed. To prevent an older saved change from restoring deleted content, we retain only a minimal deletion record containing the day, revision, and deletion time until you delete your account.

Check-in content and its associated day, timestamps, revision, and deletion record are not included in product analytics, social features, application logs, sharing, or widgets.

Storage and sharing

Some data stays on your device. If you use an account or cloud features, the data needed for those features is sent securely to StepTrove’s service providers. Apple processes App Store purchases; StepTrove does not receive your complete payment-card number.

Optional product analytics

App-usage analytics are off until you choose to share them in StepTrove. The choice is kept separately for each StepTrove account on a device. Nothing is collected while analytics are off. When enabled, analytics help us measure opted-in audience size, understand which pages are used, compare Free and Pro activity, and plan improvements. Identity-linked page analytics record allowlisted semantic page names and time while the app is in the foreground. A separate, log-only stream records a limited set of allowlisted setup and reliability events such as sign-in method, onboarding completion, starter Buddy choice, and categorized Apple Watch or HealthKit outcomes. Those event records do not include the analytics installation identifier or StepTrove account ID. Normal access and security logs process network metadata separately. Event fields come from fixed lists. Health data, fitness values, raw sensor readings, workout routes, location, search terms, URL parameters, free-form text, raw taps, and touch positions are not included.

The random installation identifier is pseudonymized by the server. Signed-in activity can be linked to the StepTrove account so it can be classified and included in an account export or deletion. Joinable raw page sessions are retained for up to 30 UTC calendar days based on when the session starts. When a session reaches that limit, its visits are reduced to page, audience, local-hour, visit-count, and viewing-time totals grouped by visit UTC day, with every installation, account, session, and visit identifier removed; those identifier-free totals are retained for up to 400 days. Short-lived pseudonymous abuse counters expire within about two and a half hours. StepTrove does not use this information to track you across other companies’ apps or websites, and does not sell it.

Notifications

Reminders about your own steps, streaks, and goals are worked out on your device and do not need an account or a network. The ones that come from us are the ones another member sets off: a friend request, a request of yours being accepted, Kudos, and your club reaching a new level. If you turn notifications on, the device also gets a notification token from Apple and sends it to us, so we know where to deliver those.

When one of those happens we queue it for you. The queued item records what kind it is, who caused it, and what it needs to say. If we cannot deliver it within a day or two we drop it, rather than send you something you have already seen in the app. Once it has been sent we keep the record for 14 days, so that we can keep a lid on how many of these reach you in a day and can look into one you tell us never arrived, and then we delete it. We delete all of them when you delete your account. We look up the other person’s name at the moment we send, so a name you see is the one they use now.

Your Friends and clubs switches and your quiet hours are stored on your account, because we have to know before we send whether you want it. Everything else on the Notifications page stays on the device that set it.

A notification token stays on your account until you turn notifications off, you sign out on that device, another account signs in on that device, or you delete your account. We also remove a token when Apple replaces it or tells us it is no longer valid. If another account signs in on that device, the token moves to that account, so the previous account stops receiving notifications there.

Notification tokens are not included in product analytics, social features, sharing, or widgets.

Your controls

You can change Health, Motion, Location, and Notification permissions in iOS Settings. In StepTrove’s Profile → Permissions, you can turn friend requests and Being listed on or off. Under Usage analytics settings, you can turn app-usage analytics off and reset the random installation identifier. Turning analytics off stops new collection and discards pending page analytics immediately, then asks the server to delete identity-linked page and viewing-time history for that installation; if the device is offline, collection remains paused while deletion retries. Resetting analytics rotates the random installation identifier after that history is deleted. Fixed operational event logs are not linked to that identifier and follow separate security and operations retention. You can also reset local app data, or request an account export. That export includes your live check-ins and any minimal deletion records retained for them, and your notification tokens without the device digest, which proves a device owns its token and is of no use to you. If you linked an email, you can sign out. Without one there is no way to sign back in, so sign-out is not offered.

You can delete your account from Profile at any time. Deletion is immediate and the account cannot be recovered. It erases your profile, generated name, any linked email, steps, workouts, buddies, awards, coins, social connections, backups, check-ins and their minimal deletion records, any notification tokens, and the dates your account was used. It also removes the raw page analytics linked to your account.

We keep a limited set of records afterwards: purchase and subscription history, kept for tax and accounting; the balance ledger, with its personal details redacted; and anti-abuse flags, including the account ban marker, kept so that a blocked account cannot return by deleting itself. Raw evidence attached to an anti-abuse flag is removed after at most 400 days; the reason and date remain.

Reports of offensive content are kept whether your account filed the report or was the subject of one. A report holds the account reported, the account that reported it, a reason from a fixed list, and the date. This means an account cannot erase a report about it by deleting itself, and a report that was filed is still there to review.

If you bought a subscription, we also keep a keyed one-way reference to the Apple or Google identity that bought it. It is not readable as an email address and is not used to contact you or to rebuild a deleted account. It exists only so that you can restore the subscription you already paid for by signing in again with that same identity. Older unkeyed references are discarded after at most 400 days unless they are used and upgraded first.

A completed account export records that the export occurred and when, without recording the downloaded filename, network address, or device details. Export files describe social and recovery records without revealing another account's concealed internal identifier. An administrator's raw page-analytics export replaces account identifiers with keyed one-way pseudonyms and records which administrator exported the range, when, and how many rows.

Otherwise, we keep data only as long as we need it to provide the service, meet security obligations, and resolve disputes.

Contact

For privacy questions or an access, export, correction, or deletion request, email privacy@steptrove.com.