Last updated: July 2026
StepClimbr ("the app") is a personal goal-tracking application. We take your privacy seriously. This policy explains what data we collect, why we collect it, and how it is stored and used.
We collect only what is necessary to run the app:
We do not collect your phone number, location, contacts, payment information, or any other personal identifiers.
StepClimbr lets you name and describe your own goals and habits in free text. If you choose to enter names or descriptions that reference health-related activities (for example, "Take medication" or "Therapy"), that text is stored the same way as any other goal data. See Data Storage and Security below. We do not analyze, categorize, or infer health information from this text, and we do not use it for any purpose beyond displaying it back to you within the app. You are free to phrase your goals however you like, including avoiding any language you'd consider sensitive.
Your data is used exclusively to operate the app:
We do not use your data for advertising, profiling, or any purpose beyond providing the app's core functionality.
Your data is stored securely using Google Firebase (Firestore and Firebase Authentication), a cloud platform operated by Google LLC. Data is encrypted in transit (TLS) and at rest. Access is restricted so that each user can only read and write their own data.
Google Firebase's privacy practices are governed by Google's Privacy Policy.
We do not sell, rent, or share your personal data with any third parties, except for Google Firebase as described above, which is required to operate the app. No analytics services, advertising networks, or other third-party services have access to your data.
Your data is retained for as long as your account is active. You may delete your account and all associated data at any time from the Profile page within the app. Deletion is permanent and cannot be undone.
StepClimbr is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
If we become aware of a security incident that compromises your personal data, we will assess the risk and, where required by law, notify affected users by email without undue delay, and notify the relevant supervisory authority within the timeframe required by applicable law (for example, within 72 hours under GDPR where feasible).
If you have questions or concerns about this privacy policy or your data, you can reach us at: