← Legal

Privacy Policy

What Steadyway collects, what stays on your phone, and what reaches our servers.

Last updated 16 September 2026

Steadyway is a tracker for people on a weekly GLP-1 medication. Almost everything you log stays on your iPhone. This policy explains the exceptions: what reaches our servers, why, who else can see it, and what you can ask us to do with it.

Who we are. Steadyway is operated by Amine Kacem PFA, established in București, Romania, which is the data controller for the information described here. For anything in this document, write to [email protected] or use the contact form — a message marked Privacy or my data is flagged as one the moment it arrives.

The short version

  • Your phone holds the original of everything you log. The app reads and writes it there first, and works with no network at all.
  • Nothing reaches us at all until you turn backup on. Steadyway is free and works with no account; if you never connect one, everything in it stays on your phone and this policy has almost nothing to describe.
  • Once backup is on, a copy syncs to our servers so a lost or replaced phone does not mean lost months of data. That copy is a backup, not the thing the app runs on.
  • We do not sell your data, we do not share it with advertisers, and there is no advertising or third-party analytics SDK in the app.
  • You can delete your account from inside the app. That is a hard deletion of the server copy, not a hidden flag.

What we collect

What you log in the app

Weigh-ins, injected doses and injection sites, side effects and their severity, daily entries (water, protein, waist measurement, energy, steps), pens and supply, and your reminder settings. Alongside those, a small profile: a display name if you set one, the date you started treatment, your starting and goal weight, height, current dose, which day you inject, and your preferred units.

This is health information, and it is treated as the most sensitive category of data we hold. See Health Data for exactly how it is stored and synced.

Account information

Setting Steadyway up creates no account. You can install it, log months of data and never give us anything at all. An account is created only when you ask for one, by turning backup and sync on, and that is also the moment any of your logged data first reaches us.

When you do, the app signs you in through Firebase Authentication. We hold an account identifier and, depending on how you sign in, the email address your provider releases to us — which for Apple may be a private relay address. We never receive your password.

Subscription information

Purchases are made through Apple, and we never see your payment details. Our record is limited to your subscription status and its renewal or expiry date, supplied to us by RevenueCat. Steadyway Pro can be bought without an account, in which case that record is attached to an identifier from Apple and RevenueCat and to no person we hold anything else about. See Subscriptions & Refunds.

If you contact us

The form on this site records your name, email address, chosen subject and message, together with the IP address and browser user-agent the request arrived with. The last two exist to deal with spam and abuse; they are deleted with the message.

When you visit this website

There is no analytics on this site, no advertising, no tracking pixel, and no third-party script. The fonts are served from our own domain rather than fetched from a font provider, so loading a page here tells nobody but us that you did.

Two things do happen, and it would be wrong to imply otherwise:

  • Two strictly necessary cookies. A session cookie and a CSRF token cookie are set so the contact form can tell a real submission from a forged one. They carry no identifier we use to recognise you, they expire in a couple of hours, and they are the reason this site has no cookie banner: cookies that exist solely to deliver a page you asked for do not require consent. We set no analytics, advertising or profiling cookies of any kind.
  • Ordinary server logs. Our host and the CDN in front of it record requests — IP address, time, page, user-agent — as every web server does, and keep them briefly for security and to work out why something broke. They are not used to build a profile of you.

What we do not collect

No advertising identifiers, no third-party analytics, no location, no contacts, no tracking across other apps or websites, and nothing that follows you off this site.

Why we hold it, and on what basis

  • To back up your data and restore it — performance of our contract with you. This is the reason we hold your logged data at all, and it only begins when you turn backup on.
  • Health data specifically — your explicit consent, given when you choose to log it. You can withdraw it by deleting your account.
  • To keep the service working and free of abuse — our legitimate interest in a functioning, unspammed service.
  • To meet legal obligations — where a law requires us to keep or produce something.

Who else sees it

Only the processors listed in Sub-processors, each acting on our instructions and for the purpose named there. We do not sell personal data and we do not share it for anyone else's marketing.

On our side, Steadyway is run by one person, and that person is the only one with access to the admin panel that reads the backup copy. It is used to answer support questions and investigate faults — never for any other purpose.

How long we keep it

  • Your logged data and profile — for as long as your account exists.
  • After you delete your account — removed from our live systems immediately. Encrypted backups roll off within 30 days.
  • Contact messages — up to 24 months, so we can pick up a thread you started last year.
  • Server logs — a short operational window, measured in days rather than months.

Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to our use of it, take it elsewhere in a portable form, and withdraw consent. Two of these you can exercise yourself, without asking us:

  • Export — the app writes out a spreadsheet of everything you have logged, notes included. It does not require a subscription and it does not require asking us. (The two-page clinician summary is a separate, paid export, and it is a summary rather than the whole of your data.)
  • Deletion — deleting your account in the app removes your identity at our authentication provider and erases the server copy of your data outright.

For anything else, use the contact form or write to [email protected], and we will answer within 30 days. Exercising any of these rights is free, and we will not treat you differently for it.

If you think we have got this wrong, you can complain to a supervisory authority. Ours is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), dataprotection.ro. If you live elsewhere in the EU or in the UK, you may complain to your own national authority instead. We would rather you told us first, but you are not obliged to.

Security

Data in transit is encrypted with TLS. The server copy sits in a managed database that is not reachable from the public internet, and access to the admin panel is limited to named accounts with their own credentials, entirely separate from app-user accounts. On your phone, the app's database is protected by iOS's own app sandbox and device encryption — which is a good reason to keep a passcode set.

No system is perfect. If a breach ever affects your personal data in a way that puts you at risk, we will tell the supervisory authority within 72 hours of becoming aware of it and tell you without undue delay, as the law requires.

Children

Steadyway is for adults on a prescribed GLP-1 medication and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.

International transfers

Your account data is stored on servers in the European Union. Some of the providers listed in Sub-processors operate internationally, including in the United States. Where personal data is transferred outside the European Economic Area, we rely on the transfer mechanisms those providers offer, including the European Commission's Standard Contractual Clauses.

Changes

If we change this policy we update the date at the top of the page. For a change that materially affects how your health data is handled, we will tell you in the app before it takes effect.

Questions about this document?

Send us a message, or email [email protected] with the name of this document in the subject line.