← Legal

Sub-processors

The third parties that process data on our behalf, and what each one sees.

Last updated 16 September 2026

We use a small number of third parties to run Steadyway. Each one processes data only on our instructions and only for the purpose named below. This list is the complete set; if we add one, this page changes and its date changes with it.

Current sub-processors

Provider What it does What it sees
Apple App distribution, in-app purchases, Sign in with Apple. Your App Store account and payment details, which we never receive. An email address or private relay address if you use Sign in with Apple.
Google (Firebase Authentication) Signs you in and issues the token that identifies your account to our servers. An account identifier, the sign-in method, and the email address released by your provider. No logged health data.
RevenueCat Reconciles App Store purchases and tells our servers your subscription status. An account identifier — or, for a purchase made without an account, one RevenueCat generated — and purchase events. No health data.
OVHcloud Hosts the application servers and the database holding the backup copy, on a server in the European Union. Everything described in Health Data, as the operator of the machine it is stored on. Encrypted in transit; not accessed by OVHcloud in the ordinary course.
Cloudflare DNS, TLS and the CDN in front of this website and the sync endpoint. Connection metadata for requests passing through it — IP address, time, page — and the encrypted traffic itself. No stored copy of your entries.

What is not on this list, deliberately

  • No analytics provider. There is no third-party analytics SDK in the app and no analytics script on this website.
  • No advertising network. Steadyway carries no advertising, so there is no ad network, no attribution SDK and no advertising identifier.
  • No font or asset CDN. The typefaces this site uses are served from our own domain, so opening a page here does not announce it to a third party.

Where the data sits

The account backup — everything in Health Data — is stored on a server in the European Union.

Some of the providers above operate internationally, including in the United States. Where personal data is transferred outside the European Economic Area, we rely on the mechanisms those providers offer for such transfers, including the European Commission's Standard Contractual Clauses.

Changes to this list

We will update this page before a new sub-processor begins processing your data. If you would like to be told when it changes, ask through the contact form and we will add you to the notice list.

Questions about this document?

Send us a message, or email [email protected] with the name of this document in the subject line.