Legal
Privacy Policy
Last updated: 2026-08-01
Emberstep (“we”) builds a walking history and achievement app. This policy describes what we collect, what we do not, and how you control your data. It is written for App Store / Play privacy labels as well as the public site at emberstep.app.
Quick facts: core features work offline with no account; Health Connect data never leaves the phone; V1 sign-in is email magic link only (no Apple/Google social login); we do not sell health data or use it for ads.
Health and activity data
On mobile, Emberstep may read steps, distance, floors climbed, and exercise minutes from system health hubs or from archives you import (for example Fitbit Takeout or Apple Health export). Sleep, weight, energy, and workout detail are not requested, not read, not stored, and not uploaded in V1.
Core product features run on-device without an account. Health facts stay on your device unless you explicitly create an Emberstep account and enable the web dashboard, and only cloud-eligible facts are uploaded under our source policy.
Android Health Connect (local only)
Facts derived from Android Health Connect are permanently localOnly in V1. They may power on-device history, badges, streaks, and user-initiated local export, but they are never uploaded to our cloud, never shown on the web dashboard, and never used for cross-device restore. This follows Google Play’s Health Connect policy against using that data to sync across incompatible devices or platforms.
Android web coverage (when you enroll) comes only from archives you import yourself and, if later enabled, Google Health API — never by re-labeling or re-reading Health Connect data into the cloud.
Google Health API and Limited Use
Emberstep may, after OAuth verification and explicit user consent, read day-level activity metrics (steps, distance, floors, and related aggregates needed for the product UI) from the Google Health API / Developer Tools. Tokens stay on the device; we do not run server-side scrapes of your provider account. Until verification and Limited Use disclosure are complete, this integration remains feature-flagged off.
The use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.
In plain terms, that means we:
- Use Google Health API data only to provide or improve user-visible Emberstep features (history, streaks, badges, export, optional web dashboard after consent).
- Do not sell that data, use it for advertising (including personalized or interest-based ads), credit/lending decisions, or medical-device functions.
- Do not transfer it to advertising platforms, data brokers, or information resellers — even if aggregated or anonymized.
- Do not allow humans to read user data except with explicit consent for a specific support need, for security/abuse investigation, to comply with law, or when data is aggregated and anonymized for internal operations under applicable law.
- Request only the minimum day-level scopes needed for product features; we do not store minute-level trajectories as a product warehouse.
What we do not do
- We do not sell health data.
- We do not use health data for advertising.
- We do not build medical scores, readiness scores, or clinical claims.
- We do not upload raw Takeout ZIP files or Apple Health XML to our servers.
Accounts and web
An Emberstep account is optional and created only when you enroll for the web dashboard from the mobile app. V1 sign-in is first-party email magic link only — we do not offer Apple, Google, SIWA, or other third-party identity sign-in. The public marketing site at emberstep.app does not host the product dashboard; signed-in product use is on my.emberstep.app. Unknown emails that were never enrolled on mobile are refused with MOBILE_ENROLLMENT_REQUIRED and never auto-create an empty cloud account from the web alone.
iOS HealthKit day aggregates become cloud-eligible only after you create an account and explicitly agree to cloud sync. Withdrawing consent stops new uploads; it does not wipe facts already on the phone.
Purchases
Subscriptions are processed by Apple App Store or Google Play via RevenueCat. We receive entitlement signals, not your full payment card details. There is no web checkout in V1.
Analytics
Product analytics use a closed event allowlist. We do not send health values, dates of activity, sources, streak lengths, badge identities, or goal numbers to analytics. Autocapture, session replay, and heatmaps are off.
Product analytics and crash diagnostics are separate optional mobile controls, both off until you choose otherwise in onboarding or Data & Privacy. Marketing analytics are anonymous and optional. We do not send health data, account identifiers, archive names, URLs, referrers, or form contents to either provider; crash reports contain only a closed technical failure category.
Export and deletion
Local export of your history is always free and does not require an account or subscription. You may delete your cloud account from the product; local phone data is separate and only erased if you choose a distinct “delete local data” action.
Contact
Privacy questions: see Support on emberstep.app. Domain and mailbox go live with public launch.