Steady.Back

Privacy Policy

Last updated: July 21, 2026

Steady is a pelvic floor training app. The topic is intimate, and we know it. That is why privacy here is not a legal paragraph at the bottom of the page: it is how the product is built. This page explains, in plain language, what data we handle, where it lives, and what you can do about it.

The short version: your training data lives on your device. If you create an account, we sync the bare minimum to a protected database. No ad trackers, no data sales, nothing shared with social platforms or data brokers.

1. Who is responsible for your data

Steady is operated by EcomRules (Switzerland). Privacy contact: info@ecomrules.com.

2. What data we handle

If you use Steady without an account, everything stays in your browser (localStorage), on your device:

  • your answers to the initial safety screening
  • your assigned program and progress (phase, week, completed sessions)
  • training session logs
  • weekly self-reported check-ins (morning wood, perceived control)
  • any pain reports
  • preferences (language, theme, sound, vibration)

This data never leaves your device. We cannot see it. Clear your browser data and it is gone.

If you create an account, the account exists so you do not lose your progress and can train on more than one device. We collect your email (the only identifying detail we ask for: it is used to sign you in with a one-time code and for nothing else, no newsletters unless you explicitly opt in) and your synced training data, that is, the same items listed above, mirrored to our database to keep your devices in step.

Your screening answers and check-ins are self-reported data about your health. Under the GDPR this is special category data (Article 9), and we only process it with your explicit consent, which you give when you register. You can withdraw it at any time by deleting your account: synced data is erased and everything goes back to living only on your device.

What we do NOT collect: name, phone number, location, contacts, photos. No Facebook pixel, no ad trackers, no fingerprinting, no selling or sharing your data for marketing.

3. Why we process it (legal bases)

  • Providing the service (account, sync, your personalized program): performance of a contract, Art. 6(1)(b) GDPR.
  • Health-related data (screening, check-ins): your explicit consent, Art. 9(2)(a) GDPR.
  • Security and abuse prevention (technical authentication logs): legitimate interest, Art. 6(1)(f) GDPR.
  • Payments and tax obligations (once you subscribe to a paid plan): contract and legal obligation.

We do no advertising profiling and make no automated decisions with legal effects on you. The program adapts to your answers, but that adaptation is the service you signed up for, not profiling for anyone else's benefit.

4. Where your data lives and who processes it for us

  • Database and authentication: Supabase. Synced data and your email live on Supabase, protected by rules that let each user read and write only their own rows.
  • Login code emails: Infomaniak (Switzerland).
  • App hosting: Infomaniak (Switzerland).
  • Payments: Stripe (once paid plans go live). Card details go directly to Stripe: we never see or store them. Your bank statement will show the neutral descriptor "STEADY".

These providers process data only on our behalf and on our instructions. Where a provider involves transfers outside the EU or Switzerland, they happen under GDPR safeguards (standard contractual clauses).

5. How long we keep it

  • Data on your device: until you delete it (from the app settings or by clearing browser data).
  • Synced data and email: for as long as your account exists. When you delete your account, we erase your data from our systems within 30 days, except the minimum the law requires us to keep (e.g. billing records, kept for the statutory period).

6. Your rights

If you are in the EU (GDPR) or Switzerland (FADP), you have the right to:

  • know what data we hold about you and get a copy (access and portability)
  • correct it if it is wrong
  • have it erased ("right to be forgotten")
  • restrict or object to processing
  • withdraw consent at any time, without affecting processing that already happened

To exercise any of these, write to info@ecomrules.com. We reply within 30 days. Data on your device you can delete yourself from the app settings; for account and synced-data deletion, write to us and we will carry it out.

If you believe we are mishandling your data, you can lodge a complaint with your supervisory authority (in Switzerland, the FDPIC; in the EU, your national data protection authority). But write to us first: these things almost always get sorted.

7. Cookies and local storage

We use no profiling cookies. Only technical storage, strictly needed to run the app: your authentication session (to keep you signed in) and app state, theme and language (localStorage). That is why there is no cookie banner: there is nothing to consent to.

8. Minimum age

Steady is built for adults. You must be at least 18. We do not knowingly collect data from minors; if we find an account belonging to one, we delete it.

9. Security

Encrypted connections (HTTPS), per-user database access rules (row level security), passwordless sign-in with one-time codes, secrets kept out of the codebase. No system is unbreakable, but collecting almost nothing is the first line of defense: what we do not have cannot leak.

10. Changes to this policy

If we change anything substantial, we will tell you in the app before it takes effect. The date at the top always reflects the current version.

11. Contact

Questions about this policy or your data: info@ecomrules.com.