Last updated 31 July 2026

Privacy policy

Steady uses your data to build and store a training block, match completed runs, and show planned-versus-actual reviews. This policy explains what Steady handles and the choices you have.

Who controls your data

Steady is operated by Cyprian Brytan, who is the data controller. Contact cyprianbrytan@gmail.com with any privacy question or request.

Account and training

When you sign in, Steady stores your account ID, email address and sign-in provider details. It stores the race, target, plan, sessions, pace settings, edits and import-review decisions you save.

For Apple sign-in, Steady may store encrypted Apple refresh tokens on its server only so it can revoke Steady’s Apple authorizations when you delete your account. The app cannot access these tokens, and they are deleted with the account.

Website waitlist

The waitlist sends your email address, optional beta-testing choice, and basic campaign, referrer and landing-page attribution to Formspree. Steady uses this to send the promised launch note, contact willing beta testers, and understand how people found the site.

Attribution is read from the current page only when you submit the form; Steady does not persist it in browser storage. Email cyprianbrytan@gmail.com to withdraw or delete a waitlist entry.

Runs and Apple Health

If you enable Apple Health, Steady reads running workouts and normalises their workout ID, name, source and device, start time, time zone, run type, distance, duration, pace, heart rate, cadence, splits and sync-quality metadata. It writes nothing to Apple Health.

Steady does not store routes or GPS traces, and does not request sleep, HRV, readiness or all-day Health data. Apple Health access is optional and can be turned off in Steady or iOS settings.

Details you add

Steady stores details you choose to add to a run: how your legs, breathing and overall effort felt; niggle body part, side, severity and timing; notes; shoe rotation and mileage; and fuel logs.

Plan import

Valid Steady JSON is validated without a model call. If pasted prose cannot be parsed deterministically, only the pasted plan is sent in bounded chunks to the configured parsing provider, Google Gemini or OpenAI. Only the active provider receives a given paste. Steady does not send your identity, activities or training history.

Operational logs exclude prompts, responses, plan titles and notes. The app keeps the current paste and import draft on your device for retry and recovery; saved server records contain the compiled plan and import metadata, not raw model output.

Analytics

When analytics is configured, PostHog receives a pseudonymous account ID, app and device basics, privacy-safe screen names and coarse interaction outcomes. Dynamic activity IDs are removed. Email, plan text, notes and health or workout metrics are not sent as analytics properties. Session replay, touch autocapture and IP-based geolocation are disabled.

The public website uses Vercel Web Analytics for aggregated page, referrer, country, device and browser statistics. Vercel states that this analytics product stores anonymised data and does not use cookies.

Service providers and sharing

Supabase hosts sign-in and saved app records. Apple and Google support sign-in, PostHog provides analytics, Google Gemini or OpenAI provides model-backed plan import, Vercel hosts and measures the public website, and Apple Health supplies runs only when you enable it. Each receives only the data needed for that function.

If you create a share link, anyone with the link can see your first name and the shared race and plan snapshot, but not your email, run history or Health data.

Sale, advertising and security

Steady has no advertising, does not sell your personal data, and does not use Health data for advertising. Saved records are tied to your authenticated account, and Steady uses encrypted network connections and access controls to protect them.

International processing

Steady’s providers may process data in the UK, EEA, United States and other countries. Formspree states that it processes form submissions in the United States and other countries where it operates. Where a transfer requires protection, Steady uses the provider’s applicable data-processing terms and safeguards required by law.

UK and European rights

Where UK or EEA law applies, Steady uses core account and training data to provide the service you requested, consent for the waitlist and optional Health data, and legitimate interests for limited analytics, security and reliability.

Depending on the circumstances, you may ask to access, correct, erase, restrict or receive your data, or object to processing. You can withdraw consent and complain to the UK Information Commissioner’s Office or your local authority. Contact cyprianbrytan@gmail.com to exercise these rights.

Retention and deletion

Steady keeps saved account data while your account is active so the app can sync and review your training. You can initiate deletion of your whole account from Account settings in the app. Account deletion includes associated personal and shared-plan data unless Steady must retain a limited record for legal or security reasons.

Waitlist data is kept until the launch or beta-testing purpose is complete, you withdraw, or it is no longer needed. For help with deletion, access or correction, email cyprianbrytan@gmail.com.

Questions

For any privacy question, email cyprianbrytan@gmail.com.