Last updated: 05/07-18
We respect your privacy, and do a lot to protect it, your trust in us is essential for us. You will always have the option to opt-out, which mean that we will delete your profile, and private information. If you wish to do so, please write to email@example.com
1. How your data is used
We collect data with three goals in mind; (1) to provide you with a great service and (2) to help similar users as you to get value from your anonymized data and (3) to help institutions create initiatives to improve the mental health of their customers/users based on your anonymised and aggregated data. The service was created in collaborating with the highly esteemed institution, Psykiatrifonden (The Danish Mental Health Fund).
The vision of Steps is to make mental health fun, affordable and accessible to everyone. Steps might choose to share data with academic and clinical researchers and other institutions by providing anonymous data. Before Steps provides data for research, the data is anonymized by removing any information that can be used for the identification of individuals. Anonymous data may be used when Steps collaborates with clinical and academic researchers and Steps may publish the results of academic, clinical or internal research in the form of data visualizations or text findings.
Steps might also share anonymised and aggregated data overviews to institutions. Particular those institutions who have a subscription with Steps to gain insight of challenges their populations might have, eg. a university can get insight on their own students. This data will always be delivered anonymised and aggregated and without any details that will enable an institution to point out any user.
All users must comply with our Terms & Conditions: www.godosteps.com/termsandconditions
2. Personal data we collect
“Personal data” includes any information that directly or indirectly identifies you. This includes things like your name, address, email address, messengerID or date of birth.
“Non-personal data” is information that cannot be connected to your identity, e.g. the number of users visiting our services or any other kind of aggregated information.
For the Steps iOS app: If you use the Steps app without creating an account, your profile and data is only stored on your device.
In this instance, Steps receives your anonymized data incl. usage data provided by your device while you are using Steps, such as your IP address, device type and model, or network provider. This helps to identify app malfunctions and helps us further improve the Steps app.
I f you create an account on the Steps app or use the Steps ChatBot then we will collect and store the following data, providing you have entered it into our services:
Profile data including your name, age, gender, primary occupation and email address. You can skip some of this information during setup, so you may have chosen not to provide this.
Your settings data which allows Steps to remember customizations you have made (i.e. which challenges you have saved and completed, customized notifications, etc.) This enables Steps to continue to work the way you want it to, even if you restore Steps from a backup.
If you use the same e-mail or other identifier to log into different channels, eg. the Steps app and the Steps messenger bot, some of your customizations and data can be syncronized for your convenience.
If you have an account with Steps, your data stored on your devices will also be stored on Steps’ servers to provide you with a backup functionality and with additional features within the Steps service.
By creating an account with Steps you agree that:
Steps may store and process personal data you share with Steps in order to provide the Steps service to you. Steps may also store and process this data to improve the services Steps is able to offer. These services include sending you information and reminders featuring personal data through the app or to the email address you shared with Steps.
Steps may use your challenge data to create anonymous information for academic and clinical research purposes, for which Steps warrants that such research data cannot be associated with you as an individual, or identify you in any way.
You may withdraw your consent at any time by requesting that Steps delete your account. To do that, contact firstname.lastname@example.org. You will no longer be able to use the Steps ChatBot but you will be able to continue using the Steps app without an account, but please manually backup your data as this will no longer be stored on Steps’ servers.
Steps does not share your personal data with third party service providers except as required to provide the Steps features you use.
If you recognize a problem with our service and submit a request to email@example.com or through any other means of communication with Steps, we store the communication history as well as the information submitted by you in the course of the communication (e.g. your email address). We do this in order to respond to inquiries and provide support.
When using our website, our web server might collect information such as:
Your IP address
The website from which you were referred to our website (e.g. if you followed a link)
The webpages you are visiting on our website
The browser you are using and its display settings
Your operating system
The date and duration of your visit
Further personal data will only be stored and processed if you voluntarily share it with us, e.g. through a contact form
Steps analyzes website usage data to optimize the site’s content and functionality and to identify technical issues.
3. Data Security
We apply security measures to protect against the misuse, loss and alteration of personal information under our control. Though we cannot ensure or guarantee that misuse, loss or alteration of information will never occur, we use all reasonable efforts to prevent it.
3.1 How Steps stores your personal data
If you have an account with Steps, your personal profile data is stored with us. Your App password is stored using one-way encryption ("hashing" plus “salting”), and it cannot be read by us.
Your data is transmitted between your device and Steps’ servers using HTTPS protocol for encryption. HTTPS is the same technology used to create secure connections for your web browser, and is indicated by a padlock icon in your browser.
3.2 Steps’ best-practice recommendations to protect your data
We believe the biggest threat to the security and privacy of your data is if someone – probably someone you know – gains access to any of your devices. The data you enter into Steps is private and it should stay that way. Below we have outlined some ways to keep your devices secure.
Activate a unique PIN code or activate TouchID/FaceID (iOS) for Steps and Messenger. If you share your device, activating a unique PIN code or TouchID will ensure you are still the only person who can access your Steps data via your phone.
Activate either PIN or TouchID/FaceID (iOS) authentication for your device. This automatically encrypts your Steps data and prevents any person without permission from using your device.
Set up a feature that will allow you to erase all the data from your device, even if it’s been lost or stolen. For iOS, activating this feature is a two-step process: first you need to Activate “Find My iPhone” via iCloud (see instructions on Apple Support pages) and then enable “Erase your device” (see instructions on Apple Support pages).
4. Data transfer outside EU and third party applications
Any personal data collected from you may only be transferred to countries outside the European Union / the European Economic Area (EEA) observing applicable privacy regulation and ensuring that your privacy rights remain protected as per the GDPR law.
4.2 Google Analytics
Google analyzes this information to offer reports for Steps on website usage and online usage of associated services. Google may also transfer this information to third parties either where this is required by law or where third parties are contracted by Google to process data. Google will not allow your IP address to be linked to any other personal data. You can prevent cookies from being installed on your computer by changing your browser settings; however, if you choose to do this, your visit to our website and use of some features may not work. By using Steps’ website, you have consented to have non-personal data used and processed by Google as described above. You can withdraw consent for your data to be collected and processed at any time, but this withdrawal only applies to future activities.
Mixpanel is a business analytics service and company with headquarter in USA, San Francisco. It tracks user interactions in the app to help us identify how to improve our service to each user. Data collected is also used to build custom reports and measure user engagement and retention.
4.4 Messenger bot
If you only use facebook to sign-in to the Steps app, and do not use the Steps facebook bot, your content data is not shared with or stored on facebook's server.
Chatfuel is a bot platform for creating an AI chatbot on Facebook. Steps uses Chatfuel to improve your experience of the Steps bot. Some of the data you enter and recieve thorugh the ChatBot is stored in Chatfuel.
Steps uses a data analysis service operated by Fabric.io for the App. Fabric uses device identifiers that are stored on your mobile device and allow for analysis of your use of the Steps app. For website analysis, Amplitude uses ‘cookies’ (small text files) that are stored on your computer and allow for analysis of your visit to our website. Data concerning your use will be transferred to and stored on a server in the USA operated by Fabric.
You can prevent cookies from being installed on your computer by changing your browser settings; however, if you choose to do this, your visit to our website and use of some functionalities of our service may be impaired. By using our Service, you are deemed to have expressly consented to the use and processing of your data collected by Amplitude as described above.
6. Communications and newsletter activities
Steps uses your personal information, such as your email address, to contact you with messages, emails, and newsletters. These include push notifications and in-app messages, informational content about mental health via email, as well as occasional promotional material that may be of interest to you, also via email.
Such newsletter services are only provided to you if you have signed up for the newsletter service or given your consent for these notifications. You can withdraw your consent at any time by unsubscribing from our newsletter. For providing such services, Steps may forward information such as your email address to third-party providers in order to carry out such newsletter service or notification. Examples of these providers are the Rocket Science Group LLC (“Mailchimp”), seated in Atlanta, USA, which may process your email address, names and usage data to send you informational and occasional commercial content via email;
You can find more information about the Privacy Shield Framework here: https://www.privacyshield.gov/welcome
We do not intentionally gather personal information from visitors who are under the age of 13. If you are under the age of 13, you are not permitted to submit any personal information to us. If we learn that a child under 13 submits personal information to Steps we will attempt to delete the information as soon as possible. If you believe that we might have any personal information from a child under 13, please contact us at firstname.lastname@example.org.
Steps is a company operated by Happy Hamster IVS, a Danish company located in Copenhagen.