Privacy Policy
Effective date: 2026-07-23
1. Who we are
StepForge is a platform comprising the Wayfare pedometer app (Android) and the stepforge.pro website (account, forum, app catalog). The data controller (under GDPR) is the individual developer Kanstantsin Tabakmakher. Data questions: stepforgepro@gmail.com.
2. What data we collect
- Account data. The app creates an anonymous account from a random device identifier — no name, email, or sign-up required. If you optionally link Google or Telegram sign-in, we receive your email and display name from that provider (only so you can sign in to the same account on another device).
- Steps and activity data. Step count, distance, active calories, and floors climbed — from your device's step sensor and via Health Connect (Android). This is the app's core data.
- Location (GPS). Only in modes you explicitly enable ("Cycling" mode and the walking route-recording mode), and only while a session is active (app on screen) — to show speed, distance, and draw the route on a map. A recorded route is stored only on your device and is not sent to us. Background location is not collected.
- Technical data. IP address and request-rate counters (abuse protection), app and OS version.
- Crash reports. On a crash, the app may send us a technical report (exception class, stack trace, app/OS version) — without any step, health, or location data.
3. Health Connect — specifically
Wayfare reads these Health Connect data types: steps, distance, active calories, floors climbed. This data is used solely for the app's core function — showing you your activity. We do not use Health Connect data for advertising and do not share it with any third party. You can revoke access at any time in Health Connect settings; the app keeps working from the device sensor.
4. Why we process data, and the legal basis
| Data | Purpose | Basis (GDPR) |
|---|---|---|
| Steps/activity | Show your stats, goal, streaks, history; sync across your devices | Consent (Art. 6(1)(a)) / service provision |
| Account (device id) | Tie your data to you without sign-up | Service provision |
| Email/name (Google/Telegram) | Sign in to the same account on another device | Consent |
| Location (cycling) | Ride speed/distance | Consent |
| Technical/crash | Security, stability, bug fixing | Legitimate interest (Art. 6(1)(f)) |
5. Who we share data with
We do not sell your data and do not share it with third parties for advertising. Your step data is stored on our own servers to sync across your devices, and is not shared with any third-party company or their apps.
Other StepForge apps — only if you connect them yourself. We publish other apps (for example the game Trailforge) built by the same developer as Wayfare. If you explicitly connect such an app, it gets read access to your steps, limited to the scope you approved when connecting. This is not third-party sharing: the data stays with the same operator (see §1) and on the same servers. Nothing is connected automatically — access exists only after an explicit action by you. You can see the list of connected apps and revoke access at any time in the app: Profile → Connected apps.
Sign-in providers (Google, Telegram) process authentication data under their own policies — only if you chose to link such a sign-in.
6. Retention and deletion
- Account and activity data is kept while your account exists.
- Deletion: in the app (Profile → Delete account) and on the website (personal cabinet) you can delete all data or the whole account — personal data is deleted by cascade. You can also delete only activity data and keep the account.
- Technical logs and crash reports are kept no longer than 90 days.
7. Your rights (GDPR)
Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent at any time. Exercise via the app/website settings or stepforgepro@gmail.com. You may lodge a complaint with a supervisory authority (in Poland, UODO).
8. Children
The service is not intended for anyone under 16; we do not knowingly collect their data.
9. International transfers
Sign-in providers (Google, Telegram) may process data outside the EEA under Standard Contractual Clauses or other GDPR-compliant mechanisms.
10. Security
Data transfer is protected by HTTPS. Access tokens are kept in the app's private, sandboxed storage, inaccessible to other apps, and are excluded from backups, device-to-device transfers and crash reports.
11. Changes
On material changes we update the effective date and, where appropriate, notify you in the app.