Privacy Policy
Last Updated: July 11, 2026
Quick Navigation
- 1. Introduction
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Data Storage & Security
- 5. Data Sharing
- 6. Your Privacy Rights
- 7. Apple HealthKit & Health Connect Data
- 8. App Analytics
- 9. Website Analytics
- 10. SMS Text Messaging
- 11. Subscription & Purchase Data
- 12. Children's Privacy
- 13. California Privacy Rights (CCPA)
- 14. GDPR Compliance
- 15. Changes to This Policy
1. Introduction
Welcome to SteadiDay™ ("we," "our," or "us"), operated by SCM Solutions LLC. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we handle your information when you use our mobile application and visit our website.
By using SteadiDay™, you agree to the practices described in this policy.
The short version: Your data is private and secure. Most data stays on your device. If you sign in, some data (medications, tasks, check-ins, and activity summaries) syncs securely for caregiver sharing and account backup. Apple Health and Health Connect records remain on your device, except that your daily step count may be included when you explicitly enable caregiver activity sharing. The app does not require an account or display third-party advertisements. We don't sell your data. We collect limited, pseudonymous analytics and crash reports through Firebase to improve the app. Mobile opt-in data and phone numbers collected for our SMS program will not be shared with or sold to third parties or affiliates for marketing or promotional purposes.
2. Information We Collect
2.1 Health Data
With your explicit permission, SteadiDay™ reads health-related information through Apple HealthKit (iOS) and Health Connect (Android), including:
- Daily step count and activity data
- Exercise minutes and workout information
- Sleep duration and quality metrics
- Heart rate and other vital signs (if shared)
- Nutrition and dietary information (if shared)
- Blood pressure
- Weight
- Walking steadiness (iOS)
Important: Health data from Apple HealthKit and Health Connect is stored locally on your device and protected by your operating system's encryption. We do not transmit health data to our servers or any third parties. Note: If you sign in and enable activity sharing, your daily step count may be included in your activity summary that syncs to our servers — but no other health metrics are synced.
2.2 User-Created Content
Information you enter into the app is stored on your device. If you sign in, some of this data syncs securely to our servers to enable backup, caregiver sharing, and multi-device access:
- Medication schedules and reminders
- Task lists and daily routines
- Emergency contacts and trusted persons
- Food and water intake logs
- Custom notes and reminders
- Medical information and doctor details
- Check-in responses and activity summaries
- Insurance card details (plan name, member ID, group number)
- Medical records (lab results, diagnoses, procedures, allergies)
- Parking spot locations and notes
What syncs when signed in: Medications, tasks, check-ins, and activity summaries are securely synced to our servers (hosted on Supabase) for caregiver sharing, account recovery, and backup. Source photos are not stored in the account-sync database, although a photo is transmitted to our AI provider when you choose a scanning feature. Apple Health records remain on your device except for an optional daily step count when caregiver activity sharing is enabled.
2.3 Photos and AI-Powered Scanning
When you use the camera to scan an insurance card or prescription label:
- The photo is temporarily sent to our secure backend server, which uses OpenAI's vision technology to extract text (such as drug names, dosages, or insurance member IDs)
- The extracted text is returned to the app and used to auto-fill form fields
- SteadiDay does not save the photo to its application database; the temporary request data is released after processing
- Only the typed text (such as your medication name or member ID) is saved in the app
Important: We use OpenAI's API solely to read text from your photos. OpenAI does not use API business data to train its models by default and may retain API inputs and outputs for up to 30 days for service delivery and abuse prevention, unless a shorter retention control applies. SteadiDay does not save the source photo to its application database. See Section 5.2 for more details on our use of third-party services.
2.4 Location Data
If you enable location-based features (such as weather or emergency SOS location sharing), your location is processed on your device. Location data is shared only with your designated emergency contacts in the following cases: (1) when you explicitly trigger the Emergency SOS feature, (2) if fall detection activates and you do not respond within the countdown period, and (3) when you start a Safety Session (see Section 2.5 below). Location data is never shared with advertisers or data brokers.
2.5 Live Location Sharing During Safety Sessions
When you start a Safety Session, SteadiDay may share your real-time location with your designated emergency contacts via a secure, tokenized link. Here is what you should know:
- Opt-in only — Live location sharing begins only when you explicitly start a Safety Session. It is never activated automatically or without your knowledge.
- Who can see your location — Only the emergency contacts you have designated in the app can view your location, and only through a unique, time-limited link that expires when the session ends.
- What is shared — Your approximate GPS coordinates are transmitted to our server and displayed on a map visible to your emergency contacts. No other personal data is included on the shared page.
- Data retention — The server keeps the most recent Safety Session coordinates so the private live link can work. Ended sessions are automatically deleted after approximately 24 hours. Abandoned active sessions expire after seven days and are then deleted by the next cleanup cycle.
- No tracking outside sessions — Outside of an active Safety Session, no location data is transmitted to our servers or shared with anyone. The app does not build a location history or movement profile.
- Background location use (iOS) — While a Safety Session is active, the app uses iOS background location services to continue sharing your position even when the app is not in the foreground. This stops immediately when the session ends.
- Your control — You can end a Safety Session at any time, which immediately stops all location sharing and invalidates the shared link. You can also choose not to use Safety Sessions at all — the rest of the app functions without location access.
2.6 Audio and Voice Input
SteadiDay™ offers optional voice input features (such as voice notes and voice-guided brain games). When you use voice input:
- Audio is recorded temporarily on your device
- The recording is sent to our secure backend server, which uses OpenAI's transcription service (Whisper) to convert speech to text
- The text transcript is returned to the app; SteadiDay does not save the source recording to its application database
- OpenAI may retain API inputs and outputs for up to 30 days for service delivery and abuse prevention, unless a shorter retention control applies
Microphone access requires your explicit permission and can be revoked at any time through your device settings.
2.7 App Analytics and Crash Reporting
SteadiDay™ uses Firebase Analytics and Firebase Crashlytics (provided by Google) to help us understand how the app is used and to identify and fix crashes. This includes:
- App open events and session frequency
- Feature usage patterns (e.g., which features are used most often, but not what you enter into them)
- Crash reports and error logs to help us fix bugs quickly
- General device information (device model, operating system version)
This data is associated with a pseudonymous app-installation identifier and may be associated with technical device information. SteadiDay does not set your signed-in account ID as the Firebase Analytics user ID. Analytics events do not include your health data, medication information, task details, personal contacts, or content you create within the app. See Section 8 for full details.
2.8 What We Do NOT Collect or Display
Except for the limited, optional uses described above, SteadiDay™ does not collect, store, or transmit:
- Apple Health or Health Connect records other than an optional daily step count when caregiver activity sharing is enabled
- Source photos in SteadiDay's application database; a photo is transmitted for scanning only when you choose an AI-powered scanning feature
- Apple advertising identifiers (IDFA) or device fingerprints
- Your biometric data (Face ID, Touch ID, and fingerprint data are handled entirely by your device's operating system and never leave your device)
Note: An account is optional. If you do not sign in, account data is not synced. Optional network features such as AI scanning, SMS alerts, and weather still send the limited information described in this policy when you choose to use them. If you do sign in, only the data described in Section 2.2 is synced.
The app also does not display third-party advertisements. SteadiDay™ contains no banner ads, video ads, sponsored content, or in-app advertising of any kind.
3. How We Use Your Information
Your personal data is used to power the app's features:
- Medication Reminders: Your medication schedules drive local notifications on your device
- Health Dashboard: Apple Health data is read and displayed within the app; only the daily step count can leave the device when you enable caregiver activity sharing
- Task Management: Your tasks and calendar data are processed on-device to show your daily schedule
- Emergency SOS: Your trusted contacts are stored locally and only contacted when you trigger SOS
- Notifications: All reminders are generated locally on your device
- Account Sync: If signed in, medications, tasks, check-ins, and activity summaries sync securely to enable caregiver sharing, backup, and multi-device access
Pseudonymous analytics data (such as app opens and sessions) is used to:
- Understand general app usage patterns (e.g., how often the app is opened)
- Measure the effectiveness of our advertising campaigns
- Help us prioritize improvements to the app
4. Data Storage and Security
4.1 On-Device Storage
Your personal data — including health information, medications, tasks, and contacts — is stored locally on your iPhone, protected by iOS device encryption.
4.2 Account Sync (Optional)
If you create an account and sign in, some data is securely synced to our servers hosted on Supabase (a SOC 2 Type II certified cloud platform):
- What syncs: Medications, tasks, check-ins, and activity summaries
- What does not enter account sync: Apple Health and Health Connect records other than the optional daily step count, source photos, and insurance card details. A source photo is separately transmitted for scanning only when you choose that feature.
- Why: To enable caregiver sharing, account recovery, and multi-device access
- Encryption: All synced data is encrypted in transit (TLS) and at rest
- Your control: You can delete your account and all synced data at any time from within the app
If you do not sign in, account data is not synced. Optional network features such as AI scanning, SMS alerts, and weather still send the limited information described in this policy when you choose to use them.
4.3 App Lock Security
SteadiDay™ includes built-in security features:
- PIN code lock with SHA-256 hashing (stored only on your device)
- Optional Face ID / Touch ID authentication via iOS native security frameworks
- Automatic lock after inactivity and when the app goes to the background
- Generic notification content — no medication names or health details shown on your lock screen
4.4 Data Backup
Your SteadiDay™ data may be included in your standard iPhone backup (via iCloud or iTunes/Finder). This is controlled by your iOS backup settings, not by SteadiDay™. We recommend keeping regular backups to protect against data loss.
5. Data Sharing and Disclosure
5.1 We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information to third parties. Period.
5.2 Third-Party Services
SteadiDay™ uses the following third-party services to provide app functionality:
- Firebase Analytics & Crashlytics (Google): Pseudonymous app usage analytics and crash reporting associated with an app-installation identifier and technical device information. No health data or app content is intentionally included. See Section 8 for details.
- OpenAI: Processes photos of medication labels and insurance cards to extract text, and transcribes voice input to text. SteadiDay does not save source photos or audio to its application database. OpenAI may retain API inputs and outputs for up to 30 days for service delivery and abuse prevention, unless a shorter retention control applies. No Apple HealthKit or Health Connect records are sent to OpenAI.
- Twilio: Delivers emergency SMS text messages to your trusted contacts during SOS and fall detection events, and check-in notifications when you opt in. See Section 10 for details.
- Supabase: Provides secure cloud infrastructure for optional account sync, authentication, and data backup. Supabase is SOC 2 Type II certified. Data synced to Supabase is encrypted in transit and at rest.
- RevenueCat: Manages optional in-app subscriptions. RevenueCat receives pseudonymous purchase data from the App Store or Google Play (such as subscription status, purchase dates, and an app user identifier) but does not receive your health data, medications, or app content.
- Apple Sign-In / Google Sign-In: If you choose to sign in, we receive your name, email address, and profile information from the authentication provider you select. We do not receive your password.
- NPI Registry (CMS) & RxNorm (NLM): Government healthcare databases used for doctor lookup and medication name autocomplete. Search terms you enter (doctor names, drug names) are sent to these public APIs.
- Open-Meteo: Provides weather data for the weather widget. Your city name (from your profile) is sent to this free, open-source weather API. No other personal data is shared.
We do not sell, rent, or trade your personal data to any third party. These services receive only the minimum data necessary to provide their specific functionality.
5.3 Emergency SOS, Fall Detection Alerts & SMS Messaging
When you activate Emergency SOS or when fall detection activates and you do not respond within the countdown period, the app automatically sends SMS text messages to your designated trusted contacts via Twilio, a third-party messaging service. These messages include your display name, GPS coordinates (as a Google Maps link), and an alert that you may need help. SteadiDay temporarily stores encrypted session/contact data to operate the alert and private live link; ended sessions are deleted after approximately 24 hours. Twilio maintains message records according to its own retention settings and legal obligations. Message and data rates may apply. See Section 10 for full details.
5.4 Legal Requirements
Most of your personal data is on your device and not accessible to us. If you have signed in and data has been synced, we may be required to disclose that data in response to valid legal requests. If required by law, we would disclose only the data we maintain (synced account data, safety/sharing records, website contact form submissions, and pseudonymous analytics).
5.5 Business Transfers
In the event of a merger, acquisition, or sale of assets, any data we do hold (synced account data, safety/sharing records, website contact form submissions, and pseudonymous analytics) may be transferred. We will notify you of any such change.
6. Your Privacy Rights
You have direct control over your data:
- Access: All your data is visible to you within the app at any time
- Deletion: Delete any or all data from within the app, or by uninstalling the app. If you have an account, you can delete your account and all synced data from the app settings.
- Export: Export your data from within the app settings
- Revoke Permissions: Withdraw HealthKit access anytime via iOS Settings → Privacy & Security → Health
- Location: Disable location access anytime via iOS Settings → Privacy & Security → Location Services
- SMS: Withdraw consent for emergency SMS messaging by removing trusted contacts or disabling fall detection in the app. See Section 10 for full opt-out details.
For any privacy questions or concerns, please contact us using the information below.
7. Apple HealthKit & Health Connect Data
We comply fully with Apple's HealthKit guidelines and Google's Health Connect requirements:
- Health data is NEVER shared with third parties for advertising or marketing
- Health data is NEVER uploaded to external servers (with the exception that daily step counts may be included in activity summaries synced to our servers if you sign in and enable activity sharing)
- Health data is NEVER included in analytics data sent to Google or any other service
- Health data is used only to display wellness information within the app
- You can revoke health permissions at any time through iOS Settings or Android Settings
- We do not use health data for any purpose other than providing app functionality
- On Android, Health Connect records remain local except that the daily step count may be included when you enable caregiver activity sharing
8. App Analytics
SteadiDay™ uses Firebase Analytics and Firebase Crashlytics (provided by Google) to collect pseudonymous usage data and crash reports. This helps us understand how the app is used, identify and fix bugs, and measure whether our advertising is effective at reaching people who benefit from the app.
8.1 What App Analytics Collects
- A pseudonymous app-installation identifier (not your Apple ID, Google account, or name)
- App open events and session frequency
- Feature usage events (e.g., that a feature was used, but not what you entered into it)
- Crash reports and error logs (via Firebase Crashlytics) to help us identify and fix bugs
- General device information (device model, operating system version)
8.2 What App Analytics Does NOT Collect
- Your health data, medications, tasks, contacts, or any content you create in the app
- Your name, email, phone number, or any personally identifiable information
- Your Apple ID, Google account, or Apple advertising identifier (IDFA)
- Your precise location
- The content of your notes, check-ins, or any text you enter
8.3 SKAdNetwork
SteadiDay™ supports Apple's SKAdNetwork framework, which allows advertising platforms like Google Ads to measure app install attribution in a privacy-safe way. SKAdNetwork is managed entirely by Apple and does not share any personal data with advertisers. It provides only aggregated, anonymous install attribution data.
8.4 Why We Collect This Data
As a small, Virginia-based company, understanding whether people are finding and using our app helps us continue to improve it and reach more adults who could benefit from it. Firebase Analytics and Firebase Crashlytics provide pseudonymous event data and aggregated reporting that help us make informed decisions about app improvements, bug fixes, and advertising effectiveness.
9. Website Analytics
Our website (steadiday.com) uses Google Analytics and Google Ads to understand how visitors find and use our website. This is separate from app analytics.
Website analytics may collect:
- Pages visited and time spent on our website
- How you arrived at our website (search engine, ad click, direct)
- General geographic region (country/city level, not precise location)
- Browser type and device category
This data is anonymized and aggregated. It helps us understand whether our website content is reaching the right audience. It does not include any data from the SteadiDay™ app. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
10. SMS Text Messaging
10.1 SMS Program Description
SteadiDay™ ("the Program") sends emergency SMS text messages to user-designated trusted contacts when the app's fall detection feature activates and the user does not respond within the countdown period, or when the user manually triggers the Emergency SOS feature. Messages are sent on behalf of SCM Solutions LLC via Twilio, a third-party messaging service.
10.2 Consent and Opt-In
By adding a trusted contact and enabling the fall detection or Emergency SOS features within the SteadiDay™ app, you expressly consent to the app sending SMS text messages to your designated trusted contacts on your behalf in emergency situations. This consent is collected in-app at the time you configure your trusted contacts. You may withdraw consent at any time by removing your trusted contacts from the app or by disabling the fall detection feature in app settings.
10.3 Message Frequency
Message frequency varies. SMS messages are sent only during emergency events (fall detection alerts or manual SOS activation). Under normal use, no messages are sent. In an emergency event, each trusted contact will receive one SMS message per incident.
10.4 Message Content
Emergency SMS messages include: the SteadiDay™ program name, the user's display name, a notification that the user may have had a fall or triggered an emergency alert, and the user's GPS location as a Google Maps link so the trusted contact can locate them.
10.5 Message and Data Rates
Message and data rates may apply. SteadiDay™ does not charge for SMS messages, but your mobile carrier's standard messaging rates apply to messages sent from or received on your device.
10.6 Opt-Out
To stop emergency SMS messages from being sent, remove your trusted contacts from the app or disable the fall detection feature. Trusted contacts who receive emergency alerts can reply STOP to the sending number to opt out of future messages from SteadiDay™. For help, trusted contacts can reply HELP or contact us at support@steadiday.com.
10.7 SMS Data Privacy
Mobile phone numbers and opt-in data collected for the SteadiDay™ SMS program will not be shared with or sold to third parties or affiliates for marketing or promotional purposes. Phone numbers are stored locally and may be temporarily stored in encrypted SteadiDay safety/check-in records so alerts can operate. Completed records are automatically deleted after approximately 24 hours; an abandoned active Safety Session may remain for up to eight days. Twilio retains message records according to its account settings and legal obligations.
11. Subscription and Purchase Data
SteadiDay™ offers optional premium subscriptions managed through RevenueCat and processed by the Apple App Store or Google Play Store. If you subscribe:
- Your purchase is processed by Apple or Google — we never receive or store your payment method, credit card number, or billing address
- RevenueCat receives pseudonymous subscription data (subscription status, purchase dates, expiration dates, and an app user identifier) from the app stores to manage your access to premium features
- We store your subscription status locally on your device to unlock premium features
- Subscription data does not include any of your health data, medications, tasks, or personal content
You can manage or cancel your subscription at any time through the App Store or Google Play Store settings on your device.
12. Children's Privacy
SteadiDay™ is designed for adults 50 and older. We do not knowingly collect personal information from children under 13. If we discover that we have collected information from a child under 13, we will delete it immediately.
13. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act. Account sync is optional, but optional network features may process the limited information described in this policy whether or not you sign in. For all data we hold (including synced account data, safety and check-in records, website contact form submissions, and analytics), you have the right to:
- Know what personal information is collected
- Request deletion of personal information
- Opt out of the sale of personal information (we do not sell data)
- Non-discrimination for exercising your rights
14. GDPR Compliance (European Users)
If you are located in the European Economic Area, you have rights under the General Data Protection Regulation. Your on-device data remains under your direct control. For any data we process (including synced account data, safety and check-in records, website data, and pseudonymous app analytics), you have the right to:
- Access, rectification, and erasure of your data
- Restriction of processing and data portability
- Object to processing
- Withdraw consent
- Lodge a complaint with a supervisory authority
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last Updated" date at the top of this page. Your continued use of the app after changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: support@steadiday.com
Contact Form: Send us a message
Company: SCM Solutions LLC, Virginia, USA
Response Time: We aim to respond to all inquiries within 48 hours.