Your Data Is Private and Secure

We built SteadiDay™ with privacy as the foundation, not an afterthought. Your data is protected by encryption on your device, in transit, and at rest on our servers.

Last Updated: July 11, 2026

Private by Default

Your data is stored on your phone and encrypted. Optional sign-in syncs securely for backup and sharing.

Encrypted Sync

When You Choose

Sign in to sync medications, tasks, and check-ins securely. Apple Health records stay on your device except for an optional daily step count when caregiver activity sharing is enabled. Account data is not synced unless you sign in.

Never Sold

Your health data is never sold or used for advertising. Daily step counts are shared only when you explicitly enable caregiver activity sharing.

Where Your Data Lives

Data Type Stored On Your Phone Sent to Our Servers
Medications & Schedules✓ Yes, encrypted⚠ Only if signed in — synced securely for backup & sharing
Tasks & Reminders✓ Yes, encrypted⚠ Only if signed in — synced securely for backup & sharing
Check-ins & Activity Summaries✓ Yes, encrypted⚠ Only if signed in — synced securely for backup & caregiver sharing
Trusted Contacts✓ Yes, encrypted⚠ Encrypted temporary safety/check-in records and Twilio message delivery
Location (Safety Sessions)✓ On-device when idle⚠ Latest active-session GPS is stored for the private live link; ended sessions are deleted after about 24 hours
Health Metrics✓ Yes, encrypted⚠ Daily step count only, when caregiver activity sharing is enabled
Food & Water Logs✓ Yes, encrypted✗ Never
Voice Recordings✗ Not saved in SteadiDay's database⚠ Sent to OpenAI; API data may be retained for up to 30 days unless shorter controls apply
Subscription Status✓ Yes, on device⚠ Pseudonymous purchase status and an app user identifier sent to RevenueCat. No health or app-content data included.
Doctor Information✓ Yes, encrypted✗ Never
Insurance Card Details✓ Text only, encrypted✗ Never
Insurance Card & Prescription Photos✗ Not saved in SteadiDay's database⚠ Sent to OpenAI; API data may be retained for up to 30 days unless shorter controls apply

Our Privacy Commitments

What We DO

  • Store data on your device with encryption
  • Encrypt all synced data in transit and at rest
  • Avoid saving source photos or audio in our application database
  • Show generic notifications only
  • Let you export your data anytime
  • Let you request complete account and app-data deletion
  • Share live location only during opt-in Safety Sessions via secure, tokenized links
  • Give you full control over what syncs

What We DON'T Do

  • Send Apple Health records to analytics or advertisers
  • Sell your information
  • Store photos of cards or prescriptions
  • Show sensitive info in notifications
  • Track your personal content, health data, or identifiable behavior within the app
  • Display third-party advertisements
  • Require an account to use the app (sign-in is optional)

A note about analytics

SteadiDay™ collects pseudonymous analytics via Firebase Analytics (app usage events and feature usage patterns) and uses Firebase Crashlytics to identify and fix bugs. This data uses an app-installation identifier and technical device information; SteadiDay does not set your signed-in account ID as the Analytics user ID. Events intentionally exclude health data, medications, tasks, contacts, and content you enter. Our website also uses Google Analytics. For full details, see our Privacy Policy.

How Photo Scanning Works

When you photograph an insurance card or prescription label, here's exactly what happens:

1

Capture

You take a photo with your camera

2

Read

Photo is securely sent to our server for AI text extraction

3

Fill

Form fields are automatically filled

4

Delete

Photo is immediately removed

Important

Photos are sent through our secure server to OpenAI for text extraction. SteadiDay does not save the source image in its application database. OpenAI may retain API inputs and outputs for up to 30 days for service delivery and abuse prevention unless shorter retention controls apply. Only the extracted text you choose to keep (such as a member ID or medication name) is saved in the app.

Built-In Security Features

App Protection

  • PIN code lock (required)
  • Face ID / Touch ID / Fingerprint support
  • Auto-lock after 15 min idle
  • Lock when app goes to background
  • Secure PIN storage (SHA-256 hashed)
  • Sensitive tokens stored in device keychain (iOS) or encrypted storage (Android)
  • Screen capture prevention capability

Privacy Notifications

  • Generic reminder text only
  • No medication names shown
  • No health info in alerts
  • No sensitive data on lock screen
  • Customizable notification content

Compliance & Standards

Our privacy-first approach aligns with major privacy regulations:

Apple HealthKit & Health Connect

Full compliance with Apple's HealthKit guidelines and Google's Health Connect requirements. Health data never shared with third parties.

Healthcare Privacy Best Practices

Follows minimum-necessary data principles. Only essential data stored, no photos retained.

GDPR/CCPA Ready

Export your data anytime. Request complete account and app-data deletion. Full transparency on data use.

Backend & Server Security

When data does leave your device (emergency alerts, synced account data, caregiver sharing), it is protected by multiple layers of security:

Ready to Take Control?

Download SteadiDay™ and keep your health information private and secure.

Download on the App Store