Privacy

Privacy Policy

Last updated: 14 May 2026 · Effective: 14 May 2026

English Deutsch

The short version. Step Town reads the step count from your phone's health system so you can earn coins in a game. We store a small profile (display name, town progress, friends list, gift history) in Firebase so it syncs across devices. We use Firebase Crashlytics to find bugs. We do not run ads, we do not sell data, and we do not share your Health data with anyone for advertising or marketing.

1. Who we are

Step Town is a single-developer project operated as a sole proprietorship by:

Friedrich Henle
Leuchtenberger Kirchweg 50a
40489 Düsseldorf
Germany
Email: henlefreddy@gmail.com

We are the data controller (verantwortliche Stelle) under Article 4(7) GDPR for everything described in this policy.

2. Data we process

2.1 Health data (step count)

On iOS we read your daily step count from Apple HealthKit. On Android we read it from Android Health Connect or the on-device step sensor. We only read the daily step count — we do not read heart rate, sleep, workouts, weight, distance, calories, or any other health record, and we do not write anything back to your health store.

The number of steps you walked each day is then stored in our database as a small record per day (e.g. 2026-05-14: 7,832 steps, 432 coins earned).

2.2 Account data

  • Anonymous user ID generated by Firebase Authentication on first launch.
  • Sign in with Apple or Sign in with Google identifier when you choose to link your account, so your village survives a reinstall or device change. Apple Sign-In gives us a relay email; we never see your real Apple ID email unless you choose to share it.
  • Display name and friend code you create in the app.

2.3 Game data

  • Town Hall level, buildings placed, villager population, coin balance, lifetime steps, lifetime coins.
  • Friends list (the friend codes you have added), pending and claimed gifts, gift counters.
  • A public projection of the above (display name, town hall level, population, friend code) which other signed-in players can see when you become friends or appear in shared leaderboards.

2.4 Diagnostics

  • Crash reports via Firebase Crashlytics: a stack trace, operating system version, device model, app version, and the anonymous user ID at the moment of crash.
  • Server logs for our Cloud Functions (gift sending, account deletion) containing the user ID and the action performed.

2.5 What we do not collect

  • We do not collect your name, email address, phone number, postal address, or any other PII unless you explicitly send it to henlefreddy@gmail.com.
  • We do not collect precise location data.
  • We do not collect contacts.
  • We do not include any advertising SDK and we do not use any analytics SDK for behavioural tracking.

3. Why we process it (legal basis)

  • Performance of a contract (Art. 6(1)(b) GDPR) — to provide the game itself: convert your steps to coins, sync your village across devices, deliver friend gifts. Without this data the app cannot function.
  • Legitimate interest (Art. 6(1)(f) GDPR) — to operate, secure, and improve the service. Crash reports and server logs fall here. Our interest is keeping the app working; the data involved is minimal and you can opt out by uninstalling.
  • Explicit consent for special-category data (Art. 9(2)(a) GDPR) — health data (step counts) is a special category under GDPR. We ask for HealthKit / Health Connect permission inside the app; you can revoke it at any time from your phone's Settings.

4. Service providers we use

To run the app we rely on a small number of processors. We have data processing agreements (DPA) with each of them as required by Art. 28 GDPR.

  • Google Ireland Ltd. — Firebase (Authentication, Firestore database, Cloud Functions, Crashlytics, Cloud Storage). Hosting is on Google Cloud infrastructure (multi-region, currently us-central1 for Cloud Functions; data may also be replicated to other Google regions). Google's terms: firebase.google.com/terms/data-processing-terms.
  • Apple Inc. — HealthKit, Sign in with Apple, App Store. Health data is read on-device and never transmitted to Apple by us. Apple's privacy policy: apple.com/legal/privacy.
  • Google LLC — Android Health Connect, Sign in with Google, Google Play. Google's privacy policy: policies.google.com/privacy.

We do not share your data with anyone else and we never sell data.

5. How long we keep your data

  • Account, game, and friends data: for as long as you keep the app installed and signed in. If you delete your account from inside the app (Settings → Delete Account), all of it is purged from our database within minutes.
  • Crash reports: retained by Firebase Crashlytics for 90 days, then automatically deleted.
  • Server logs: retained for 30 days, then automatically deleted.
  • Backups: Firestore performs internal backups managed by Google with rolling retention up to 7 days, after which deleted data is unrecoverable.

6. Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Rectify inaccurate data (Art. 16). You can change your display name in Settings.
  • Erase your data (Art. 17). Use Settings → Delete Account, or email us.
  • Restrict processing (Art. 18).
  • Data portability (Art. 20) — request a copy of your data.
  • Object to processing based on legitimate interest (Art. 21).
  • Withdraw consent at any time, by disabling HealthKit / Health Connect permission and uninstalling the app.
  • Complain to a supervisory authority. For Step Town this is the data protection authority of the German federal state of North Rhine-Westphalia: Landesbeauftragte für Datenschutz und Informationsfreiheit NRW.

To exercise any right, email henlefreddy@gmail.com. We respond within 30 days.

7. Account deletion

Open the app, tap Settings → Delete Account. We will immediately:

  • Delete your user record, town, buildings, coins, step history, and gift history.
  • Remove your entry from every friend's list.
  • Delete the public profile mirror (display name, town hall level) other players can see.
  • Delete your Firebase Auth account.

If you cannot access the app, email henlefreddy@gmail.com with the friend code visible in your profile and we will delete the account manually.

8. Children

Step Town is rated 4+ on the App Store and PEGI 3 on Google Play. The game does not contain ads, in-app purchases, or open chat. We do not knowingly collect data from children under 13 (under 16 in the EU). If you are a parent or guardian and believe your child has provided data without your consent, email henlefreddy@gmail.com and we will delete the account on receipt.

9. International transfers

Firebase services are operated by Google. Some processing occurs on servers in the United States. Where personal data is transferred outside the European Economic Area, the transfer is covered by Google's EU Standard Contractual Clauses and Google's adherence to the EU–US Data Privacy Framework.

10. Changes to this policy

If we materially change this policy we will update the "Last updated" date at the top and, where required by law, notify you in-app. Continued use of Step Town after a change means you accept the new policy.

11. Contact

Friedrich Henle
Leuchtenberger Kirchweg 50a
40489 Düsseldorf, Germany
henlefreddy@gmail.com