Privacy Policy

Privacy Policy

Privacy Policy

Last Updated: July 20, 2026

Controller: Macrosifter LLC, a Delaware limited liability company

1. Scope

This Privacy Policy explains how Macrosifter LLC (“Steady Signals,” “we,” “us”) collects, uses, discloses, and protects personal information through the Steady Signals app, website, support channels, and related services.

Steady Signals is intended for adults age 18 and older in the United States, Canada, United Kingdom, Ireland, Australia, and New Zealand.

2. Information we collect

Account and transaction information

We may collect your email address, optional name, authentication identifiers, country or region, subscription status, purchase identifiers, trial dates, consent records, and account settings. Apple, Google, RevenueCat, and the applicable app store may process payment and authentication information under their own policies. We do not receive full payment-card numbers from app stores.

Sensitive recovery information you choose to provide

We treat recovery entries as sensitive even where a particular law does not classify them as protected health information. This may include:

• steadiness, stress/calm, energy, and sleep check-ins;

• free-text notes, small wins, and post-breathwork journal entries;

• breathwork sessions, reflections, streaks, and reminder preferences;

• recovery context, such as conditions or symptoms you select;

• use of Dizzy Right Now, gentle actions, vestibular rehabilitation resources, and related support tools; and

• trend calculations, clinician-ready summaries, and AI-assisted weekly reflections derived from those entries.

Device, security, and product-use information

We may collect app version, device platform, device identifier generated by the app, time zone, push token, crash information, sync state, security events, and limited product analytics. We design app analytics so they do not contain free-text notes, health values, diagnoses, AI output, or the content of recovery entries.

Website and marketing information

Our public website may use first-party analytics and, with consent where required, advertising or campaign technologies from providers such as Google or Meta. These technologies are limited to general website events such as landing-page, pricing, install, or purchase activity. We do not send app recovery entries, diagnoses, notes, or AI reflections to advertising platforms.

3. How we use information

We use information to:

• create and secure accounts;

• save and synchronize entries across app sessions;

• provide check-ins, breathwork, reminders, streaks, trends, summaries, and exports;

• generate AI-assisted weekly reflections when you enable that feature;

• provide support and respond to privacy requests;

• administer trials, subscriptions, purchases, and entitlement checks;

• send service communications and, where permitted, optional founder notes or product updates;

• diagnose crashes, prevent abuse, monitor reliability, and improve the Service using limited analytics; and

• comply with legal obligations and enforce our agreements.

4. Legal bases for UK, EEA, and similar jurisdictions

Where applicable, we rely on:

• contract to provide the account and features you request;

• explicit consent to process health-related recovery entries and to generate optional AI reflections;

• consent for optional marketing communications and non-essential website advertising technologies where required;

• legitimate interests for narrowly scoped security, fraud prevention, service reliability, and first-party product improvement, balanced against your rights; and

• legal obligations for tax, accounting, consumer, privacy, and security requirements.

You may withdraw consent at any time through Account settings or by contacting us. Withdrawal does not affect processing that was lawful before withdrawal. Required health-data processing must remain enabled to use health-tracking features; you may instead delete your account.

5. AI-assisted reflections

When enabled, Steady Signals sends a structured weekly packet containing check-ins, notes, breathwork and support activity, and derived metrics to an AI model provider to generate your reflection. We do not include your name or email in that packet. AI output is supportive reflection, not medical advice.

We do not permit model providers to use personal entries to train their general models. We retain the generated reflection with your account until you delete it or your account. Any duplicate or temporary AI input retained by our systems is deleted within 30 days.

6. When we disclose information

We disclose information only as needed to service providers acting for us, including providers for:

• authentication and cloud infrastructure (Amazon Web Services/Cognito);

• application database and synchronization (Neon/Postgres);

• AI-assisted reflections (OpenAI);

• subscriptions and purchase verification (RevenueCat, Apple, and Google);

• email and push delivery (Amazon SES and Expo);

• crash reporting, security, and limited first-party analytics; and

• professional advisers, regulators, or authorities where legally required.

We do not sell sensitive recovery information. We do not use it for targeted advertising or disclose it to advertising platforms. We do not train general AI models on your personal entries.

If the business is involved in a merger, financing, acquisition, reorganization, bankruptcy, or asset sale, information may be transferred subject to this Policy and applicable law.

7. International transfers

We primarily host production systems in the United States. If you use the Service from another country, information may be transferred to and processed in the United States. Where required, we use appropriate safeguards such as contractual protections and conduct transfer assessments.

8. Retention

We retain active account and recovery data while your account remains open. When you confirm permanent deletion, we disable cloud access immediately, delete local encrypted data and its key from the device, and begin deleting cloud recovery data. We target completion within 30 days. Encrypted backups may persist until they age out, no later than 90 days.

Additional periods are described in our retention schedule:

• temporary duplicate AI input: no more than 30 days;

• generated AI reflections: until account deletion;

• security and audit logs without health payloads: 180 days;

• analytics without health payloads: 14 months;

• support records: 2 years;

• billing and tax records without health details: 7 years; and

• consent and policy-acceptance evidence: 6 years after account closure.

We may retain a minimal suppression record to honor unsubscribe or deletion choices and information needed to establish, exercise, or defend legal claims. Retained records are restricted from normal product use.

9. Security

We take the security of your information seriously. We use safeguards designed for sensitive information, including encrypted transport, encrypted local SQLite storage with a device-protected key, access controls, row-level database security, server-owned billing and AI records, secrets management, monitoring, and deletion procedures. We regularly review these safeguards as the Service develops. No system is perfectly secure, and we cannot guarantee absolute security.

10. Your choices and rights

Depending on where you live, you may have rights to access, know, correct, delete, restrict, object, withdraw consent, obtain a portable copy, limit certain uses, opt out of marketing, or appeal a decision. California residents may also have rights under the CCPA/CPRA. We do not discriminate for exercising privacy rights.

You can update many settings in Account, prepare a PDF recovery summary, or permanently delete your account in the app. For a structured JSON or similar export, or for another privacy request, email privacy@getsteadysignals.com. We may verify your identity before fulfilling a request. You may use an authorized agent where law permits.

You may complain to your local privacy regulator, including the UK Information Commissioner’s Office, the Irish Data Protection Commission, the Office of the Privacy Commissioner of Canada, the California Privacy Protection Agency, or the Office of the Australian Information Commissioner, as applicable.

11. Communications

Service and security messages are necessary to operate your account. Optional founder notes, product updates, and promotional messages can be disabled at any time. Marketing defaults on only for United States onboarding; it is off by default in Canada, the United Kingdom, Ireland, Australia, and New Zealand. You can unsubscribe through the message or Account settings.

Push notifications are designed not to expose health details on a lock screen. You control push permissions through the app and device settings.

12. Children

The Service is not directed to anyone under 18. If we learn that we collected personal information from a person under 18, we will delete it.

13. Health data breach notices

Where the U.S. Federal Trade Commission Health Breach Notification Rule or another breach-notification law applies, we will investigate and provide notices as required.

14. Changes

We may update this Policy. We will notify you of material changes as required and seek renewed consent where the nature or purpose of sensitive processing materially changes.

15. Contact

Macrosifter LLC 7803 Inception Way San Diego, CA 92108, United States privacy@getsteadysignals.com

© 2026 Steady Signals

Macrosifter LLC