Privacy Policy

Privacy Policy

Privacy Policy

Last Updated: August 4, 2026

Controller: Macrosifter LLC, a Delaware limited liability company

1. Scope

This Privacy Policy explains how Macrosifter LLC (“Steady Signals,” “we,” “us”) collects, uses, discloses, and protects personal information through the Steady Signals app, website, support channels, and related services.

Steady Signals is intended for adults age 18 and older in the United States, Canada, United Kingdom, Ireland, Australia, and New Zealand.

2. Information we collect

Account and transaction information

We may collect your email address, optional name, authentication identifiers, country or region, subscription status, purchase identifiers, trial dates, consent records, and account settings. Apple, Google, RevenueCat, and the applicable app store may process payment and authentication information under their own policies. We do not receive full payment-card numbers from app stores.

Sensitive recovery information you choose to provide

We treat recovery entries as sensitive even where a particular law does not classify them as protected health information. This may include:

• steadiness, stress/calm, energy, and sleep check-ins;

• free-text notes, small wins, and post-breathwork journal entries;

• breathwork sessions, reflections, streaks, and reminder preferences;

• recovery context, such as conditions or symptoms you select;

• use of Dizzy Right Now, gentle actions, vestibular rehabilitation resources, and related support tools; and

• trend calculations, clinician-ready summaries, and AI-assisted weekly reflections derived from those entries.

Device, security, product-use, and campaign information

We may collect app version, device platform and model, operating-system version, device identifier generated by the app, AppsFlyer identifier, IP address, time zone, push token, crash information, sync state, security events, and limited product analytics. If you allow campaign measurement, we may also process advertising-attribution information, app opens, successful registration, first onboarding completion, and limited subscription events. On Android, this may include the Google Advertising ID. On iOS, this may include IDFA only when Apple reports tracking permission as authorized.

We design app campaign analytics so they do not contain your name, email address, country, free-text notes, health values, diagnoses, symptoms, check-in answers, breathing activity, AI output, reflections, resources viewed, or onboarding path. Limited subscription events sent by RevenueCat may include a pseudonymous AppsFlyer or RevenueCat identifier, the store product identifier, revenue, currency, and subscription lifecycle state.

Website and marketing information

Our public website may use first-party analytics and, with consent where required, advertising or campaign technologies from providers such as Google or Meta. These technologies are limited to general website events such as landing-page, pricing, install, or purchase activity. We do not send app recovery entries, diagnoses, notes, or AI reflections to advertising platforms.

3. How we use information

We use information to:

• create and secure accounts;

• save and synchronize entries across app sessions;

• provide check-ins, breathwork, reminders, streaks, trends, summaries, and exports;

• generate AI-assisted weekly reflections when you enable that feature;

• provide support and respond to privacy requests;

• administer trials, subscriptions, purchases, and entitlement checks;

• measure which advertising campaigns lead to app installs, completed setup, and paid subscriptions when permitted;

• send service communications and, where permitted, optional founder notes or product updates;

• diagnose crashes, prevent abuse, monitor reliability, and improve the Service using limited analytics; and

• comply with legal obligations and enforce our agreements.

4. Campaign measurement

Steady Signals uses AppsFlyer as a campaign-measurement provider. On the first app launch after installation, AppsFlyer receives one privacy-limited install or first-open signal with advertising-ID collection disabled. We stop the AppsFlyer SDK immediately after that signal. Until you allow campaign measurement, the app sends no AppsFlyer registration, tutorial, session, or purchase events.

If you allow campaign measurement, AppsFlyer may process app launches and generic conversion events for successful account registration and completion of the first Quick Check-In or Dizzy Right Now action. Registration and tutorial events contain no custom parameters. RevenueCat may send AppsFlyer limited subscription lifecycle events, including purchases, trial starts and conversions, renewals, cancellations, expirations, billing issues, refunds, and product changes. Those events may include a pseudonymous AppsFlyer or RevenueCat identifier, the store product identifier, gross revenue, currency, and renewal state. Steady Signals does not manually send client-side purchase events.

On Android, allowing campaign measurement enables Google Advertising ID collection when available. On iOS, we request Apple’s App Tracking Transparency permission after you allow campaign measurement. IDFA is enabled only if Apple reports authorization. If Apple permission is denied or restricted, IDFA remains disabled and AppsFlyer operates under Aggregated Advanced Privacy. Advertising personalization consent is always set to false.

You may decline without losing any feature. You can change the setting later under Account → Data & Privacy. Turning it off stops future AppsFlyer collection from the app, disables advertising-ID collection, and instructs RevenueCat to block future sharing to AppsFlyer. We do not backfill events after re-enabling.

5. Legal bases for UK, EEA, and similar jurisdictions

Where applicable, we rely on:

• contract to provide the account and features you request;

• explicit consent to process health-related recovery entries and to generate optional AI reflections;

• consent for optional campaign measurement, marketing communications, and non-essential website advertising technologies where required;

• legitimate interests for narrowly scoped security, fraud prevention, service reliability, and first-party product improvement, balanced against your rights; and

• legal obligations for tax, accounting, consumer, privacy, and security requirements.

You may withdraw consent at any time through Account settings or by contacting us. Withdrawal does not affect processing that was lawful before withdrawal. Required health-data processing must remain enabled to use health-tracking features; you may instead delete your account.

6. AI-assisted reflections

When enabled, Steady Signals sends a structured weekly packet containing check-ins, notes, breathwork and support activity, and derived metrics to an AI model provider to generate your reflection. We do not include your name or email in that packet. AI output is supportive reflection, not medical advice.

We do not permit model providers to use personal entries to train their general models. We retain the generated reflection with your account until you delete it or your account. Any duplicate or temporary AI input retained by our systems is deleted within 30 days.

7. When we disclose information

We disclose information only as needed to service providers acting for us, including providers for:

• authentication and cloud infrastructure (Amazon Web Services/Cognito);

• application database and synchronization (Neon/Postgres);

• AI-assisted reflections (OpenAI);

• privacy-limited campaign measurement and subscription attribution (AppsFlyer and RevenueCat);

• subscriptions and purchase verification (RevenueCat, Apple, and Google);

• email and push delivery (Amazon SES and Expo);

• crash reporting, security, and limited first-party analytics; and

• professional advisers, regulators, or authorities where legally required.

We do not sell sensitive recovery information. We do not use it for targeted advertising or disclose it to advertising platforms. We do not train general AI models on your personal entries.

If the business is involved in a merger, financing, acquisition, reorganization, bankruptcy, or asset sale, information may be transferred subject to this Policy and applicable law.

8. International transfers

We primarily host production systems in the United States. If you use the Service from another country, information may be transferred to and processed in the United States. Where required, we use appropriate safeguards such as contractual protections and conduct transfer assessments.

9. Retention

We retain active account and recovery data while your account remains open. When you confirm permanent deletion, we disable cloud access immediately, delete local encrypted data and its key from the device, and begin deleting cloud recovery data. We target completion within 30 days. Encrypted backups may persist until they age out, no later than 90 days.

Additional periods are described in our retention schedule:

• temporary duplicate AI input: no more than 30 days;

• generated AI reflections: until account deletion;

• security and audit logs without health payloads: 180 days;

• analytics without health payloads: 14 months;

• AppsFlyer user-level campaign data: up to 24 months, and aggregated campaign reports: up to 25 months;

• support records: 2 years;

• billing and tax records without health details: 7 years; and

• consent and policy-acceptance evidence: 6 years after account closure.

We may retain a minimal suppression record to honor unsubscribe or deletion choices and information needed to establish, exercise, or defend legal claims. Retained records are restricted from normal product use.

10. Security

We take the security of your information seriously. We use safeguards designed for sensitive information, including encrypted transport, encrypted local SQLite storage with a device-protected key, access controls, row-level database security, server-owned billing and AI records, secrets management, monitoring, and deletion procedures. We regularly review these safeguards as the Service develops. No system is perfectly secure, and we cannot guarantee absolute security.

11. Your choices and rights

Depending on where you live, you may have rights to access, know, correct, delete, restrict, object, withdraw consent, obtain a portable copy, limit certain uses, opt out of marketing, or appeal a decision. California residents may also have rights under the CCPA/CPRA. We do not discriminate for exercising privacy rights.

You can update many settings in Account, withdraw campaign measurement or AI consent, prepare a PDF recovery summary, or permanently delete your account in the app. For a structured JSON or similar export, an AppsFlyer access or deletion request, or another privacy request, email privacy@getsteadysignals.com. We may verify your identity before fulfilling a request. You may use an authorized agent where law permits.

You may complain to your local privacy regulator, including the UK Information Commissioner’s Office, the Irish Data Protection Commission, the Office of the Privacy Commissioner of Canada, the California Privacy Protection Agency, or the Office of the Australian Information Commissioner, as applicable.

12. Communications

Service and security messages are necessary to operate your account. Optional founder notes, product updates, and promotional messages can be disabled at any time. Marketing defaults on only for United States onboarding; it is off by default in Canada, the United Kingdom, Ireland, Australia, and New Zealand. You can unsubscribe through the message or Account settings.

Push notifications are designed not to expose health details on a lock screen. You control push permissions through the app and device settings.

13. Children

The Service is not directed to anyone under 18. If we learn that we collected personal information from a person under 18, we will delete it.

14. Health data breach notices

Where the U.S. Federal Trade Commission Health Breach Notification Rule or another breach-notification law applies, we will investigate and provide notices as required.

15. Changes

We may update this Policy. We will notify you of material changes as required and seek renewed consent where the nature or purpose of sensitive processing materially changes.

16. Contact

Macrosifter LLC 7803 Inception Way San Diego, CA 92108, United States privacy@getsteadysignals.com

© 2026 Steady Signals

Macrosifter LLC