Privacy Policy
Last updated: June 26, 2026
Stepply AI LTDA ("Stepply", "we", "our", or "us"), located at Av. Ibirapuera, 2120, Conj. 0142, Indianópolis, São Paulo/SP, CEP 04.028-001, Brazil, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our mobile application ("App"), website (https://stepply.ai), and related services (collectively, the "Platform").
By accessing or using our Platform, you agree to the collection and use of information in accordance with this Privacy Policy and our Terms of Service. If you do not agree with this policy, please do not use our Platform.
1. Definitions
- Personal Data: Any information that directly or indirectly identifies a natural person.
- User: A person registered with Stepply to use the Platform.
- Challenge: A goal-based activity created by users or organizations within the App.
- Check-in: A user submission (photo, video, or text) proving participation in a challenge activity.
- Organization: A business entity registered on Stepply to create and manage challenges.
- Device: Any internet-connected device (phone, tablet, computer) used to access the Platform.
- Processing: Any operation performed on personal data (collection, storage, use, sharing, deletion).
2. Information We Collect
2.1 Information You Provide Directly
When you create an account or use the Platform, we collect:
- Full name — Account identification and profile
- Email address — Authentication, communications, account recovery
- Phone number — Account verification and contact
- CPF (Brazilian tax ID) — Financial transactions and legal compliance (PIX payments)
- Date of birth — Age verification and legal compliance
- Mailing address (street, city, state, postal code) — Payment processing and legal compliance
- Profile photo — User profile display
- Biography — User profile display
- Gender — Personalization (optional)
- Language and currency preferences — App localization
- PIX key — Receiving prize payouts (stored with encryption)
2.2 Information Collected Through App Usage
- Check-in photos and videos — Challenge participation verification
- Check-in text descriptions — Activity documentation
- Check-in location — Activity context (when provided)
- Challenge content (titles, descriptions, banners) — Challenge creation and display
- Payment transactions — Ticket purchases, prizes, and payouts
- Wallet balance and transaction history — Financial account management
- Social interactions (follows, join requests) — Social features within the App
- Health and fitness data — Heart rate, active calories, steps, and distance traveled, collected from Apple HealthKit (iOS) and Google Health Connect (Android) only when you grant permission. Workout duration is measured by the App's own timer and the activity type is chosen by you in the App — neither is read from Health Connect
2.3 Information Collected Automatically
- Device platform (Android, iOS, Web) — Push notifications and compatibility
- Push notification token — Delivering notifications to your device
- App usage events — Analytics and service improvement
- Error and crash data — Debugging and stability improvement
2.4 Information from Third Parties
We receive authentication data (email, name) from our identity provider (Clerk) when you create an account or sign in.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Account management: Creating and maintaining your account, authenticating your identity
- Service delivery: Enabling you to create, join, and participate in challenges
- Health data processing: Recording wearable training session results for challenge activity verification and displaying your training progress
- Payment processing: Processing ticket purchases, distributing prizes, and managing payouts via PIX
- AI-powered verification: Analyzing check-in media to verify activity completion (see Section 4)
- Push notifications: Sending relevant updates about challenges, achievements, and social interactions
- Email communications: Sending transactional emails (account-related, challenge updates)
- Analytics: Understanding how the Platform is used to improve the user experience
- Error monitoring: Identifying and fixing bugs and crashes
- Security: Protecting against fraud, unauthorized access, and abuse
- Legal compliance: Fulfilling legal obligations under Brazilian law (LGPD, tax regulations)
4. Artificial Intelligence Processing
We use artificial intelligence to verify check-ins in paid challenges:
- Check-in media analysis: In paid challenges, when you submit a photo or video as a check-in, it may be analyzed by an AI service (currently OpenAI gpt-4o, gpt-5.1 or newer model) to evaluate whether the media is consistent with the claimed activity. The result feeds the participant's integrity score (used for tiebreakers and fraud prevention) and does not add points to the ranking. In free challenges, media is not analyzed by AI.
Important details about AI processing:
- AI analysis is used for activity verification, not for facial recognition or personal identification.
- Data used for the AI analysis is purely related to the check-in -> activity -> challenge sent by the user; no personal data (that can identify a user outside the app) is sent to the AI service, besides possibly an internal user ID.
- The images and video frames sent to OpenAI are processed according to OpenAI's usage policies and privacy policy.
- AI prompts and responses are logged internally for cost tracking and service improvement.
5. Automated Processing
We use automated systems to operate the Platform:
- Background workers: Process push notifications, generate media thumbnails, evaluate check-in media via AI, process challenge start/end events, award badges, and send emails.
- Scheduled jobs: Automatically identify challenges that have started or ended, and remove expired notifications (notifications older than 5 days are automatically deleted).
These automated processes handle your data according to this Privacy Policy and do not involve human review unless required for support or dispute resolution.
6. Third-Party Service Providers
We share data with the following third-party service providers to operate the Platform. Each provider processes data in accordance with their own privacy policy:
- Clerk — User authentication. Data shared: email, name, password (managed by Clerk). Privacy Policy
- Stripe — Credit-card payment processing. Data shared: email, payment method details. Privacy Policy
- AbacatePay — PIX payment processing (ticket purchases, challenge creation fee, and prize payouts). Data shared: name, CPF, PIX key, and transaction data. Privacy Policy
- Amazon Web Services (S3) — Media file storage. Data shared: photos, videos, profile images. Privacy Policy
- Amazon Web Services (SQS) — Message queue processing. Data shared: internal identifiers only. Privacy Policy
- OpenAI — AI analysis of check-in media. Data shared: images and video frames. Privacy Policy
- Resend — Transactional email delivery. Data shared: recipient email address. Privacy Policy
- Expo (Push Notifications) — Push notification delivery. Data shared: device tokens, notification content. Privacy Policy
- Firebase Cloud Messaging — Push notification infrastructure. Data shared: device tokens. Privacy Policy
- Sentry — Error and crash monitoring. Data shared: device info, error stack traces. Privacy Policy
- Vexo Analytics — App usage analytics. Data shared: usage events, obfuscated email. Privacy Policy
We require that all third-party providers handle your data with protections consistent with this Privacy Policy and applicable data protection laws.
7. Data Storage and Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption in transit: All data transmitted between your device and our servers uses HTTPS/TLS encryption.
- Encryption at rest: Sensitive financial data (PIX keys) is encrypted using envelope encryption (AES-GCM with wrapped data encryption keys).
- Authentication security: Passwords and authentication are managed by Clerk, a dedicated identity provider, and are never stored directly by Stepply.
- Cloud storage: Media files are stored in Amazon S3 with access controls.
- Access control: Only authorized personnel and systems can access personal data.
- Secure storage on device: Sensitive data on your device is stored using platform-secure storage mechanisms (Keychain on iOS, Keystore on Android).
While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
8. International Data Transfers
Stepply is based in Brazil. However, some of our third-party service providers operate in other countries, primarily the United States. Your data may be transferred to and processed in countries outside of Brazil, including but not limited to:
- United States: AWS (storage and processing), OpenAI (AI analysis), Stripe (payments), Sentry (error monitoring), Clerk (authentication)
These transfers are made in accordance with applicable data protection laws. We ensure that service providers receiving your data provide adequate levels of data protection consistent with Brazilian law (LGPD) and this Privacy Policy.
9. Data Retention and Deletion
We retain your data as follows:
- Account data — Until you delete your account
- Check-in media (photos, videos) — Until you delete your account
- Health and fitness data — Until you delete your account
- Push notification records — 5 days (automatically deleted)
- Payment transaction records — As required by Brazilian tax law (minimum 5 years)
- AI processing logs — Retained for cost tracking and auditing
- Error/crash logs (Sentry) — According to Sentry's retention policy
Account Deletion
You can delete your account at any time through the App settings. When you delete your account:
- Your personal data is anonymized (name, email, phone, CPF, address, etc. are overwritten)
- Your stored media files (photos, videos) are permanently deleted from cloud storage (AWS S3)
- Your authentication account is deleted from our identity provider (Clerk)
- Your payment customer record is deleted from our payment processor (Stripe)
- Related data (follows, devices, badges, interests, feedback) is deleted
Some data may be retained in anonymized form for legal compliance or in non-erasable backup systems.
10. Your Rights
Under the Brazilian General Data Protection Law (LGPD — Lei n.º 13.709/2018), you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention obligations)
- Portability: Request transfer of your data to another service provider
- Revocation of consent: Withdraw your consent for data processing at any time
- Opposition: Object to data processing that you consider non-compliant with the LGPD
- Information about sharing: Request information about which third parties your data has been shared with
- Information about consent: Be informed about the possibility and consequences of not providing consent
To exercise any of these rights, contact us at the email provided in the "Contact Us" section. We will respond within 15 business days.
For users in the European Economic Area (EEA), we also comply with applicable GDPR requirements. For users in California, we comply with applicable CCPA requirements.
11. Push Notifications
We use push notifications to keep you informed about:
- Challenge updates (start, end, results)
- Social interactions (follow requests, join requests)
- Achievement notifications (badges, rankings)
Push notifications are opt-in — you must grant permission on your device to receive them. You can disable push notifications at any time through your device settings. Push notification tokens are stored to deliver messages and are deleted when you delete your account.
12. Biometric Authentication
The App supports biometric authentication (Face ID, Touch ID, fingerprint) for convenient access. Biometric data is processed and stored entirely on your device by the operating system and is never transmitted to or stored on our servers. We only receive a success/failure result from your device's biometric system.
13. Camera, Microphone, and Media Access
The App requests access to your device's camera, microphone, and photo library for:
- Camera: Taking photos and recording videos for challenge check-ins
- Microphone: Recording audio as part of video check-ins
- Photo library: Selecting existing photos or videos for check-ins, profile pictures, and challenge banners
- Media saving: Saving downloaded media to your device
These permissions are requested at the time of use and can be revoked at any time through your device settings. Media captured through the App may be uploaded to our servers and analyzed by AI as described in Section 4.
14. Health and Fitness Data
The App integrates with Apple HealthKit (on iOS) and Google Health Connect (on Android) to collect health and fitness data for challenge activities. This data is collected only when you explicitly grant permission through your device's health data sharing settings.
Data We Collect
When you allow health data collection, we may collect the following data during your training sessions:
- Heart rate (real-time measurements and session average)
- Active calories burned
- Steps count
- Distance traveled
The workout duration is measured by the App's own timer (not read from Health Connect) and the activity type is chosen by you when starting the workout.
How We Use Health Data
Health and fitness data is used exclusively to:
- Validate and record your participation in challenge activities
- Calculate your score and ranking position (distance, steps, and calories count toward your points)
- Confirm, via heart rate, that the workout came from a wearable — which feeds the integrity score used for tiebreakers and fraud prevention in money-prize challenges
- Display your training session summaries and progress within the App
How We Protect Health Data
- Health data is never sold to third parties — not even in anonymized or aggregated form. Unlike other data, health data is expressly excluded from any sale or licensing of anonymized data
- Health data is never used for advertising or marketing purposes, even when anonymized
- Health data is never shared with third parties for purposes unrelated to the App's core functionality. The numeric health values (heart rate, distance, steps, calories) are not sent to the AI analysis service — only the check-in media (photo/video) is analyzed
- Health data is not used for purposes unrelated to challenge activity verification and progress tracking
- Health data is transmitted to our servers using HTTPS/TLS encryption and stored with the same security measures described in Section 7
Your Control Over Health Data
- You can grant or revoke health data access at any time through your device settings (Settings > Health on iOS; or Settings > Health Connect on Android)
- If you revoke access, the App will no longer collect new health data, but previously collected data will be retained until you delete your account
- Upon account deletion, all health data is permanently deleted along with your other personal data as described in Section 9
Apple HealthKit and Google Health Connect Compliance
Our use of Apple HealthKit and Google Health Connect data complies with Apple's and Google's respective developer guidelines. We do not write data back to HealthKit or Health Connect. Health data collected through these services is handled in accordance with this Privacy Policy and is subject to the same rights described in Section 10.
15. Location Data
The App may request access to your location for providing weather information and local content.
16. Children's Privacy
The Platform is not directed to children under 13 years of age (or under 12 years in Brazil, as per the LGPD and the Brazilian Child and Adolescent Statute — ECA). We do not knowingly collect personal data from children under these ages.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that information.
17. Cookies and Similar Technologies
Our website (https://stepply.ai) may use cookies and similar technologies for:
- Essential cookies: Maintaining your session and authentication
- Analytics cookies: Understanding website usage patterns
The mobile App uses local storage and secure storage for maintaining your session and preferences. You can manage cookie preferences through your browser settings.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Notify you through the App or by email for significant changes
Your continued use of the Platform after changes are posted constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.
19. Governing Law
This Privacy Policy is governed by the laws of the Federative Republic of Brazil, particularly the LGPD (Lei n.º 13.709/2018). Any disputes arising from this policy shall be resolved in the courts of São Paulo, SP, Brazil.
20. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have any concerns about how we handle your data, please contact us:
- Email: [email protected]
- Address: Stepply AI LTDA, Av. Ibirapuera, 2120, Conj. 0142, Indianópolis, São Paulo/SP, CEP 04.028-001, Brazil
For data protection inquiries under the LGPD, you may also contact Brazil's National Data Protection Authority (ANPD) at gov.br/anpd.