Skip to main content
DaySteps
  • Individuals Families Clinicians Teachers
  • Routines Daily Tools Insights Connections Classroom Sessions
  • Pricing
  • The Science Resources Team FAQ
  • Contact
Download
  • Who's it for
    • Individuals
    • Families
    • Clinicians
    • Teachers
  • Features
    • Routines
    • Daily Tools
    • Insights
    • Connections
    • Classroom Sessions
  • About
    • The Science
    • Resources
    • Team
    • FAQ
    • Contact
  • Pricing
  • Get the app

Legal

Privacy Policy

Last updated: August 24, 2026

1. About DaySteps and This Policy

DaySteps is a routine management application that helps people with ADHD, autism, and other executive function challenges build calm, consistent daily routines. It is used by adults managing their own days, by parents and guardians supporting their children, and by authorized teachers and care professionals. DaySteps is not a medical device, not a clinical intervention, and does not diagnose or treat any medical or developmental condition. It is a structured daily support application designed to complement professional care.

DaySteps LLC ("DaySteps," "we," "us," or "our") is committed to protecting the privacy of everyone who uses DaySteps — adults and children alike. This Privacy Policy explains how we collect, use, share, and protect personal information for all users of the DaySteps application and website. Section 11 (Children's Privacy) addresses children's information specifically and contains the disclosures required by the Children's Online Privacy Protection Act (COPPA, as amended by the FTC's 2025 Rule), consolidated in one clearly labeled section as permitted by 16 CFR §312.4(d).

This policy is designed to comply with COPPA, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Quebec's Law 25.

Privacy Officer: Michael Kessler | privacy@daysteps.app | daysteps.app

2. Who Uses DaySteps

DaySteps supports four account configurations: Adult, Adult + Teacher, Adult + Care Team, and Child (a parent-managed profile, not a standalone account). Account holders must be at least 14 years old; family members under 14 participate only through a child profile created and consented to by their parent or guardian (see Section 11).

  • Adults using DaySteps for themselves: your own routines, focus timer, to-do lists, mood check-ins, and insights.
  • Parents and guardians: everything above, plus creating and managing child profiles and approving who else may see a child's information.
  • Teachers and care professionals: adult accounts with an added professional surface for classes or clients, connected to a child only with the parent's explicit consent.
  • Children: PIN-gated child mode on a linked device, under a profile their parent controls.

3. Information We Collect From Adults

This section covers information about adult account holders (including teachers and care professionals). Information about children is covered in Section 11.

3.1 Account and Identity

  • Display name and email address.
  • Sign-in credentials: you may sign in with Apple, with Google, or with an email address and password. For email/password accounts, a salted, hashed form of your password is stored by our authentication provider (Supabase Auth) — never in plain text and never in application code. For Apple and Google sign-in, authentication tokens are managed by those providers.
  • Optional profile details: avatar image or color, and — for professional accounts — your professional role, license or credential details, and practice or school name.
  • Terms of Service acceptance (timestamp and version) and your selected plan.

3.2 Subscriptions and Purchases

  • Your subscription tier (Free, Family, or Practice), its expiry date, and whether you hold the one-time Founding Member purchase.
  • A RevenueCat customer identifier (our internal account id) and purchase receipt/entitlement data processed by RevenueCat, our subscription-management provider.
  • Payments are processed entirely by Apple through the App Store. DaySteps never sees or stores your card number or banking details.

3.3 Content and Activity

  • Routines, steps, and schedules you create; to-do items; focus session records; and — if you use them for yourself — your own mood check-ins (including any optional notes you write) and insights data.
  • Onboarding survey answers (role and setup questions you answer when creating your account).
  • Connections you create with other adults (for example, a partner or co-guardian) and the sharing settings for each connection.

3.4 Calendar Integration (Optional)

If you connect Google Calendar or Microsoft Outlook, DaySteps requests read-only access with the minimum necessary scope and imports events into your DaySteps calendar. Imported events (title, times, and related details) are stored as mirror copies in our Canadian database so they can be displayed and scheduled around. Disconnecting the integration stops new imports; stored data is removed with your account.

3.5 Music for the Focus Timer (Optional)

The Focus timer can play music from Spotify instead of the built-in ambient audio. If you choose it, you authorize DaySteps through Spotify once for your whole account. Spotify requires a client secret to exchange and refresh authorization codes, and advises against keeping that secret inside a mobile app, so the exchange runs on our server rather than on your device: the resulting Spotify refresh token is stored on your account record in our Canadian database and your device only ever receives a one-hour access token. That token column carries no read permission for the app or for any signed-in browser session, and writes to it are blocked by a database trigger — a single server-side function is its only reader and writer. We also store your chosen playlist's identifier and name so the picker can show it. Spotify receives your authorization and your playback commands and handles them under Spotify's own privacy policy and terms; DaySteps receives no listening history. Disconnecting Spotify clears the stored token, and it is cleared automatically if Spotify stops accepting it. Deleting your DaySteps account removes it along with the rest of your account record; you can also withdraw DaySteps' access from your Spotify account settings at any time.

3.6 Consent Evidence and Security Records

  • When you give consent (for a child profile, a sharing connection, or the Terms of Service), the consent record captures evidence: timestamp, consent version and text digest, and — on adult records only — IP address, user agent, and a device fingerprint. Records tied to a child never carry this evidence (enforced by a database constraint).
  • Security telemetry: invite-code validation attempts and sign-in rate-limit records (device fingerprint and timestamps), kept for abuse prevention.
  • Push notification delivery: your device's Apple push token (readable only by our backend), and a short-lived delivery-failure log holding hashed tokens, purged after 30 days.

3.7 Website Waitlist and Contact Form

Waitlist. DaySteps was released on the App Store on 10 August 2026. If you joined the waitlist on our website before then, we still hold the email address you submitted.

Contact form. If you write to us through the contact form on our website, we hold the name, email address, role and message you send, and use them only to answer you. Submissions are written by a server-side function and cannot be read back by any browser or app session — including a signed-in one. Row-level security is enabled on that table with no read policy at all, so only our server-side service role can reach them.

You can ask us to delete either at any time (privacy@daysteps.app).

4. How We Use Information

We use personal information only for the purposes below. We do not sell personal information. We do not use personal information for advertising, marketing profiles, or any form of behavioral ad targeting.

  • To deliver the DaySteps service: routines, timers, calendars, to-dos, insights, and coordination between the people you authorize.
  • To operate subscriptions and honor entitlements.
  • To send notifications you or your family configure (see Section 7).
  • To maintain security, prevent abuse, and keep audit records the law requires (including consent records).
  • To comply with legal obligations.

5. How We Share Information

DaySteps does not sell personal information. We share personal information only: (1) within the platform, with people you have explicitly connected or authorized (Section 6 and, for children, Section 11); and (2) with the service providers below, who process data on our behalf under written terms and may not use it for any other purpose.

Category Provider Location Agreement Data Received
Hosting & database Supabase Inc. Canada (ca-central-1, AWS Montreal) DPA executed All application data. Primary data processor. Data stored in Canada. Account and authentication email (sign-up confirmation, password reset) is generated by Supabase Auth and delivered via Resend — see the Transactional email row below.
Crash reporting Sentry (Functional Software, Inc.) United States Data Processing Amendment v5.1.0, signed 2026-05-01 Redacted crash reports. We disable default PII collection and apply key-based redaction before sending, but events may still include device metadata and app breadcrumbs. Retention is managed by Sentry (platform default; not separately configurable on our current plan).
Authentication & push Apple Inc. United States Developer Agreement Authentication tokens and device push tokens (APNs). Routine-tied push payloads may carry a child's first name and routine name in transit through Apple's push infrastructure; lock-screen text is kept generic.
Authentication & calendar Google LLC United States Google API Terms Authentication tokens. If you connect Google Calendar: read-only event data, which is imported and stored in our Canadian database (Section 3.4).
Calendar Microsoft Corporation United States Microsoft API Terms If you connect Outlook: OAuth tokens and read-only event data, imported and stored in our Canadian database (Section 3.4).
Subscriptions RevenueCat, Inc. United States Standard terms (DPA status being confirmed — open item) An internal account identifier and purchase receipt/entitlement data. No name, no email, no card data.
Transactional email Resend, Inc. United States Standard terms (DPA status being confirmed — open item) Recipient email address and account/authentication email content (sign-up confirmation, password reset). Configured as Supabase Auth's SMTP provider (sender noreply@updates.daysteps.app). Transactional account email only; no marketing email.
Website Cloudflare Inc. Global CDN Standard terms Static website content delivery only. No application personal information.
Music for the Focus timer (optional) Spotify AB / Spotify USA Inc. Sweden / United States Spotify Developer Terms (DPA status being confirmed — open item) Only if you connect Spotify to the Focus timer: your authorization and your playback commands, which Spotify handles under its own privacy policy. The resulting refresh token is stored on your account record in Canada, with no read permission for the app or any signed-in browser session and client writes blocked by a database trigger (Section 3.5). DaySteps receives no listening history.

Note: A DaySteps-operated push relay for the optional Follow-Along feature exists in our codebase but is not currently reachable from the shipped app; if and when it is enabled, it will hold push tokens and family/child identifiers, and this policy and our security program will be updated with its hosting details first (open item).

5.1 Legal Requirements

We may disclose personal information if required by law, regulation, court order, or lawful government request. We will notify affected users to the extent permitted by law before making any such disclosure.

6. Role-Based Data Access — Who Sees What

All access to family data is governed by permissions you control, enforced at the database layer via Row-Level Security. The table below describes each role's access as actually enforced. Items marked configurable can be expanded or restricted by the managing parent or guardian at any time.

Role Access (as enforced) Cannot Access
Parent / Guardian Full access to their child's data: routine structure, step-level completions, initiation latency, mood entries, reflection ratings, focus sessions, progression settings, device link status, and all connection approvals. Full administrative control. Other adults' account data. Adults connected to the same child cannot see each other's personal data.
Co-guardian Full access to the shared child's data, equivalent to the inviting guardian, once the guardian approves the connection. The inviting guardian's own adult data; children not shared with them.
Care Team member (clinician, OT, BCBA, school psychologist) With your approval of the connection: routine and step-level completion detail, reflection ratings, initiation-latency data, and progress trends; may submit modification suggestions, which you approve before any change takes effect. Mood entries are visible only when the connection's sharing settings allow it (configurable). Your other family members' data; your account settings and PIN; any data after you revoke the connection. DaySteps holds no clinical or diagnostic records for anyone to access.
Teacher For enrolled students, with your consent: class-routine completion status within a 30-day window and aggregate class rates. Mood entries; reflection entries; personal (non-class) routines; data older than 30 days; any clinical or health-related data.
Observer A today-only view of the specific child's routine activity, when you create an observer connection. Anything beyond the current day; configuration and settings surfaces.
Guest (classroom session — feature designed, not yet launched) Will see a live, read-only, anonymous broadcast of the current routine step. Everything else. No data will be collected; no account will exist.

A note on candor: an earlier version of this policy described care team access as excluding step-level detail and reflection content unconditionally. The enforced database rules grant authorized care team connections that access, with mood entries gated per connection. This version describes the rules as they are actually enforced.

7. Notifications

DaySteps sends notifications to support routines — both local notifications scheduled on the device and, for some features (such as the family inbox), remote push notifications delivered through Apple's push service. All child-facing notification copy is calm, non-punitive, and non-urgent. We never send marketing notifications to children.

  • Notifications fire at the times you or your family configure. DaySteps does not currently apply a quiet-hours window; if a configurable quiet-hours setting ships, it will be under your control, not silently imposed.
  • Approved copy examples: "Time to start your morning routine!" | "[Name], your routine is ready." Forbidden copy: "You're late," "Hurry up," "Don't forget," "You missed," or any language implying failure or urgency.
  • Remote push payloads for routine events may carry the child's first name and routine name in transit through Apple's infrastructure; lock-screen text is kept generic (see Section 5).

8. Data Retention

Our full Written Data Retention Policy describes retention for every data store, honestly including the places where a purge schedule is still an open item. Summary of the main rules:

Data Retention How Deletion Works
Account and family data (routines, completions, mood, reflections, focus sessions, to-dos) Life of the account or child profile Deleting your account starts a 30-day grace period during which you can cancel; a nightly job then permanently deletes. If you are the only guardian of a child profile, deletion is refused until the child's profile is handled first (so a child's records are never orphaned).
Consent records Retained indefinitely as append-only legal records Not deletable from the app by design; references to deleted accounts are severed while the record is retained.
Crash reports (Sentry) Sentry platform default (not separately configurable on our current plan) Managed by Sentry.
Push delivery-failure log 30 days (hashed tokens) Nightly purge.
Invite codes Expire 30 days after issuance Cannot be redeemed after expiry.
Anonymous / abandoned sign-ups Days, not months Nightly cleanup jobs.

There is currently no automated deletion based on account inactivity; if one is introduced, this policy will be updated with advance notice first.

9. Data Security

  • Encryption in transit: TLS 1.3 for all client-to-server communication.
  • Encryption at rest: AES-256 for all data stored in Supabase (AWS ca-central-1).
  • Row-Level Security enforced on all 49 database tables — every request is evaluated against role-based access policies before data is returned.
  • Passwords: email/password accounts are protected by salted password hashing in our authentication layer (Supabase Auth); Apple and Google sign-in credentials never touch DaySteps at all.
  • Child device link uses a cryptographic fingerprint held in the iOS Keychain — it cannot be forged through app preferences.
  • Invite codes are high-entropy, expire after 30 days, and validation attempts are rate-limited.
  • Primary data storage in Canada (Supabase ca-central-1, AWS Montreal).
  • No advertising SDKs, no third-party analytics SDKs, no tracking pixels.

10. Your Rights (All Users)

Right What It Means How to Exercise
Access / Review Request a copy of the data DaySteps holds about you (or your child — Section 11). Email privacy@daysteps.app — response within 30 days.
Correct Correct inaccurate information. In-app Settings, or email privacy@daysteps.app.
Delete Delete your account and associated data. Settings > Delete Account, or email privacy@daysteps.app. A 30-day cancelable grace period applies; permanent deletion follows automatically — no later than 31 days from the request.
Restrict sharing Remove any connection's access — effective immediately. In-app Settings > Connections.
Portability (Quebec) Receive computerized personal information in a structured, commonly used format. Email privacy@daysteps.app.

Quebec users: under Law 25 you also have the right to be informed of, and object to, any automated decision-making. DaySteps does not make automated decisions with legal or similarly significant effects. Canadian users: under PIPEDA you may challenge compliance by contacting the Privacy Officer or the Office of the Privacy Commissioner of Canada.

11. Children's Privacy (COPPA and Law 25)

This section is the children's privacy notice for DaySteps. It consolidates every disclosure specific to children's personal information. For consent purposes, DaySteps treats every family member under 14 as a child — this exceeds COPPA's under-13 scope and matches Quebec Law 25's age of self-consent, applied universally regardless of jurisdiction.

11.1 Pre-Consent Data Rule

Before a parent completes the consent step for a child, DaySteps stores no information about that child. The child's first name (or nickname) and age group entered during setup are held only on the parent's device and are discarded if consent is not completed. No child behavioral or activity data is collected prior to consent.

This rule applies universally. No exception exists for teachers, clinicians, or any other party. DaySteps does not create child profiles on behalf of third parties: only a parent or guardian, on their own device, can create a child profile. Teachers and care professionals can only connect to an existing profile, and only with the parent's separate, explicit sharing consent.

11.2 What We Collect About Children — After Consent Only

  • First name or nickname, and age group (parent-entered; the age group controls the consent path and age-appropriate features). We do not collect your child's last name.
  • Routine structure (configured by the parent, or suggested by an authorized professional and approved by the parent) and routine completion data: which steps were completed, skipped, or not attempted, and when.
  • Initiation latency: time between a scheduled routine start and when the child tapped Start.
  • Mood entries: optional self-reported ratings via illustrated face cards, plus an optional short free-text note in the child's own words about what went well or was hard.
  • Reflection entries: optional post-routine difficulty/affect ratings.
  • Focus sessions (if enabled): when a focus timer was started and finished.
  • To-do items (if enabled) and proposed routine changes (older children, when the parent grants that autonomy level).
  • Avatar configuration, time zone, and (if the parent provides it) grade level.
  • Device identifier: a cryptographic fingerprint stored in the iOS Keychain, used solely to link the child's device to their profile — never for advertising.
  • Progression settings (parent-configured scaffolding levels).

Where it comes from: profile and configuration data is entered by parents. Once a child uses their linked device, some data is generated by the child's own activity — completions, mood entries (including any free-text notes), reflections, focus sessions, and proposed routine changes. All of it is collected under the parent's prior consent, attributed to the child profile the parent controls, and visible to the parent.

DaySteps does NOT collect from or about children: last names, photographs, location data, biometric data, government-issued identifiers, health records, medical history, diagnostic codes (ICD/CPT/DSM), treatment plans, clinical assessment scores, or any health-related clinical data. Entry of clinical or diagnostic data is prohibited by our Terms of Service.

11.3 Verifiable Parental Consent — and the 14+ Path

DaySteps does not collect, use, or share personal information about a child until verifiable parental consent (VPC) is obtained from a parent or legal guardian, in-app, at the moment of profile creation. The consent flow is age-branched:

  • Under 14: full COPPA VPC. The parent reviews a plain-language direct notice before any data entry, then gives explicit checkbox consent. The consent event is written to an append-only consent ledger before the child profile is created — if that write fails, no profile is created anywhere.
  • 14–17 (and adult family members): the parent or account holder records a family-member consent acknowledging data collection. This is not a COPPA VPC — it reflects Quebec Law 25's age of self-consent (14), which DaySteps applies as the universal threshold.

Identity verification uses the email-plus-confirmation method (16 CFR §312.5(b)(2)(iii)): the parent holds an authenticated account — via Sign in with Apple, Google Sign-In, or an email/password account verified by confirmation email — and completes explicit checkbox consent. Consent records capture timestamp, consent version, a digest of the consent text, and (on the parent's records only) supporting evidence; records tied to a child never carry that evidence.

Sharing with a teacher or care professional always requires a separate, specific consent naming that person — consenting to collection never implies consenting to sharing.

11.4 Parental Rights Over a Child's Information

  • Review: request a copy of all data DaySteps holds about your child — email privacy@daysteps.app, response within 30 days.
  • Correct: correct inaccurate information in-app or by email.
  • Delete / refuse further collection: delete the child's profile or your account at any time. Deletion follows the 30-day cancelable grace period described in Section 8, after which removal is permanent.
  • Revoke consent: withdrawing consent is effected by deleting the child's profile or account and follows the same process. Consent records themselves are retained as append-only legal records.
  • Restrict sharing: remove any authorized person's access instantly from Settings > Connections.

11.5 Guest Classroom Mode — Designed for Zero Collection (Not Yet Launched)

A guest classroom mode — in which students view a live, read-only routine broadcast with no account, no name, and nothing retained — has been designed but is not yet launched. It is architected to be COPPA-invisible: because no personal information of any kind would be collected, COPPA's consent requirements would not be triggered. This policy will be updated when the feature ships.

12. COPPA, PIPEDA, and Quebec Law 25

12.1 United States — COPPA

Child profiles on DaySteps are a child-directed portion of a mixed-audience service, and COPPA (as amended by the FTC's 2025 Rule) applies to them. DaySteps obtains verifiable parental consent before any child data is collected and applies its consent threshold at 14 — exceeding COPPA's under-13 requirement. Parents may review, correct, and delete their child's information at any time (Section 11.4).

12.2 Canada — PIPEDA

PIPEDA applies to DaySteps' handling of personal information about Canadian users. DaySteps applies parental consent for all children under 14 — at or above the level suggested by OPC guidance — and applies the same consent requirements universally regardless of jurisdiction.

12.3 Quebec — Law 25 (Compliance Ceiling)

Quebec's Law 25 is the most demanding regime DaySteps operates under, and our architecture is designed against it:

  • Age of consent: 14 — applied universally as DaySteps' consent threshold.
  • Privacy by default: no child data is collected until a parent explicitly creates a profile and consents.
  • Data residency: primary storage in Canada (Supabase ca-central-1, AWS Montreal). Limited cross-border flows to the service providers in Section 5 are disclosed there.
  • Privacy Impact Assessment: in progress — a draft PIA exists and is being finalized before public launch.
  • Privacy Officer: Michael Kessler, privacy@daysteps.app.
  • French-language version: planned; not yet available. This policy will link the French text when it is published.

13. Changes to This Policy

We may update this policy from time to time. For material changes, we will notify users through the app and update the effective date above. For changes materially affecting children's privacy or parental rights, we will provide 30 days' advance notice and, where required, obtain fresh parental consent.

14. Contact

Privacy Officer: Michael Kessler | privacy@daysteps.app | daysteps.app

Privacy Policy Terms of Service Data Retention Policy
DaySteps

A calm external scaffold that compensates for executive-function challenges. Designed with clinicians, built for daily life.

Use Cases

  • Individuals
  • Families
  • Clinicians
  • Teachers

The System

  • Routines
  • Daily Tools
  • Insights
  • Connections
  • Classroom Sessions

About

  • The Science
  • Resources
  • Team
  • FAQ
  • Contact

© 2026 DaySteps LLC · A therapeutic support tool, not a standalone clinical intervention.

Privacy Terms Data Retention