Who we are
Stappn is provided by Stappn Bilişim Teknolojileri Sanayi ve Ticaret Anonim Şirketi, located at Demetevler Mah. 362. Cad. Elif Sitesi B Blok No: 21 İç Kapı No: 50, Yenimahalle/Ankara, Türkiye ("Stappn", "we", "us"). Stappn Bilişim Teknolojileri Sanayi ve Ticaret Anonim Şirketi is the controller of the personal data described in this policy.
Privacy requests: support@stappn.com
Telephone: +90 533 161 10 00
Scope and intended users
This policy applies to the Stappn mobile app, stappn.com, support services, and related features. Stappn is only for adults aged 18 or older.
Stappn is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. See our Health Notice for important safety information.
Data we collect
We may collect:
• Account data: name, email, Stappn user ID, Apple/Google sign-in identifiers, language, region, and time zone.
• Consumer health and lifestyle data: GLP-1 medication, injection day/time, side-effect and symptom logs, energy/well-being responses, weight, height and body measurements, joint or movement limitations, exercise capacity/history, sleep, stress, goals, and motivation preferences.
• Activity and user content: assigned/completed sessions, duration, skipped movements, workout feedback, water/protein/movement logs, measurements, coach messages, notes, and progress entries.
• Device and technical data: device and OS type, app version, language, time zone, push token, IP address, security events, crash and performance information to the extent collected by our infrastructure.
• Optional connected health data: step or activity data from Apple Health/HealthKit or Android Health Connect only after device permission.
• Subscription data: product ID, transaction reference, entitlement, trial/grace status, and access status received through RevenueCat and the app stores. We do not receive payment card or bank details.
Progress photos that remain only on the device are not collected by Stappn. We will update this policy and obtain required permission before offering cloud upload or backup.
Sources of data
We collect data directly from you; from your app interactions and messages; from device or health services you authorize; from Apple, Google, and the app stores; and from service providers used to operate and secure the app. We explain permission-based access before requesting it.
How and why we use data
We use data to create and secure accounts, authenticate users, provide requested plans and features, personalize movement around user-provided information, display progress, send requested service reminders, administer subscriptions, provide support, prevent fraud, diagnose errors, comply with law, and establish or defend legal claims.
We process consumer health data only for the disclosed Stappn functionality and with affirmative consent where required. We do not use or disclose consumer health data for advertising, data brokerage, or cross-context behavioral advertising. We do not sell consumer health data.
AI processing is subject to separate disclosure and permission. Refusing or withdrawing AI permission disables the AI coach; where offered, a non-AI or generic experience remains available.
AI coach
If you enable the AI coach, we may send the minimum context needed to Anthropic's commercial API, such as injection-cycle information, recent sessions, limitations you reported, and the message you submit. We do not intentionally include your name or direct contact details, although personal information you type into free-form text may be processed.
Anthropic does not use commercial API inputs or outputs to train general models unless the commercial customer opts in. Under standard API terms, content is generally retained for up to 30 days, with exceptions for usage-policy enforcement, security, and legal obligations. AI output may be incomplete or inaccurate and is not medical advice.
International processing
Providers including Supabase, Anthropic, Cloudflare, Expo, Apple, Google, and RevenueCat may process data in the United States and other countries. We use applicable data-processing agreements, standard contractual protections, and other legally recognized safeguards. Where consent is the required transfer mechanism, we request separate, informed permission before the transfer.
Retention
• Account, profile, health, coach, and activity data: while the account is active; deleted from active systems within 30 days after a verified deletion request.
• Backups: deleted through the backup cycle within 7 days.
• Anthropic API content: generally up to 30 days under standard API terms, subject to stated exceptions.
• Support records: 24 months after closure.
• Security and diagnostic logs: 30 days; only relevant records may be retained longer when required for an incident, fraud investigation, legal obligation, or claim.
• Subscription transaction references: for the legally required accounting, reconciliation, or claims period.
When data is no longer required, we delete it or irreversibly de-identify it.
Your rights
Depending on applicable law, you may request access, confirmation, a copy, correction, deletion, restriction, portability, withdrawal of consent, or objection. You may request a list of third parties with whom consumer health data was shared. We do not discriminate against anyone for exercising privacy rights.
Use Profile → Privacy & My Data in the app or contact support@stappn.com. We may verify your identity. To appeal a denied request, email the same address with "Appeal" in the subject line. Authorized agents may submit requests where local law permits and proof of authority is provided.
California residents may exercise applicable rights concerning access, correction, deletion, and sensitive personal information. We do not sell personal information or share it for cross-context behavioral advertising. Washington and Nevada consumers also have the rights described in our separate Consumer Health Data Privacy Policy.
Account deletion
Deleting an account initiates deletion of associated profile, health, coach, measurement, and activity data and is communicated to relevant processors. Limited records may be retained only when legally required. Account deletion does not cancel an App Store or Google Play subscription. See https://stappn.com/account-deletion
Security and breach notice
We use reasonable administrative and technical safeguards, including encryption in transit, restricted access, row-level security, logging, and data minimization. No system is completely secure. If an incident requires notice, we will notify affected individuals and authorities within applicable legal deadlines.
Children
Stappn is only for adults aged 18 or older. We do not knowingly collect data from children. Contact support@stappn.com if you believe a minor has provided data.
Changes
We may update this policy. We will notify users of material changes before they take effect and request renewed permission where required. New data categories or purposes will not be applied retroactively on the basis of an earlier consent.