Privacy Policy
Last updated: June 29, 2026
Stepfolio is a virtual trading simulator. No real money is ever used, collected, or transferred. All portfolio values and earnings exist only within the game.
1. Data controller
Stepfolio is developed and operated by Artem S., an individual developer based in Poland.
Contact: stepfolio451@gmail.com
When this policy says "we", "us", or "our", it refers to this individual.
This policy is available at https://www.stepfolio.site/privacy and is linked from the Google Play Store listing and from in-app Settings.
Play Console Data safety: this policy is the source of truth for the Play Console Data safety section. Any mismatch between this policy and the Data safety form must be resolved before submitting the app for review.
2. Data we collect and why
The table below maps each data type to its purpose and whether it is transmitted off your device.
| Data type | Purpose | Off-device? |
|---|---|---|
| Email address | Account authentication and support | Yes — Firebase Auth |
| Display name | In-game profile (Google Sign-In only) | Yes — Firebase Auth |
| User ID | Link game data to your account | Yes — our servers |
| Aggregated daily step total | Calculate V-Cash earnings | Yes — our servers only |
| Gameplay events (e.g. trades, check-ins) | Game functionality, analytics to improve the app | Yes — PostHog (pseudonymous) |
| Advertising and device/account identifiers | Non-personalised in-app advertising, ad analytics, and fraud prevention | Yes — Google AdMob |
| Device type and app version | Crash diagnosis and analytics | Yes — PostHog |
| IAP purchase token and product ID | Verify entitlements and unlock purchased in-game content | Yes — Google Play Billing |
3. Health and fitness data — special handling
Step data is treated as sensitive health data. Only an aggregated daily total (a single number) ever leaves your device. Raw per-step records never leave your device.
The app requests read-only access to your step count via Android Health Connect. The pedometer data is processed entirely on your device. At the end of each day, we transmit only the total step count for that day to our servers to calculate your V-Cash reward.
- Raw step records, timestamps, or activity sessions remain on your device and are never transmitted.
- Aggregated daily step totals are stored on our servers only for the duration of the active season plus a 14-day grace period (approximately 44 days), then permanently deleted.
- Step or health data is not shared with PostHog, Google AdMob, or any other third party.
- Step data is never used for advertising or sold.
4. Third-party SDKs — data collected on our behalf
Google Play requires us to disclose data collected by SDKs as if it were our own. The following SDKs are active in the app.
Firebase Authentication (Google LLC)
- Collects: email address, hashed authentication credential, user ID, sign-in method (email/password or Google)
- Purpose: account creation, sign-in, session management
- Not used for advertising or profiling
- Firebase Privacy Policy
Google Sign-In (Google LLC)
- Collects: Google account email, display name, Google profile picture URL, Google user ID
- Purpose: optional sign-in via Google account
- Google Privacy Policy
Google AdMob (Google LLC)
- Collects automatically on the app's behalf: Android Advertising ID, device identifiers, device model and OS version, IP address (used for approximate geolocation), user interactions with ads, app diagnostic information, and fraud-prevention signals
- Purpose: serving non-personalised in-app advertisements, ad analytics, and fraud prevention
- The app requests non-personalised ads only (
requestNonPersonalizedAdsOnly: true). AdMob does not build a personalised profile for Stepfolio users. The Advertising ID is used only for frequency capping and fraud prevention, not for targeting - AdMob does not receive health or step data
- Google Privacy Policy · AdMob data practices
PostHog (PostHog, Inc.)
- Collects: your account user ID (used as the analytics distinct ID), event names (e.g. "daily_checkin", "order_placed", "season_tier_reached"), event timestamps, app version, device type
- In Play Console Data safety terms: this is Analytics — App interactions, linked to user identity, required for app functionality, not shared with third parties
- The user ID linkage is used for product support and improving gameplay only — not for advertising
- Purpose: product analytics to understand how the game is used and improve it
- PostHog does not receive health, step, or financial data
- Data is processed on PostHog's EU-hosted infrastructure
- PostHog Privacy Policy
Android Health Connect (Google LLC)
- Collects: step count (read-only permission)
- Before any step data is read, the app requests your explicit permission via the Android Health Connect system dialog. You can revoke this permission at any time in your device settings under Health Connect → App permissions → Stepfolio
- Raw records remain on-device. Only the aggregated daily total is transmitted to our servers. Revoking permission prevents future step submissions; previously submitted daily totals are retained until account deletion or the end of the season retention window
- No other health data types are requested
- Health Connect overview
Google Play Billing (Google LLC)
- Collects: purchase token, product ID, purchase timestamp
- Purpose: processing in-app purchases of virtual items (Starter Pack, Diamond Bundles)
- We never receive or store payment card details — all payment processing is handled by Google Play
- Google Privacy Policy
Finnhub / Twelve Data (market data providers)
- Used for real-time market price feeds only
- No personal data is transmitted to these services
5. Encryption and security
All data transmitted from the app to our servers — including account information, aggregated daily step totals, and gameplay events — is encrypted in transit using TLS. Credentials are never transmitted in plaintext.
Additional measures include:
- Authentication credentials are managed by Firebase Auth and never stored by us in plaintext
- Access to our backend is restricted to authenticated requests; internal admin endpoints require a separate secret key
- Database access is limited to least-privilege service accounts
No security system is infallible. If you discover a vulnerability, please contact stepfolio451@gmail.com.
6. Data sharing
We do not sell your personal data. Data is shared only with the third-party services listed in Section 4, each strictly for the purpose described. We may disclose data to comply with a legal obligation or to protect our legal rights.
7. Retention periods
Account data
- Email address, user ID, display name — retained for as long as your account is active
- Upon deletion: access is revoked immediately; all personal data is permanently purged from our active systems and processors within 30 days, except where longer retention is required by law
Step data (aggregated daily totals)
- Retained for the duration of the active season (approximately 30 days) plus a 14-day grace period — approximately 44 days in total
- Permanently deleted after the grace period ends, or immediately upon account deletion
Gameplay and analytics events
- Retained on PostHog for up to 12 months, then automatically deleted
IAP purchase records
- Purchase tokens and product IDs retained for the life of the account to verify entitlements
- Deleted upon account deletion. We do not retain independent financial records — payment processing and transaction history are held by Google Play, not by us
8. Your rights and account deletion
You have the right to access or correct your personal data at any time by emailing stepfolio451@gmail.com. We will respond within 30 days.
Account deletion is available in two ways:
- In the app — Settings → Danger Zone → Delete account. Type "Delete" to confirm. Your account access is revoked immediately and all personal data is permanently purged from our systems and processors within 30 days.
- Web request — visit stepfolio.site/delete-account for instructions, including an email option for users who cannot access the app.
Some third-party providers (Firebase, AdMob, Google Play Billing) may offer their own privacy controls for data held under your Google account. However, requests specifically about Stepfolio account data must be directed to us — not to those providers — since we are the data controller for your Stepfolio data.
9. Children
Stepfolio is not directed at children under 13 and is not designed for use by children. We do not knowingly collect personal data from anyone under 13.
The app requires account creation with an email address. The sign-up screen includes an age confirmation: by creating an account you confirm that you are 13 years of age or older. If we discover that a user is under 13, we will delete their account and all associated data promptly without requiring a request.
Parents or guardians who believe a child under 13 has created an account can request deletion by emailing stepfolio451@gmail.com with the subject "Minor Account Deletion". Verification means confirming by email reply that the request comes from a parent or guardian — no additional documentation is required. We will delete the account within 30 days of confirmation.
This app has not enrolled in the Google Play Families policy programme.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. For material changes, we will notify you via an in-app notice or email. Continued use of the app after the effective date of an update constitutes acceptance of the revised policy.
11. Contact
Artem S. — individual developer, Poland
stepfolio451@gmail.com
For data access, correction, or deletion requests, please include "Privacy Request" in your subject line and email from your registered address.