Gildstep Privacy Policy
Last updated: October 4, 2026
Gildstep ("Gildstep," "we," "us," or "our") is operated by [OPERATOR NAME]. This Privacy Policy explains what information we collect when you use the Gildstep mobile app and website (together, the "Service"), how we use it, who we share it with, how long we keep it, and the choices and rights you have.
The short version:
- We collect what you type into the app, plus the basics needed to run your account. We don't use ad networks, advertising IDs, cross-app tracking, or data brokers. Our optional usage analytics and crash reports never include what you write.
- Your goals, check-ins, reflections, One Things, weekly reviews, and settings are private to you. The only things other people can see are what you choose to share on the community Feed and your public profile card.
- We do not sell your personal information, and we don't share it for targeted advertising.
- You can export all of your data or permanently delete your account at any time from Profile → Settings → Data.
1. Information we collect
1.1 Information you give us
| Category | Examples | Where it's used |
|---|---|---|
| Account information | Email address, password (stored only as a secure hash by our authentication provider) | Signing in, account recovery, important service emails |
| Profile information | Display name, username, profile photo, identity statement | Your Profile page. Name, username, and photo also appear on the Feed if you join it. The identity statement is private. |
| Goals and plans | Goal titles, why each goal matters to you (optional), target timeframes, check-in schedule, monthly and weekly plan items, goal status (active, paused, archived, completed) | Tracking your progress |
| Check-ins | Dates you checked in, and any metrics you choose to track: percent complete, numeric values, time spent, effort, difficulty, confidence, mood ratings, and written reflections | Streaks, rates, summaries, milestones |
| Daily "One Thing" | Your daily focus text and whether you completed it | Streaks, XP, milestones |
| Weekly reviews | What went well, what got in the way, next week's focus | Your weekly review and Home screen |
| Community content | Posts you share, the goal and milestone attached to a post, cheers you give, posts you save | The community Feed |
| Friends | Friend requests you send and receive, who your friends are, friends whose post notifications you've muted | Friends features: the Friends list, the Friend tag and Friends filter on the Feed, friend notifications |
| Activity | Notifications we create for you: friend requests, accepted requests, who cheered your posts, friends' milestones, and whether you've read them | Your Activity inbox, the unread badge, and push notifications |
| Finished goals | Goals you finish: when, a snapshot of their numbers (days, check-ins, steps, time logged, best streak), what you wrote about finishing, and who can see the trophy | Your Trophy case. Trophies you share with friends (and their plan outline and check-in dates, never your check-in notes or ratings) are shown to your friends; Only-me trophies to no one |
| Usage analytics (if you leave it on) | Which features you use and when (for example "checked in", "opened a reminder", "finished a goal early"), tied to a random ID that isn't your account, email or username. Never the text of your goals, steps, notes or reflections | Understanding which features help people keep going, so we can improve them. Processed by PostHog (EU). Turn it off in Settings → Privacy → Share anonymous usage data |
| Settings | Reminder times, quiet hours, weekly review preference, default post visibility, "hide streaks", your time zone, and when you finished the intro | Personalizing the app. Your time zone decides when "today" starts for daily limits |
| Premium waitlist | That you asked to be told when Premium launches, and when | Telling you when it launches. Only the count is ever looked at, and it's deleted with your account |
| AI features and plan | Your plan (Free or Premium) and when it changed, how many tries of each AI feature you've used, and each AI response (feedback, goal check, suggested plan) | Showing a response again when you reopen the app, applying your plan's limits (active goals, streak freezes, AI tries), and enforcing daily limits (Section 5) |
| Feedback you send us | Your message, the type (bug, idea, other), an optional screenshot you attach, the app version, and your device's operating system and model | Fixing bugs and improving the app. Linked to your account so we can follow up by email |
| Safety reports and blocks | Posts and people you report, the reason and any details you add; people you block | Reviewing reports, hiding reported posts from you, and keeping you and people you block apart |
| Your agreement | The version of these policies you agreed to, when you agreed, and your confirmation that you meet the minimum age | Recording that you accepted our Terms and this policy |
| Messages to us | Anything you send us by email or support request | Responding to you |
Some of this, like mood ratings and reflections, can be personal. We treat it as private data: it's never shown to other users or shared with anyone, except with the service providers described in Section 4 who store it on our behalf. Gildstep is not a medical or mental-health service, and we don't ask for health diagnoses or medical records. Please don't enter information you wouldn't want stored.
1.2 Information created as you use the app
From your entries, we calculate things like your daily streak, best streak, streak freezes, days active, check-in rates, XP and level, milestones and the dates you unlocked them, and weekly summaries. These are stored or derived from your own data and are private, except as described in Section 3.
Push notifications. If you allow notifications, we store your device's push token and time zone so we can send notifications (friend requests, accepted requests, cheers on your posts, and friends' milestones) from our servers and hold them during your quiet hours. Signing out removes the token for that device; you can turn each kind off in Settings.
Crash and error reports (if enabled in this version of the app). When the app crashes or hits an error, a report is sent to Sentry with technical details: what went wrong in the code, the app version, your device model and operating system, and the screens visited just before. Reports don't include your account ID, email, username, or anything you've written (goal titles, steps, notes, reflections). We remove those before a report leaves your device.
We also store routine technical records needed to run the Service securely, such as when rows were created or updated, sign-in session tokens, and server logs kept by our infrastructure providers (which can include IP addresses, device and browser type, and request times).
- Focus sessions. When you run a focus session, we save which goal (and step, if you started it from one) it was for, the words of the step or One Thing you were working on, the length you chose, when it started and ended, whether it ran to the end, and the minutes counted. The end-of-session notification is scheduled on your device.
- Monthly report image. The share image is made on your device and goes only where you choose to share it.
1.3 Information stored only on your device
- Sign-in session: keeps you logged in.
- Reminder schedule: reminders are scheduled as local notifications on your device.
- Small app preferences: for example, when you tap "Not now" on a "Still working on this?" prompt.
- A copy of your progress: the app keeps the last copy of your goals, plans, check-ins and XP on the device so it opens instantly, then refreshes it. It's removed when you sign out or delete your account.
- Intro progress: while you're going through the intro, your progress is kept on the device so you can pick up where you left off. It's removed when you finish.
This information stays on your device and is removed when you uninstall the app.
1.4 Device permissions
- Photos: only when you choose an image: a profile photo, or a screenshot for feedback you send us. You pick one image and we upload just that image. We don't access the rest of your library.
- Notifications: only if you allow them. They're used for the reminders you configure and for friend notifications. You can turn them off anytime in the app or in your device settings.
We don't access your contacts, precise location, camera, microphone, or health data from other apps.
1.5 What we don't collect
We don't use advertising identifiers, cross-app tracking, or social-media tracking pixels, and we don't buy data about you from other sources. The only analytics is the optional, anonymous usage analytics described above, which you can turn off.
2. How we use information
We use information to:
- Provide the Service. This includes creating your account, saving your goals and check-ins, calculating streaks and stats, showing your Profile, running the Feed, and scheduling your reminders.
- Provide optional AI features (AI feedback, AI goal check, AI plan builder). See Section 5.
- Keep the Service secure. This includes authenticating you, preventing abuse, enforcing our Terms, and debugging problems.
- Communicate with you. This covers account emails (such as confirming an email change or resetting a password) and replies to your messages. We don't send marketing email unless you opt in.
- Comply with law and protect the rights, safety, and property of our users, the public, and Gildstep.
We don't use your data for advertising, and we don't sell it or use it to build profiles for anyone else.
Legal bases (EEA/UK users). We process your information to perform our contract with you (running the Service you signed up for), for our legitimate interests (security, fixing bugs, improving the Service in ways you'd reasonably expect), with your consent (for example, optional AI features, notifications, and photo access, which you can withdraw at any time), and to meet legal obligations.
3. What other people can see
Everything is private by default. Some things become visible to others only through choices you make:
- Public profile card. When you join the community Feed, your display name, username, profile photo, level, current streak, and milestone count become visible to other users. Turn on Settings → Privacy → Hide streaks to keep your streak off your profile and off new posts.
- Posts. A post set to Everyone can be seen by other users together with your public profile card, the goal text and milestone you attached, and your streak at the time (unless hidden). A post set to Friends is visible only to your friends. A post set to Only me is visible only to you. You choose a default in Settings → Privacy and can change it for each post.
- Cheers. Only a post's author sees how many cheers it got. Other users see only whether they cheered it themselves.
- Friends. Friendships are mutual: they exist only when one of you sends a request and the other accepts. Your friends list and friend count are visible only to you. Your friends see a "Friend" tag on your posts, your friends-only posts, and (if they've turned it on) notifications when you post. Declining a request or removing a friend is silent: the other person isn't notified.
- Today's activity. When you check in, other signed-in users may see your name and photo, and be counted, in a line like "Sam and 8 others checked in today" on Home. Your friends may also see whether you've checked in or finished your One Thing today (for example "Sam already finished today's one thing."), and in the evening, if you haven't checked in yet, a friend can send you one "rooting for you" nudge a day. Only public profiles ever appear; turn off Settings → Privacy → Show me in today's activity to stay out of all of it, or Settings → Notifications → Nudges from friends to stop nudges.
- Profile photos are stored at links that anyone with the link can open, because they appear on your public profile card. Only use a photo you're comfortable being public. (Screenshots you send with feedback are private.)
Anything you share publicly can be viewed, and possibly copied, by others. Deleting it from Gildstep removes it from the Service, but we can't control copies other people have already made.
Reports and blocks are private. When you report a post or a person, they aren't told who reported them. When you block someone, they aren't notified. You stop seeing their posts, they can no longer see your profile or posts or send you friend requests, and any friendship or pending request between you ends.
Never shared with other users: your goals list (except goal text you attach to a post), check-ins, metrics, mood ratings, reflections, One Things, weekly reviews, identity statement, email address, and settings.
4. How we share information
We share personal information only in these cases:
Service providers (processors) that host and operate the Service for us, under contracts that limit their use of your data to providing services to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase, Inc. | Database, user authentication, file storage, and server functions (for example, account deletion) | All account and app data described above |
| Anthropic, PBC | Generating optional AI responses (Section 5) | Only when you tap an AI button, and only the text that feature needs (listed in Section 5) |
| Apple / Google | App distribution, and delivering local notifications on your device | Governed by their own privacy policies. We don't send them your app content. |
| [EMAIL PROVIDER] | Sending account emails (sign-up and password-reset codes, email-change confirmations) | Your email address and the email content |
| PostHog, Inc. (EU hosting) | Optional, anonymous usage analytics (Section 1.1) | Event names (e.g. "checked in") with a random ID; never your content. Not sent if you turn it off |
| Functional Software, Inc. (Sentry) | Crash and error reports (Section 1.2) | Technical crash details, app version, device model and OS; no account ID or content |
| Expo (650 Industries, Inc.) | App framework, app build and update delivery, and delivering push notifications (Expo Push Service) | Technical app and update information; for push notifications, your device's push token and the notification text |
Other cases:
- Legal requirements: if we reasonably believe disclosure is required by law, subpoena, or other legal process, or is needed to protect someone's safety, investigate fraud or abuse, or enforce our Terms.
- Business transfers: in a merger, acquisition, financing, or sale of assets, your information may be transferred. We'll notify you before it becomes subject to a different privacy policy.
- With your direction: for example, when you export your data and share the file yourself.
We do not sell personal information or "share" it for cross-context behavioral advertising, as those terms are defined under California law, and we haven't done so in the past 12 months.
5. AI features
Gildstep has six optional AI features. Each runs only when you ask for it (by tapping its button, or by opening a finished month's report on Premium); nothing is sent to an AI provider in the background. Free accounts get a few tries of the first three; the last three are part of Premium, with a set number per goal each week or month.
What each one sends. Our server (not the app) reads only what that feature needs, for that one request, and sends that text to Anthropic's Claude API (Anthropic, PBC), which writes the response:
| Feature | What's sent |
|---|---|
| AI feedback on your One Thing ("Get AI feedback") | The title of the goal your One Thing is for, this month's focus for that goal, this week's steps for it (up to five), and today's One Thing |
| AI goal check ("Check my goal") | The goal's title, timeframe and category, and the first 140 characters of your optional "why" for it |
| AI plan builder ("Build my plan") | The same as the goal check: the goal's title, timeframe, category and the first 140 characters of its "why" |
| Weekly AI coach ("Get my coach review", Premium) | For one goal and the week being reviewed: the goal's title, timeframe and the first 140 characters of its "why"; this month's focus; how many check-ins you made and on which weekdays; minutes you logged (check-ins and focus sessions) and the day with the most; and the titles of that week's steps, done and not done |
| Plan tune-up ("Tune up my plan", Premium) | For one goal and its current plan month: the goal's title, timeframe and the first 140 characters of its "why"; the month's focus and dates; the titles of this month's steps, done and not done, week by week; and how many check-ins you made this month |
| Monthly report reflection (Premium) | For one goal and one finished plan month: the goal's title, timeframe and the first 140 characters of its "why"; the month's focus and the next month's; how many check-ins and active days, your best streak in the month, the weekday you checked in most, minutes logged; and the titles of that month's steps, done and not done |
Your name, username, email, other goals, check-in notes, ratings and reflections are never sent. For the last three features, check-ins are sent only as counts and days, never what you wrote in them.
- Anthropic processes requests on our behalf under its commercial terms, which don't allow it to use API inputs or outputs to train its models. It may retain data briefly for trust-and-safety purposes as those terms describe.
- What we save. We save each response (the feedback and any suggested rewording, with the one thing as you'd written it; the goal check's results and suggested rewrite; the suggested plan; the coach's review and suggested steps; the suggested tune-up; or the month's reflection) with your account, so it's still there when you reopen the app. We also save your plan and how many tries you've used. All of it is deleted with your account.
- Nothing changes unless you choose it. "Use this" replaces your One Thing or goal with the suggestion. A suggested plan is shown for review, and only the months and steps you accept are saved to your goal. The weekly coach's steps are added one at a time, only when you tap Add. A plan tune-up changes nothing until you tap Apply; the steps it replaces are kept, hidden, so Undo tune-up can bring them back, and they're deleted with the goal or your account.
- Not in analytics or crash reports. We never send the text of your goals, your "why," steps, One Thing, or any AI response to analytics or crash reporting. Our logs record only which feature was used, your plan, and whether it worked.
AI responses can be wrong or unhelpful. They're a nudge, not professional advice (see our Terms of Service).
6. How long we keep information
- While your account is open, we keep your data so the app works: your history is what your streaks, stats, and milestones are built from. Archiving or pausing a goal keeps its history; you can delete a goal outright from its edit screen.
- Community posts stay until you delete them or your account. We may also remove older posts that no one has saved, to keep the Feed current.
- When you delete your account (Profile → Settings → Data → Delete account), we immediately and permanently delete your account and all associated data from our live systems. This covers goals, check-ins, One Things, weekly reviews, posts, cheers, saves, milestones, settings, profile, friendships and friend requests, muted friends, notifications, XP history, trophies, AI requests and responses, plan records, feedback you've sent us and its screenshots, push tokens, reports you've filed, people you've blocked, and your uploaded photos. Usage analytics use a random ID that isn't linked to your account, so they can't be traced back to you once your account is gone; we can also delete them on request. Crash reports don't contain your account ID and expire under Sentry's retention period.
- Reported content. When someone reports a post, we keep a copy of that post's text and photo link with the report, so we can review it and act on it even if the post is edited or deleted. These report records are kept for up to [REPORT RETENTION PERIOD]. That's true even if the author deletes their account, though the report is then no longer linked to their account.
- Backups held by our infrastructure provider may retain deleted data for up to [BACKUP WINDOW], after which it's overwritten. We don't restore deleted accounts from backups.
- Server logs are kept by our providers for a limited period for security and troubleshooting.
- Feedback you send us is kept for up to [FEEDBACK RETENTION PERIOD] while your account is open, and deleted with your account.
- We may keep limited information longer if the law requires it, or to resolve disputes and enforce our agreements.
7. Your choices and rights
In the app, available to everyone:
- Access and export: Profile → Settings → Data → Export as JSON (everything) or Export check-ins as CSV.
- Correct: edit your profile, goals, plans, and settings at any time.
- Delete: delete individual goals or posts, or your whole account (Profile → Settings → Data → Delete account).
- Control visibility: choose post visibility (Everyone, Friends, or Only me), hide your streak, stay out of today's activity, or simply don't join the Feed.
- Notifications: turn reminders and each kind of friend notification on or off, mute a friend's posts, set quiet hours, or disable notifications in your device settings.
Depending on where you live, you may also have the right to:
- EEA, UK, and Switzerland: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent at any time. You can also lodge a complaint with your local data-protection authority.
- California and other U.S. states with privacy laws: know or access, correct, delete, and obtain a portable copy of your personal information; opt out of sale, sharing, or targeted advertising (we don't do these); and limit use of sensitive personal information (we use it only to provide the Service). We won't discriminate against you for exercising these rights.
To make a request we can't handle in the app, email support@gildstep.com. We'll verify the request by confirming it comes from your account's email address, and respond within the time required by law (generally 30 to 45 days). You may use an authorized agent where the law allows; we may ask the agent for proof of authority. If we deny your request, you can appeal by replying to our decision.
8. Security
We protect your data with industry-standard measures:
- Encrypted connections (TLS) between the app and our servers.
- Passwords stored only as salted hashes.
- Database rules that restrict each account's private data to that account.
- Storage rules that let you write only to your own folder.
- Account deletion that requires your signed-in session.
No system is perfectly secure, so please use a strong, unique password. If we learn of a security breach affecting your personal information, we'll notify you and the relevant authorities as required by law.
9. Children
Gildstep isn't directed to children. You must be at least 13 years old to use it, or older if your country requires a higher age for consent to data processing (for example, 16 in some EU countries). We don't knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact support@gildstep.com and we'll delete it.
10. International users
We're based in [COUNTRY] and our service providers store data in [DATA LOCATION]. If you use Gildstep from another country, your information will be transferred to, stored in, and processed in those locations. Where required, we rely on appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses.
11. Changes to this policy
We'll update this policy as the Service changes. If we make material changes, we'll notify you in the app or by email before they take effect, and update the "Last updated" date above. Continuing to use the Service after changes take effect means you accept the updated policy.
12. Contact us
Questions, requests, or complaints about privacy:
[OPERATOR NAME] Email: support@gildstep.com Mail: [MAILING ADDRESS]