Privacy policy

Last updated: 13 August 2026

StepsMCP is a step counter. This policy explains exactly what it collects, where that lives, and who can read it. Short version: your step data is yours, it is never sold, and you can delete all of it at any time from inside the app.

What we collect

  • Daily step counts, read from Apple Health with your explicit permission. StepsMCP reads step count only. It does not read your workouts, heart rate, sleep, weight, location, or any other health category.
  • Your email address, used solely to sign you in.
  • Subscription status, so we know whether your account has Pro features. Payment itself is handled entirely by Apple — we never see your card details.

The app requests permission to write sample step data only in development builds, so the app can be tested on a simulator. The version published on the App Store never writes to Apple Health.

Where it is stored

Step data is stored in a Supabase (PostgreSQL) database hosted in the United States, and transmitted over HTTPS. Database access is protected by row-level security, which means the database itself enforces that one account cannot read another account's rows.

Who can read it

Only you. Your step history is readable through two paths, both of which you control:

  • The StepsMCP iOS app, while signed in to your account.
  • A personal API key that you generate from your dashboard, if you have a Pro subscription. This is what lets your AI assistant and other MCP clients read your step data on your behalf.

API keys are read-only: a key can retrieve step counts and nothing else. It cannot modify or delete your data, change your subscription, or read your email address. We store only a cryptographic hash of each key, never the key itself, which is why we can only show it to you once. You can revoke any key at any time from your dashboard, and revocation takes effect immediately.

What we never do

  • We never sell your data.
  • We never share health data with advertisers or data brokers.
  • We never use health data for advertising, marketing, or any use-based data mining.
  • We never use your health data for any purpose other than providing StepsMCP back to you.

Notifications

Daily nudges are off by default. If you turn them on, StepsMCP sends two check-ins a day comparing today against your recent average. These are composed and scheduled entirely on your iPhone — your step data is not sent anywhere to generate them, and we do not operate a push server. Step counts are deliberately kept out of notification titles so they don't appear on your lock screen. You can turn them off at any time in Settings.

Deleting your data

Two ways, both immediate and both irreversible:

  • In the app — Settings → Delete account.
  • On the web — your dashboard, under Delete account.

Either one permanently erases your account, your entire step history, your subscription record, and every API key you have created. Deletion cascades at the database level, and the server verifies afterwards that no rows belonging to you remain — if anything survived, you are told so rather than being given a false confirmation.

Deleting the app alone does not delete your cloud data. Use Delete account for that.

Children

StepsMCP is not directed at children under 13 and we do not knowingly collect their data.

Changes

If this policy changes materially, we will update the date above and notify users in the app before the change takes effect.

Contact

Questions about privacy or a data request: privacy@stepsmcp.com