Steady: Stress & HRV Tracker

Privacy Policy

Last updated: September 25, 2026

The short version

  • Your health data never leaves your iPhone. Steady reads it from Apple Health, does all the arithmetic on your iPhone, and stores the results there.
  • There is no account and no server of ours. No sign-up, no password, no cloud sync, nothing for us to look up.
  • What does leave your phone is never health data: your App Store purchase record and Apple Ads attribution, which go to RevenueCat so we can unlock what you paid for and see which of our ads work, and anonymous usage statistics — which screens you opened and which buttons you pressed — which go to PostHog.
  • You can switch usage statistics off in Settings → Privacy and your data.
  • You can export everything and delete everything from the same screen, at any time, without asking us.
  • No ads in the app, no tracking, and nothing sold or shared for anyone else’s marketing.

1. Who we are

Steady is made by Resonance Logic, LLC, a software studio in New York. The app is Steady: Stress & HRV Tracker (“Steady”) for iPhone. This policy covers that app.

You can reach us at steady@rizenhq.com.

2. There is no account and no server of ours

The app has no sign-up, no login, no password and no user profile on any machine we own.

Everything Steady works out and everything you tell it is written to a database inside the app’s own storage on your iPhone: your stress scores and stress periods, recovery scores and the readings behind them, your answers to the questions during setup, your check-ins, context tags, tension ratings, notes, breathing sessions, and your settings.

That database is protected by iOS file encryption and is excluded from iCloud and device backups. It is not synced, not uploaded, and not readable by us. We chose to exclude it from backup on purpose: we would rather you lose a history than have it copied somewhere you did not choose.

We cannot read it, and we cannot recover it. Deleting the app deletes it.

Two small things are kept outside that database, in ordinary app storage that iOS includes in your iPhone’s backups (and in iCloud Backup, if you use it): the summary the Home Screen widget shows — today’s stress score, its band and the day’s stress periods — and the random usage-statistics identifier described in section 6.

3. Apple Health (HealthKit)

With your permission, Steady reads the following from Apple Health:

  • heart rate, and the beat-to-beat (heartbeat series) data behind it
  • heart rate variability (SDNN)
  • resting heart rate
  • respiratory rate
  • wrist temperature during sleep
  • sleep, including stages when your Watch records them
  • steps and active energy
  • workouts
  • mindful minutes

It uses them to build your own baseline, work out your stress score through the day and your recovery score in the morning, and leave out readings that would be misleading — during and after a workout, while you are moving, or while you are asleep.

Writes: one thing only. The breathing and relaxation sessions you finish are saved to Apple Health as Mindful Minutes. Steady asks for that separately, the first time you finish a session. It never writes heart rate, heart rate variability or any figure of its own into Health.

Health data is never sent to us, to our analytics provider, or to any third party. It is never used for advertising, marketing or data mining. It is read, processed and stored on your iPhone only.

You can change what Steady may read at any time in iOS Settings → Health → Data Access & Devices → Steady.

4. What Steady does not access

Steady has no access to your camera, microphone, contacts, photos, calendar or location, and asks for none. It never guesses what you were doing: when it asks what was happening during a stress period, you pick from a fixed list, and the answer stays on your iPhone.

5. Purchases — RevenueCat

Subscriptions and the lifetime purchase are sold by Apple through the App Store. Apple takes the payment. We never see your card number, your billing address, your Apple Account, your name or your email.

To unlock and restore what you bought, we use RevenueCat, Inc. as our processor. RevenueCat receives from your iPhone:

  • a random identifier generated on your phone, not linked to you;
  • the App Store transaction: which product, when, in which currency, when it expires, whether it renewed or was refunded, and the country of your App Store storefront;
  • your device type, iOS version and app version;
  • the random identifier our usage statistics use (section 6), so we can see how many people who reached the subscription screen started a trial. If you turn usage statistics off, this is not sent.
  • an attribution token from Apple. RevenueCat exchanges it with Apple to learn whether you installed Steady after seeing one of our Apple Ads on the App Store, and if so which campaign, ad group and search keyword. It contains no advertising identifier and needs no tracking prompt. It is sent once per install whether or not usage statistics are on, because it describes how the app was found, not how you use it.

Apart from the technical details every internet connection carries, such as your IP address, that is the complete list. RevenueCat never receives anything derived from your health data.

RevenueCat also reports purchase events — a trial started, a subscription renewed or was cancelled — to our usage statistics (section 6), with the Apple Ads campaign information above. While usage statistics are on, those events are filed under your usage-statistics identifier. While they are off, they are still reported, but under RevenueCat’s own random identifier, so they are not connected to your usage statistics.

You can manage or cancel a subscription in iOS Settings → Apple Account → Subscriptions. Refunds are handled by Apple, not by us.

6. Anonymous usage statistics — PostHog

Unless you turn it off, Steady sends anonymous product analytics to PostHog (US cloud, us.i.posthog.com) as our processor, so we can see which parts of the app people use and where things go wrong.

Who it says you are

A random identifier created on your phone the first time you open Steady. We never identify you to PostHog. There is no name, no email, no account, and nothing to join it to.

What is sent

  • The name of a screen you opened.
  • The name of a button you pressed.
  • Whether an action succeeded or failed.
  • When the app was opened or put in the background.
  • Standard technical details: your iPhone model, iOS version, the Steady version, and when Steady was installed or updated.
  • Which version of a feature or experiment the app gave you.
  • The purchase events RevenueCat reports on our behalf, described in section 5.

Every event and detail Steady itself sends is chosen from a fixed list written into the app, and nothing you type is ever included. The standard details the PostHog library adds are filtered against a blocklist that removes, among others, your IP address, device name, time zone, locale and network.

What is never sent — enforced in code

Your stress score, your stress periods, your recovery score, your heart rate, heart rate variability, sleep, breathing rate, wrist temperature or steps; your check-in answers, tension ratings, context tags or notes; the time of any reading; your name, email, location or any contact information. Not as a number, not as a range, and not as a word like “low” or “high”.

Before any event leaves your iPhone, the events and details Steady defines are checked against the fixed list, and anything not on it is dropped. A second filter drops anything whose name looks like health data. Automated tests fail the build if either check is bypassed.

What we deliberately turned off

  • Automatic tap capture is off. Only the events we wrote in are sent.
  • Session recording and screenshot capture are off.
  • IP-based location is off, and PostHog is set to discard your IP address.
  • There is no crash-reporting service in the app.
  • Opening the “Talk to someone” page sends nothing — no event, not even a screen name.

Your control

Usage statistics are on by default and off in two taps: Settings → Privacy and your data → Anonymous usage statistics. Turning it off sends one last event recording that you turned it off, together with anything already waiting to be sent, and then stops. Anything that could not be sent in those few seconds is deleted from your phone. Purchase events continue as described in section 5, no longer connected to your usage statistics.

If you want statistics we already received to be deleted, “Copy my analytics ID” on the same screen gives you the identifier to send us. Copy it before using “Delete everything”, which replaces it with a new one.

7. No advertising, no tracking, no selling

Steady shows no advertising and contains no advertising SDK. We advertise Steady itself on the App Store with Apple Ads, and the Apple attribution token described in section 5 tells us which of those ads lead to downloads and purchases. Apple Ads receives no advertising identifier from us and nothing about how you use Steady, and no other advertising network receives anything at all.

We do not track you across other companies’ apps or websites, and there are no data brokers. That is why Steady never shows the App Tracking Transparency prompt — there is nothing to ask you about.

8. Notifications

Stress alerts, the morning notification and the trial reminder are all local. The app schedules them on your iPhone. There is no push server, and no notification content is sent anywhere.

9. The Home Screen widget

The widget reads a summary the app leaves for it in storage the two share on your iPhone. Nothing is transmitted. As section 2 explains, that summary is included in your iPhone’s backups.

10. Exports and emails you send

Export (JSON or CSV) and the doctor summary PDF are built on your iPhone and handed to the iOS share sheet. The file is deleted from your iPhone as soon as the share sheet closes, whether you shared it or not. Where you send it is your choice, and we never receive a copy unless you send it to us.

If you choose to email us feedback from the app, it opens a draft in your own mail app. The draft includes the app version, iOS version and iPhone model so we can reproduce a problem. It never includes anything read from Health, and nothing is sent unless you send it.

11. How this lines up with our privacy declarations to Apple

We declare four kinds of data to Apple:

  • Purchase History, for App Functionality and Analytics;
  • Product Interaction, for Analytics;
  • Advertising Data (the Apple Ads attribution in section 5), for Analytics;
  • User ID (the two random identifiers in sections 5 and 6), for App Functionality and Analytics.

All four are not linked to your identity and not used for tracking. Health and fitness data is not collected, because it never leaves your iPhone.

12. Third parties, in full

This is the complete list. There are no others.

  • RevenueCat

    Purchases and Apple Ads attribution

    Checks with Apple whether a purchase is valid and unlocks Steady Pro. Receives the items listed in section 5. Servers in the United States.

    RevenueCat privacy policy
  • PostHog

    Anonymous usage statistics

    Receives the anonymous usage events described in section 6, unless you turn them off. Processed on PostHog’s US cloud.

    PostHog privacy policy
  • Apple

    Payments, App Store, Apple Ads, HealthKit

    Takes the payment and runs the App Store. Answers RevenueCat’s Apple Ads attribution request. HealthKit is on-device only — nothing from it reaches us.

    Apple privacy policy

RevenueCat and PostHog process data on our behalf, under agreements that limit them to that purpose.

13. Retention and deletion

  • On your iPhone: until you delete it. Nothing expires on its own.
  • Usage statistics at PostHog: kept under our project’s retention setting. You can ask us to delete them using the identifier from “Copy my analytics ID” — copied before any “Delete everything”, which replaces it.
  • Billing records at RevenueCat: for as long as we have a business or legal reason to keep them — typically the life of the subscription plus the period tax law requires. Because there is no account, we cannot look you up: Settings → Steady Pro → Copy my billing ID gives you the identifier to send us. Deleting the billing record does not cancel a subscription.

“Delete everything” in Settings → Privacy and your data deletes the database file, removes the app’s encryption key from the Keychain, cancels every scheduled notification and background job, blanks the widget, and throws away the anonymous usage-statistics identifier and replaces it with a new one. It cannot be undone.

Two things are not ours to delete: your purchase history, which Apple keeps, and any Mindful Minutes Steady saved into Apple Health, which you can remove in the Health app.

For any deletion request, email steady@rizenhq.com.

14. Children

Steady is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has used Steady and want the billing or usage identifier deleted, email us.

15. Your rights (GDPR, UK GDPR, CCPA/CPRA)

Depending on where you live, you have the right to access, correct, delete, restrict, object to and export the data we hold about you.

In practice we hold almost nothing about you. For the data on your iPhone you exercise all of those rights yourself, on your device, instantly, with Export and Delete everything, because we hold no copy to hand over. For the two off-device records, the identifiers in section 13 are how we find them: email us and we will answer within 30 days.

Our legal basis for billing records is performing our contract with you. For usage statistics it is our legitimate interest in making the app work properly, and you can object at any time with the switch in Settings — you do not have to give a reason, and nothing in the app stops working. For Apple Ads attribution it is our legitimate interest in knowing which of our ads work; you can object to that by emailing us. If you are in the EU or UK you can also complain to your local data-protection authority.

We do not sell or share personal information as those terms are defined under the CCPA and CPRA. We do not use your data for cross-context behavioral advertising. This policy and any dispute about it are governed by the laws of the State of New York.

16. International transfers

Your health data goes nowhere. Usage statistics are processed in the United States by PostHog, and billing records in the United States by RevenueCat. If you are outside the United States, those records are processed there.

17. Security

Steady’s database on your iPhone is protected by iOS file encryption and kept out of backups. Everything Steady sends leaves over HTTPS. We hold no health data on any server, which is the strongest protection we can offer: there is nothing to breach.

18. Changes to this policy

If we change this policy we will update the “Last updated” date at the top of this page and publish the new version here. If a change materially affects what we collect, we will say so in the app before it takes effect.

19. Contact

Resonance Logic, LLC — questions about this policy or about your data:

steady@rizenhq.com