Privacy policy (LeanStep)

LeanStep is a step counter and GPS activity-tracking app developed by Leandersson Consulting. We are committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights under GDPR.

What data we collect:
• Step count data (via your phone’s built-in pedometer sensor)
• Daily step totals until reset or app un-install
• GPS location data — only while you explicitly start and are actively tracking a Running/Cycling/Skiing session. Never collected in the background or outside an active session.
• Session summaries (distance, duration, pace) for sessions you choose to save
• App appearance preferences (colors, fonts, backgrounds)
• Purchase records for optional premium themes, handled entirely by Google Play (see “Purchases” below)
• Crash and error reports, via Google Firebase Crashlytics (see “Crash reporting” below)

We do NOT collect:
• Your name or identity
• Location data outside an active session you started
• Contact information
• Any data from other apps
• Step counts, GPS coordinates, or session data in crash reports — these are never included (see “Crash reporting” below)

Where data is stored:
All step, activity-session, and preference data is stored exclusively on your device using AES-256 encrypted storage. This data is never transmitted to our servers — we do not operate any backend, and we have no access to it. The only exceptions are crash reports (via Firebase Crashlytics) and app update checks (via the Google Play Store), both described below, each handled directly by Google.

Crash reporting:
LeanStep uses Google Firebase Crashlytics to automatically report app crashes, so we can find and fix bugs. If the app crashes, basic technical information (a stack trace, device model, OS version, and app version) is sent to Firebase/Google on your next app launch. This report never includes your step counts, GPS location, session data, or any other personal data from within the app. We do not use Crashlytics for analytics or tracking — only automatic crash reports. See Google’s privacy policy for how Firebase/Google handles this data.

App updates:
LeanStep uses the Google Play Store’s built-in update check (Play In-App Updates) to let you know when a newer version is available. This only checks your installed version against the Play Store and does not share any of your app data.

Purchases:
Premium themes are purchased through Google Play Billing. Google processes the payment and purchase record — we never see or store your payment details. We only store, on your device, which themes you’ve purchased, so they stay unlocked. See Google Play’s own privacy policy for how Google handles that transaction.

Permissions we request:
• ACTIVITY_RECOGNITION – Required to read your step count from the phone’s sensor. Without this permission the app cannot function.
• ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION – Only used while you’ve explicitly started a Running/Cycling/Skiing session, to compute distance and pace. Not used in the background, and never requested until you tap Start Activity. Declining it still lets you use passive step counting.
• POST_NOTIFICATIONS – Used to show your ongoing step count and an active-session notification while tracking. Purely informational; no data leaves your device.
• Background photos are chosen via the system Photo Picker, which requires no storage permission at all. We do not store or process the photo beyond displaying it on your device.

Your GDPR rights:
Under GDPR you have the right to:
• Access – All your data is visible directly in the app
• Erasure – Uninstalling the app permanently deletes all data. You can also delete individual data types (e.g. reset step history) from within Settings.
• Portability – Your app data never leaves your device, except for purchase records handled by Google Play, and crash reports handled by Firebase Crashlytics, as described above
• Objection – You can revoke the Activity Recognition, Location, or Notification permissions at any time in Android Settings; declining Location only disables GPS session tracking and does not affect step counting

Since all app data is stored locally on your device and we have no server access, most GDPR rights are exercised directly through your device, or through Google Play/Firebase for purchase records and crash reports respectively.

Data retention:
Step and activity-session history is kept for the duration of the app installation. All data is permanently deleted when you reset data in Settings or uninstall the app.

Leandersson Consulting:
For privacy inquiries please contact us via https://sleandersson.com/about-me/contact/