Privacy Policy
Effective August 24, 2026
This is what we collect and why. Short version: we collect the minimum needed to run Stepzu, we strip photo metadata, and Stepzu currently uses no advertising or third-party client-side tracking scripts, SDKs, or cookies. If that changes, we will update this policy and provide any notice, consent, or controls the law requires before the change takes effect.
What we collect
Account: a verified account identifier from Google or Apple sign-in, the username you pick, any public display name you add, and the usage tag you choose at onboarding. We do not store your email address or the name on your Google or Apple account.
Content: the photos, voice recordings, and text you upload to make guides. Photo EXIF metadata (location, device info) is removed at upload, before storage.
Usage: basic product events (e.g. a guide was created, a shared link was viewed) so we can understand what works. View counts don't identify viewers.
Referrals: if you sign up after opening a shared guide, we record which guide's link brought you here so both of you can receive a bonus spark. This travels as a parameter on the sign-up link and in your sign-in session — not in a cookie — and we keep a keyed, one-way fingerprint of your sign-in identifier so the sign-up bonus can only be granted once.
Notifications: if you turn on push notifications in our mobile apps, a device push token so we can deliver them. It is used only to send you notifications (like when someone likes your guide or follows you), and it is shared with Apple (APNs) or Google (FCM) solely to deliver the message to your device. You can turn notifications off in your device settings; we delete the token when you sign out, and when your account is deleted or suspended.
Social actions: if you follow a creator, like a public guide, or block an account, we store that relationship so those features work. Follower, following, and like counts appear on public pages; your block list is visible only to you. These records are removed when your account is deleted — in both directions, including likes and follows pointing at you.
Cookies: one essential session cookie to keep you signed in. As of this policy's effective date, we do not use advertising or third-party tracking cookies on any page.
Reports: if you report a guide, we keep the link, what you told us, and any contact detail you choose to give.
Our commitments
We do not sell or rent your data, disguise advertising as guide content, or collect more than the service needs. Shared guides currently have no advertising or third-party client-side tracking scripts, SDKs, or cookies. Our Android app includes Firebase Cloud Messaging for push delivery only, with its analytics collection disabled — it is a delivery channel, not a tracker. Before introducing advertising or third-party tracking, we will update this policy and any required consent or controls.
How your content is processed
Hosting and storage run on Cloudflare.
When you choose the AI drafting mode, your photos, recording (or text), and their transcript are sent to AI providers to generate your draft: OpenAI for speech-to-text and Google (Gemini) for structuring. Content in manual guides is never used to generate drafts — but it is covered by the safety screening described next.
To keep shared guides safe, we run automated content checks: photos are screened at upload, and a guide's text is screened when you publish it to your public page — for manual and AI guides alike. Screening means the photo or text is sent to OpenAI's Moderation endpoint, a safety classification service. We store the check's result scores and a zero-dollar cost record — not another copy of your content in that record — and we use the result only for safety, never for advertising.
When you submit a username or public display name, that name may be sent to OpenAI's Moderation endpoint to detect harmful names. We store the check result and zero-dollar cost record, but not another copy of the name in that AI job record. If the safety service is unavailable, the name is handled by our other rules and reporting process.
Signing in uses Google, or Apple in our mobile apps. The provider sends a signed token identifying your account; from it we keep only the account identifier that tells us it's you — not your email address or name. We don't ask Apple for your name or email at all.
Who can see your guides
Private guides are visible to anyone who has the link — that's how no-signup sharing works, so share links with care. Private links are excluded from search engines.
Guides you explicitly publish to your public page are visible to everyone and indexable by search engines.
Your public page shows your username and, if you type one in, the display name you chose. That name is public and indexable — which is why we ask you to type it rather than filling it in for you. Your Google or Apple account name is never published, and we do not keep it.
Your public page also shows your published guides and their like counts, and your follower and following counts. It does not list who those people are.
Deletion and your rights
If we remove content for breaking the rules, we keep a record of the removal — what came down, when, and why. That record is how a repeat-offender policy can exist at all.
Deleting a guide removes its steps and its photos and recordings from storage. You can do this yourself, anytime.
You can delete your whole account from your dashboard. The account, sign-in identity, guides, steps, and uploaded files are removed immediately, and existing sessions and upload links stop working.
After account deletion, product-event and AI-cost records may remain only without the account or guide identifiers. We may retain moderation records when needed to enforce our rules, protect rights, or meet legal obligations. If a suspended account is deleted, we retain a keyed fingerprint of its sign-in identifier to prevent enforcement evasion.
We retain a keyed, one-way fingerprint of the former username so someone else cannot claim a deleted public address. It is not displayed and is not linked to the deleted account.
You can ask us to access or correct your data, or get help with deletion, at hello@stepzu.com. We answer within 30 days.
Changes and contact
Stepzu is not directed at children under 13.
If this policy changes materially, we will note it on the site. Questions or requests: hello@stepzu.com. Operator: Stepzu (stepzu.com), Republic of Korea.