Privacy policy
Version 0.2.0 · updated 2026-10-05
Draft — to be reviewed by a lawyer before publication. Passages in brackets [to be completed] are waiting for information from the publisher or for a check.
In short
- Steko only asks for what is useful right now. No contacts, no location, no photos. Saying no never blocks the app.
- You see your plan before you create an account. At first you use an anonymous session, with no email.
- What you write can be sensitive (health, religious beliefs, money). We use it only to build your plan, with your explicit consent, and never for advertising.
- An AI reads your goals. The text of your goals, your constraints and your check-in notes are sent to an AI provider that processes them in China, without your name, email or identifier. China does not offer the same level of protection as the European Union: you can say no and continue without the AI.
- Your journal stays on your phone, encrypted. It is only sent to the AI if you allow it.
- You stay in control. Export your data or delete your account from the app (Me, then My data) or from the web. We sell nothing and run no targeted advertising.
- The same rights everywhere. We apply the principles of the GDPR to everyone, whatever their country.
- Steko is for people aged 16 and over.
Who is responsible for your data
The data controller is Jean-Paul ADOGLI, an individual, sole publisher of Steko, based in Togo. There is no publishing company at this time.
- Postal address: [to be completed]
- Contact for any question or request about your data: adoglijeanpaul@gmail.com (suggested subject: "Personal data")
- Website: steko.app
- Representative in the European Union or the United Kingdom (Article 27 GDPR): none appointed at this time [to be decided by the publisher before launch in these regions]
- Data protection officer: none appointed at this time
If the publisher changes (for example if a company is created), this policy will be updated and you will be informed as described in "Changes to this policy".
The data we process, why, and on what basis
A "legal basis" is the reason that allows us to process a piece of data. It is stated for each category.
Your account
At first, an anonymous session (a technical identifier, no email). If you save your plan, we add your email or the identifier provided by Google or Apple, and your first name. Purpose: let you recover your plan when you change phones. Basis: performing the service you request (Article 6.1.b GDPR).
Your age
At first launch, you declare that you are 16 or older. We do not ask for your date of birth and we do not verify your age: it is a simple declaration (see "Children"). Basis: performing the service and our duty not to provide it to younger people.
What you tell Steko
Your story, your goals in the six life dimensions offered (Faith, Body, Mind, Work and study, Money, Relationships), your deadlines, your anchor, your available time, your constraints, your check-in answers (energy, mood if you give it, reason for a miss), as well as your plan, your actions and their results. Purpose: build and adjust your plan. Basis: performing the service and, for AI processing, your consent (Article 6.1.a).
Sensitive data: religious beliefs, health
Some of the data you entrust to us are special categories under Article 9 GDPR:
- your religious or philosophical beliefs, if you choose the Faith dimension or mention them in your story, journal or conversations;
- your health data, if you follow the Body dimension (weight, height, waist, sleep, workouts, walking) or mention your health.
We only process them for your plan and your tracking, on the basis of your explicit consent (Article 9.2.a), which you can withdraw at any time in Me. For body measurements and sleep, the database refuses any write until you have turned on the "health data" consent. These measurements are stored on our servers and are not sent to the AI provider; however, anything you write yourself in a text sent to the AI is. You can say nothing sensitive: Steko works without it.
Your journal
The journal (evening entries, prayers, notes) is encrypted on your phone, with a key kept in the device's secure vault. It is not sent to our servers unless you turn on the "journal analysis" consent: in that case, the analysed content is transmitted to our servers and then to the AI provider, like the rest of your story. There is currently no cloud backup of the journal: if you lose or reset your phone, the journal is lost. If an encrypted backup is added one day, this policy will be updated before it goes live and you will be informed.
Voice
Dictation uses your phone's speech recognition service (Google's or Apple's, depending on the device). Depending on your device and its settings, the audio may be processed on the device or sent to that service, under its own terms. Steko only receives the transcribed text: it does not record or keep your voice. The microphone is only requested on first use.
Technical data
Language, time zone, country, app version, system (Android or iOS), notification token, device attestation tokens. Purpose: display the app, notify at the right time, protect the service from abuse. Basis: performing the service and our legitimate interest in securing the service (Article 6.1.f). Notifications are only sent if you have accepted them.
Usage measurement
With your consent, we measure simple events (opening, a step completed) under a pseudonymous identifier, with no free text. They are recorded on our servers and, if this measurement is enabled, sent to PostHog. Purpose: understand whether the app really helps. You can refuse in Me without losing any feature. Basis: your consent.
Weekly product interview (optional)
If you agree, Steko may offer you a short interview about once a week (at most 8 exchanges), run by an AI, to learn what helps or bothers you. You can skip or stop at any time. Before being stored, your answers are stripped of your first name, email and phone number. The text is sent to the same AI provider as for your plan (see below); the AI does not try to get you to talk about health, religion or money. A distress word list stops the interview and points you to help resources. Basis: your consent, separate from all others and withdrawable in one tap in Me.
Help and contact
If you write to support from the app, your message goes through your own email app to adoglijeanpaul@gmail.com: it is handled like any email you send us. The app only records the subject you chose, the channel used and, if you tick the box, technical information (version, system, language, pseudonymous identifier). Basis: performing the service and your request.
Subscription and payment
Paid plans are not open yet. When they are, payment will go through the app stores (Google Play, App Store), RevenueCat for the subscription status and, in some countries, a mobile money payment provider (GeniusPay). Steko will not receive or keep your card number or your full mobile money number: only the status of your subscription. Basis: performing the contract and our legal obligations (accounting, tax). This policy will be updated, with the details of these providers, before payments open.
What we never collect
Your contacts, your precise location, your photos.
Artificial intelligence
Steko uses a generative AI model to turn your story into a plan, to answer in the conversation and to run the optional interview. You are talking to an AI, not a person.
- What goes to the AI provider: the text of your goals, your constraints, your check-in notes and what you write to the assistant.
- What never goes there: your first name, your email, your account identifier, your body and sleep measurements, and your journal unless you explicitly agree. If you write your name or a sensitive detail yourself in a text that is sent, it will be sent: only write what you are willing to share.
- The provider processes these texts in China (see "Who receives your data"). [To be checked at publication, in its API terms: how long it keeps texts and whether it is barred from training its models on them. Until this is checked, do not assume it does not reuse them.]
- The AI can be wrong. Its proposals are suggestions: you accept, edit or refuse them. No decision with a legal effect or similarly significant effect on you rests on it alone. A human (the publisher) can review, on request, a situation that concerns you.
- You can refuse the AI ("Continue without AI") and build your plan by hand. Features that do not use the AI remain available.
Who receives your data
The providers below process data on our behalf, on our instructions (they are "processors"), unless stated otherwise. The publisher accepts their data processing terms [to be completed: confirm for each one that the data processing agreement is accepted and kept].
Supabase (database, accounts, server functions)
- Role: hosts your account, your plan and your consents.
- Processing location: European Union (hosting region: Frankfurt, Germany).
- Safeguards: EU hosting; data processing agreement; standard contractual clauses for any access from a third country [to be checked].
DeepSeek (AI model)
- Role: generates plans, answers and interviews from the text sent.
- Processing location: China. According to the provider's policy, data is stored on servers located in China.
- Safeguards: China has no adequacy decision from the European Union or the United Kingdom. This transfer relies on your explicit consent, given in knowledge of the risks (Article 49.1.a GDPR and UK GDPR). We back it with mitigation measures: no direct identifier is sent; sending is optional and a path without AI exists; you can withdraw your consent at any time. No standard contractual clauses are signed with this provider at this time [to be completed if that changes].
- Risks to know about: the authorities of the country of processing may be allowed to access the data, without the remedies you would have in the European Union; the rights you have over this data may be harder to exercise against the provider.
OpenAI (numerical representations of text, only if this feature is turned on)
- Role: turns texts into vectors to find the information useful for your answers. This feature is not active until we have declared it here.
- Processing location: United States [to be confirmed].
- Safeguards: EU–US data privacy framework or standard contractual clauses [to be checked].
Google Firebase (notifications, app attestation)
- Role: deliver notifications (FCM); check that requests come from the genuine app (App Check, Play Integrity).
- Processing location: United States and other countries where Google operates.
- Safeguards: standard contractual clauses built into Firebase's data processing terms; EU–US data privacy framework [to be checked].
- If a crash reporting tool is added one day, it will be added here before it goes live.
Google and Apple (sign-in, stores, iOS notifications)
- Role: if you sign in with Google or Apple, these companies send us your email and identifier; they also deliver iOS notifications (APNs) and app attestation (App Attest). For your Google or Apple account and for store purchases, they act on their own behalf and their own privacy policy applies.
- Processing location: United States and other countries where they operate.
- Safeguards: each company's processing terms and standard contractual clauses; EU–US data privacy framework [to be checked].
PostHog (usage measurement, with your consent)
- Role: usage statistics under a pseudonymous identifier.
- Processing location: European Union (European instance) [to be confirmed in the configuration].
- Safeguards: EU hosting; data processing agreement.
RevenueCat (subscriptions, once paid plans open)
- Role: manages subscription status between the stores and Steko.
- Processing location: United States [to be confirmed].
- Safeguards: standard contractual clauses or EU–US data privacy framework [to be checked].
GeniusPay (mobile money payment, once paid plans open)
- Role: collects mobile money payments.
- Processing location: [to be completed].
- Safeguards: [to be completed].
We do not sell your data. We do not share it for advertising. We may disclose it to an authority if the law requires us to.
International transfers
Steko is published worldwide and the publisher is based in Togo. Your data is therefore processed in several countries. Each time it leaves your region, we rely on one of these means, stated provider by provider above: an adequacy decision, standard contractual clauses, a recognised certification framework, or your explicit consent for a specific transfer (this is the case for the AI provider). You can ask for a copy of the safeguards by writing to us.
How long we keep your data
| Data | Duration |
|---|---|
| Account, goals, plans, results, consents, proof of acceptance of the texts | As long as your account exists; erased from our database when the account is deleted. The host's technical backup copies disappear on its cycle, within 30 days at the latest [to be checked against the hosting plan] |
| Facts Steko keeps about you | Until their end date or until you erase them |
| Inactive anonymous session | Deleted after 30 days of inactivity |
| Journal | On your phone, until you delete it or uninstall the app; no copy at Steko, except content sent for analysis if you allowed it (kept like the rest of your story) |
| Usage events | 90 days in our database; then archived under their pseudonymous identifier, without your account identifier, only if they were consented to. After your account is deleted, the pseudonymous identifier is no longer linked to you. Archive duration: [to be decided by the publisher] |
| Raw interview answers | 12 months after the interview ends, then erased; everything is erased when the account is deleted |
| Notification tokens | Until sign-out, account deletion or the token becoming invalid |
| Technical logs | From 1 to 180 days depending on their nature (for example 7 days for scheduled-task logs, 180 days for the operations log) |
| Emails you write to us | The time needed to handle your request, then 12 months at most [to be confirmed by the publisher] |
| Invoices and accounting records (paid plans) | Legal period applicable to the publisher [to be completed] |
Your rights
We grant them to everyone, wherever they live: access, rectification, erasure, restriction, objection, portability, withdrawal of consent at any time, and the right not to be subject to a decision based solely on automated processing.
- From the app: Me, then My data. There you export your data (readable file), see what Steko knows about you, correct or erase a fact, withdraw a consent, and delete your account. The export does not yet contain the record of your acceptances of the texts: ask for it in writing.
- From the web: account deletion page on steko.app, without reinstalling the app.
- In writing: at adoglijeanpaul@gmail.com. We may ask you to prove the request comes from you. We answer within 30 days at the latest (in Brazil, a complete copy of the data is provided within 15 days on request).
Withdrawing a consent does not affect the lawfulness of what was done before. If you believe your rights are not being respected, you can contact the data protection authority of your country (see "Depending on your country").
Deleting your account
- In the app: Me, My data, Delete my account. Type DELETE to confirm. The action is final.
- On the web: enter your account's email address on the deletion page. If an account exists, you receive a confirmation link, without the page revealing whether the address is known. The deletion starts when you open the link.
- Effects: your account and your data are erased from our database; technical backups then disappear on their cycle (see "How long we keep your data"). An anonymous session with no email can be deleted from the app, or disappears by itself after 30 days of inactivity. Data you entrusted to Google, Apple or your email provider is governed by their own rules. We may keep what the law requires us to keep (for example an invoice).
Security
Encryption in transit, access to data limited to your own account by server-side rules, checks that requests come from the genuine app, journal encrypted on the device, secrets never present in the app's code. No system is infallible. In the event of a breach likely to harm you, we inform you and notify the competent authority within the legal deadlines (72 hours under European law).
Children
Steko is for people aged 16 and over. We ask you to confirm this at first launch; it is a declaration, we do not check your age and we do not ask for your date of birth. If we learn that a younger person is using Steko, we delete their account. A parent who thinks their child is using Steko can write to us. Under 18, no advertising and no paid plan without the agreement of a parent or legal guardian.
Notifications, cookies and trackers
The mobile app does not use cookies. It uses a notification token and technical identifiers, necessary for the service. Notifications are only sent if you have accepted them; their text goes through Google or Apple. Usage measurement is only active with your consent. The web pages on steko.app (legal texts, account deletion) use no trackers.
Depending on your country
The rights above apply everywhere. Here is what each regime adds.
European Union, European Economic Area and United Kingdom (GDPR and UK GDPR)
The legal bases are those described above. You can contact the authority of your country; in the United Kingdom, the Information Commissioner's Office. Transfers outside the EU or the United Kingdom rely on the safeguards stated for each provider (EU standard contractual clauses, UK addendum, data privacy framework, or explicit consent).
California and the United States (CCPA and CPRA)
You can ask to know, correct and delete your personal information and to limit the use of sensitive information. We do not sell your personal information and do not share it for behavioural advertising. We do not discriminate against anyone who exercises their rights. An authorised agent can make the request for you. We use your sensitive information only to provide the service you request.
Brazil (LGPD, Law No. 13,709/2018)
You have the rights of Article 18 (confirmation of processing, access, correction, anonymisation, portability, information on sharing, withdrawal of consent). The transfer to the AI provider relies on your specific consent (Article 33, VIII). You can contact the National Data Protection Authority (ANPD). Data protection contact (encarregado): the publisher, at adoglijeanpaul@gmail.com.
Nigeria (Nigeria Data Protection Act 2023, NDPA)
Your rights of access, rectification, erasure, objection and portability are recognised. Transfers outside Nigeria rely on adequate safeguards or on your consent. You can contact the Nigeria Data Protection Commission (NDPC).
Kenya (Data Protection Act, 2019)
You can ask for access to your data, its rectification and erasure, object to certain processing and obtain portability. Transfer of sensitive data outside Kenya relies on your consent. You can contact the Office of the Data Protection Commissioner.
Ghana (Data Protection Act, 2012)
You can ask for access to your data, its correction and deletion, and object to certain processing. You can contact the Ghana Data Protection Commission.
Canada (PIPEDA and provincial laws, including Quebec's Law 25)
You can access your personal information, have it corrected, withdraw your consent and file a complaint with the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information. You are informed here of the communication of information outside Quebec (United States, China) and of the safeguards chosen.
Côte d'Ivoire and Senegal
In Côte d'Ivoire (Law No. 2013-450 of 19 June 2013), you can contact the Telecommunications Regulatory Authority (ARTCI). In Senegal (Law No. 2008-12 of 25 January 2008), you can contact the Personal Data Protection Commission (CDP). The rights of access, rectification, objection and deletion are yours.
Togo and ECOWAS (the publisher's country of establishment)
The publisher is established in Togo. Accordingly, Togolese Law No. 2019-014 of 29 October 2019 on the protection of personal data applies to the publisher, under the supervision of the Personal Data Protection Authority (IPDCP), as does the 2010 ECOWAS Supplementary Act on data protection. Formalities with the IPDCP: [to be completed].
Changes to this policy
Each version has a number and a date. If an important change concerns you (new provider, new purpose, new country of processing), Steko announces it in the app before it takes effect, with a clear summary, and asks you to accept it; if the change requires your consent, you may refuse it. A minor change is simply flagged once. The version history stays available in the app.
Contact us
Jean-Paul ADOGLI, publisher of Steko, adoglijeanpaul@gmail.com, steko.app. Postal address: [to be completed].