Steppe Summit Studio Effective date: July 21, 2026
We designed our apps around a simple principle: your data belongs to you and stays with you.
Details follow below, but here is the short version:
No accounts. Our apps never ask for your name, email, phone number, or any sign-up.
Your data stays on your device. Everything you create in our apps is stored locally on your iPhone or iPad. We do not have access to it and cannot see it.
No tracking, no ads, no data sales. Our apps contain no advertising, no third-party analytics SDKs, and no trackers. We never sell or share your personal information.
AI features are transient. When you use an AI feature, only the content you submit is sent to our server for processing, the answer comes back, and the content is not used to profile you, advertise to you, or train AI models.
Payments are Apple's. Purchases go through Apple; we never see your payment details.
Delete anytime. Deleting content in an app, or deleting the app itself, removes your data. There is no server copy to request or erase.
Steppe Summit Studio is an independent iOS software studio and the developer of the applications covered by this policy. For the purposes of data protection law (including the EU/UK General Data Protection Regulation), Steppe Summit Studio is the "data controller" for the limited processing described in this policy.
Contact: pradeep.aneesh@gmail.com
This policy covers every iOS application published under the Steppe Summit Studio developer account on the Apple App Store, on iPhone and iPad. It also covers our support communications. It does not cover third-party services that operate under their own privacy policies (such as Apple's App Store), though we describe below how they interact with our apps.
Our apps are built local-first and account-free:
There is no registration, login, or user profile.
We operate no cloud database of user content. There is no server where your entries, records, photos, or documents are stored.
Because we never receive your content, we cannot read it, lose it, sell it, or hand it to anyone. The most private data is data that never leaves your device — that is our architecture, not just our promise.
When you use our apps, the content you create is saved in the app's private local database on your device. Depending on the app, this may include, for example: text entries, records and logs, notes, tasks, dates, numbers and calculations, categories and tags, photos and images you add, scanned or attached documents, and app settings.
We do not have access to any of this information. It is protected by your device's built-in security (device encryption, passcode, Face ID/Touch ID at the operating-system level) and by iOS's app sandboxing, which isolates each app's data from other apps.
Device backups. Your local app data is included in your normal device backups (iCloud Backup or computer backups) as part of iOS's standard backup system. Those backups are managed by you and Apple under Apple's terms — we have no access to them.
Some apps request iOS permissions to enable specific features. Permissions are always optional, always requested through the standard iOS prompt, and can be changed anytime in Settings → Privacy & Security:
Camera — to capture photos or documents within the app. Images are stored locally on your device.
Photo Library — to let you attach existing photos. Selected images are stored locally.
Notifications — to deliver reminders you set. Our apps use local notifications, scheduled entirely on your device; we do not operate push-notification servers.
Face ID / Touch ID — some apps offer an optional biometric lock. Authentication is performed entirely by iOS; your biometric data never leaves your device's Secure Enclave and is never accessible to us or our apps.
Data gathered through these permissions stays on your device and is not transmitted to us, with one exception you control: content you explicitly submit to an AI feature (see Section 5).
Some of our apps include optional AI-powered features (for example, analyzing text you enter, recognizing items in a photo, or generating summaries and suggestions). These features require sending data off your device — here is exactly what happens:
What is sent. Only the content you explicitly submit to the AI feature — typically text and, in some apps, images. Nothing else from your device or from elsewhere in the app is included.
Where it goes. Your request travels over an encrypted (TLS/HTTPS) connection to our server endpoint, which runs on Cloudflare's infrastructure. Our server relays the request to our AI model provider, Anthropic, whose large language model generates the response, which is returned to your app.
How long is it kept. The request is processed transiently to produce your response. Our server acts as a relay and does not maintain a database of your AI request content. Our AI provider processes API requests under its commercial API terms, under which submitted content is not used to train AI models; the provider may retain data for a limited period strictly for abuse prevention and safety, after which it is deleted, as described in its own policies.
What it is not used for. AI request content is not used to identify you, build a profile of you, advertise to you, or train AI models. Because our apps have no accounts, AI requests are not linked to your name, email, or Apple ID.
Technical data. Like any internet service, delivering AI responses involves processing basic technical information — such as your IP address and request metadata — by our infrastructure provider, in order to route responses, protect against abuse, and enforce fair-use limits. We do not use this information to identify you.
Your choice. AI features are always user-initiated. If you prefer that nothing ever leaves your device, simply don't use the AI features — every other part of our apps works fully offline. We also recommend not submitting information to AI features that you would not want processed by a server (for example, other people's sensitive personal details), since the feature necessarily involves transmission.
Relevant third-party policies: Anthropic (https://www.anthropic.com/legal/privacy) and Cloudflare (https://www.cloudflare.com/privacypolicy/).
In-app purchases and subscriptions are processed entirely by Apple through your Apple ID. We never receive, see, or store your payment card details, billing address, or Apple ID credentials.
To unlock features you have paid for, our apps use Apple's StoreKit system on your device to verify your purchase entitlement. The transaction information involved (such as whether a valid purchase exists and its type) does not include your identity or payment details. Apple's handling of your payment information is governed by Apple's privacy policy: https://www.apple.com/legal/privacy/.
Refunds are handled exclusively by Apple (https://reportaproblem.apple.com); we do not receive your payment information as part of that process.
Our apps contain no third-party analytics SDKs.
Our apps contain no advertising and no ad networks.
Our apps do not track you across other companies' apps or websites, and do not use the iOS advertising identifier (IDFA). Because there is no tracking, our apps do not need to show the App Tracking Transparency prompt.
We do not sell, rent, or share personal information with data brokers or anyone else.
Apple may provide us with aggregated, anonymized statistics (such as total download counts or crash summaries) through App Store Connect, only from users who have opted in to sharing analytics with developers in their iOS settings. These statistics contain no personal information and cannot be used to identify anyone.
If you email us, we receive your email address and whatever information you choose to include. We use it solely to respond to you and improve our apps. We keep support correspondence only as long as needed to resolve your request and maintain a basic record of our communication, and we never add support emails to marketing lists (we don't have marketing lists).
Your content: stored on your device for as long as you keep it. You can delete individual items inside each app at any time, and deleting an app permanently removes its entire local database from your device. Copies may persist in your own device backups until those backups are rotated — backups are under your control.
AI requests: processed transiently as described in Section 5; not stored by us.
Purchase records: maintained by Apple under Apple's policies.
Support emails: retained as described in Section 8; you may ask us to delete past correspondence at any time.
Because we hold no user accounts and no user content, there is no "delete my account" process — deletion is fully in your hands, instantly, on your device.
We protect the limited data flows that exist:
All network communication between our apps and our servers uses encryption in transit (TLS/HTTPS).
Your on-device data is protected by iOS security architecture: hardware-backed device encryption, your passcode/Face ID/Touch ID, and per-app sandboxing.
Our server infrastructure runs on established platforms (Cloudflare) with modern security practices, and — by design — stores no database of user content, which eliminates the most serious category of breach risk.
No method of transmission or storage is 100% secure, but our architecture minimizes risk by minimizing data: what we never collect can never be breached.
Our apps are professional and personal productivity tools intended for general audiences. They are not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. Since our apps collect no accounts or identities from anyone, no such data exists on our side; if you believe a child has nonetheless submitted personal information to us (for example, by email), contact us and we will delete it.
If you are in the EEA, UK, or Switzerland, the GDPR (and UK GDPR) gives you rights over personal data that a controller holds about you. Our processing is minimal, and our legal bases are:
Performance of a contract — providing app functionality you request, including processing AI requests you initiate.
Legitimate interests — securing our services, preventing abuse, enforcing fair-use limits, and responding to support requests.
Consent — where you grant optional iOS permissions (camera, photos, notifications), which you may withdraw at any time in iOS Settings.
You have the right to request access, rectification, erasure, restriction of processing, data portability, and to object to processing, and the right not to be subject to automated decision-making with legal effects (we do none). In practice, nearly all data our apps handle is stored on your own device, under your direct control — you can access, correct, export, and erase it yourself within the apps. For the little we may hold (essentially, support correspondence), email us at pradeep.aneesh@gmail.com and we will respond within the timelines the law requires.
You also have the right to lodge a complaint with your local data protection supervisory authority.
If you are a California resident, the California Consumer Privacy Act, as amended, gives you specific rights. Our disclosures:
Categories of personal information collected: internet activity information limited to technical request data (such as IP address) processed transiently when you use AI features or connect to our services; user-submitted content processed transiently for AI features; and contact information you voluntarily provide by emailing support. We collect no identifiers such as name, account, or precise geolocation, and no sensitive personal information categories beyond what you may voluntarily include in AI submissions or emails.
We do not sell personal information and do not share it for cross-context behavioral advertising, and have not done so. No "Do Not Sell or Share" opt-out is needed, because there is nothing to opt out of.
Your rights: to know what personal information we have about you, to delete it, to correct it, and to not be discriminated against for exercising these rights. Because we hold essentially nothing beyond any emails you have sent us, requests are simple: contact pradeep.aneesh@gmail.com and we will verify and fulfill your request as required by law. You may use an authorized agent to submit a request on your behalf.
We publish apps worldwide. When you use AI features, your request may be processed on servers located in other countries — including the United States — operated by our infrastructure and AI providers (Cloudflare and Anthropic). These providers maintain appropriate safeguards for international transfers, including recognized transfer mechanisms such as standard contractual clauses, as described in their own privacy documentation. All other app data remains on your device in your own country, wherever that is.
All Steppe Summit Studio apps follow the practices in this policy. Where an individual app has an additional, feature-specific behavior, it is either listed here or disclosed inside the app at the point of use:
Some apps that capture photos may optionally include standard photo metadata (such as date, time, and — only if you have granted location permission — GPS coordinates) embedded in the images, in order to serve as accurate records. This metadata is stored locally with your photos on your device and is shared only if and when you yourself export or share those files.
Our apps interact with a small, fixed set of third parties, each governed by its own privacy policy:
Apple Inc. — App Store distribution, payments, subscriptions, device backups, and iOS system services. https://www.apple.com/legal/privacy/
Cloudflare, Inc. — server infrastructure that relays AI requests. https://www.cloudflare.com/privacypolicy/
Anthropic — AI model provider that processes AI feature requests. https://www.anthropic.com/legal/privacy
This policy page itself is hosted on Google Sites; when you visit this page, Google may process standard technical data (such as your IP address) as the hosting provider, under Google's privacy policy: https://policies.google.com/privacy.
We do not embed any other third-party SDKs, trackers, or services in our apps.
Our apps or this page may contain links to external websites (for example, Apple support pages). We are not responsible for the content or privacy practices of external sites and encourage you to review their policies.
We may update this policy from time to time — for example, if we add new features or if legal requirements change. When we do, we will update the effective date at the top of this page and, for material changes, provide notice within the relevant apps or on this page. Continued use of our apps after an update means the revised policy applies. We encourage you to review this page occasionally.
Questions, concerns, or requests about privacy — or anything else — are always welcome:
Steppe Summit Studio Email: pradeep.aneesh@gmail.com
We read every message and typically respond within 24–48 hours.
In short: we built our apps so that we don't need your data — and so that you don't need to trust us with it.