Smoothstep Privacy Policy

Last Updated: March 6, 2026


1. Introduction

Welcome to Smoothstep!

Smoothstep is a family habit management app designed to help parents establish and track daily routines for their family. We understand the importance of protecting privacy and are committed to providing a safe, transparent app environment.

Our Privacy Principles:
  • All data is stored completely locally on your device
  • Personal data is not uploaded to any servers (except subscription verification service, see Section 5.2)
  • Parents have complete control over all data
  • Compliant with COPPA (Children's Online Privacy Protection Act) and GDPR (General Data Protection Regulation)

This Privacy Policy explains how we collect, use, and protect your information. Please read it carefully before using this app.


2. Information We Collect

Smoothstep collects only the minimum information necessary for operation, and all data is stored locally on your device.

2.1 Profile Information

2.2 Habit and Progress Data

2.3 Wish List Data

2.4 Travel Mode Data (Optional)

2.5 Device Information (For Backup Compatibility Only)

We Do NOT Collect:
  • ❌ Real photos or videos
  • ❌ Precise GPS location
  • ❌ Phone numbers or email addresses
  • ❌ School or home addresses
  • ❌ Social media accounts
  • ❌ Biometric information

3. How We Use Your Data

3.1 Core Functionality

Your data is stored completely locally on your device and used for:

3.2 The Growth Key Mechanism

Design Purpose: To encourage honest thinking and autonomous decision-making, rather than simply "checking off" tasks.

How It Works:

Important Statements:
  • This is NOT punishment or restriction, but rather a habit of building honest communication and self-reflection
  • All choices remain local only: Not uploaded or used for any commercial purpose
  • Follows educational principles: Design based on positive parenting and reflective learning theories

This mechanism aims to help develop intrinsic motivation, rather than external monitoring.

3.3 Key Statement

All data is stored completely locally on your device. We DO NOT:

  • ❌ Upload personal data or habit records to cloud servers
  • ❌ Share personal information with third parties
  • ❌ Conduct any form of data analysis or ad targeting
  • ❌ Track your usage behavior

3.4 Backup and Restore (By Your Initiative)

Parents can choose to:

Important Notes:


4. Data Security Measures

We employ multiple layers of security to protect your data:

4.1 Encryption Protection

We employ a multi-layered encryption strategy to protect your data:

Local Database Encryption (Always Enabled)

Backup File Encryption (Your Choice)

4.2 Local Storage

4.3 Limited Network Transmission

Except for the font loading service and subscription verification service (see Chapter 5), Smoothstep does not perform any network communication. Your personal data, habit records, and family information are never transmitted over the network.


5. Third-Party Services

Smoothstep uses the following third-party services:

5.1 Google Fonts (Font Loading Service)

Purpose: Load Lexend and Noto Sans TC fonts to provide the best reading experience

Data Collection:

How to Manage:

Applicable Policies:

5.2 RevenueCat (Subscription Management Service)

Purpose: Manage and verify in-app subscription (Premium plan) purchase status

Data Transmitted:

NOT Transmitted:

Data Protection:

Applicable Policies:

We Do NOT Use:
  • ❌ Ad services (Google AdMob, Facebook Ads, etc.)
  • ❌ Analytics tools (Google Analytics, Firebase Analytics, etc.)
  • ❌ Social login (Facebook Login, Google Sign-In, etc.)
  • ❌ Any tracking or behavior analysis services

6. Parental Rights

As a parent or guardian, you have complete data control:

6.1 View Data

Through the app interface, you can view at any time:

6.2 Modify Data

You can at any time:

6.3 Export Data

Through the "Backup" feature, you can export all data as a JSON format backup file, achieving data portability.

Backup Options:

You can choose the backup method based on your security requirements.

6.4 Delete Data

You can delete data by:

Note: Deleted data cannot be recovered unless you previously exported a backup file.


7. Data Retention

7.1 Local Storage Duration

Data is stored permanently on your device until you actively delete it or uninstall the app.

7.2 After Uninstallation

When you uninstall Smoothstep, all local data will be automatically cleared by the system.

7.3 Backup Files

You manage the retention period of backup files you export. We cannot access or delete them.


8. COPPA Compliance Statement

Smoothstep strictly complies with the U.S. Children's Online Privacy Protection Act (COPPA):

8.1 Parental Consent

8.2 Data Minimization

8.3 No Third-Party Sharing

8.4 Parental Control


9. GDPR Compliance Statement (For EU Users)

For users located in the European Economic Area (EEA), Smoothstep complies with the General Data Protection Regulation (GDPR):

9.1 Legal Basis for Data Processing

9.2 Data Subject Rights

Under GDPR, you have the following rights:

9.3 Data Protection Principles

9.4 Cross-Border Data Transfers

Data Processing Location:

Limited Network Communications:

Only the following services involve network requests (not including personal data):

  1. Google Fonts: Font file requests (CDN may be in EU/US)
    • Transmitted data: Device IP, User-Agent (no personally identifiable information)
    • Subject to Google's EU data protection commitments
  2. RevenueCat: Subscription verification service (servers in the US)
    • Transmitted data: Anonymous identifier + purchase receipts (no personally identifiable information)
    • Protected by Standard Contractual Clauses

Important Statement: Your habit records, family member information, progress statistics and other personal data are never transmitted over the network or processed across borders.

9.5 Data Protection Officer (DPO)

To comply with GDPR Article 37 requirements, we designate the following contact for data protection matters:

Data Protection Contact (DPO): privacy@caiyu.app

Rights You Can Exercise with the DPO:

9.6 Supervisory Authority

If you believe we have not properly protected your data, you have the right to file a complaint with the data protection supervisory authority in your country.


10. Contact Us

If you have any questions, comments, or requests regarding this privacy policy or data protection, please contact us through:

10.1 General Privacy Questions

Privacy Questions Email: support@caiyu.app

10.2 GDPR Data Protection Officer (For EU Users)

Data Protection Contact (DPO): privacy@caiyu.app

Questions You Can Ask the DPO:

10.3 COPPA Parental Rights

Parental Rights Email: support@caiyu.app

Questions You Can Ask:


11. Privacy Policy Changes

We may update this privacy policy periodically to reflect app feature changes or regulatory requirements.

Change Notification Method:

Recommendation: Please check this privacy policy regularly to stay informed of the latest data protection measures.


12. Data Safety Commitment

Protecting your family's digital privacy and safety is our top priority.

We Promise:
  • ✅ Always put the family's best interests and privacy protection first
  • ✅ Collect only the minimum necessary information actively provided by parents
  • ✅ As a parental assistance tool, designed as a management tool for adults
  • ✅ Provide transparent, easy-to-understand privacy protection mechanisms
  • ✅ Continuously improve security measures to protect your family data

Thank you for choosing Smoothstep to build great habits together!