Privacy Notice
Last updated: 18 August 2026 · Covers the Steady On website and the Steady On app
The short version
You are logging health information, and we treat it that way. Everything you record is private to your account, stored in the United Kingdom, and never sold, never shared with advertisers, and never used to train anything.
We do not run adverts. We have no analytics company, no Google Analytics, no Meta pixel, no advertising SDK. Page counting records the page, the referring site and the time, and nothing else.
The only email we send that you can switch off is an occasional reminder if you have not logged anything for a while. It contains no health information and no marketing.
You can download everything we hold, in one file, at any time. You can delete your account and all of it in a few taps. Both are in the app under More → Account & your data.
This notice explains what Steady On collects, why, who else is involved, and what you can make us do about it. It is written in plain English on purpose. If anything here is unclear, ask us and we will fix the wording.
Who we are
Steady On is operated by Symington Intelligence Group Ltd ("we", "us"), a company registered in England and Wales, company number 17234629, registered office 5 Brayford Square, London, United Kingdom, E1 0SG. The company is the data controller for everything described below.
Contact for anything in this notice, including any of the rights listed further down: enquiries@symingtonintelligencegroup.co.uk.
What we collect
Your account
Your email address. We do not ask you to create a password. You sign in with a one-time code we email you, so there is nothing for you to remember and no password for us to hold or lose. Accounts created before 18 August 2026 may still have one; where that is the case it is stored only as a salted hash by our authentication provider, which means neither we nor anyone else can read it. We also store a record of which version of our terms and health-data consent you agreed to, and when, and a record that you confirmed at signup that you are 16 or over.
What you choose to log
This is the heart of the app, and it is special category health data under UK GDPR Article 9. We only ever have what you type in. Nothing is inferred from your phone, and nothing is collected in the background.
- Heart rate and blood pressure readings, the position you were in, any tags and comments
- Symptoms and their severity, fluids, salt and sleep
- Lean test results, including the individual readings during the test
- Medications you record: name, dose note, what it is for, when you started or stopped
- Menstrual cycle start dates and notes, if you use that feature
- Your 12-Week Reset progress: which sessions you completed, how each one went, weeks repeated
- Flare periods, pacing settings, personal experiments
- Appointments: who you are seeing, your goal, your questions, and what was decided
- Which investigations you have recorded as done, asked about, or not relevant
- Daily maximum and minimum temperature for the dates you have logged, if you turn on weather
Payment
If you subscribe or buy the programme, we never see or hold your card details. Payment is handled entirely by Stripe. We store only a Stripe customer reference and what you are entitled to (which plan, when it started, when it renews). Stripe acts as merchant of record for the sale.
Technical data
Our hosting providers keep standard server logs, such as IP address and browser type, for security and reliability. We do not use these for analytics.
Page counting
We count page views so we know whether anyone is finding the site. Each view records three things: which page was opened, the site you arrived from if there was one, and the time. That is the entire record. No cookie, no device storage, no visitor ID, no fingerprint, nothing sent to any third party. Because nothing recorded can be traced to a person, this is not personal data and there is no cookie banner to click.
Emails we send you
There are two kinds, and they are separate.
Emails you cannot turn off are the ones the service cannot work without: the code that signs you in, and a receipt or notice if you pay for something. There are no others, and we do not send newsletters, offers or marketing.
Who sends them. All of our email, including the sign-in code, goes through Resend, which acts as our processor. Resend receives your email address and the message itself, and nothing else. It never receives any of your health data. A sign-in code is valid for one hour, can be used once, and is not stored anywhere in a form that could be read back. The transfer outside the UK is covered under “Where your data lives” below.
The reminder email you can turn off. If nothing has been logged on your account for about a week, we may send one short email saying your history is still there. It counts nothing, mentions no symptoms, readings or health information of any kind, and the subject line is deliberately neutral so that it gives nothing away on a lock screen. You will get at most one a fortnight, and if two in a row go unanswered we stop sending them altogether.
To send it we use the fact that you have an account and the date something was last logged. As with every other email we send, Resend receives only your email address and the message itself.
You can switch it off in the app under More → Account & your data → Email, or with the link at the bottom of any one of them, or with your mail app’s own unsubscribe button. Any of the three works immediately and changes nothing else about your account. Our lawful basis is our legitimate interest, under Article 6(1)(f), in helping people get value from a service they chose to sign up to, balanced against how easy it is to stop.
What we do not do
- We do not sell your data, and we do not share it for anyone else's marketing
- We do not use your data to train artificial intelligence, ours or anyone else's
- We do not run advertising or take sponsorship on any tier, including the free one
- We do not make automated decisions about you, and there is no profiling in the Article 22 sense. The app shows you patterns in your own data; a person, meaning you, decides what to do about them
- We do not diagnose. Steady On tracks and displays. It does not interpret your results as a clinician would, and it is not a medical device
Our lawful basis
| What | Article 6 basis | Article 9 basis |
|---|---|---|
| Running your account and providing the app | Contract, 6(1)(b) | Explicit consent, 9(2)(a) |
| The health information you log | Contract, 6(1)(b) | Explicit consent, 9(2)(a), given at signup |
| Taking payment and keeping sales records | Contract, 6(1)(b), and legal obligation, 6(1)(c) | Not applicable, no health data involved |
| Emailing you the one-time code that signs you in | Contract, 6(1)(b) | Not applicable, no health data is used or included |
| Security, backups and keeping the service working | Legitimate interests, 6(1)(f) | Explicit consent, 9(2)(a) |
| The waitlist, if you joined it | Consent, 6(1)(a) | Explicit consent, 9(2)(a), if you picked a health-related category |
| The occasional reminder email, if you have not logged for a while | Legitimate interests, 6(1)(f) | Not applicable, no health data is used or included |
Where we rely on consent, you can withdraw it at any time, and withdrawing it does not make anything you did before unlawful. In practice, withdrawing consent for the health data means deleting your account, because the health data is the app.
Who else touches your data
These are our processors. They act on our instructions under their standard data processing terms, and none of them may use your data for their own purposes.
| Who | What for | Where |
|---|---|---|
| Supabase | Database, sign-in, and the server functions behind account deletion and payment | London, United Kingdom (eu-west-2) |
| Netlify | Serving the website and the app, server logs | Global network, US company |
| Stripe | Taking payment and keeping the sales record. Merchant of record | Ireland and US |
| Open-Meteo | Looking up temperatures, only if you turn weather on | Germany |
| Resend | Sending email. Three things: the one-time code that signs you in; the occasional reminder email, if you have not switched it off; and our own business summary to us, which carries counts only and no information about you. Resend never receives health data of any kind | US company, sending from Ireland (eu-west-1) |
| YouTube (Google) | Playing a PoTS UK exercise video, only after you tap to load one | US and global |
About the exercise videos. The 12-Week Reset links to demonstration videos published by the charity PoTS UK. These are hosted on YouTube. Nothing is requested from Google, and no cookie is set, until you tap the play placeholder. Tapping is your choice and your consent. Once you do, Google receives your IP address and may set cookies and show its own advertising, which is outside our control. If you would rather not, do not tap: the animated figure and the written instructions cover the same movement without any third party being involved.
Where your data lives
Your account and everything you log are stored in a database hosted in London, United Kingdom. Some of our processors are US companies and may access data from outside the UK for support and maintenance. Where that happens it is covered by the UK International Data Transfer Addendum or the UK extension to the EU-US Data Privacy Framework, as applicable to each provider.
Sharing with someone else
You can create a read-only link so a parent, partner or carer can see a summary. That only ever happens because you chose to create it. The link is unguessable, you can set it to expire, and you can revoke it at any moment in the app. Anyone holding the link can see the summary, so only send it to someone you trust, and revoke it when it is no longer needed.
How long we keep it
- Your account and health logs: for as long as your account exists. Delete the account and they go with it.
- Payment records: six years, because HMRC requires proof of sales to be kept for that long. These sit with Stripe and contain no health information.
- Encrypted database backups: these roll on a schedule, so deleted rows can persist inside a backup for up to a week before ageing out. Nobody reads them. They exist only to restore the whole database after a failure.
- Server logs: a short period set by our hosting providers, for security.
- Page counts: indefinitely, because they contain nothing about any person.
- Waitlist entries: until you join, ask to be removed, or we retire the list. Deleting your account also removes your waitlist entry if you had one.
Deleting your account
In the app: More → Account & your data → Delete account. You type DELETE to confirm, and it happens immediately and cannot be undone.
If you no longer have the app, use the public Steady On account deletion page to request deletion by email.
It removes your sign-in, your readings, symptom entries, lean tests, programme progress, medications, cycles, appointments, experiments, checks, flares, weather history, any carer link you created, your entitlements and your waitlist entry. The only things that survive are the two named under "How long we keep it": the Stripe payment record if you ever paid, and rows sitting in an encrypted backup until it rotates.
Download your data first if you want a copy. Once it is gone we cannot get it back for you.
Your rights
Under UK GDPR you have the right to:
- Get a copy of what we hold (Article 15). Do it yourself, instantly, with "Download all my data" in the app. It is a single JSON file covering every table that holds anything of yours.
- Take it elsewhere (Article 20). The same file is machine-readable and yours to move.
- Correct anything wrong (Article 16). Most of it you can edit directly. Email us for anything you cannot.
- Erase it (Article 17). Delete your account in the app, or email us.
- Restrict or object to processing (Articles 18 and 21).
- Withdraw consent at any time.
- Complain to the Information Commissioner's Office at ico.org.uk, or 0303 123 1113. We would rather you came to us first so we can put it right, but you do not have to.
We will respond to any request within one month, and there is no charge.
Cookies
There is no cookie banner because there is almost nothing to consent to. The app stores one thing on your device: the token that keeps you signed in. It is strictly necessary for a service you asked for, so it needs no consent under PECR. We set no analytics, advertising or tracking cookies of any kind. The only third-party cookies that can ever appear are Google's, on a video you have chosen to load.
Children and young people
Steady On is intended for people aged 16 and over. POTS is commonly diagnosed in teenagers, and we know younger people want this. At present we cannot properly handle parental consent, so we ask that under-16s do not create an account.
When you create an account we ask you to confirm that you are 16 or over, as a separate question from the health-data consent, and we record your answer against the date and version of the wording you saw. We do not ask for your date of birth and we do not verify your age, because collecting proof of identity from people logging health information would be a bigger intrusion than the problem it solves. It is a declaration, and we treat it as one.
If you are a parent or guardian
If an account has been created by someone under 16, email enquiries@symingtonintelligencegroup.co.uk and we will delete the account and everything in it. You do not need to explain yourself, there is no charge, and we will confirm once it is done. You do not need to be able to sign in to ask.
The same route is signposted inside the app, under More → Account & your data, so you can find it on the device itself.
Security
Your data is protected by row-level security in the database, which means the rules preventing one account reading another's data are enforced by the database itself rather than by the app. Everything travels over an encrypted connection and is encrypted at rest. Entitlements are stored where the browser cannot write to them. We are a very small operation and we do not pretend to be a bank, but the design assumes the app can be tampered with and puts the important checks on the server.
Not medical advice
Steady On is for education and self-tracking. It is not medical advice, diagnosis or treatment, it is not a regulated medical device, and it is not a substitute for your doctor. Nothing in it should be used to decide whether to start, stop or change a medication.
Changes
We will update this page and the date at the top whenever anything material changes. If a change affects how we use the health information you have already logged, we will tell you in the app before it takes effect rather than quietly editing this page.