Last Updated: June 24, 2026
This Privacy Policy explains how we handle your information when you use the One Small Step iOS app ("the app").
The app is built by Marta Basznianin Software, operating as Nami Apps, an independent software studio based in Poland. We are the data controller for any personal data described below. You can reach us at [email protected].
This data sits in the app's iOS sandbox. It's encrypted when your device is locked (standard iOS Data Protection) and is included in your iOS backups (iCloud or local) if you have those turned on. Apple — not us — controls what happens in those backups; see Apple's Privacy Policy.
The app does not actively sync your data to any server. We do not have copies of it.
When you tap the breakdown button, the text from your brain dump is sent over HTTPS to a server we operate (a Supabase Edge Function), which forwards it to OpenAI's API and returns the result. We use the relay so the OpenAI API key isn't exposed in the app — it's a pass-through that doesn't log the body of your request.
Our relay function is hosted by Supabase, based in the United States. Supabase processes the request only to forward it; we have not configured the function to log request bodies. Supabase sees standard request metadata (timestamps, status codes, and your device's IP address, which counts as personal data under GDPR). See Supabase's Privacy Policy.
If you subscribe to One Small Step Pro, we use RevenueCat to verify your subscription status without operating our own server. RevenueCat receives:
RevenueCat does not receive your tasks, brain dumps, or focus-session data. Apple processes the actual payment; we never see your Apple ID, payment method, or billing address. RevenueCat is based in the United States. See RevenueCat's Privacy Policy.
Standard interactions with the App Store (download, install, in-app purchase) are governed by Apple's Privacy Policy. If you have Share With App Developers enabled in iOS Settings → Privacy & Security → Analytics & Improvements, Apple may share aggregated, non-identifying usage and crash data with us through App Store Connect. We do not receive identifiers tied to you through this channel. App Store Connect analytics is separate from the PostHog and Sentry data described below.
To understand how the app is used and improve it, the app sends anonymous product events to PostHog, hosted in the European Union. Events include things like which screens you visit and which buttons you tap (e.g. "brain dump submitted", "focus session started", "paywall shown"), and aggregate properties such as brain-dump character count, step counts, focus-session durations, and whether you are on the free or premium plan. Each event is tagged with a randomly generated, app-local identifier so we can count distinct devices without identifying you.
We do not send your brain-dump text, generated step titles, name, email, IDFA, or any other personal identifier. Analytics is not collected from development (Debug) builds. The app does not currently include an in-app toggle to disable analytics; deleting the app stops further events from being sent. See PostHog's Privacy Policy.
If the app crashes or hits an unexpected error, the app sends a crash report to Sentry, hosted in the European Union. The report contains the crash stack trace, iOS version, device model, app version and build number, and an anonymous device identifier. Crash reports do not include your task content, brain-dump text, or any personal identifier. The app does not currently include an in-app toggle to disable crash reporting; deleting the app stops further reports from being sent. See Sentry's Privacy Policy.
We do not collect names, emails, contacts, location, photos, calendar data, device identifiers used for advertising, or any other category not listed above. The app does not request permission to access your camera, microphone, photo library, contacts, or location.
If you use the AI breakdown feature, your text is transferred to the United States (OpenAI, Supabase). Subscription metadata is processed in the United States (RevenueCat). These providers contractually rely on the European Commission's Standard Contractual Clauses or equivalent safeguards under Articles 44–49 of the GDPR. Analytics (PostHog) and crash reports (Sentry) are processed within the European Union — no international transfer occurs for those data flows.
You have the right to access, correct, erase, restrict, port, or object to the processing of personal data we hold, and to withdraw consent at any time. The only data we have any connection to consists of AI requests (not stored), subscription metadata (RevenueCat), and anonymous analytics and crash data (PostHog, Sentry). In practice:
If you believe we've handled your data incorrectly, you can lodge a complaint with your local data protection authority. In Poland, this is the President of the Personal Data Protection Office (UODO) — uodo.gov.pl.
One Small Step is not directed at children. Where the GDPR digital-consent threshold applies (16 in most EEA countries, including Poland), we do not knowingly process data from children below the applicable threshold. If you believe a child has used the app in a way that resulted in personal data being sent to us, contact us and we will act on it.
Data is encrypted in transit (HTTPS/TLS) and on your device (iOS Data Protection, encrypted while the device is locked). We don't store user data, so there's no central database to breach. The only credential held is the OpenAI API key, which lives on the Edge Function and is never shipped with the app.
We'll update this policy as the app evolves. The "Last Updated" date at the top will reflect any change. For material changes that affect what leaves your device, we will additionally make the change visible from inside the app or on this website before continuing to process data under the new terms.
Marta Basznianin Software (Nami Apps), Poland
Email: [email protected]