If your work makes you care about standards, this section is for you. Steady Pace was built on one architectural decision: it collects no personal data and makes zero network connections. Everything runs on your phone. Modern privacy law attaches obligations to data that is collected, stored, and transferred. There is none of that here.
The architecture
Steady Pace has no account, sends no analytics, serves no ads, and never connects to a server. Your pace, routes, distance, and history are computed and kept on the device. The GPS offset is discarded on the phone during processing, so even the local data is not a clean map back to you. Nothing is uploaded, so nothing can be sold, shared, breached, subpoenaed from a server, or exposed by a changed setting.
Framework by framework
EU
GDPR
Data minimization and privacy by design are met by construction, because no personal data is processed or transferred.
California
CCPA and CPRA
The strongest version of "we do not sell or share your data": there is no data collected to sell or share.
Apple
App Store privacy label
An app that collects nothing qualifies for Apple's clearest label: Data Not Collected.
Apple
App Tracking Transparency
No tracking prompt, because there is no tracking and no ad identifier read.
Canada
PIPEDA
Canada's privacy law: nothing collected, used, or disclosed off your phone.
Principle
Data minimization and privacy by design
The privacy principles the app is built on, and how they line up with recognized frameworks.
Check it yourself
Put the app in airplane mode and it works exactly the same, because it never used the connection. An app that runs identically with every radio off collects and sends nothing. You can verify this in ten seconds on your own phone.
Data that is never collected cannot be breached or sold. Steady Pace is built that way.