Data minimization and privacy by design

The principles behind every serious privacy framework are simple: collect the least you can, and build protection in from the start. Steady Pace treats them as absolutes rather than targets. Here is what each one means, and how far the app takes it.

The short answer: Two ideas sit under most privacy law: data minimization, collect only what you need, and privacy by design, build protection into the product from the start. Steady Pace treats both as absolutes. It collects nothing off your phone and stores everything on the device. The protective state is the only state the app has. These principles appear in frameworks like ISO/IEC 29100. Steady Pace expresses them in their strongest form: no data collected.

Data minimization, as zero

Data minimization usually means trimming. Ask for the postal code instead of the full address; keep records for a year rather than forever. To hold your pace and log your run, Steady Pace needs no account, no cloud profile, and no server copy of your route. The offset on your GPS is discarded on the phone during processing. There is no dataset on a server, because the app needs nothing at all.

Privacy by design, as the only design

Privacy by design asks that protection be the default and built in from the start, rather than offered as a setting a user can find. Steady Pace has no privacy settings, because there is no less-private mode. The app cannot share your runs, cannot upload your route, and cannot show you an ad, because those options were never built. The protective behavior is the only behavior.

Purpose limitation, by construction

Purpose limitation says data collected for one reason should not be quietly reused for another. A fitness app that sells your location to advertisers breaks this. Steady Pace cannot, because the data never leaves your phone. There is no second purpose available for information never collected.

PrincipleThe usual readingSteady Pace
Data minimizationCollect a little lessCollect nothing off the device
Privacy by design and defaultProtective settings, on by defaultNo settings, because there is no other mode
Purpose limitationDo not reuse data for new purposesNo data leaves the phone to reuse
Storage limitationDelete data after a whileData lives only on your device, under your control

Steady Pace collects nothing and keeps everything on your phone. These are the principles taken literally.

What is data minimization?

The principle that you should collect only the personal data you need, and no more. Steady Pace needs nothing off your phone to hold a pace and log a run, so it collects nothing.

What is privacy by design?

Building data protection into a product from the start and making it the default, rather than an option a user must enable. Steady Pace has no privacy settings because there is no less-private mode; the protective behavior is the only behavior.

Which frameworks are these principles from?

They run through the GDPR, California's CCPA and CPRA, and privacy frameworks like ISO/IEC 29100. Steady Pace is built on the principles themselves, in their strongest form: no data collected, everything kept on your device.

How is "no data" stronger than "less data"?

Data that is never collected cannot be breached, sold, subpoenaed from a server, or exposed by a policy change. Collecting none removes those risks entirely.

Hold your pace by ear

Set a target pace. A tone rises when you slow and falls when you speed up, so you hold it without looking at your phone. No ads, no account, no subscription.

Download on the App Store