The short answer: Steady Pace collects no personal data, stores everything on your device, and makes no network connections, so it does not transmit or process your personal data on any server. The GDPR's obligations attach to the processing of personal data. Steady Pace does none of that off your phone, so the duties that normally apply to a data controller do not arise. The app is built around two GDPR ideas: data minimization and data protection by design and by default.
Data minimization, taken to its limit
Article 5 of the GDPR says personal data should be adequate, relevant, and limited to what is necessary. To hold your pace and log your run, the app does not need an account, a cloud profile, or a server copy of your route, so it does not create any of them. The data it works with never leaves your phone. There is no collected dataset for the principle to limit, because none was gathered.
Privacy by design and by default
Article 25 asks that data protection be built into a product from the start and be the default state, rather than an option a user must switch on. Steady Pace has no privacy settings to configure because the private behavior is the only behavior. There is no sharing toggle set wrong, no default that leaks. The protective behavior is the built-in one and the only one.
The obligations that never come into play
| GDPR question | Steady Pace |
|---|---|
| Does it process your personal data on a server? | No, nothing is transmitted |
| Does it transfer data outside the EU? | No transfers at all, data stays on your device |
| Does it need a lawful basis or consent to collect? | Nothing is collected, so neither applies |
| Could a server breach expose your runs? | There is no server and no stored data to breach |
Lawful basis for processing, cross-border transfer rules, breach notification are the hard parts of the regulation. Every one of them is about data that leaves the user and lands on a company's systems. Steady Pace keeps your data on your phone, so none of them apply. Run the app in airplane mode and it works exactly the same, because it never used the connection.
Steady Pace collects and moves no data, so it meets data minimization and privacy by design by keeping everything on your phone.
California
CCPA and CPRA
The same architecture under US state law.
Principle
Privacy by design
The idea underneath the regulation.
Blog
Doesn't sell your data
Nothing collected, nothing to sell.
Is Steady Pace GDPR compliant?
It is built so the GDPR's core obligations never arise. It collects no personal data, keeps everything on your device, and makes no transfers, so there is no processing to have a lawful basis for and no server-side data to expose. It meets data minimization and privacy by design in the most direct way there is.
Does the app process my personal data?
Only on your own phone, to show your pace and log your run. It never transmits that data to a server, so there is no off-device processing, no transfer, and no server-side copy of your information.
Do I need to give consent or manage privacy settings?
No. There is nothing collected or shared to consent to, and there are no privacy settings to configure because the protective behavior is the only behavior the app has.
How can I verify the app transmits nothing?
Run it in airplane mode. Every feature works exactly the same with the radios off, which is only possible if the app was never relying on a connection to collect or send your data. You can run this test yourself in ten seconds.