Overview
What this policy covers
StepBranch is an application for documenting workflows and processes using steps and decision points. This policy explains what information StepBranch collects, how it's stored, and who it's shared with, across the web app at stepbranch.app and the iOS/macOS app.
Note
This is a significant change from earlier versions of StepBranch. Versions before sign-in and sync existed stored all data locally on your device only, with no account and no internet connection required. That is no longer how the app works \u2014 this policy reflects the current version.
Accounts
Signing in
StepBranch requires you to sign in using either Sign in with Apple or Microsoft (Azure AD) sign-in. StepBranch does not collect or store a separate password \u2014 authentication is handled entirely by Apple or Microsoft, and StepBranch only receives:
- A unique account identifier
- The email address associated with your Apple ID or Microsoft account (or a private relay address, if you choose to hide your email with Sign in with Apple)
- A display name, if provided by Apple or Microsoft
StepBranch does not see or store your Apple ID or Microsoft account password at any point.
Your content
What StepBranch stores
Once signed in, the workflows you create are stored in your account, including:
- Workflow and folder names
- Steps, decision points, and branch options you create
- Metadata you add to steps (system, role, location)
- Timestamps for when items are created and changed
This data is stored so it can sync automatically across every device where you're signed in with the same account, and so you can access it from the web app and the iOS/macOS app interchangeably.
Infrastructure
Where your data is stored
StepBranch uses Supabase, a third-party database and authentication provider, to store account and workflow data. Data is hosted on Supabase's infrastructure in the Northeast Asia (Seoul) region.
Supabase acts as a data processor on StepBranch's behalf \u2014 it stores the data but does not use it for its own purposes. You can read Supabase's own privacy practices at supabase.com/privacy.
Note
If you're located outside Northeast Asia, this means your data is transferred to and stored in a different region than where you use the app.
Sign-in providers
Apple and Microsoft
When you sign in, Apple or Microsoft authenticate you and share basic profile information (as described above) with StepBranch. StepBranch does not control how Apple or Microsoft handle your data on their side \u2014 refer to their own privacy policies:
Exporting and importing
Files you create
StepBranch lets you export workflows as CSV, JSON, PDF, or Draw.io files. Exported files are generated on your device (web) or within the app (iOS/macOS) and are only stored or shared where you choose to save or send them \u2014 StepBranch does not separately retain a copy of an exported file beyond what's already stored in your account as the underlying workflow.
You can also import a JSON backup file (including older v1-format backups). Imported data is added to your account in the same way as anything you create directly in the app.
Tracking
Analytics and third parties
StepBranch does not use third-party advertising networks, and does not sell or share your data with advertisers. StepBranch does not currently use analytics or tracking tools beyond what's necessary for Supabase to operate (such as error logging needed to keep the service running).
Payments
Subscriptions and purchases
StepBranch does not currently offer any paid plans, subscriptions, or in-app purchases. If this changes in the future, this policy will be updated to describe what payment information is collected and by whom (for example, Apple's In-App Purchase system or a payment processor) before any payment feature is introduced.
Your choices
Accessing and deleting your data
You can delete individual workflows, folders, and steps at any time from within the app.
You can also permanently delete your entire account and all associated data yourself, directly from the app: open your account menu and select "Delete Account." This immediately and permanently removes every workflow, folder, step, and decision branch you've created, along with your authentication record \u2014 it cannot be undone, and there is no recovery period or grace window.
Important
Deleting individual workflows from the app removes them from your active list, but the underlying record isn't immediately and permanently erased from the database \u2014 use "Delete Account" if you need everything fully and immediately erased, or contact us directly for a partial deletion request.
Eligibility
Children's privacy
StepBranch is a workflow-documentation tool intended for general and professional use, and is not directed at children. StepBranch does not knowingly collect information from children under 13 (or the relevant minimum age in your region). If you believe a child has created an account, contact us and it will be removed.
Updates
Changes to this policy
This policy may be updated as StepBranch adds new features, such as subscriptions or new sign-in options. Material changes will be reflected by updating the "last updated" date at the top of this page. Continuing to use StepBranch after a change means you accept the updated policy.
Get in touch
Contact
If you have questions about this policy, or want to request access to or deletion of your data, contact: