QSTEP Privacy Policy
Effective date: July 24, 2026 · Last amended: August 10, 2026
QSTEP is a walking and habit companion operated by JETSKI LLC. This policy explains what the QSTEP iOS app and API process, why they process it, who can receive it, and the choices available to you.
1. Who operates QSTEP
JETSKI LLC is responsible for QSTEP. “QSTEP,” “we,” and “us” in this policy refer to JETSKI LLC. Our contact details appear at the end of this policy. QSTEP is operated from the United States, so information may be processed in the United States and in countries where the service providers described below operate.
2. Information QSTEP processes
- Motion & Fitness activity. With your permission, QSTEP reads daily step totals and estimated walking distance from Apple Core Motion. If you connect a public Qubic wallet identity and accept the in-app fitness-data disclosure, QSTEP sends daily aggregate steps and estimated distance to the QSTEP API for progress history, rankings, and reward eligibility. QSTEP does not upload raw motion samples. If you use Explore First without a wallet, these activity totals are not sent to the QSTEP API.
- Public wallet and reward information. QSTEP processes the public Qubic identity you enter, cached QUBIC balance snapshots and their check times, qualifying-day counts, projected reward amounts, and any settled or paid reward records. A configured Qubic RPC provider receives the public wallet identity when the API checks its public on-chain balance. QSTEP never asks for or stores your wallet seed phrase, private wallet key, or spending key.
- Device authorization information. The app creates an opaque installation identifier and a P-256 signing key. The QSTEP API receives the installation identifier, public key, binding generation, and registration timestamps so it can authenticate activity reports and prevent unauthorized rebinding. The private signing key remains in the device Keychain and is not sent to QSTEP. This mechanism proves control of the registered device key; it does not prove ownership of a Qubic wallet.
- Optional approximate location and weather. If you grant location permission, the app rounds latitude and longitude to two decimal places (approximately one kilometre) and sends them directly to Open-Meteo over HTTPS for current weather and day/night presentation. QSTEP does not send location to the QSTEP API, store it in the reward ledger, or use it for rewards. Open-Meteo also receives the IP address used for that request and handles it under its own terms and privacy practices.
-
On-device to-do and preference data. Habit names,
completion dates, and streak history are stored in a local
habits.jsonfile and are not sent to QSTEP. The app marks that file as excluded from iCloud Backup. Unit choices, onboarding state, and notification preferences are stored on the device or in iOS system settings. QSTEP reminders are local notifications; QSTEP does not use remote push notifications. - Technical and security data. Hosting, reverse-proxy, and network providers may process IP addresses, timestamps, user-agent data, request paths, and response status information in access or security logs. The QSTEP application logs route patterns, status codes, request duration, limited operational errors, aggregate balance-refresh results, and pseudonymous balance-check events; it does not intentionally log request bodies, authentication signatures, or admin secrets. The API also uses client IP addresses in memory for rate limiting. Inactive rate-limit entries are normally discarded within approximately six minutes, active entries roll while requests continue, and those entries are not written to the QSTEP database.
3. How QSTEP uses information
QSTEP uses the information described above to:
- show walking progress, credited history, goals, habits, and weather presentation;
- sync daily activity and calculate pseudonymous rankings;
- check QUBIC holding and walking-day criteria, estimate rewards, settle an epoch, and maintain payment records;
- authenticate registered devices and protect wallet-linked history from unauthorized rebinding;
- operate, secure, troubleshoot, back up, and improve the service; and
- respond to requests, resolve disputes, prevent abuse, and meet legal obligations.
4. Public leaderboard and blockchain visibility
Daily and epoch leaderboards are public. They show rank, aggregate step and
distance totals, and a stable label in the form QSTEP-<12 HEX>
instead of the raw wallet identity. This is pseudonymous, not anonymous:
the label is stable and may be linkable when someone already knows the
associated public wallet. Final Qubic transfers and transaction references
may also be visible permanently on the public Qubic network independently
of QSTEP.
You may optionally choose a display name (3–16 letters, digits, or underscore). A chosen name is shown publicly on the leaderboards in place of the pseudonymous label until you change it, clear it back to the pseudonym in Settings, or it is reset by the operator. Names are validated against a reserved-word and content policy, any user can report a name from the app, and the operator can reset a reported name; moderation resets are recorded in the operator audit log. Deleting your account removes your display name and any open name reports. Operator audit records of name-moderation actions, which include the wallet identity and the moderated name, are retained for accountability and abuse prevention.
5. When information is shared
QSTEP shares or makes information available only as needed for these purposes:
- Infrastructure providers, including hosting, reverse-proxy, network-security, and backup providers, process service traffic and stored records on our behalf.
- Open-Meteo receives optional rounded coordinates and the weather request's IP address directly from your device.
- The configured Qubic RPC provider receives a public wallet identity so QSTEP can retrieve its public balance.
- Other users and the public can see pseudonymous leaderboard information, and public-chain participants can see Qubic transactions.
- Authorities, advisers, or counterparties may receive information when reasonably necessary to comply with law, protect rights and safety, investigate abuse, resolve a dispute, or complete a corporate transaction subject to appropriate safeguards.
QSTEP does not sell or rent personal information. It does not use advertising SDKs, third-party analytics SDKs, or cross-app tracking, and it does not use fitness, location, wallet, or habit data for advertising, marketing profiles, or unrelated data mining.
6. Retention and deletion
- Active account and activity data. We keep the public wallet identity, mutable account, active device binding, cached balance, and daily step and estimated-distance totals while the account remains active. Disconnecting a wallet in the app only disconnects that device; it does not erase server records.
- Authenticated account deletion. “Delete account and server data” removes the mutable account, active device binding, cached balance, and daily activity from the live database when the authenticated request completes. It does not remove the retained records described below.
- Operational backups. Database backups use a rolling 14-day operational schedule. Records removed from the live database may remain until those backups rotate out. Backups are restricted and used only for security, continuity, and disaster recovery.
- Wallet claims and financial ledger. We retain the public wallet-to-public-key claim and claim timestamp without a fixed expiry to prevent a different key from reopening or taking over wallet-linked financial history. A later registration using the matching device key can recreate a mutable account. We also retain frozen settlement, payout, transaction, and associated operator-audit records without a fixed expiry for security, payment, dispute, legal, tax, and ledger-integrity purposes. These records may include the public wallet, epoch, qualifying-day count, balance snapshot, payout amount and status, settlement and payment times, transaction reference, and operator audit events.
- Technical logs. Application and infrastructure-log retention follows rolling service and provider configurations and does not have one fixed period across every source. We minimize those logs and keep them only as needed for security, reliability, abuse prevention, and legal compliance.
- Information on your device. Server-account deletion does not clear the separate on-device to-do file, general preferences, or the device identifier and signing key held in Keychain. Clear to-do data with its in-app control. The current app does not erase the device identifier or signing key from Keychain when server-account deletion completes. Those Keychain credentials are device-only security material and the private key is not uploaded.
7. Your choices and rights
You can decline Motion & Fitness or location access in iOS Settings. Location is optional and is not required for step tracking or rewards. You can use Explore First without connecting a wallet, disconnect a wallet, turn off local reminders, clear to-do information, or submit the authenticated server-deletion command in QSTEP Settings.
Depending on where you live, you may have rights to request access to, correction of, a portable copy of, deletion of, or restriction of personal information; object to certain processing; withdraw consent for future processing; and complain to a competent data-protection authority. These rights can be limited where retained security, public-blockchain, financial, tax, legal, or audit records must be preserved.
Email us to exercise a right, challenge an anti-takeover wallet claim, or request help after losing a registered device. We may request reasonable verification appropriate to the data and request. We will never ask you to send a wallet seed phrase or private key.
8. Security
QSTEP uses safeguards designed for the sensitivity of the records, including an HTTPS public API, device-generated request signatures, a device-only Keychain private key, restricted production database and backup access, security headers, rate limits, and authenticated account deletion. No system is completely secure, and no device signature can prove that reported steps came from an unmodified sensor or that the device owner owns the public wallet entered.
9. Policy changes
We may update this policy when QSTEP, its providers, or legal requirements change. We will publish the revised policy here and change the effective date. Material changes may also be presented in the app where appropriate.
10. Contact
For privacy questions or requests, contact:
JETSKI LLC1209 Mountain Road Pl NE, Ste N
Albuquerque, NM 87110-7845
USA
Email: admin@jetskipool.ai