Who we are
NorthStep (“NorthStep”, “we”, “us”) provides the NorthStep mobile application, a private management notebook for line managers. For the purposes of UK and EU data protection law, we are the data controller for the personal data described below.
You can reach us about anything on this page at hello@northstephq.com.
The short version. Your notes, follow-ups and goals are visible only to you. We do not sell data, we do not run advertising, and there are no third-party analytics or tracking SDKs in the app. You can delete your account and everything in it from inside Settings.
What we collect
Account information
- Your email address, and your first and last name.
- Optionally, your job title, company name and profile picture.
- If you sign in with Apple or Google, the identifier and basic profile details (name and email) that provider returns. We never receive your password for those accounts. If you use Apple’s Hide My Email, we only ever see the relay address.
Content you create
Everything you enter about the people you manage, which you should assume includes personal data about them:
- The names, roles, start dates and 1:1 cadences of your direct reports.
- Your raw 1:1 notes and the structured action items, discussion points and follow-ups derived from them.
- Follow-up items, deadlines and completion state.
- Goals, KPIs and OKRs, with their targets and status history.
- Casual conversation notes, peer feedback you record, and development aspirations.
Technical information
- Authentication records — sign-in times, session tokens and IP address — kept by our authentication provider for security and abuse prevention.
- Server logs generated when the app calls our backend, used to diagnose errors.
We do not collect location data, contacts, your device’s advertising identifier, or any usage analytics.
How we use it
- To run the app — storing and syncing your data so it is there on your device when you open it. Lawful basis: performance of our contract with you.
- To structure your notes with AI — when you record a 1:1 or ask for suggested topics, the relevant text is sent to our AI provider and the result is returned to you. Lawful basis: performance of our contract with you.
- To keep accounts secure — authentication, abuse prevention and error diagnosis. Lawful basis: our legitimate interest in operating a secure service.
- To answer you — if you email us for support. Lawful basis: our legitimate interest in supporting users.
We do not use your content for advertising, profiling, or to train any machine-learning model of our own.
Who processes your data
We use a small number of sub-processors, each bound by contract to handle data only on our instructions:
- Supabase — database, authentication and server hosting. Your account and content are stored in Supabase’s Asia Pacific (Tokyo) region.
- Anthropic — the AI model that structures your 1:1 notes and generates suggested topics and coaching insights. Text you submit to those features is sent to Anthropic’s API for processing and returned to you. Under Anthropic’s commercial API terms, this content is not used to train their models.
- Apple and Google — only if you choose to sign in with those providers, and only for authenticating you.
Because our infrastructure is hosted outside the UK and EEA, your data is transferred internationally. Those transfers are covered by the standard contractual clauses in our agreements with the providers above.
We will disclose data to anyone else only where we are legally required to, or where it is necessary to establish or defend legal claims.
Notes about other people
NorthStep is designed to hold information about your direct reports. Where you use NorthStep for work, your employer is generally the controller of that information and you are recording it in your role as their manager — the same as any other management note you keep. You are responsible for what you record and for meeting your employer’s policies and applicable law, including keeping notes relevant, accurate and proportionate. We act only as a processor of that content on your behalf.
If you are a direct report and believe a manager holds information about you in NorthStep, please raise it with your employer first, as they control that data. You can also contact us at hello@northstephq.com and we will assist them in responding.
How your data is protected
- Every record is tagged with your user ID and enforced by database row-level security, so one account cannot read or write another account’s data — this is enforced at the database, not just in the app.
- All traffic between the app and our servers is encrypted in transit with TLS, and data is encrypted at rest by our hosting provider.
- Passwords are stored only as salted hashes by our authentication provider. We never see them.
No system is perfect. If we ever suffer a breach affecting your personal data, we will notify the relevant supervisory authority and, where the risk to you is high, notify you directly.
How long we keep it
We keep your account and content for as long as your account exists. When you delete your account, the account record and all data linked to it — reports, 1:1 records, follow-ups, goals, notes and aspirations — are deleted immediately and permanently by cascade. Backups and server logs age out within 30 days.
Deleting your account
Open Settings in the app and choose Delete account. This cannot be undone, and we cannot recover the data afterwards. If you would rather we did it for you, email hello@northstephq.com from your account address.
Your rights
Under the UK GDPR and equivalent laws you have the right to access, correct, delete or export your personal data, to restrict or object to certain processing, and to withdraw consent where we rely on it. Most of these you can exercise directly in the app; for anything else, email us and we will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority.
Children
NorthStep is a workplace tool intended for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.
Questions about your data?
Email hello@northstephq.com and a human will reply.