12steps← Home

Privacy Policy

Last updated: 27 July 2026

Who we are

12steps is operated by Community Tech Ltd (company number 16760348), registered at 80 Greenham Road, Newbury, England, RG14 7HX. Community Tech Ltd is the data controller for the personal data described in this policy. For data protection enquiries, contact support@12steps.life.

Your journal, step work, inventories, amends and other private entries are encrypted on your device before they are ever sent to our servers. How far that protection goes depends on the account mode you chose at sign-up. Private accounts are zero-knowledge: the key exists only on your devices, we store ciphertext we have no way to decrypt, and we could not read your work even if asked. Standard accounts (the default) use the same on-device encryption, but a protected server-side key lets us restore your access when you reset your password by email — which means our systems could technically decrypt that content. We never use that key to read your work; it exists solely for account recovery. Peer support is different in both modes: posts and replies in that shared queue are visible to peer responders and moderators.

Information we collect

  • Email address: used to sign you in and to send reminders you opt into. It is encrypted at rest on our servers and indexed only so you can log in.
  • Password: never stored. We keep only a one-way hash used to verify sign-in. On a Private account your password also derives the key that encrypts your data, and that key never leaves your device.
  • Your private recovery content: journal entries, step work, inventories, prayers, meetings and similar private entries are encrypted on your device. On a Private account the key is held only by you and we store ciphertext we cannot read; on a Standard account a protected server-side key exists so that email password recovery can restore your access.
  • Peer support messages: if you post or reply in peer support, the alias, topic and message text are visible to peer responders and moderators so they can answer and keep the queue safe.
  • Notification token: if you enable reminders, your device's push token is stored so we can deliver them. Reminders contain only generic prompts, never your content.
  • Meeting location: if you choose a town or postcode, the selected place and its approximate coordinates are saved on your device so the meeting finder can remember it. The search text passes through our server without being stored, then is sent to Postcodes.io to find matching places. If you choose Use my location, your device supplies a one-off location which is kept in memory while the finder is open. It isn't saved or sent to 12steps. Only when you open the map, your browser or app requests map tiles from the OpenStreetMap Foundation. That service receives normal technical request information, such as your IP address, and can infer the approximate area shown on the map. It does not receive your 12steps account or recovery work.
  • Basic technical logs: standard request logs needed to operate and secure the service.
  • Website usage: 12steps.life uses our self-hosted, cookie-free Umami service to count page views and show us which parts of the website are used. It never receives your email address or private recovery content, and it is not loaded in the iOS or Android app.

What we never do

  • We do not use advertising, cross-site trackers, session replay, or an advertising identifier.
  • We do not track you across apps or websites.
  • We do not continuously track your location or keep a location history.
  • We do not sell or rent your information.
  • We never read your private recovery content — not for ads, training, or any other purpose. On a Private account we could not read it even if we wanted to.

How your data is protected

Your private recovery content is encrypted with AES-256-GCM before it leaves your device. On a Standard account, a protected server-side key allows us to restore your access after an email password reset. On a Private account, the key is derived from your password (Argon2id) and held only in your device's memory, with a 12-word recovery phrase as the offline backup. Because of that design, on a Private account, if you lose both your password and your recovery phrase, your encrypted private recovery data cannot be recovered by anyone, including us.

Data retention and deletion

You can delete your account at any time from Settings → Danger Zone, which permanently removes your account and all associated data. See the account deletion help page for details.

Children

12steps is intended for adults (18+) and is not directed to children.

Your rights

You can export your data at any time from within the app and delete your account on demand. For other requests regarding your personal data, contact us using the details below.

Changes

We will update this policy as the app evolves and post the new effective date here.

Contact

Questions about privacy? Email support@12steps.life.

© 12steps

Privacy·Terms·Support