Legal
Privacy Policy
OneStepTwo helps parents and guardians track potty-training routines. This policy explains what information the app and website process, why, where it may be processed, and the choices available to your family.
Who Is Responsible for This Service
Brandon Hogan operates OneStepTwo and is the contact for questions about this policy or personal information. Contact: onesteptwoapp@gmail.com. This policy applies to the OneStepTwo mobile apps and website.
What We Process
Child and family information: a child's nickname, approximate birth date (birth month and year), and family name. We do not ask for a child's full date of birth, legal name, photo, gender, or biometric information.
Health-related routine data and content: potty-training events you or other caregivers log, including their time, type, and optional notes. We also process Sleep and Break availability intervals when those features are used. These records can describe bathroom habits, routines, or sleep, so we describe them as health-related data in our App Store privacy disclosures. Notes are optional and may contain other content you choose to enter.
Parent, guardian, and caregiver information: email address, Clerk account and organization identifiers, family membership and role information, invitations, and the family name. Clerk processes sign-in credentials and account identity information. We use account and family identifiers to control access to the right family's records.
Consent and preferences: a record that a parent or guardian confirmed the child-profile consent, including when it was given and, for signed-in profiles, the account identifier that gave it. In guest mode, the local consent record uses a guest marker rather than an account identifier. We also process notification and reminder preferences and related settings.
Device, notification, and diagnostic information: Firebase Cloud Messaging is initialized when the iOS app launches. It and its provider may process device and app information and messaging-registration metadata even before you allow notification alerts. For eligible guardians, the app requests alert permission and registers for remote notifications even if permission is declined, so a token can remain available if alerts are enabled later. When the app sends a token to our backend, we store the Firebase registration token and device platform. We use it for visible alerts and silent availability-state synchronization; a silent synchronization message does not itself display an alert.
We also use Sentry for crash reports, error reports, diagnostic breadcrumbs, and app or device context used to investigate reliability issues. Sentry events can be associated with the Clerk user identifier after sign-in. Provider and SDK configuration can affect the diagnostic and performance information processed.
Subscription records: if a family purchases a subscription, we receive and retain the StoreKit transaction information needed to verify and maintain the family's entitlement, such as the store platform, product, subscription status, expiry, and original transaction identifier. Apple handles payment-card and billing details; we do not receive those details from StoreKit.
Waitlist information: if you join the waitlist, we store your email address, selected iOS/Android interest, signup timestamp, and an opaque referral code. If you use a referral code, we record the relationship between your signup and the referring waitlist signup. We keep the request IP address in process memory for rate limiting until the service process restarts; it is not stored in the waitlist database.
Website Cookies and Browser Storage
Our public website does not currently use advertising cookies or third-party analytics trackers. If you arrive through a referral link, we ask before saving its code in this tab's session storage (os2_ref). If you allow it and join the waitlist, we use that code to link your signup to the referring waitlist signup. You can browse and sign up without allowing referral storage.
We save your allow or decline choice in session storage (os2_referral_consent) to respect that choice during this tab session. These entries normally disappear when the tab is closed; your browser's session-restore features may retain them. You can withdraw permission and clear the saved referral using Referral privacy settings below. Withdrawal stops future referral attribution in this tab; it does not undo a referral already submitted with a signup. Contact us about deleting information already submitted.
Guest Mode and Children's Privacy
OneStepTwo is for parents and guardians, not for children to use by themselves. Before a child profile is created, the app asks the parent or guardian to confirm by checkbox that they are the child's parent or legal guardian and are 18 years of age or older.
In guest mode, the child's profile, consent record, potty events, and related app data are stored locally on the device before an account is created. The local consent record is marked as a guest record rather than linked to a Clerk account. That local data is not backed up to our backend until the guest creates an account and the app successfully migrates the local child, consent record, and activity data to the new family. Uninstalling the app can remove guest-only data.
Guest users can choose Delete all local data in Settings to erase the local guest records. This does not erase records already migrated to an account, which use the account deletion options below. We do not claim that the checkbox process alone satisfies every parental-consent requirement in every jurisdiction.
Why We Use This Information
We use information to provide tracking, history, reminders, notifications, family access, milestones, account authentication, subscription access, support, security, and service reliability. We also use diagnostic information to understand how the app operates and to improve reliability.
The legal basis for processing depends on the information and the law that applies where you live. It may include providing the service you request, consent where we ask for it (including the parent or guardian's child-profile confirmation), and legitimate interests in operating a secure and reliable service where that basis is permitted. Some laws may apply additional conditions to health-related or children's information.
Service Providers and International Processing
We use Clerk for authentication and account identity; Firebase Cloud Messaging for push messaging; Sentry for crash reporting and diagnostics; Apple StoreKit for in-app subscriptions; and Railway to host the application backend and PostgreSQL database. Our operational design may also store database backup copies in Cloudflare R2. These providers process information needed to provide their services under their own terms and privacy practices.
Our current architecture uses U.S. hosting for the backend and database. If you use the service from outside the United States, your information may be transferred to and processed in the United States and in other locations where our providers operate. We do not state in this policy that any particular transfer safeguard, certification, or contract has been executed; provider and legal requirements can vary by transfer and location.
In App Store Connect, the selected disclosures identify Email Address, Health, Other User Content, User ID, Device ID, Purchases, Crash Data, Performance Data, Other Diagnostic Data, and Other Data. They are marked as linked to the user. We use them primarily for App Functionality; Other Data may also be used for Analytics to understand app operation and reliability. They are not used for tracking across other companies' apps or websites.
Retention, Deletion, and Subscriptions
We keep family data while it is needed to provide the service or until the applicable deletion action is completed. A child deletion hard-deletes that child's server-side child record, consent record, potty events, availability sessions, related notification records, and preferences. The app then attempts corresponding local deletion; if local cleanup is interrupted, the app may require a retry.
A caregiver who leaves one family loses that family's access. The service removes the membership through Clerk first and then makes a best-effort cleanup of that member's family-role and notification/reminder preference records for that family; it does not by itself delete the person's Clerk account, other family memberships, or all device tokens.
Event and availability records retain the account identifiers used to log, create, update, or delete them. Availability-notification outbox rows also retain recipient account identifiers so the service can check eligibility and deliver or cancel a scheduled message. These identifiers are used for App Functionality and are not automatically removed merely because a member leaves a family; they remain with the relevant family data until that data is deleted under its applicable retention path.
Deleting an account processes every family the account belongs to. For a family administered by that account, the backend deletes its child data, preferences, device tokens, entitlement record, and family-role records, subject to the pending-invitation exception below. For other families, the backend removes that account's local family-role and preference records. After the backend deletion commits, we make best-effort requests to Clerk to delete the relevant organization and Clerk user. Clerk memberships are removed only if those Clerk requests succeed. A Clerk-side request can fail after the backend deletion has succeeded and may require follow-up.
Pending family invitations retain the invited email address, family identifier, selected role, and creation time until the service later reconciles the person after they join. They are not currently removed automatically by family or account deletion, so an unaccepted invitation can remain until it is reconciled or manually cleaned up. We do not publish a fixed retention period for these pending invitation records.
On iOS, signed-in app data is stored in a local SQLDelight database. Signing out or deleting an account does not currently automatically remove that on-device database, so local copies can remain until the app is removed or a future cleanup process removes them.
Deleting a single potty event or availability session can leave a deletion marker (sometimes called a tombstone) while devices synchronize the deletion. These markers are part of the synchronization process and are distinct from an account or child erasure, which uses hard deletion. We do not publish a fixed retention period for synchronization tombstones, provider-side records, diagnostic data, or operational backups because those periods depend on the provider, configuration, and operational need.
We retain a limited erasure-audit record to document child, account, or membership deletion. It becomes eligible for purge after 90 days, but is removed only opportunistically when a later child or account deletion request runs, so it may remain longer than 90 days. The audit record is separate from the family activity data that the deletion flow removes.
Waitlist entries remain until we remove them following a request to onesteptwoapp@gmail.com; this is currently a manual process. Deleting app data or an account does not cancel an Apple subscription. To stop future subscription charges, cancel separately in your Apple account's subscription settings.
Your Choices and Rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction or objection to some processing, portability, or to complain to a data protection authority. These rights and any exceptions vary by jurisdiction. To make a request or ask about your information, email onesteptwoapp@gmail.com.
Security, No Selling, and Changes
We do not sell personal information, show ads, or use the information described here for cross-app or cross-website advertising tracking. We use measures intended to protect the information we hold, but no service can guarantee absolute security.
If we make material changes to this policy, we will update the date above and may notify you through the app or by email.
Contact Us
Questions about this policy or your data? Email onesteptwoapp@gmail.com.