Under the hood

Technology & privacy

Curious how StepByStepApp works under the hood? Below are the questions we get most often — about privacy, accounts, offline use and where your data lives.

Can I join without an account?

By default the app is fully anonymous. Visitors don’t need to log in to join — their progress simply stays on their own device.

The organiser decides per tour how much is needed: fully anonymous, just a name for the leaderboard, or a real account to keep progress across devices. That last option is off by default.

Which cookies does the app use?

No tracking cookies, no ad networks, no Google Analytics or Facebook pixel. That’s why the app doesn’t need an annoying cookie banner.

The only cookies are functional session cookies — and you only get those if you log in yourself (as an admin or participant).

For statistics we anonymously count how often something is found. No IP address, no idea who you are.

What stays on my device?

Your progress, language choice and whether sound is on are stored locally in your browser (localStorage). That stays on your device and doesn’t come to us — unless you create an account.

The app also keeps a temporary copy of itself in a cache, so everything loads fast and works without internet.

Does the app work offline?

StepByStepApp is a Progressive Web App (PWA): a website that behaves like a real app. You can add it to your home screen and use it without an app store.

On first load the app stores the whole tour — pages and photos. So everything keeps working without signal: in a basement, a forest or a crowded festival site.

Optionally a tour can send push notifications, without us storing your identity.

How do organisers sign in?

Admins log in with email and password, or with their Google or Microsoft account (single sign-on).

We store passwords encrypted (bcrypt hashing) — we can’t read them back ourselves. Invitations and password resets use one-time email links.

Where is my data stored?

Everything runs on a server in the EU (Germany, at Hetzner) — no US cloud. We send email through our own mail server.

We stick to data minimisation: we ask for and keep as little as possible. GDPR-friendly, with EU hosting.

How secure is it?

All connections run over HTTPS, with strict security headers and encrypted sessions.

Submitted photos, audio or answers are automatically deleted after a retention period (90 days by default).

Another question?

Don’t see your question here? We’re happy to help — technical or not.

Email us

StepByStepApp — driven by Rivven