Help us fix this

Tell us what went wrong. Please leave out private messages, residency documents, passwords, and sign-in codes.

Add an email if you'd like us to follow up.

Off until you choose it. Keeps up to 10 minutes or 100 technical events on this device, only while this page session is open. This activity history is uploaded only when you include it in a report. No typed text or screen recordings.

Including technical details also links up to five recent crash references shown below. Anonymous crash monitoring runs separately; your description and activity history stay in Steppe.

Review technical details

Page: /legal/privacy

App release: 276972c35898c9b6dd8e25d4616d5946c2f3e48b

No earlier steps are available. Enable technical history, close this panel, and repeat the problem to capture them.

null

Reports are private to Steppe support and removed after 30 days. Reports sent while signed in are linked to your account and included in account export/deletion.

Email support
Vol. I · No. 1Redmond · Central Oregon · Est. 2026
·
Steppe
CharterMembershipExchangePreviewContact
01Charter02Membership03Exchange04Preview05Contact
·
← Back to the plain-language summary

Privacy Policy

Effective date:  On publication for the founding beta
Version:         Draft v2
Last updated:    September 16, 2026
Status:          Draft (pending legal review)

Steppe is ad-free civic infrastructure in development for Redmond and Central Oregon. Steppe has a signed fiscal-sponsorship agreement with Ignite Empowerment Foundation, a Central Oregon 501(c)(3). Gregory Chism operates the member app and handles member data. Ignite handles sponsor-routed grants, donations, and other sponsored responsibilities, but does not routinely handle the membership database or member subscriptions. A particular contract may be handled by Gregory Chism or Ignite; the contract will identify its actual party.

This policy explains what the founding beta collects, why, who handles it, and the choices members have. The plain-language summary is at steppe.community/privacy.

Contents
  • 1. Information We Collect
  • 2. How We Use Information
  • 3. Legal Bases for Processing
  • 4. How We Share Information
  • 5. Retention and Account Deletion
  • 6. Your Rights and Choices
  • 7. Security
  • 8. Children's Privacy
  • 9. Changes to This Policy
  • 10. Contact

1. Information We Collect

We collect the minimum needed for the interest list and, once beta accounts are enabled, a verified local community.

CategoryExamplesWhy we collect it
Beta interestEmail; optional first name and area response; explicit email consentSend the one beta-readiness notice requested
Account basicsEmail, display name, languageSign-in and member-to-member contact
Residency checkProof of local addressIntended for one eligibility decision; collection remains closed until deletion and orphan cleanup are verified
Member contentListings, messages, group activity, votesProvide the service the member requested
Safety intakeA report and an excerpt a participant chooses to discloseLet a human moderator review the report
Technical supportProblem description, optional expected result and reply email; account association when signed in; optional reviewed technical detailsInvestigate and resolve a reported problem
Minimal logsBasic technical and security recordsKeep the service working and safe

The founding beta is free and does not collect member subscription payments. Before paid membership begins, this policy and the checkout flow will name the payment provider and describe the data it receives. Gregory Chism will administer member subscriptions directly rather than routing them through Ignite.

2. How We Use Information

We use information to operate the beta list and member service, verify local eligibility, provide the exchange, groups, messages, and governance, send service email, respond to reports, and secure the platform. We do not use member data for advertising or behavioral profiling, and we do not sell it.

Contact-form messages are delivered through Resend to the Steppe inbox. They are not stored in the app. Direct messages are readable in the app only by the two participants; moderators and administrators have no message-reader interface. Database operators can technically access plaintext stored in the database, but Steppe policy and ordinary tooling prohibit routine access.

Optional bug reports and crash monitoring

The beta's Report a bug control sends your description, normalized page name, language and app release to Steppe. Signed-in reports are linked to your account. You may add an expected result or reply email. Please leave out passwords, sign-in codes, residency documents and private messages.

Technical history is off until you turn it on. It remembers at most 100 technical navigation/action/error events from the previous ten minutes in page-session memory. You can inspect the history and browser, operating-system, viewport, language, connectivity and release details before choosing to include them. Typed field values, message contents, vote choices, screenshots, session replay and raw exception text are excluded. Your written description may itself contain personal information. Signing out, changing accounts or leaving the page session clears the local history.

Separately, Sentry receives anonymous browser session health and sanitized error records to help us detect crashes. These records exclude member identity, submitted text, request content, browsing history and session replay. If you choose to include technical details in a report, up to five recent error references from that page session can connect the report to its exact Sentry errors. Designated support operators see matching error type, time, app release and code locations in the private case. Report descriptions and the optional activity history stay in Steppe; they are not copied to Sentry.

3. Legal Bases for Processing

Where a legal basis is required, Steppe relies on the requested service or membership agreement, explicit consent for the beta-readiness email and other optional communications, legal obligations, and the legitimate interest in operating a secure community service.

4. How We Share Information

We do not sell or rent member information. We disclose the minimum needed to service providers operating under contract, to Ignite when a sponsored responsibility actually requires it, or when valid legal process requires it.

RecipientPurposeWhat they receive
SupabaseAuthentication, database, and private verification storageAccount and app data needed to provide those services
ResendService email and contact-form deliveryRecipient email; contact content in transit; bug-report alerts contain only a reference and private review link, not the report description or diagnostics
SentryBrowser crash health and maintenance monitoringAnonymous session health, sanitized error/code details and maintenance check-in status; no report descriptions or optional activity history
Hosting/infrastructure providersRun and secure the appRequests and operational data needed to host it
Ignite Empowerment FoundationAdminister sponsored funds and responsibilitiesOnly information needed for the applicable sponsored matter; no routine membership-database access
A future payment providerProcess member subscriptions after betaPayment and transaction data entered with that provider

The future payment provider will be named before paid membership data is collected. A contract handled by Ignite or Gregory Chism will identify that party rather than treating “Steppe” as an unspecified legal entity.

5. Retention and Account Deletion

We do not keep member data merely because storage is available.

DataRetention
Beta-interest emailUntil the notice is sent or the person asks to be removed
Account basicsWhile the account is active; intended to be removed or scrubbed on deletion after the deletion/session-revocation gate passes
Residency proofNot collected until delete-after-review and orphan cleanup are verified end to end
MessagesIntended to remain participant-only and to remove a person's sent messages on account deletion; both behavior and session revocation must pass the beta gate
Safety reportsUntil resolved or the reporter deletes their account; a participant-supplied excerpt may remain even if the source conversation is later deleted
Consent, closed-ballot, moderation, and audit recordsKept in minimized or anonymized form when deletion would make the governance or accountability record inaccurate
Bug reports and private case historyExpire 30 days after submission; ordinary access ends at expiry and the next successful hourly cleanup deletes the stored content. Cleanup failure can delay physical deletion. Account deletion removes linked reports.
Minimal operational logsKept only as long as operationally needed; no fixed purge promise is made until it is technically enforced and verified

Support operators must delete downloaded bug-report copies by the report's 30-day expiry, or earlier when handling a valid deletion request. Downloads are separate copies and must not be placed in shared public folders. Provider recovery copies are subject to provider retention; deleting a live record does not promise immediate erasure of every recovery copy. If data is restored, expired reports and previously requested deletions must be reapplied before ordinary access resumes. The current Supabase Free plan does not provide project backups; this does not establish a retention period for provider-internal recovery copies.

Account exports include the member's own unexpired bug reports, excluding private support notes. Anonymous reports are not retrospectively linked after sign-in.

A valid legal hold may temporarily stop deletion of the specific records covered by that hold. Steppe will not broaden a hold beyond its lawful scope.

6. Your Rights and Choices

The intended beta process lets you ask to see, export, or correct information, withdraw optional communication consent, and delete your account. Before beta invitations, Steppe must verify that export coverage is complete, deletion removes ordinary account data and authored messages, and every surviving session loses authority. Integrity-required governance, consent, moderation, and audit records may remain attached only to a scrubbed “Former member” profile where necessary.

7. Security

Steppe uses access controls, row-level database rules, least-privilege service credentials, private verification storage, and human review for consequential moderation. No system is perfectly secure. Steppe will give notices required by applicable breach law.

8. Children's Privacy

The founding beta is for adults and is not directed to children. A version for ages 13–17 will not launch without separate safeguards and legal review. Steppe does not knowingly collect information from a child under 13.

9. Changes to This Policy

We will post a revised version with a new effective date and give advance notice of material changes where required. A material privacy promise will not be published before the product can actually perform it.

10. Contact

Privacy questions and requests go to hello@steppe.community or by mail to 3566 NW 8th Street, Redmond, OR 97756. Gregory Chism handles member-data requests. Ignite should be contacted only for a sponsored matter that Ignite actually administers.

← Back to the plain-language summary

Steppe Strata Seal, Redmond, Oregon

Steppe is a fiscally sponsored civic project building toward a member-governed Oregon public benefit nonprofit. Fiscal sponsor: Ignite Empowerment Foundation. Founding beta in development. hello@steppe.community

ContactPrivacyTermsFor partners

Led by Greg Chism

REDMOND · CENTRAL OREGON · EST. 2026