Privacy Policy
Version 1.0 · Effective 13 August 2026
The short version
- FocusPulse has no accounts. There is nothing to sign up for, so we hold no profile of you.
- The app contains no analytics and no third-party SDKs. It never sends us your sessions, your listening, or anything you type.
- Your history, favourites, settings and sigil gallery live on your device only. Deleting the app deletes them, and we cannot restore them.
- Payments are handled entirely by Apple. We never see your card, name or address.
- Our servers keep no access log, and because the site sits behind Cloudflare they never see your IP address in the first place.
- If you subscribe, Apple sends us the transaction record — a transaction number, the product, the price and the country. No name, no email. That is the only thing we store about anyone.
1. Who we are
FocusPulse (the “app”) and this website are operated by B&B LLP (“we”, “us”), registered in the Republic of Kazakhstan under business identification number (BIN) 221040031087, registered address Taras Shevchenko Street 4/1, premises 17, Astana, Republic of Kazakhstan.
For the purposes of the UK and EU General Data Protection Regulation, B&B LLP is the data controller for the limited processing described below. You can reach us at [email protected].
2. What stays on your device
Almost everything the app knows about you never leaves your iPhone. That includes:
- your session history, including durations, the states you chose and completion;
- the sigils minted by finished sessions — your gallery;
- favourites, preferences, Pulse depth and any intention text you write before a dive;
- downloaded audio and the cached catalog that lets the app open offline.
This information is stored in the app's own container on your device. We have no access to it, it is not backed up to us, and no feature of the app transmits it. If you delete the app, it is gone; because we never held a copy, we cannot recover it for you.
3. What our servers receive
The app makes two kinds of network request, both read-only:
- a request to our catalog service for the list of states and tracks;
- requests to our content delivery network for audio files and cover images.
The app sends no personal information with these requests, and — unusually — our servers keep no access log at all. The web server is configured without request logging: the only thing it records is its own certificate maintenance. There is no file of who asked for what.
Our servers also never see your IP address. The site and the API sit behind Cloudflare, which terminates every connection, so what reaches our machine is a Cloudflare address rather than yours. Cloudflare does process your IP — it has to, in order to route the request and to keep the service from being attacked — and it keeps its own short-lived security and traffic data under its own terms. We do not receive raw logs from it, and we run no analytics on top of it.
The practical result: for someone who never subscribes, we hold nothing at all.
4. Subscriptions and payments
Premium is sold as an auto-renewing subscription through Apple. Apple processes the payment, handles renewals and refunds, and holds the billing relationship with you. We never receive your payment details, your name, your address or your Apple ID. What the app receives from Apple is a receipt that says whether an active entitlement exists — validated on your device.
If you subscribe, one thing does reach our server. Apple sends us a signed notification whenever a subscription starts, renews, fails to renew, is cancelled or is refunded, and we store those notifications. Each one contains a transaction identifier, the product bought, its price and currency, the storefront country, and the relevant dates. It contains no name, no email, no address and no payment details — Apple does not send those, and we could not ask for them.
We keep these because they are the sales record of our own business: they are how we know a subscription renewed or a refund happened. They are pseudonymous — there is no account to attach them to, so we cannot tell from a transaction identifier who you are, and we make no attempt to.
Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)) and our legal obligation to keep accounting records (Art. 6(1)(c)). Retention: for as long as tax and accounting law requires us to keep records of a sale.
Apple's own handling of your data is governed by the Apple Privacy Policy.
5. Apple Health
If you grant permission, the app can write Mindful Minutes and State of Mind entries to Apple Health when a session ends. This is optional, off until you allow it, and can be revoked at any time in the Health app or in iOS Settings.
The app only ever writes: it does not request read access to your Health data, and no Health information is ever transmitted to us or to anyone else. Health data is never used for advertising or shared with third parties.
6. Cookies and similar technologies
The app uses no cookies, no advertising identifiers (IDFA), no fingerprinting and no tracking of any kind. This website sets no cookies of its own and loads no third-party scripts, fonts or images — everything it needs is served from our own domain. Our network provider may set a strictly necessary security cookie to distinguish humans from automated traffic; it is not used to profile you.
7. Service providers
We keep the list of companies that touch any part of this service deliberately short:
| Provider | Role | What it sees |
|---|---|---|
| Cloudflare, Inc. | DNS, CDN and object storage for audio and images | Your IP address and the file requested, to route the traffic and protect it. This is the only place your address is seen at all. |
| is*hosting | The machine our catalog service and this website run on | Nothing that identifies you: we keep no access log, and the origin sees Cloudflare's addresses rather than yours. |
| Apple Inc. | App distribution, subscriptions, optional Apple Health | Your purchase relationship. Apple sends us the transaction record described in section 4 — never your identity. |
We do not sell or share personal information, and we have never done so. There are no advertising networks, data brokers or analytics vendors in this list because the app sends them nothing to receive.
8. Where the data sits, and international transfers
B&B LLP is established in Kazakhstan. Our catalog service runs on a server in the United States, and our content delivery network serves files from whichever location is nearest to you. So anything we hold is held outside the UK and the EEA, in countries that do not have a UK or European Commission adequacy decision.
What that actually amounts to is narrow. We keep no access log, so there is no browsing data to transfer. The one thing that crosses a border is the subscription record described in section 4 — a transaction number, a product, a price, a country — and it comes from Apple in the first place. Where personal data originating in the UK or EEA is processed outside it, whether by us or by Cloudflare, that transfer relies on the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, as implemented in our providers' data processing agreements.
9. Your rights
If you are in the UK or the EEA, you have the right to access, correct, erase, restrict or object to the processing of your personal data, and the right to data portability and to lodge a complaint with your supervisory authority. If you are in California, you have the rights to know, delete, correct and opt out of sale or sharing under the CCPA/CPRA — we do not sell or share personal information, so there is nothing to opt out of.
In practice these rights reach one thing only: the subscription records in section 4, because that is the only personal data we hold. If you never subscribed, we have nothing of yours to show, correct or erase — and we would rather say that than invent a process.
Since there is no account to look you up by, a request needs something we can match on: the original transaction identifier from your App Store purchase history, or the receipt Apple emailed you. Write to [email protected] and we will respond within one month. Note that accounting law obliges us to keep records of a sale for a set period, so erasure of a transaction record may have to wait for that period to end.
Everything else — your sessions, sigils and settings — is already fully under your control, since it lives only on your device.
As a Kazakhstan company we are also subject to the Law of the Republic of Kazakhstan “On Personal Data and its Protection”, and we apply the same standard to everyone regardless of where they live: we hold no profile of you to begin with.
10. Children
FocusPulse is not directed to children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect personal data from anyone, children included. The app contains no social features, no user-to-user content and no advertising.
11. Security
All traffic between the app, this website and our servers is encrypted with TLS. There is no user database, because there are no users to put in one — which removes an entire category of breach from the picture. The subscription records in section 4 are held in a separate area of our database that the public API has no rights to read, and the service that writes them can reach nothing else.
12. Changes to this policy
If this policy changes, the updated version will be published at this address with a new version number and effective date. Material changes affecting how the app handles data will also be noted in the app's release notes.
13. Contact
B&B LLP · BIN 221040031087
Taras Shevchenko Street 4/1, premises 17, Astana, Republic of Kazakhstan
Privacy enquiries: [email protected]
General support: [email protected]