Privacy Policy
Version 1.0 · Effective 13 August 2026
The short version
- FocusPulse has no accounts. There is nothing to sign up for, so we hold no profile of you.
- The app contains no analytics and no third-party SDKs. It never sends us your sessions, your listening, or anything you type.
- Your history, favourites, settings and sigil gallery live on your device only. Deleting the app deletes them, and we cannot restore them.
- Payments are handled entirely by Apple. We never see your card, name or address.
- Our servers see only what any website sees when a file is requested — an IP address and the file requested — kept briefly for security and capacity.
1. Who we are
FocusPulse (the “app”) and this website are operated by B&B LLP (“we”, “us”), registered in [jurisdiction] under company number [registration number], registered address [registered address].
For the purposes of the UK and EU General Data Protection Regulation, B&B LLP is the data controller for the limited processing described below. You can reach us at [email protected].
2. What stays on your device
Almost everything the app knows about you never leaves your iPhone. That includes:
- your session history, including durations, the states you chose and completion;
- the sigils minted by finished sessions — your gallery;
- favourites, preferences, Pulse depth and any intention text you write before a dive;
- downloaded audio and the cached catalog that lets the app open offline.
This information is stored in the app's own container on your device. We have no access to it, it is not backed up to us, and no feature of the app transmits it. If you delete the app, it is gone; because we never held a copy, we cannot recover it for you.
3. What our servers receive
The app makes two kinds of network request, both read-only:
- a request to our catalog service for the list of states and tracks;
- requests to our content delivery network for audio files and cover images.
The app sends no personal information with these requests. As with any internet service, the servers and the CDN automatically record standard technical entries — IP address, timestamp, the file requested, and basic device/user-agent information. Under the GDPR an IP address can be personal data, so we treat these logs accordingly: they are used only to deliver the files, to keep the service available and to defend it from abuse. We do not use them to build profiles, and we do not attempt to link them to individuals.
Legal basis (GDPR Art. 6(1)(f)): our legitimate interest in operating a secure, functioning service. Retention: these logs are kept for no longer than [30] days and then deleted or aggregated.
4. Subscriptions and payments
Premium is sold as an auto-renewing subscription through Apple. Apple processes the payment, handles renewals and refunds, and holds the billing relationship with you. We never receive your payment details, your name, your address or your Apple ID. What the app receives from Apple is a receipt that says whether an active entitlement exists — validated on your device.
Apple's own handling of your data is governed by the Apple Privacy Policy.
5. Apple Health
If you grant permission, the app can write Mindful Minutes and State of Mind entries to Apple Health when a session ends. This is optional, off until you allow it, and can be revoked at any time in the Health app or in iOS Settings.
The app only ever writes: it does not request read access to your Health data, and no Health information is ever transmitted to us or to anyone else. Health data is never used for advertising or shared with third parties.
6. Cookies and similar technologies
The app uses no cookies, no advertising identifiers (IDFA), no fingerprinting and no tracking of any kind. This website sets no cookies of its own and loads no third-party scripts, fonts or images — everything it needs is served from our own domain. Our network provider may set a strictly necessary security cookie to distinguish humans from automated traffic; it is not used to profile you.
7. Service providers
We keep the list of companies that touch any part of this service deliberately short:
| Provider | Role | What it sees |
|---|---|---|
| Cloudflare, Inc. | DNS, CDN and object storage for audio and images | Technical request logs (IP, timestamp, file requested) |
| [VPS provider] | Hosting the catalog service and this website | Technical request logs |
| Apple Inc. | App distribution, subscriptions, optional Apple Health | Your purchase relationship (we never receive it) |
We do not sell or share personal information, and we have never done so. There are no advertising networks, data brokers or analytics vendors in this list because the app sends them nothing to receive.
8. International transfers
Our catalog service runs on a server in the [United States], and our content delivery network serves files from the location nearest to you. Where technical log data originating in the UK or EEA is processed outside it, that transfer relies on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) as implemented in our providers' data processing agreements.
9. Your rights
If you are in the UK or the EEA, you have the right to access, correct, erase, restrict or object to the processing of your personal data, and the right to data portability and to lodge a complaint with your supervisory authority. If you are in California, you have the rights to know, delete, correct and opt out of sale or sharing under the CCPA/CPRA — we do not sell or share personal information, so there is nothing to opt out of.
In practice these rights reach only our technical logs, because that is the only personal data we ever hold. We have no account to look you up by, so to exercise a right over log data we will normally need the approximate date and the IP address involved. Write to [email protected] and we will respond within one month.
Everything else — your sessions, sigils and settings — is already fully under your control, since it lives only on your device.
10. Children
FocusPulse is not directed to children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect personal data from anyone, children included. The app contains no social features, no user-to-user content and no advertising.
11. Security
All traffic between the app, this website and our servers is encrypted with TLS. Our servers are access-controlled and hold no user database, because there is no user database to hold — which removes an entire category of breach from the picture.
12. Changes to this policy
If this policy changes, the updated version will be published at this address with a new version number and effective date. Material changes affecting how the app handles data will also be noted in the app's release notes.
13. Contact
B&B LLP · [registered address]
Privacy enquiries: [email protected]
General support: [email protected]