Privacy Policy

Bursta mobile application

Effective date: 31 August 2026 · Version 1.0

1. Introduction

This Privacy Policy describes how personal data is processed in connection with the Bursta mobile application for Android (the “Application”). It is issued in accordance with Regulation (EU) 2016/679 (the “GDPR”) and applicable national data protection law.

The Application is an interval timer. It operates without a user account, without a cloud service, and without user authentication of any kind. The data described in Section 4 is the entirety of what leaves the user’s device.

2. Data controller

The data controller responsible for the processing described in this Policy is the developer of the Application, contactable at:

hello@bursta.app

Enquiries relating to this Policy, and requests made under Section 8, should be addressed to that address. The controller responds to requests from data subjects without undue delay and in any event within one month of receipt, in accordance with Article 12(3) of the GDPR. Where a request is complex, that period may be extended by two further months, and the data subject will be informed of the extension and of the reasons for it within one month.

No Data Protection Officer has been appointed. The conditions set out in Article 37(1) of the GDPR are not met: the controller is not a public authority, the processing described in this Policy does not consist of regular and systematic monitoring of data subjects on a large scale, and no special categories of data within the meaning of Article 9 are processed.

3. Data stored solely on the user’s device

The following categories of data are created and retained exclusively in the Application’s local storage on the user’s device. They are not transmitted to the controller, to any processor, or to any third party:

This data is removed when the Application is uninstalled. The controller holds no copy of it and cannot restore it.

4. Data transmitted from the device

4.1 Software update checks

On launch, the Application queries the update service operated by Expo Application Services, Inc. to determine whether a newer version of its program code is available. The request transmits the platform, the application version and the release channel. The receiving server records the request, including the originating IP address, in the ordinary course of operating a network service.

4.2 Performance and usage measurement

The Application collects technical measurements relating to its own performance, processed by Expo Application Services, Inc. The following are transmitted:

EventValues transmitted
Workout startednumber of rounds; whether a built-in preset was used
Workout finishedrounds planned; rounds completed; whether completed in full; elapsed active duration
Backup savednone
Backup restorednumber of sections that could not be read

Names assigned by the user to workouts are not transmitted. The event structure admits numeric and boolean values only and provides no field capable of carrying free text.

4.3 Diagnostic reports on application failure

Where the Application terminates unexpectedly, a diagnostic report is transmitted to Functional Software, Inc. (trading as Sentry). The report comprises the error and its location within the program code, the device model, the operating system version, and the application and update version in use. It does not include the data described in Section 3. Reports are not transmitted from development builds of the Application.

4.4 Feedback submitted by the user

The Application’s settings screen provides a link to a feedback form hosted by Google LLC. The form is opened in the device’s browser. No data is transmitted unless the user completes and submits the form, in which case the content submitted is received by Google LLC and by the controller.

4.5 Backup files

Where the user creates a backup, the Application writes a file and passes it to the operating system’s sharing interface. The destination is determined solely by the user. The controller does not receive, access or retain such files. A backup file contains the data described in Section 3 in human-readable form.

5. Purposes and legal bases

ProcessingPurposeLegal basis
Update checks (4.1)Delivery of corrections and improvements to the ApplicationLegitimate interests, Art. 6(1)(f) GDPR — maintaining a functioning and secure application
Performance measurement (4.2)Identification and correction of performance defects; understanding which functions are usedLegitimate interests, Art. 6(1)(f) GDPR — improving the Application. Data is pseudonymous and limited to technical values
Diagnostic reports (4.3)Identification and correction of defects causing failureLegitimate interests, Art. 6(1)(f) GDPR — ensuring the Application functions as intended
Feedback (4.4)Responding to the user’s enquiryConsent, Art. 6(1)(a) GDPR, given by submitting the form

Where processing rests on legitimate interests, the controller has assessed those interests against the rights and freedoms of the data subject and considers the processing proportionate, having regard to its limitation to technical and pseudonymous data and to the absence of any profiling, advertising or automated decision-making.

6. Recipients and international transfers

RecipientRoleLocation
Expo Application Services, Inc.Processor — update delivery and performance measurementUnited States
Functional Software, Inc. (Sentry)Processor — diagnostic reportsUnited States
Google LLCProcessor — feedback form, where submittedUnited States

Data is not disclosed to any recipient other than those listed. It is not sold, licensed or made available for advertising purposes.

The recipients listed are established in the United States. Transfers are made on the basis of the standard contractual clauses adopted by the European Commission, or of an adequacy decision where one applies to the recipient, in accordance with Chapter V of the GDPR. The respective privacy notices are published at expo.dev/privacy, sentry.io/privacy and policies.google.com/privacy.

7. Retention

8. Rights of the data subject

Subject to the conditions laid down in the GDPR, the data subject has the right to request access to personal data concerning them (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing carried out on the basis of legitimate interests (Art. 21). Where processing is based on consent, that consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

The controller draws attention to Article 11 of the GDPR. The Application collects no name, address, electronic mail address, account or device identifier by which a data subject could be identified. The controller is accordingly not in a position to identify the data subject from the data described in Section 4.2, and cannot associate a request with a particular installation. Where a data subject provides additional information enabling identification, the controller will give effect to the rights above.

The following measures are available to the data subject directly:

A data subject who considers that processing infringes the GDPR has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or of the alleged infringement (Art. 77 GDPR).

9. Children

The Application is not directed at children and does not knowingly process the personal data of children. It requests no personal information from any user.

10. Automated decision-making

No automated decision-making within the meaning of Article 22 of the GDPR, and no profiling, is carried out.

11. Security

Data transmitted as described in Section 4 is sent over encrypted connections. Data described in Section 3 is held in the Application’s private storage area, to which other applications have no access under the operating system’s security model. Backup files created by the user are not encrypted and their protection is a matter for the user.

12. Amendments

This Policy is amended where the processing it describes changes. The effective date and version at the head of this document are updated accordingly. The current version is published at bursta.app/privacy.

Where an amendment materially alters the categories of data processed, the purposes of processing or the recipients, the amended Policy is published not less than 30 days before it takes effect, and notice is given within the Application. Continued use of the Application after that date constitutes acknowledgement of the amended Policy. Where an amendment requires consent under applicable law, that consent will be sought before the change takes effect.

13. Cookies and similar technologies

The Application is a native mobile application. It does not use cookies, web beacons, advertising identifiers, or any comparable tracking technology, and it contains no embedded web view through which such technology could operate.

The anonymous installation identifier described in Section 4.2 is not an advertising identifier. It is not shared with any advertising network, cannot be matched against identifiers held by third parties, and is reset when the Application is reinstalled.

Where the user opens the feedback form described in Section 4.4, that form is displayed in the device’s own browser and is subject to the cookie practices of Google LLC, over which the controller exercises no control.

14. Residents of California

This Section applies to residents of the State of California and supplements the foregoing for the purposes of the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”).

In the twelve months preceding the effective date of this Policy, the categories of personal information collected are those described in Section 4: internet or other electronic network activity information, and device and diagnostic information. No categories of sensitive personal information within the meaning of the CCPA are collected.

Personal information is not sold, and is not shared for cross-context behavioural advertising. No such sale or sharing has occurred in the preceding twelve months, and none is intended. Personal information of minors under 16 is not knowingly collected and accordingly no opt-in is applicable.

California residents have the right to know what personal information is collected and for what purpose, the right to request deletion, the right to correct inaccurate information, and the right not to be discriminated against for exercising those rights. Requests may be submitted to the address in Section 2. The limitation described in Section 8 applies equally: the controller holds no identifier capable of connecting a request to a particular installation, and will say so rather than deny the request on other grounds.

15. General provisions

15.1 Governing law

This Policy is governed by, and construed in accordance with, the law of the controller’s place of establishment, without prejudice to the mandatory protections afforded to data subjects by the law of their habitual residence, and without prejudice to the right to lodge a complaint with a supervisory authority under Article 77 of the GDPR.

15.2 Third-party destinations

This Policy addresses only the Application. Where the Application directs the user to a resource operated by another party — the feedback form described in Section 4.4, or the privacy notices referenced in Section 6 — that resource is governed by the privacy practices of its operator, for which the controller bears no responsibility.

15.3 Severability

Where a provision of this Policy is or becomes invalid or unenforceable, the remaining provisions continue in full force, and the invalid provision is replaced by such valid provision as most nearly reflects its purpose.