Legal
Privacy Policy
This policy explains what personal data Better Yoga collects, why we collect it, who we share it with, and the choices and rights you have. We have tried to write it in plain language rather than in the language of lawyers.
The short version. We collect the answers you give during setup, the practice history you build in the app, and standard analytics and crash diagnostics. We use that to build your daily plan and to keep the app working. We do not sell your data and we show you no ads inside the app. The pages you open on our website, and the links you click there, are reported to Google Analytics, and our website and web quiz also carry advertising pixels, so those pages are reported to Meta and TikTok; your practice history never is. You can delete your account and everything in it at any time.
1. Who we are
Better Yoga (the “app”) is operated by BS Bridge Softwares OÜ, a private limited company registered in Estonia (“we”, “us”, “our”). For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the personal data described in this policy.
You can reach us about anything in this policy at fakher.hakim@bridge-softwares.com.
2. Scope of this policy
This policy covers the Better Yoga mobile app for iOS and Android, this website, and our web sign-up quiz, the pages that ask about your goal, your day and your time, and where you can subscribe before installing the app. It does not cover services operated by other companies that you may reach from the app, for example the Apple App Store or Google Play, which are governed by their own privacy policies.
3. Data we collect
3.1 Data you give us
- Account details. When you create an account we receive a user identifier from Firebase Authentication. Depending on the method you choose, this includes your email address, and, for Google or Apple sign-in, the display name and profile picture those services return. If you sign in with Apple and choose to hide your email, we only ever see Apple’s private relay address.
- Guest use. If you continue as a guest, we create an anonymous identifier that is not linked to your name or email. It exists only so your plan survives closing the app.
- Setup answers. The first name you choose to give, and your answers about your goal, gender (optional, and “I’d rather not say” is a real answer), age range, focus areas, experience level and the time you have available.
- Web quiz answers. If you start on our web sign-up quiz, the same kind of setup answers as above, plus a few questions the app does not ask: whether you have used a daily plan app before, what else your plan should care about, how your energy runs, what you do when you are too tired, and where you will move.
- Email on the web quiz. Part-way through the web quiz we ask for your email address so we can send your plan and reach you if you do not finish. Giving it creates no account. A separate, unticked checkbox asks whether you also want a weekly recap. That one is marketing, and one click unsubscribes.
- Correspondence. If you email us, we keep the message and your email address so we can reply.
3.2 Data created by using the app
- Practice history. Sessions you start, complete or skip, the plans generated for you, and any sessions you mark as favourites.
- App preferences. Your theme choice, notification preference and whether you have finished onboarding. These are stored on your device, and on our servers when you have an account.
3.3 Data collected automatically
- Usage analytics. Through Google Firebase Analytics: screens you view, actions such as starting or completing a session, session counts and duration, a pseudonymous app-instance identifier, your device model, operating system version, app version, language and country (derived from IP address, which Firebase does not store in a form we can access).
- Website analytics. Through Google Analytics, the same Firebase measurement stream as the app: which marketing page you open, the language it is written in, and the links you click on it — the destination, the wording of the link and where on the page it sat. It sets a first-party
_gacookie so a second visit is not counted as a second person, and it reports the same page and step data on the web quiz. Your name, email address and practice history are never attached to it. - Crash and stability diagnostics. Through Google Firebase Crashlytics: crash stack traces, device state at the time of a crash, and the recent app events that led to it. Crash reporting is switched off entirely in development builds.
- Technical request data. When the app fetches exercise content, our provider receives standard request information such as IP address and timestamps. We do not send your name, email, account identifier or practice history with those requests.
- Campaign source. If you reach our web sign-up quiz from an advert or a link, we read the campaign tags and click identifier on that link (for example
utm_source,utm_campaign,gclid), along with the referring page. We keep the first one we see so we can tell which campaigns bring people who stay, and we pass it to the measurement and advertising providers listed in section 6. We do not sell it. - Web quiz storage. The web quiz saves your answers, your campaign source, your email address and whether you have subscribed in your browser’s local storage, under the key
by_funnel_v1. That is what lets you close the tab and pick up where you left off. It expires after 30 days, and it is cleared as soon as you reach the final step and open the app. Clearing your browser’s site data removes it immediately. - Analytics and advertising on the web. Google Analytics and the advertising pixels start as soon as a marketing page or the web quiz opens. We do not show a consent banner and do not ask you first, so there is nothing to accept and no choice of yours is recorded. To stop them, block third-party cookies in your browser, or use a browser or extension that blocks trackers; on the quiz, clearing your site data also removes the stored answers described above.
- Advertising pixels. Our marketing pages load the Meta (Facebook) pixel, and the web quiz loads both the Meta and TikTok pixels. They record which page or step you are on and set their own cookies (
_fbpand_fbcfor Meta) so a subscription bought later can be matched to the advert that brought you. Where you have given us your email address on the quiz, it reaches them only as an irreversible SHA-256 hash, never in the clear. Neither pixel loads on this page or on our terms page, where Google Analytics is absent too, and neither runs inside the app.
3.4 What we do not collect
- We do not collect precise location, contacts, photos, microphone or camera data.
- We show you no adverts in the app and run no ad-serving SDK. We do use attribution tools: on iOS, if you allow tracking when the system asks, AppsFlyer may read the device advertising identifier so an install can be credited to the advert that led to it. Refusing that prompt stops it.
- We do not track you across other companies’ apps or websites from inside the app. On the web, the advertising pixels in section 3.3 do report your visit to Meta and TikTok.
- We never see or store your payment card details. Payment is handled entirely by the Apple App Store, Google Play, or, for subscriptions bought on the web, Stripe.
4. Why we use it
| Purpose | Data used |
|---|---|
| Build and adapt your daily plan | Setup answers, practice history |
| Keep you signed in and sync across devices | Account details, app preferences |
| Send the one daily reminder, if you asked for it | Notification preference, device push token |
| Fix crashes and diagnose failures | Crash diagnostics, app and device version |
| Understand which features help people keep moving | Aggregated usage analytics |
| Measure which adverts bring people who subscribe | Campaign tags, web page views, hashed email address |
| Prevent abuse and secure the service | Account identifiers, technical request data |
| Answer your support messages | Correspondence |
| Meet our legal and accounting obligations | Purchase records held by the app stores |
We do not use your data to make decisions about you that produce legal or similarly significant effects. We do not profile you ourselves beyond adapting your training plan; the advertising platforms in section 6 may use what their pixels receive to target their own advertising.
5. Legal bases
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)), for creating your account, generating your plans, storing your practice history and providing support.
- Consent (Art. 6(1)(a)), for push notifications, which we ask for separately and which you can switch off at any time in your device settings. You can withdraw consent at any time without affecting processing carried out before you withdrew it.
- Legitimate interests (Art. 6(1)(f)), for crash diagnostics, security, abuse prevention and product improvement. Our interest is in operating a stable and useful app; we balance it against your rights by using pseudonymous identifiers and aggregated reporting wherever we can.
- Legal obligation (Art. 6(1)(c)), for tax, accounting and responding to lawful requests.
Answers about your gender and age range are used to tune the language and load of your plan. We do not use them to infer health conditions, and we do not treat them as special-category data under Art. 9. If you would rather not answer, every one of those questions can be skipped.
7. International transfers
Our providers may process data outside the European Economic Area, including in the United States. Where that happens, the transfer is covered by the European Commission’s Standard Contractual Clauses, by an adequacy decision such as the EU–US Data Privacy Framework, or by another lawful transfer mechanism. You can request a copy of the safeguards we rely on by writing to us.
8. How long we keep it
- Account and practice data, for as long as your account exists. When you delete your account, we delete it within 30 days from our live systems and within 90 days from encrypted backups.
- Guest data, until you delete the app or clear its data. Anonymous accounts that go unused for 12 months are removed.
- Analytics, retained by Firebase for at most 14 months, then deleted or aggregated.
- Web quiz data in your browser, 30 days, or until you finish the quiz and open the app, whichever comes first.
- Email given on the web quiz without subscribing, up to 12 months, so we can send your plan and follow up once; sooner if you unsubscribe.
- Crash diagnostics, up to 90 days.
- Support correspondence, up to 24 months after the conversation ends.
- Records we must keep by law, for the period the relevant law requires, typically seven years for accounting records.
9. Your rights
Subject to local law, you have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is wrong or incomplete.
- Delete your data (“right to be forgotten”).
- Restrict or object to processing based on legitimate interests.
- Port your data to another service in a structured, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
- Complain to a supervisory authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee); you may also complain to the authority where you live or work.
Write to fakher.hakim@bridge-softwares.com to exercise any of these. We will respond within one month, and will tell you if we need longer because the request is complex. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to confirm the email address on your account before acting.
10. Your choices in the app
- Delete your account. Available from the app’s settings. This removes your profile, plans, practice history and favourites.
- Turn off reminders. Switch them off in the app, or revoke the notification permission in your device settings.
- Skip questions. Name, gender and every other setup question can be skipped; the plan is simply less tailored.
- Use it as a guest. You can practise without ever giving us an email address.
- Reset the analytics identifier. Reinstalling the app issues a new pseudonymous app-instance identifier.
11. Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to production systems is limited to people who need it, protected by multi-factor authentication. Database rules restrict every account to reading and writing only its own records. Application logs are written without credentials, tokens or personal identifiers.
No system is perfectly secure. If a breach affects your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will notify you directly where the law requires it.
12. Children
Better Yoga is not directed at children. You must be at least 16 years old to create an account, or older if the law where you live sets a higher age for consenting to data processing. We do not knowingly collect data from children below that age. If you believe a child has given us personal data, write to us and we will delete it.
13. Regional disclosures
13.1 United Kingdom
Where UK GDPR applies, the rights in section 9 apply equally and complaints may be made to the Information Commissioner’s Office.
13.2 California
We do not sell personal information. We do share it for cross-context behavioural advertising, as that term is defined by the California Consumer Privacy Act, through the advertising pixels described in section 3.3; blocking third-party cookies in your browser, or using a browser or extension that blocks trackers, opts you out. California residents may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and are entitled not to be discriminated against for exercising those rights. Use the contact address in section 15.
13.3 Other jurisdictions
If you live somewhere that grants you privacy rights not listed here, write to us and we will honour them where the law applies to us.
14. Changes to this policy
We update this policy when the app changes. The effective date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect and, where the law requires it, ask for your consent again.
15. Contact us
BS Bridge Softwares OÜ
Estonia
fakher.hakim@bridge-softwares.com
Please put “Privacy” in the subject line so your message reaches the right place quickly.