The short version
Your health data never leaves your iPhone. Burnlock reads workouts and active energy from Apple Health and only reads — it never writes. Calories, workouts, heart data and activity types are never uploaded to us, never placed in iCloud, never sent to any analytics or advertising service and never sold. The only thing that syncs between your own devices is the number of minutes you have banked.
There is no account. You never give us a name, an email address or a password to use Burnlock.
Who we are
Burnlock is made by Bebra Apps. If you have a question about this policy, write to support@bebra.app. For the purposes of the GDPR, Bebra Apps is the data controller for the limited data described below.
Health and fitness data
With your permission, Burnlock reads the following from Apple Health:
- Workouts — type, duration and the energy recorded against them.
- Active energy burned — the calories Apple Health attributes to movement.
- Step count — used only as a fallback when there is no reliable calorie data, typically when you have no Apple Watch.
All of it is processed on your device, and it stays there. Burnlock converts it into a number of minutes, and it is the minutes — not the calories — that the app stores and syncs.
We do not transmit, upload, store on our servers, share, sell or use health data for advertising. We do not use it to build a profile of you. It is not sent to Firebase, to Meta, to RevenueCat, or to anyone else. Apple's App Review Guideline 5.1.3 forbids using HealthKit data for advertising or data mining, and the app is built so that it structurally cannot.
Burnlock has read-only access to Apple Health. It never writes anything back.
You can revoke Health access at any time in the iOS Settings app, under Privacy & Security → Health → Burnlock. Burnlock will simply stop earning new minutes; the minutes already banked remain yours.
Which apps you shield
Shielding is handled entirely by Apple's Screen Time frameworks (Family Controls, Managed Settings and Device Activity). When you choose apps or categories, iOS gives Burnlock opaque tokens rather than names or bundle identifiers. The app can shield and unshield them, and it can count them — it cannot read which apps they are, and neither can we.
What syncs through iCloud
So that your balance follows you between your own devices, Burnlock stores the following in your personal iCloud key-value store: your banked minutes, the per-day record of minutes earned and spent, your chosen effort level and daily goal, your notification preferences, and your language choice.
This is your iCloud account. The data is governed by Apple's privacy policy, and we have no access to it. No calorie figure, workout or activity type is ever placed there.
Third-party services
Burnlock uses a small number of services, none of which receives health data.
| Service | What it receives | Why |
|---|---|---|
| Google Firebase Analytics & Remote Config |
Anonymous usage events — screens viewed, whether a purchase completed, how many minutes were spent, coarse buckets such as “workout” or “movement”. A device-generated identifier. No calories, no workout types, no health values of any kind. | To see which parts of the app are used and which are broken, and to adjust tuning values without shipping an update. |
| Meta (Facebook) App Events & SKAdNetwork |
App install, session start, purchase, and one event marking a first successful unlock. Your device's advertising identifier only if you allow tracking when iOS asks. | To measure which advertising campaigns bring people to the app. |
| RevenueCat | An anonymous app user ID and your subscription receipt status. | To know whether Premium is active, and to restore purchases on a new device. |
| Apple | Purchase and subscription handling, iCloud sync, and SKAdNetwork attribution. | Payments, sync and privacy-preserving ad measurement. |
| Google Forms | Only what you type into the support form, plus the diagnostic details shown to you before you send: app version, iOS version, device model, language and your current effort setting. | To answer support requests. Nothing is sent unless you press send. |
Tracking and advertising
On first launch, iOS asks whether Burnlock may track you across apps and websites. This is Apple's App Tracking Transparency prompt, and your answer is entirely yours to give.
- If you allow it, Meta receives your device's advertising identifier so an install can be matched to the ad that led to it.
- If you decline, iOS returns an all-zero identifier and attribution falls back to Apple's SKAdNetwork, which reports only aggregated campaign results.
Nothing in the app is gated on that answer. Every feature works identically either way. Your health data is not part of this in either case.
What we never do
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising beyond the advertising identifier described above.
- We do not use your camera, microphone, contacts, photos or precise location. The app requests none of them.
- We do not require an account, an email address or a sign-in of any kind.
- We do not use your health data to train models.
Retention and deletion
Health data is read into memory, converted into minutes and discarded; only a watermark noting how far the app has already read is kept on the device. The minutes ledger is pruned to 24 months.
Settings → Data & privacy → Delete my data erases everything Burnlock holds: your balance, your ledgers, your settings and your watermarks, on this device and in your iCloud. Deleting the app removes the local copy. Analytics events already sent to Firebase are retained under Google's own schedule, up to 14 months.
Children
Burnlock is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has provided us with information through the support form, write to support@bebra.app and we will delete it.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to processing, and to withdraw consent. Because Burnlock holds almost nothing about you, most of these are exercised directly in the app: revoke Health access in iOS Settings, answer the tracking prompt however you like, or use Delete my data. For anything else, write to support@bebra.app and we will respond within 30 days.
California residents: we do not sell personal information as that term is defined by the CCPA, and we do not knowingly sell the personal information of minors under 16.
International transfers
The services listed above may process data on servers outside your country, including in the United States. Where required, those transfers rely on the Standard Contractual Clauses or an equivalent safeguard operated by the provider.
Changes to this policy
If this policy changes in a way that affects you, the date at the top of this page changes and the current version is always published here. Continuing to use Burnlock after a change means you accept the updated policy.
Contact
Bebra Apps — support@bebra.app