Privacy Policy
Last updated: 16 May 2026
Nenuzo is a mobile app that helps you track buses in real time. This policy explains what personal data is collected when you use the app, why it is collected, how long it is kept, and what rights you have.
1. Who we are
Nenuzo is developed and operated by Scott Pritchard, an individual based in the United Kingdom. Scott Pritchard is the data controller for the personal data described in this policy.
2. What data we collect and why
2.1 Your location
What:Your precise GPS location while you are actively tracking a bus.
Why:The app uses your location to find nearby buses, to calculate arrival estimates relative to where you are, and — if you choose to track a bus to a specific stop — to determine your proximity to that stop.
How it is handled:Your location is sent to our server at the start of a tracking session and periodically during the session — at most once every 30 seconds, and only when you have moved 25 metres or more. It is stored against your session only; we do not build a history of where you have been. If you use a pinned stop instead of your live location, your GPS coordinates are not sent at all.
Lawful basis:Legitimate interests — location data is necessary to provide the core function of the app.
2.2 Push token (Live Activity notifications)
What:A device-specific token issued by Apple's Push Notification service (APNs), used to deliver Live Activity updates to your lock screen and Dynamic Island.
Why:Without this token, the app cannot send arrival updates to your device.
How it is handled:The token is stored on our server only for the duration of your tracking session. It is deleted as soon as you end the session.
Lawful basis:Legitimate interests — the token is necessary to deliver the notification feature you have enabled.
2.3 Subscription status (via RevenueCat)
What:An anonymous identifier generated by RevenueCat — a randomly assigned UUID not linked to your name, email address, or any device serial number.
Why:To check whether you have an active Pro subscription, so the app can unlock Pro features.
How it is handled:The identifier is sent to our server each time the app verifies your subscription status. It is also stored on your tracking session record to associate the session with your subscription. The session record is deleted within 24 hours of the session ending. The identifier also appears in our API request logs, which are retained for up to 30 days and then permanently deleted.
Lawful basis:Legitimate interests — entitlement checking is necessary to deliver the subscription you have purchased.
2.4 Essential diagnostics (always active)
What:Crash reports, error and warning messages logged by the app, rage tap detection (repeated taps on the same area of the screen), and your device model, operating system version, and app version.
Why:To detect and fix problems that affect app stability and usability.
How it is handled:This data is split between two processors. Crash reports and error/warning messages are processed by Sentry (see section 4); rage tap detection is processed by Rejourney (see section 4). Your device model, operating system, and app version are sent to both so we can reproduce issues accurately. Neither processor receives your name, email address, precise location, or any text you have typed. Sentry events are not linked to any account identifier. Rejourney events are tagged with the anonymous RevenueCat identifier described in section 2.3 so diagnostic data can be correlated with subscription state.
Lawful basis:Legitimate interests — basic diagnostic data is necessary to maintain a working app.
2.5 Support emails
What:Your email address, name (if included), and the content of any message you send to [email protected].
Why:To respond to your support enquiry.
How it is handled:Support emails are stored on our server for the duration of the conversation and for up to 6 months from the date of your last message. After that period, the entire conversation — including your email address and message content — is permanently deleted by an automated job.
Lawful basis:Legitimate interests — responding to a support request you have initiated.
2.6 Enhanced Recording (opt-in, off by default)
What:A replay of what happens inside the Nenuzo app during your session; a log of the app's network requests (showing which actions the app performed, whether they succeeded, and how long they took); and your approximate location based on your internet connection, typically accurate to city or county level — not your precise GPS location.
Why:To help us understand and reproduce problems that are difficult to diagnose from logs alone.
How it is handled:Enhanced Recording is off by default. You can turn it on or off at any time from Settings → Your Privacy Choices. A summary of what is collected is shown before your choice is recorded. You can withdraw your consent at any time from the same screen.
Lawful basis:Consent — you have explicitly opted in.
2.7 Performance Analytics (opt-in, off by default)
What:Timing data for screen loads, slow or stuttering frames, and the duration and outcome of outgoing network requests the app makes to our server.
Why:To find and fix performance issues — for example, slow screens, long-running requests, or frame drops that affect the experience.
How it is handled:Performance Analytics is off by default. You can turn it on or off at any time from Settings → Your Privacy Choices. This data is processed by Sentry (see section 4). It does not include your name, email address, precise location, or any text you have typed, and is not linked to any account identifier.
Lawful basis:Consent — you have explicitly opted in.
3. How long we keep your data
| Data | Retention |
| Your location during a session | Stored on the active session record only; deleted within 24 hours of the session ending |
| Push token | Deleted when you end your tracking session |
| RevenueCat anonymous ID (tracking session) | Deleted within 24 hours of the session ending |
| RevenueCat anonymous ID (API request logs) | Deleted after 30 days |
| Support emails | Deleted 6 months after the last message in the conversation |
| Data subject rights requests | Email content and your address are deleted 30 days after the case is closed; an audit record of the request type, dates, and outcome is kept for up to 3 years |
| Essential diagnostics (Rejourney) | Up to 60 days |
| Enhanced Recording sessions (Rejourney) | Up to 60 days |
| Crash, error, and warning events (Sentry) | Up to 90 days |
| Performance Analytics transactions (Sentry, if opted in) | Up to 30 days |
Tracking sessions expire automatically after 4 hours. Expired and ended sessions are permanently deleted by an automated overnight job.
4. Who we share your data with
We do not sell your data or share it with advertisers. The following service providers process data on our behalf as data processors.
Hetzner Online GmbH
Purpose:Cloud server infrastructure — our API and database run on Hetzner servers.
Location:Germany (European Union)
Transfer mechanism:None required — data remains within the EU.
RevenueCat, Inc.
Purpose:Subscription management — verifying whether you have an active Pro subscription.
Location:United States
Transfer mechanism:Standard Contractual Clauses (SCCs) under their Data Processing Agreement.
Data retained by RevenueCat:Anonymous purchase and subscription history — no name, email address, advertising identifier (IDFA), or device serial number. Retained for the duration of the agreement and as required by applicable law (standard for transaction records).
Apple Inc. (APNs)
Purpose:Delivering Live Activity updates and push notifications to your device.
Location:United States
Transfer mechanism:Standard Contractual Clauses (SCCs) under Apple's Data Processing Agreement.
Rejourney
Purpose:App diagnostics and, if you have enabled it, Enhanced Recording.
Location:Germany (European Union)
Transfer mechanism:None required — data is hosted in the EU.
Data retained by Rejourney:Session diagnostics and recordings for up to 60 days.
Sentry (Functional Software Inc.)
Purpose:Crash and error reporting (always active), and — if you have enabled it — Performance Analytics.
Location:United States (corporate parent); event data is stored in Germany (European Union) via Sentry's EU region.
Transfer mechanism:Standard Contractual Clauses (SCCs) under their Data Processing Agreement.
Data retained by Sentry:Crash, error, and warning events for up to 90 days; performance transactions for up to 30 days. Sentry events are not linked to any account identifier — no name, email, IP address, or RevenueCat ID is sent.
5. International data transfers
Our server infrastructure is located in Germany, within the European Union. Where data is transferred to US-based processors (RevenueCat, Apple, Sentry), we rely on Standard Contractual Clauses (SCCs) approved under UK GDPR and EU GDPR, as documented in each processor's Data Processing Agreement. Sentry stores event data in its EU region, but its corporate parent is US-based, so SCCs apply.
6. Your rights
Under UK GDPR and EU GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Erasure — request that your data is deleted
- Rectification — request that inaccurate data is corrected
- Restriction — request that we limit how your data is used in certain circumstances
- Portability — receive your data in a portable, machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — if processing is based on your consent (Enhanced Recording, Performance Analytics), you can withdraw at any time via Settings → Your Privacy Choices, without affecting the lawfulness of processing before withdrawal
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Note: Because Nenuzo has no account or login, we cannot identify you by name or email address alone. To help us locate your data, please include your in-app identifier (visible under Settings → Privacy → Your identifier in the app) and the approximate dates of your sessions.
For data held by RevenueCat:To request deletion of your anonymous purchase history, contact RevenueCat directly at [email protected].
Right to complain:If you are based in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. If you are based in the EU, you may contact your local data protection supervisory authority.
7. Children
Nenuzo is not directed at children under the age of 18. We do not knowingly collect personal data from children.
8. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of this page will always reflect the most recent version. We recommend checking this page periodically, particularly before enabling any optional data collection features.
9. Contact