BassState is built local-first. This policy covers both the BassState app and our website, bassstate.com. The short version:
- The app needs no account. It never asks for your email, phone number, or contacts. Your name, habits, sessions, streaks, and health data stay on your device — we cannot see them.
- Apple Health data never leaves your device. It is read with your permission, and the sessions you finish are written back only to Apple Health on your device (for example, Mindful Minutes for a breathing session). It is never transmitted to us, sold, or used for advertising.
- From the app, the only data that leaves your device is anonymous usage analytics and crash reports — and only if you opt in.
- On the website, if you request beta access or subscribe to updates we store the email you give us, and the site uses cookies and analytics to measure how it is used (see §11).
- We never sell your data, and there are no ads in the app.
The rest of this policy explains all of that in the detail UK GDPR requires.
1. Who we are
BassState is operated by BassState (“we”, “us”). We are the data controller for the personal data described in this policy, which applies to both the BassState iOS app and our website at bassstate.com.
Contact: hello@bassstate.com
2. Data that stays on your device
The app stores the following only on your device, in local app storage. It is never transmitted to us or anyone else. We have no access to it.
| Data | Purpose | Your control |
|---|---|---|
| The name you optionally enter | Greeting personalisation | Edit any time; Settings → Privacy → Erase local data |
| Habits you create (titles, schedules, check-offs) | Habit tracking | Edit/delete per habit; Erase local data |
| Session history, streaks, practice stats | Your progress views | Erase local data |
| Apple Health cache (sleep, heart rate, HRV — last 30 days), if you connect Apple Health | On-device recovery/sleep insights | Revoke in iOS Settings → Privacy & Security → Health; Erase local data |
| App preferences (sounds, haptics, notification choices) | Remembering your settings | Change any time; Erase local data |
Deleting the app removes all of this permanently. Settings → Privacy → Erase local data does the same without deleting the app.
Because this data never reaches us, we cannot view, recover, or restore it — and no data breach on our side can expose it.
3. Apple Health (HealthKit)
If you choose to connect Apple Health, BassState works with it in two ways, both on your device:
- It reads the categories you approve (sleep analysis, heart rate, heart rate variability) to show recovery and sleep insights.
- It writes back a record of the sessions you complete — breathing and NSDR sessions as Mindful Minutes, focus sessions as Mind & Body workouts — so your practice appears in Apple Health alongside the rest of your activity.
In both directions this data:
- is processed and stored within Apple Health and the app on your device only, and is never transmitted off it to us or anyone else;
- is never used for advertising, marketing, or analytics, and is never shared with or sold to anyone;
- can be turned off at any time in iOS Settings → Privacy & Security → Health → BassState — which stops both reading and writing — and its local cache removed via Erase local data.
Where UK GDPR applies to this on-device processing, our basis is your explicit consent, given through Apple’s Health permission flow (which asks separately about reading and writing) and revocable there at any time.
4. Data that leaves your device — only with your consent
On first launch we ask whether you want to share usage analytics and crash reports. If you decline, none of the data in this section is collected. You can change your choice any time in Settings → Privacy.
a) Usage analytics (Google Firebase Analytics). Event-level usage data — for example which features are used, session start/completion events, screen views — together with technical context: app version, device model, OS version, language, country (from a truncated IP), and a random per-install identifier. It is not linked to your name (we never have your name — see §2). We use it to understand what works and improve the product. Retention: 14 months, then automatic deletion.
b) Crash diagnostics (Google Firebase Crashlytics). If the app crashes: stack traces, device state at crash, OS/app version, and a random install identifier. Used solely to find and fix defects. Retention: 90 days.
Lawful basis for both: your consent (UK GDPR Art. 6(1)(a); PECR reg. 6 for on-device storage/access). Withdrawing consent stops collection immediately; already-collected data ages out per the retention periods above, or sooner on request (§8).
5. Purchases
Subscriptions are sold through Apple’s App Store. Apple processes your payment — we never receive your card details, billing address, or Apple ID. We receive only anonymised transaction confirmations (product purchased, validity period) to unlock premium features on your device.
6. Our processors and international transfers
| Processor | What they process | Location & safeguard |
|---|---|---|
| Google LLC (Firebase Analytics, Crashlytics) | §4 data (app) | US — UK Extension to the EU–US Data Privacy Framework, and/or standard contractual clauses with the UK Addendum |
| Apple Inc. (App Store, HealthKit permissions, payments) | §5 purchase processing | Apple’s own controller/processor terms |
| Resend (Resend, Inc.) | Website beta/newsletter sign-ups: your email address and an intent tag (beta or newsletter); sending the beta confirmation email (§11) | US — DPF and/or SCCs with UK Addendum |
| Vercel (Vercel Inc.) | Website hosting; privacy-friendly, cookieless traffic analytics; standard server request logs (§11) | US — DPF and/or SCCs with UK Addendum |
| Google LLC (Google Analytics 4, Google Tag Manager) | Website usage analytics and hashed-email conversion measurement (§11) | US — UK Extension to the EU–US Data Privacy Framework, and/or SCCs with the UK Addendum |
We do not sell personal data. The app contains no advertising networks or third-party marketing SDKs. The website’s analytics and conversion measurement are described in §11; the only advertising-related use of your data is the hashed-email conversion matching set out there, and we never share your readable email address with an advertiser.
7. How long we keep data
App: we hold no data about you beyond §4 — analytics 14 months, crash reports 90 days, both automatic; everything else lives on your device under your control (§2).
Website (§11): the email you submit is held by Resend until you unsubscribe or ask us to delete it; website analytics data is retained for the period configured in Google Analytics.
8. Your rights (UK GDPR)
You have the right of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior lawful processing.
Practical routes, given our local-first design:
- Stop all collection: Settings → Privacy → toggle off usage sharing.
- Erase device data: Settings → Privacy → Erase local data (or delete the app).
- Erase analytics/crash data held by our processors: email hello@bassstate.com from the device in question; because analytics identifiers are random and not linked to your identity, we will guide you through providing the app’s install identifier (shown in Settings → Privacy) so we can action deletion via our processors. We respond within one month.
- Website email & analytics: unsubscribe from any email we send (or reply asking to be removed), and email hello@bassstate.com to have your address deleted from our list. You can block or delete cookies in your browser to stop the site’s cookie-based analytics — see §11.
You also have the right to complain to the Information Commissioner’s Office (ico.org.uk), though we’d welcome the chance to resolve any concern first at hello@bassstate.com.
9. Children
BassState is not directed at children under 16, and we do not knowingly collect personal data from them.
10. Security
Data that stays on your device is protected by iOS’s own encryption and your device passcode. Consent-gated analytics/crash data, and website form submissions, are transmitted over TLS to the processors in §6. Aside from the email addresses our email processor (Resend) holds for website beta/newsletter sign-ups (§11), we operate no server-side database of user data.
11. The website (bassstate.com)
This section covers bassstate.com, as distinct from the app above. The website is where you can read the blog, join the beta, and subscribe to updates.
a) Email you give us (Resend). If you request beta access or subscribe to blog updates, we store the email address you enter and a tag recording which list you joined (beta or newsletter). We use Resend (our email processor) to hold that address and to send you the emails you asked for — for a beta request, a single confirmation that you are on the list; for the newsletter, our occasional posts. We use your email only for what you signed up for, and we never sell it. You can opt out any time: use the unsubscribe link in any email we send, reply asking to be removed, or email hello@bassstate.com.
b) Site analytics and cookies (Google Analytics 4 via Google Tag Manager, and Vercel). When you browse bassstate.com we measure how the site is used so we can improve it:
- Google Analytics 4, loaded through Google Tag Manager, records page views and interactions — for example which pages and calls-to-action you use, when a form is started, and blog reads — along with technical context such as your device and viewport type, approximate location (from your IP address), referrer, and the pages you view. This uses cookies and similar identifiers, and stores small flags in your browser’s local storage (for example, whether you have visited before and whether you have already submitted a form).
- Vercel Analytics, provided by our host, gives us privacy-friendly, cookieless aggregate traffic figures.
c) Conversion measurement — hashed email (Google “Enhanced Conversions”). When you submit a sign-up form, the site also creates a SHA-256 hash of your email address — a one-way fingerprint, not your readable address — and sends it to Google together with the analytics event. Where our analytics is linked to Google Ads, this lets Google match your sign-up to an earlier ad interaction (“Enhanced Conversions”) so we can understand which channels bring people to BassState. We never send your readable email address to Google, and we do not use it to show you ads on other sites.
d) Your choice, and how it is enforced. When you first visit bassstate.com a consent banner asks whether to allow analytics cookies, with Accept and Decline offered equally. Nothing in (b) or (c) runs until you choose Accept — Google Tag Manager is not loaded, no analytics or advertising cookies are set, and the returning-visitor and form-submitted markers are not written. Choose Decline and none of it runs; any analytics cookies already present are cleared. You can change your decision at any time through Cookie choices in the site footer.
Cookies and local storage. The only thing stored before you choose is the record of your choice itself:
| Name | Type | Purpose | Set |
|---|---|---|---|
bs_consent | Strictly necessary | Remembers your Accept/Decline choice so we don’t ask on every visit | Always (the one item stored before you choose) |
bs_visited, bs_lead_generated | Analytics (first-party) | Whether you are a returning visitor / have already submitted a form | Only after you Accept |
_ga, _ga_* | Analytics (Google Analytics 4) | Distinguish visitors and sessions for aggregate usage stats | Only after you Accept |
| Vercel Analytics | None (cookieless) | Aggregate traffic counts; sets no cookie or identifier | Always; no personal data |
Beyond storing your choice, you can also block or delete cookies in your browser, opt out of email as in (a), and ask us at hello@bassstate.com what we hold and to delete it.
Lawful basis (website).
- Your email (a): your consent, given when you submit the form, together with our legitimate interest in responding to your request and running a beta.
- Analytics, cookies, and hashed-email measurement (b, c): your consent (UK PECR reg. 6; UK GDPR Art. 6(1)(a)), obtained through the banner in (d) before any non-essential cookie or identifier is set. Declining, or later withdrawing via Cookie choices, stops all of it.
Website data is processed by the processors listed in §6, and your UK GDPR rights (§8) apply to it.
12. Changes to this policy
We’ll post updates here with a revised date, and flag material changes in-app before they take effect.