Boxing Timer support

Privacy Policy

Effective 3 September 2026

1. Controller and scope

This policy explains how the Boxing Timer app for iPhone and iPad (the “App”) and its support and legal pages handle information. The data controller is APP BOX EOOD (Bulgarian: “Апп Бокс” ЕООД), UIC 207060361, with registered office at Lazur District, Block 109, Apartment 5, 8000 Burgas, Bulgaria (“APP BOX”, “we”, “us”). Privacy requests may be sent to info@appbox.group.

At a glance: the App has no account, advertising, or cross-app tracking. Workout details stay on your device. Google Analytics for Firebase and Firebase Crashlytics collect pseudonymous usage, purchase, device, and diagnostic information in standard App builds so we can understand and improve the product.

2. Information kept on your device

Your timer presets, custom timer names, current workout state, selected language, sound and display preferences, and onboarding status are stored in the App’s private container on your device. APP BOX does not receive these workout details. You can delete custom timers in the App and remove the remaining local data by deleting the App.

3. Purchases

Subscriptions and Lifetime Access are processed by Apple through the App Store and StoreKit. The App receives product identifiers and verified transaction and entitlement status so it can show offers, complete purchases, restore access, and unlock premium features. Google Analytics for Firebase also measures in-app purchase and subscription events, including product ID, name, price, and purchase-flow outcome, associated by default with a pseudonymous App instance ID. APP BOX does not receive your payment-card details or Apple Account password. Apple processes purchase information under its App Store Privacy Notice.

4. Analytics and crash diagnostics

In standard App builds, Google Analytics for Firebase and Firebase Crashlytics are enabled when the App launches. Analytics assigns a pseudonymous App instance identifier and measures App lifecycle events, screen and feature interactions, onboarding progress, timer actions, paywall plan selection, and purchase or restore outcomes. It also receives general App, device, operating-system, language, and coarse geographic information derived from masked IP addresses. Crashlytics sends crash traces and technical state needed to diagnose stability problems, including pseudonymous installation and session identifiers, crash time, App version and bundle identifier, operating-system version, device model and architecture, available memory and storage, and device state.

We do not set a Firebase user ID, include the advertising identifier, enable advertising personalization, or add custom timer names, detailed workout settings, email addresses, payment-card information, or Apple Account credentials to analytics or crash reports. The data is not used for cross-app tracking, advertising, or profiling. These services are not controlled by a separate in-App switch.

We process this information for our legitimate interests in understanding feature use, measuring the purchase funnel, maintaining security and reliability, diagnosing failures, and improving the App. You may object to this processing by contacting us. Google states that Crashlytics retains crash traces and associated identifiers for 90 days before beginning removal from live and backup systems. Analytics event-level data is retained under our configured Google Analytics retention settings; aggregated reporting may be retained longer. Learn more in Privacy and Security in Firebase, Google’s App Store data-disclosure guidance, and the Google Privacy Policy.

5. Notifications and audio

If you grant notification permission, workout alerts are generated and scheduled locally by iOS. The App does not use remote push notifications. Timer sounds are bundled with the App and are played locally.

6. Website access and support messages

These support and legal pages do not use advertising, analytics scripts, or cookies. When you visit them, our hosting infrastructure processes standard access-log information such as IP address, request time, requested path, user agent, and response status to deliver and secure the site. Access logs are rotated and retained for no more than 30 days. This processing is based on our legitimate interest in operating a secure and reliable website.

If you email support, we use your email address, message, and any information you choose to include to answer and administer your request. Please do not send health information or other sensitive personal data. Support correspondence is retained only while needed for support and legitimate legal or business records, normally no longer than 24 months after the request is closed.

7. Purposes and legal bases

8. Sharing and international processing

We do not sell personal information and do not use it for advertising, profiling, or cross-app tracking. Information is shared only as needed with Apple for purchases, Google for analytics and diagnostics, our hosting and technical service providers, professional advisers, or public authorities where legally required. Google and Apple may process information on global infrastructure, including outside the European Economic Area, under their published safeguards and applicable data-transfer mechanisms.

9. Retention and your choices

10. Your data-protection rights

Subject to applicable law, including the GDPR, you may request access, correction, deletion, restriction, or portability of your personal data and object to processing based on legitimate interests. Because the App has no account and Firebase identifiers are not linked by us to your name or contact details, we may be unable to identify a particular analytics or diagnostic record without additional information. Send requests to info@appbox.group. We may ask for information reasonably necessary to verify your request.

You may also lodge a complaint with the Bulgarian Commission for Personal Data Protection or the supervisory authority where you live or work.

11. Children

The App is a general fitness timing tool and is not designed to solicit personal information from children. It has no account or social feature. A parent or guardian who believes a child has sent information through support may contact us so we can assess and delete it where possible.

12. Security and changes

We use reasonable technical and organisational safeguards appropriate to the limited information processed, but no transmission or storage method is completely secure. We may update this policy when the App, service providers, or legal requirements change. Material changes will be communicated through the App or App Store listing where appropriate, and the effective date above will be updated.