BeLoop — Privacy Policy
Last updated: July 7, 2026
1. Overview
BeLoop is a workout timer app that helps you manage interval training, Tabata, EMOM, AMRAP, countdown, and stopwatch workouts on Android, iOS, and the web. This policy explains what data BeLoop collects, how we use it, and the choices you have. We are committed to collecting as little personal data as possible.
App: BeLoop — Workout Timer
Provider: fonszi Kft. ("Fonszi," "we," "us," "our")
Contact: dev@fonszi.com
This is the product-specific policy for BeLoop. For the full company-wide policy, including detailed GDPR and CCPA disclosures that apply across all Fonszi products, see our main Privacy Policy.
2. Accounts and Sign-In
Mobile (Android and iOS): BeLoop requires an account to use the app on mobile. You can sign in with:
- Email and password (with email verification and password reset)
- Sign in with Google (Android)
- Sign in with Apple (iOS)
Your account is a shared Fonszi account managed by our backend at api.fonszi.com. We store your email address and a securely hashed password (or the identifier returned by Google/Apple sign-in). Authentication tokens are stored securely on your device (Android: EncryptedSharedPreferences; iOS: Keychain).
Single-device sessions: to protect your account and enforce Pro entitlements, we send a stable device identifier at login (Android: ANDROID_ID; iOS: a randomly generated app UUID). Signing in on a new device signs you out of the previous one. We do not use advertising identifiers (IDFA/GAID) for this.
Web: The web version of BeLoop is a free, sign-up-free experience. It runs entirely in your browser and does not create an account.
Deleting your account: You can permanently delete your BeLoop account and its associated data from within the app (Settings › Delete account). Deleting your BeLoop account does not affect your account on other Fonszi apps.
3. Data We Collect
3.1 Account Data
- Email address (required for a mobile account)
- Securely hashed password, or the sign-in identifier from Google/Apple
- Authentication tokens and a device identifier (for single-device sessions)
Account data is stored on our backend (api.fonszi.com) and can be permanently deleted via in-app account deletion.
3.2 Workout Data (Local Only)
- Workout configurations (rounds, work/rest durations, sets)
- Workout history (completion timestamps, duration, mode used)
- Custom workout programs you create
- In-progress timer state (saved to disk so a workout survives a force-close)
Your workout data is stored locally on your device. We do not upload your workouts or workout history to our servers.
3.3 Analytics Data (Anonymous)
We use Firebase Analytics to collect anonymous, aggregate usage data:
- App open/close events and screen views
- Which timer modes are used and workout completion rates
- Performance metrics
This data is anonymous and cannot be used to identify you personally.
3.4 Crash and Error Reports
We use Firebase Crashlytics and Fonsitor (our own error-monitoring tool) to collect crash and runtime-error reports:
- Device model, OS version, and app version
- Stack traces and the screen where an error occurred
- No personally identifiable information is included in these reports
3.5 Advertising (Free Tier Only)
- Free-tier users see ads served by Google AdMob. Ads are not shown during an active workout.
- Pro users do not see ads.
- iOS App Tracking Transparency (ATT): On iOS, BeLoop presents Apple's ATT prompt before any advertising identifier is accessed. If you decline, only contextual (non-personalized) ads are served. You can change this any time in Settings › Privacy & Security › Tracking.
- Android: You can opt out of personalized ads in Settings › Privacy › Ads.
3.6 Billing and Subscriptions
BeLoop Pro is available as a one-time lifetime purchase or a monthly subscription. Subscription status is managed by RevenueCat and linked to your Fonszi account. Purchases are processed by the Apple App Store or Google Play Store. We never receive or store your payment card details — those are handled entirely by Apple, Google, and RevenueCat.
4. Data We Do NOT Collect
- We do not collect your location or GPS data
- We do not access your contacts, photos, camera, or microphone
- We do not collect your phone number or physical address
- We do not collect health or biometric data (a "biometric login enabled" flag, if set, is stored locally only)
- We do not sell or rent your personal data to anyone
5. Third-Party Services
ServicePurposePrivacy PolicyFirebase Analytics (Google)Anonymous usage analyticsFirebase / GoogleFirebase Crashlytics (Google)Crash reportingFirebase / GoogleGoogle AdMob (Google)Ads for free-tier usersGoogle AdsRevenueCatSubscription & purchase managementRevenueCatFonsitor (Fonszi)Runtime error monitoringFirst-party (see this policy)Apple App StoreDistribution & billing (iOS)AppleGoogle Play StoreDistribution & billing (Android)Google
6. Data Storage and Security
- Workout data is stored locally using on-device databases.
- Account data (email, hashed password) is stored in our secure cloud-hosted backend at api.fonszi.com.
- All data transmitted between the app and our servers or third-party services uses encrypted connections (HTTPS/TLS).
- Passwords are securely hashed and never stored in plaintext. API access uses token-based authentication with expiry and rotation, and rate limiting.
7. Data Retention
- Account data: retained while your account is active; permanently deleted within 30 days of an in-app deletion request, except where retention is required by law.
- Workout data: stored on your device until you delete it in the app or uninstall.
- Analytics: Firebase Analytics data is retained for 14 months, then automatically deleted.
- Error reports: Fonsitor reports expire after 90 days; Firebase Crashlytics data is retained by Google.
- Billing records: retained as required by tax and financial regulations.
8. Children's Privacy
BeLoop is not directed at children under 13, and we do not knowingly collect personal data from them. In the European Economic Area, the applicable minimum age may be higher (up to 16, depending on the country). If you believe a child has provided us with personal data, contact us and we will delete it.
9. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent. In particular, you can:
- Access or delete your account and data via in-app account deletion, or by contacting us;
- Delete local workout data by clearing app data or uninstalling;
- Opt out of personalized advertising via your device settings (or the iOS ATT prompt);
- Upgrade to Pro to remove ads entirely.
For full details of your rights under GDPR and CCPA/CPRA — including legal bases for processing and how to exercise each right — see our main Privacy Policy. To make a request, email dev@fonszi.com.
10. Changes to This Policy
We may update this policy from time to time. Changes are posted here with an updated "Last updated" date. For material changes, we will provide additional notice (e.g., in-app). Continued use of the app after changes take effect constitutes acceptance.
11. Contact Us
If you have questions about this privacy policy:
Email: dev@fonszi.com
Website: https://fonszi.com