Privacy Policy
Effective Date: August 15, 2026
Last Updated: August 15, 2026
Sonance Software ("we," "us," or "our") operates the Booko Buddy mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App on iOS devices. Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access or use the App.
We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates. You will be deemed to have been made aware of, will be subject to, and will be deemed to have accepted the changes in any revised Privacy Policy by your continued use of the App after the date such revised Privacy Policy is posted.
1. Information We Collect
We understand that privacy is important to you. We have designed our App to minimize data collection and protect your privacy. The information we collect is limited to what is necessary to provide you with a functional and reliable service.
1.1 Crash Reports
We collect crash reports and diagnostic information when the App experiences technical problems or crashes. This information helps us identify and fix bugs, improve App stability, and enhance your user experience. Crash reports may include:
- Device type and model information
- Operating system version (iOS version)
- App version number
- Timestamp of when the crash occurred
- Technical data about the App's state at the time of the crash
- Stack traces and error logs
- Memory usage and performance metrics
- Device identifier (in anonymized or hashed form)
This crash data is collected automatically when a crash occurs and is typically transmitted to our servers when your device next connects to the internet. The data is technical in nature and does not include personal content you may have created or stored within the App.
1.2 Information We Do Not Collect
We want to be transparent about what we do not collect. We do not collect:
- Personal identification information such as your name, email address (except when you voluntarily contact us), phone number, or mailing address
- Location data or geolocation information
- Photos, contacts, or other media from your device
- Payment or financial information
- User-generated content or data you create within the App (unless explicitly stored on your device only)
- Browsing history or search queries
- Social media profile information
- Biometric data
- Marketing or advertising identifiers for tracking purposes
1.3 Automatically Collected Information
Beyond crash reports, we do not automatically collect analytics, usage statistics, or behavioral data through the App. We have deliberately chosen not to integrate analytics platforms or tracking mechanisms to respect your privacy.
2. How We Use Your Information
We use the crash reports and technical information we collect for the following specific purposes:
2.1 App Improvement and Maintenance
The primary purpose of collecting crash reports is to improve the App's stability, performance, and functionality. We analyze crash data to:
- Identify and diagnose technical issues and bugs
- Prioritize fixes for the most critical or frequent crashes
- Test and verify that bug fixes are effective
- Monitor App performance across different iOS versions and device types
- Understand which features or functions may be causing problems
- Improve overall App quality and user experience
- Optimize code efficiency and resource usage
2.2 Technical Support
If you contact us for technical support regarding App crashes or problems, crash reports may help us understand and resolve your specific issue more quickly and effectively.
2.3 Purposes We Do Not Use Your Information For
We want to be clear about how we do not use your information:
- We do not use crash data for advertising or marketing purposes
- We do not sell crash data or any other information to third parties
- We do not use crash data to profile you or track your behavior
- We do not combine crash data with other datasets to identify you personally
- We do not use crash data for purposes unrelated to App functionality and improvement
3. Disclosure of Your Information
We respect your privacy and do not share your information except in the limited circumstances described below.
3.1 No Third-Party Services
We do not integrate third-party analytics services, advertising networks, or other third-party platforms that would have access to crash reports or any other data from the App. All crash data is processed internally by our own systems.
3.2 Service Providers
We may share crash reports with trusted service providers who assist us with App development, hosting, or technical infrastructure, but only to the extent necessary for them to perform their services. These service providers are contractually obligated to:
- Use the information only for the specific purposes we authorize
- Maintain the confidentiality and security of the information
- Not disclose the information to other parties
- Comply with applicable data protection laws
3.3 Legal Obligations
We may disclose crash reports or other information if required to do so by law or in response to valid requests by public authorities, including to:
- Comply with a legal obligation, court order, or subpoena
- Enforce our Terms of Service or other agreements
- Protect our rights, property, or safety, or that of others
- Investigate potential violations of our policies
- Detect, prevent, or address fraud, security, or technical issues
- Respond to government or regulatory requests when legally required
3.4 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, crash reports and related technical information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy, and you will have the opportunity to delete the App before such transfer if you do not agree to the new policy.
3.5 Aggregate and De-Identified Information
We may create aggregate or de-identified information from crash reports that cannot reasonably be used to identify you. For example, we might publish statistics about the overall crash rate across different iOS versions. Such aggregate or de-identified information is not subject to this Privacy Policy and may be used and disclosed for any purpose.
4. Data Security
We take the security of your information seriously and implement appropriate technical and organizational measures to protect crash reports and any other information we collect.
4.1 Security Measures
Our security measures include:
- Encryption of data in transit using industry-standard SSL/TLS protocols
- Encryption of data at rest on our servers
- Access controls limiting who within our organization can access crash data
- Regular security assessments and updates to our systems
- Secure authentication mechanisms for internal systems
- Monitoring for unauthorized access or security breaches
- Regular backups to prevent data loss
- Employee training on data privacy and security practices
4.2 Limitations of Security
While we strive to use commercially acceptable means to protect your information, please be aware that no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security of your information. Despite our efforts, we cannot ensure or warrant the security of any information you transmit to us, and you do so at your own risk.
4.3 Security Breach Notification
In the event of a data breach that affects crash reports or other information we collect, we will notify affected users in accordance with applicable laws and regulations. Notification will be provided through the App or via email if we have your contact information, and will include information about the nature of the breach, the data affected, and steps you can take to protect yourself.
5. Data Retention
We retain crash reports and related technical information only for as long as necessary to fulfill the purposes described in this Privacy Policy.
5.1 Retention Period
We typically retain crash reports for a period of twelve months from the date they are collected. After this period, crash reports are automatically deleted from our systems unless there is a legitimate reason to retain them longer, such as:
- Ongoing investigation of a specific bug that requires historical data
- Legal or regulatory requirements to maintain records
- Pending legal claims or disputes where the data may be relevant
- Security investigations or fraud prevention purposes
5.2 Deletion and Anonymization
When crash reports are deleted, they are permanently removed from our active systems and cannot be recovered. In some cases, we may choose to anonymize crash data rather than delete it entirely, removing all device identifiers and other potentially identifying information so that the data can be used for long-term trend analysis without privacy concerns.
5.3 Backup Retention
Deleted crash reports may persist in backup systems for up to 90 days after deletion from active systems. After this backup retention period, the information is permanently purged.
6. Your Privacy Rights
Depending on your location and applicable laws, you may have certain rights regarding the crash reports and information we collect.
6.1 Access and Information
You have the right to request information about what crash data we have collected from your device. To make such a request, please contact us using the information provided at the end of this Privacy Policy. We will respond to your request within the timeframe required by applicable law, typically within 30 days.
6.2 Correction and Update
Because crash reports are technical logs generated automatically by the App, there is typically no "correction" necessary. However, if you believe we have inaccurate information about you, you may contact us to discuss the issue.
6.3 Deletion and Erasure
You have the right to request deletion of crash reports associated with your device. Please note that:
- Deleting the App from your device will prevent future crash reports from being sent
- You can request deletion of past crash reports by contacting us
- Deletion requests will be honored within 30 days, subject to legal exceptions
- Some anonymized or aggregate data derived from your crash reports may be retained
- We may retain certain data if required by law or for legitimate business purposes
6.4 Opt-Out and Data Collection Control
While crash reporting is important for maintaining App quality, you can effectively opt out by:
- Uninstalling the App from your device
- Disabling crash reporting in your iOS system settings if such an option is available
- Contacting us to request that future crash reports from your device not be processed
6.5 Data Portability
In some jurisdictions, you have the right to receive crash reports we have collected about you in a structured, commonly used, machine-readable format. To request data portability, please contact us. We will provide the data in JSON or CSV format where technically feasible.
6.6 Objection and Restriction
You may have the right to object to or restrict our processing of crash reports. If you exercise this right, we may not be able to provide you with certain App features or support services, and App quality may be impacted. To object to processing, please contact us.
6.7 Withdrawal of Consent
Where we rely on consent to collect crash reports, you have the right to withdraw that consent at any time by contacting us or uninstalling the App.
6.8 Automated Decision-Making
We do not use crash reports for automated decision-making or profiling that produces legal effects or similarly significantly affects you.
6.9 Lodge a Complaint
If you are located in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with a data protection authority, you have the right to lodge a complaint with your local supervisory authority if you believe our processing of crash reports violates applicable data protection laws.
7. International Data Transfers
As Booko Buddy is available globally, crash reports may be transferred to and processed in countries other than the country where you are located. These countries may have data protection laws that are different from the laws of your country.
7.1 Transfer Mechanisms
When we transfer crash reports internationally, we implement appropriate safeguards to ensure your information remains protected, including:
- Standard Contractual Clauses approved by relevant authorities
- Ensuring that service providers comply with recognized data protection frameworks
- Implementing technical security measures such as encryption
- Conducting privacy impact assessments for international transfers
- Complying with cross-border data transfer requirements under applicable laws
7.2 Legal Basis for Processing
For users in jurisdictions requiring a legal basis for data processing, we process crash reports based on:
- Legitimate interests in improving App quality, stability, and user experience
- Consent, where required by law and obtained through your acceptance of this Privacy Policy
- Necessity to perform our services and fulfill our contract with you
- Compliance with legal obligations
8. Children's Privacy
We are committed to protecting the privacy of children who may use our App.
8.1 Age Restrictions
The App is not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction, which may be 14, 15, 16, or another age). We do not knowingly collect personal information from children under these ages.
8.2 Parental Rights
If you are a parent or guardian and believe that your child has provided us with crash reports or other information, please contact us. If we learn that we have collected information from a child under the applicable age without proper parental consent, we will take steps to delete that information as quickly as possible.
8.3 COPPA Compliance
For users in the United States, we comply with the Children's Online Privacy Protection Act (COPPA). Crash reports are technical in nature and do not constitute personal information as defined by COPPA, but we nevertheless apply privacy protections to all users regardless of age.
8.4 School and Educational Use
If the App is used in a school or educational setting, the educational institution is responsible for obtaining any necessary parental consents and ensuring compliance with applicable student privacy laws such as FERPA in the United States.
9. California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
9.1 Categories of Information
Under California law, the crash reports we collect fall into the following categories:
- Identifiers (such as device identifiers, in hashed or anonymized form)
- Internet or network activity information (such as crash logs and error reports)
- Inferences drawn from the above (such as which App features may need improvement)
9.2 California Consumer Rights
California residents have the right to:
- Know: Request information about the categories and specific pieces of personal information we have collected, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share information
- Delete: Request deletion of personal information we have collected from you
- Correct: Request correction of inaccurate personal information
- Opt-Out: Opt out of the sale or sharing of personal information (note: we do not sell or share personal information)
- Limit Use: Limit the use and disclosure of sensitive personal information (note: we do not collect sensitive personal information as defined by the CPRA)
- Non-Discrimination: Not receive discriminatory treatment for exercising your privacy rights
9.3 Exercising Your Rights
To exercise any of these rights, please contact us at support@bookobuddy.com. We will verify your identity before processing your request. We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded.
9.4 Response Timing
We will respond to verifiable consumer requests within 45 days of receipt. If we require more time (up to 90 days total), we will inform you of the reason and extension period in writing.
9.5 Authorized Agents
You may designate an authorized agent to make a request on your behalf. We will require proof of authorization before processing such requests.
9.6 Sale and Sharing of Personal Information
We do not sell personal information as defined by the CCPA/CPRA. We do not share personal information for cross-context behavioral advertising. Over the past 12 months, we have not sold or shared personal information of California residents.
9.7 California "Shine the Light" Law
Under California Civil Code Section 1798.83, California residents are entitled to request information regarding the disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
10. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) and equivalent laws.
10.1 Data Controller
Sonance Software is the data controller responsible for processing your personal data under the GDPR.
10.2 Legal Basis for Processing
We process crash reports based on the following legal bases:
- Legitimate Interests: We have a legitimate interest in improving App quality, fixing bugs, and ensuring App stability. We have assessed that this interest is not overridden by your privacy rights.
- Consent: Where required, we obtain your consent for processing crash reports through your acceptance of this Privacy Policy and continued use of the App.
- Contract Performance: Processing may be necessary to provide you with the App functionality you expect.
10.3 Your GDPR Rights
Under the GDPR, you have the right to:
- Access: Obtain confirmation of whether we process your personal data and receive a copy of that data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Restriction: Restrict processing in certain circumstances
- Data Portability: Receive your personal data in a structured, machine-readable format
- Object: Object to processing based on legitimate interests or for direct marketing
- Withdraw Consent: Withdraw consent at any time where processing is based on consent
- Lodge a Complaint: File a complaint with your local data protection authority
10.4 Data Protection Officer
If you have questions about our GDPR compliance, you may contact us at support@bookobuddy.com. While we have not appointed a formal Data Protection Officer as we do not meet the GDPR threshold requiring such appointment, your inquiries will be handled promptly.
10.5 EU Representative
If required under Article 27 GDPR, we will appoint an EU representative and provide contact details in an update to this Privacy Policy.
11. Other Regional Privacy Rights
We respect privacy rights globally and comply with applicable laws in all jurisdictions where users are located.
11.1 Brazil (LGPD)
For users in Brazil, we comply with the Lei Geral de Proteção de Dados (LGPD). You have rights similar to those described under GDPR, including rights to access, correction, deletion, portability, and information about data sharing. You may contact the Brazilian National Data Protection Authority (ANPD) if you have concerns about our processing.
11.2 Canada (PIPEDA)
For Canadian users, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. You have the right to access personal information we hold about you and to challenge its accuracy. You may file a complaint with the Office of the Privacy Commissioner of Canada if you believe we have not complied with privacy laws.
11.3 Australia (Privacy Act)
For Australian users, we comply with the Privacy Act 1988 and the Australian Privacy Principles. You have rights to access and correct personal information, and to complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have interfered with your privacy.
11.4 United Kingdom
For users in the United Kingdom, we comply with the UK GDPR and Data Protection Act 2018. You have the same rights as described in the GDPR section above. You may lodge a complaint with the Information Commissioner's Office (ICO) if you have concerns about our data practices.
11.5 Other US States
For residents of Virginia, Colorado, Connecticut, Utah, and other US states with comprehensive privacy laws, you have rights similar to those described under California law, including rights to access, delete, correct, and opt out of data sales (which we do not engage in). Contact us to exercise these rights.
11.6 Other Jurisdictions
If you are located in a jurisdiction not specifically mentioned, you may still have privacy rights under local law. Please contact us to inquire about your rights and how to exercise them.
12. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors.
12.1 Notification of Changes
When we make changes to this Privacy Policy, we will:
- Update the "Last Updated" date at the top of this policy
- Provide notice within the App if changes are material
- Obtain your consent if required by applicable law
- Give you the opportunity to review changes before they take effect
12.2 Material Changes
If we make material changes that significantly affect how we handle crash reports or your privacy rights, we will provide prominent notice at least 30 days before the changes take effect. Material changes might include:
- Collecting new categories of information
- Using crash reports for significantly different purposes
- Sharing data with third parties when we previously did not
- Transferring data to new countries or jurisdictions
- Reducing your privacy rights or protections
12.3 Your Acceptance
Your continued use of the App after changes to this Privacy Policy become effective constitutes your acceptance of the revised policy. If you do not agree to the changes, you should discontinue use of the App and may request deletion of your crash data.
13. Third-Party Services and Links
While we do not currently integrate third-party services into the App, this section addresses potential interactions with external parties.
13.1 No Third-Party Integration
The App does not integrate third-party analytics, advertising, social media, or other third-party platforms. We do not use third-party SDKs or libraries that collect data independently.
13.2 External Links
The App may contain links to external websites or resources. We are not responsible for the privacy practices of these third-party sites. When you leave the App environment, we encourage you to read the privacy policies of every website you visit.
13.3 Third-Party Services You Choose
If you choose to interact with third-party services through your device's operating system features (such as sharing App content through social media), those interactions are governed by the third party's privacy policy, not this one.
14. Data Storage and Infrastructure
This section provides transparency about where and how we store crash reports.
14.1 Storage Location
Crash reports are stored on secure servers that may be located in various countries. We select server locations based on technical requirements, cost efficiency, and legal compliance. Data may be stored in data centers in the United States, European Union, or other jurisdictions.
14.2 Cloud Infrastructure
We may use reputable cloud infrastructure providers to host crash data. These providers maintain appropriate security certifications and comply with industry standards such as ISO 27001, SOC 2, and others.
14.3 Redundancy and Backup
Crash reports are backed up regularly to prevent data loss and ensure service continuity. Backups are encrypted and stored securely, with access restricted to authorized personnel only.
15. Business Purposes and Data Minimization
We are committed to collecting only the minimum data necessary to operate and improve the App.
15.1 Purpose Limitation
We collect crash reports solely for the purposes explicitly stated in this Privacy Policy. We do not use crash data for unrelated purposes without obtaining your consent or updating this policy.
15.2 Data Minimization Practices
We implement data minimization principles by:
- Collecting only technical crash data, not personal content or behavior
- Anonymizing or hashing device identifiers where possible
- Not collecting location, contacts, photos, or other sensitive device data
- Regularly reviewing what data is collected and eliminating unnecessary collection
- Deleting crash data after the retention period expires
15.3 Privacy by Design
We incorporate privacy considerations into our App design and development process, ensuring that privacy is a fundamental consideration rather than an afterthought.
16. User Control and Transparency
We believe you should have meaningful control over crash data collection.
16.1 Transparency
We are committed to being transparent about our data practices. This Privacy Policy is written in clear language to help you understand what we collect and why. If anything is unclear, please contact us for clarification.
16.2 Control Mechanisms
You can control crash data collection by:
- Reviewing iOS system settings related to crash reporting and diagnostics
- Contacting us to opt out of crash data processing
- Uninstalling the App to cease future data collection
- Requesting deletion of previously collected crash data
16.3 Access to This Policy
This Privacy Policy is always accessible within the App and on our website (when available). You can review it at any time to understand our current practices.
17. Contact Information and Privacy Inquiries
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us.
17.1 Primary Contact
Email: support@bookobuddy.com
When contacting us about privacy matters, please include "Privacy Inquiry" in your subject line to ensure your message is routed appropriately.
17.2 Response Time
We strive to respond to all privacy inquiries within 7 business days for general questions and within 30 days (or as otherwise required by law) for formal requests to exercise privacy rights.
17.3 Information to Include
When submitting a privacy request, please include:
- Your full name and contact information
- A description of your request or concern
- Any relevant details about your device or App usage that may help us locate your data
- Proof of identity if requesting access to or deletion of data
17.4 Identity Verification
To protect your privacy, we may need to verify your identity before responding to certain requests. This verification process will be commensurate with the sensitivity of the information and the nature of the request.
18. Legal Disclosures
18.1 Compliance with Laws
We comply with all applicable privacy and data protection laws in the jurisdictions where we operate and where our users are located. This includes but is not limited to GDPR, CCPA/CPRA, COPPA, PIPEDA, LGPD, and other regional privacy regulations.
18.2 Law Enforcement and Legal Process
We may disclose crash reports in response to lawful requests from law enforcement, courts, or other government authorities. We will carefully review such requests to ensure they are legally valid and limited in scope. Where permitted by law, we will attempt to notify you of such requests.
18.3 Harm Prevention
We may disclose information, including crash reports, if we believe in good faith that disclosure is necessary to:
- Protect the safety, rights, or property of any person
- Investigate, prevent, or take action regarding illegal activities or fraud
- Respond to emergency situations that threaten someone's health or safety
- Enforce our Terms of Service or other legal agreements
19. Cookies and Tracking Technologies
The App does not use cookies, web beacons, tracking pixels, or similar technologies to collect information about your browsing activities. We do not track you across websites or apps. The crash reports we collect are generated by the App itself, not by third-party tracking mechanisms.
20. "Do Not Track" Signals
Some browsers and devices offer "Do Not Track" (DNT) signals. Because we do not track users for advertising or behavioral purposes, DNT signals do not affect our data collection practices. We collect crash reports regardless of DNT settings because such collection is necessary for App functionality and