Privacy Policy for BMS Pal
Effective Date: August 30, 2026
1. What We Never Collect
BMS Pal has no user accounts and no sign-in. We do not collect, and the app does not transmit, any of the following — ever:
- Names, email addresses, or contact information.
- Location data.
- Advertising identifiers, analytics, usage tracking, or crash reports.
- Anything in the background: the app makes no automatic or scheduled network transmissions. The only network activity, other than Apple’s own App Store services, happens when you explicitly tap a button, as described below.
2. Your Data on Your Device
Battery telemetry (voltages, current, temperature, state of charge, and history), your device profiles and groups, and saved sanity-check reports live only in the app’s local storage on your device. You can delete any saved device, its history, and its saved reports in the app at any time.
To keep the free trial fair across reinstalls, the app stores a single trial-start timestamp in your device’s Keychain. It contains no personal information and never leaves your device. Purchases are handled entirely by Apple through the App Store; we never see your payment details.
3. Battery Data & Bluetooth
BMS Pal uses Bluetooth Low Energy strictly to communicate locally with your battery hardware. Bluetooth data is not sent anywhere else.
4. Data You Can Choose to Share With Us
The app has optional features that send data to our service at api.bmspal.app only when you explicitly tap a Share / Send / Check button:
- Sanity Check — sends your BMS configuration and a live telemetry snapshot so a review report can be generated.
- Confirm Device Support — sends your device’s protocol details and a telemetry snapshot to confirm compatibility and improve the supported-device list.
- Report a Problem / Send Feedback — sends the text you write and, only if you attach them, screenshots you choose.
The share screen offers a copy-to-clipboard of the exact payload sent, so you can inspect precisely what was shared. The service is account-free: no user accounts, no install identifiers, and no per-user identifiers of any kind in these payloads. A sanity-check request includes your preferred report language (for example “en-US”) so the report reads in your language — a coarse preference, not an identifier. Screenshots are entirely your choice; please avoid including personal information in them.
Our service runs on Cloudflare’s infrastructure. As with any internet service, network metadata such as your IP address is processed transiently to deliver a request you make; BMS Pal’s own records do not store your IP address.
5. AI Processing of Shared Data
Sanity Check reports (and a duplicate-detection pass on problem reports) are generated by a large-language-model provider we select on the server. All AI traffic is routed through Cloudflare. As of this policy’s Effective Date, the configured provider is OpenAI, reached through OpenRouter (a model-routing service); a Cloudflare-hosted Meta Llama model serves as an automatic backup, and Anthropic (Claude) may also be selected. We have configured our AI routing to disallow providers that train on submitted inputs, to disable request logging at the routing layer, and to require zero-data-retention endpoints for the Anthropic, OpenAI, and Google provider families. No account or user identifier accompanies any AI request. If we materially change which providers can process shared data, we will update this policy first.
6. EcoFlow Sign-In (Optional)
If you add an EcoFlow device, the app offers a “Sign in to EcoFlow” step, because EcoFlow devices require an account-derived key to communicate. When you tap it, the email and password you type are sent once, directly to EcoFlow’s own login service (api-*.ecoflow.com). BMS Pal never stores, logs, or reuses your credentials; only the numeric account ID EcoFlow returns is kept, in your device’s Keychain, to unlock communication with your own device. Nothing happens unless you use this feature and tap sign in.
7. Retention and Deletion
Shared data is kept only as long as it is useful, then deleted automatically:
- Sanity-check and device-confirmation requests: deleted within 7 days.
- Problem reports, their message threads, and attached screenshots: kept while the report is open, then deleted 90 days after it is resolved. Screenshot uploads never attached to a report are deleted within an hour.
- Reward records tied to reports: deleted 30–90 days after they conclude.
- Anonymous device-compatibility statistics (protocol and model identifiers only — no telemetry, no personal data) are retained to build the supported-device list.
Every problem report shows a reference code (a “bugRef”) in the app. To have a report and its data deleted early, contact us with that code — it is a support handle, not an identity.
8. Your Rights (GDPR, CCPA, PIPEDA, and similar)
Because BMS Pal holds no account and no identity for you, most privacy rights are directly in your hands: on-device data is yours to view and delete in the app, and shared data is deleted on the schedule above — or earlier on request using your reference code. We do not sell data, we do not profile users, and we hold nothing that links shared data to you as a person.
9. Children
BMS Pal is a hardware utility not directed at children, and we knowingly collect no data from anyone, including children.
10. Data Security
Shared payloads travel over TLS and carry an integrity signature to prevent tampering. Our service stores only the minimum described above, on Cloudflare infrastructure. You remain responsible for securing your own devices.
11. Changes to This Policy
We may update this policy from time to time; changes are reflected by the Effective Date at the top of this page. If a change materially expands what can be shared or who processes it, the policy update lands before the change ships.
12. Contact
Questions or deletion requests: email hello@support.bmspal.app, use Settings → Support and Feedback in the app (reachable without a purchase), or contact the developer via the official App Store support channel.