BusYa

Privacy Policy

Effective date: 2026-07-27

Versión en español: PRIVACY_POLICY_ES.md

BusYa ("the app", "we", "us") provides public-transit information for Montevideo, Uruguay. It does not require an account, login, or payment.

This policy describes the Android and iOS app's current data practices. The BusYa project team is responsible for the processing described below.

Data We Process

Foreground Location

If you grant location permission, the app accesses precise location only while you use it. Location supports showing your position, finding nearby stops, centering the map, and selecting a trip origin. Trip planning runs on your device.

Location normally remains on your device. When you ask the app to identify a point on the map, that point's coordinates are sent over HTTPS to the BusYa Cloudflare Worker and then to Mapbox for reverse geocoding. The Worker processes the coordinates only to answer that request and does not write them to D1 or KV. The app does not collect background location or keep a server-side location history.

Search and Reverse Geocoding

Stop, line, and place searches use data bundled with the app and stay on your device. Address-search text is sent over HTTPS through the BusYa Worker to Mapbox. Coordinates selected on the map are sent through the same path for reverse geocoding. These values are processed for the request and are not written to BusYa's D1 analytics database or feedback KV store.

Recent search selections may be saved locally on your device. You can remove them from the app, and uninstalling the app removes its local data.

Anonymous Daily Usage Count

Once per app launch, the app sends:

The app creates the daily identifier by applying SHA-256 to a random installation value, a purpose label, and the current UTC date. The underlying installation value never leaves the device. The daily value changes every day, is separate from feedback and Sentry, and cannot be used by BusYa to follow an installation across days.

Cloudflare D1 stores one row per daily identifier and automatically deletes rows older than 90 days. We use these rows only to count daily active installations and understand version/platform adoption.

Crash Reports and Diagnostics

When Sentry is enabled in a release, the app and Worker send crash and error diagnostics to Sentry. These may include stack traces, app/OS/device technical information, endpoint names, and sanitized app-interaction breadcrumbs needed to diagnose the error.

BusYa does not assign a user or device identifier to Sentry events. Before sending, the app removes precise coordinates, search/address text, raw UUIDs, tokens, request and response bodies, and URL query strings. Sentry tracing, profiling, session replay, and automatic session tracking are disabled. Sentry events and attachments must be configured for retention of no more than 90 days.

Feedback You Choose to Send

When you use the feedback feature, the app sends:

The app and Worker both remove sensitive diagnostic fields, UUIDs, URL query strings, request/response bodies, coordinates, and search/address values before feedback reaches storage. Please do not put personal or confidential information in the message itself.

The Worker stores the text and sanitized context in Cloudflare KV for 28 days. It uses a random report ID that does not identify you. The masked screenshot is sent only to Sentry, not KV. When Sentry is enabled, KV may contain the random Sentry event ID needed to match the two copies. Sentry retains the report and attachment for no more than 90 days.

Network Information

Like any internet service, Cloudflare, Mapbox, and Sentry receive connection information such as an IP address while serving a request. BusYa does not write IP addresses to D1 or KV. Mapbox states that it keeps IP addresses used for service delivery, billing, and security for 30 days unless needed for an ongoing security or misuse investigation.

Purposes

We process data only to:

We do not sell personal data, use it for advertising, or create user profiles.

Processors and International Transfers

BusYa uses:

These providers process data under their own security and privacy terms and may process it outside Uruguay. See the Cloudflare Privacy Policy, Mapbox Privacy Policy, and Sentry Privacy Policy.

Retention and Deletion

Data BusYa retention
Coordinates and address requests Ephemeral request processing; not stored in D1 or KV
Daily analytics rows in D1 90 days
Feedback text and sanitized context in KV 28 days
Sentry events, feedback, and attachments No more than 90 days
Recent selections and installation value On device until removed or the app is uninstalled

Backups or security records held by a processor may follow that processor's documented deletion cycle or be retained when legally required.

Your Choices and Rights

You can deny or revoke location permission in system settings and still browse the map and search transit data. Feedback is optional.

Under Uruguay's Ley N.º 18.331, you may request information about processing or ask to access, correct, update, or delete personal data. Send a request to BusYaApp+support@gmail.com. To help locate optional feedback without collecting another identifier, include its approximate submission time and a short description of the message. Do not email sensitive location or identity documents unless we specifically ask for what is necessary to verify a request. We will respond within five business days where the law requires it.

Daily analytics cannot be linked back to an installation and expire automatically. Ephemeral geocoding requests are not retained by BusYa.

You may also contact Uruguay's Unidad Reguladora y de Control de Datos Personales.

Children's Privacy

BusYa is a general-audience transit app and is not directed at children. We do not knowingly collect children's personal information.

Changes

We may update this policy as the app changes. The effective date above identifies the current version.

Contact

Questions about this policy can be sent to: BusYaApp+support@gmail.com