Privacy Policy
Version 1.2Current Official ReleaseConsent requiredEffective Date: 2026-08-04 · Last Updated: 2026-08-04
Privacy Policy
1. Our Approach
Donnas-Bandwidth-Booster™ collects network *quality* telemetry (connection performance metrics) to make network-path decisions — it is not designed to build a behavioral profile of you. This policy describes what we actually collect, why, how long we keep it, and how you can control or remove it.
2. What We Collect
| Category | Examples | Purpose |
|---|---|---|
| Account information | Email address, hashed password, role | Authentication, account management |
| Device registration | Platform (Android/iOS), device model, app version | Device management, compatibility |
| Network quality telemetry | Round-trip time, jitter, packet loss, throughput estimate, transport type (Wi-Fi/cellular), timestamp | Core Service function — AI-assisted network optimization |
| Diagnostic reports (opt-in only) | Free-text description you submit when requesting support | Troubleshooting, customer support |
| License and subscription data | Plan tier, activation status | Entitlement and billing |
| Security and audit events | Login attempts, administrative actions, timestamps | Account security, fraud prevention, compliance |
We do not collect precise location data, browsing history, or app-usage data from other applications on your device — the Service has no legitimate use for either, and our telemetry schema is fixed and does not include a free-form field that could be used to collect data outside this table.
3. Consent
- Routine network-quality telemetry is governed by a per-device
`telemetry_consent` setting, defaulted to the minimum viable data needed for the Service to function.
- Diagnostic *reports* (richer, user-initiated, e.g. "send diagnostics to
support") are a separate, explicitly opt-in action and are never bundled into routine telemetry.
- Any future product-analytics collection (as opposed to network-quality
telemetry) is gated by its own, separate, off-by-default consent flag and will not be folded into network telemetry.
- Changes to your consent settings are logged for audit purposes.
4. How We Use Information
- To operate, maintain, and improve the Service, including the AI
network-scoring engine — see our AI & Automated Insights Disclaimer for how these features work and their limits.
- To authenticate you and secure your account.
- To provide customer support when you request it.
- To detect, investigate, and prevent fraud, abuse, and security
incidents.
- To comply with legal obligations.
We do not sell your personal information.
5. How We Protect Information
- All traffic between the application and our servers is encrypted in
transit (TLS 1.3).
- Sensitive free-text fields (such as opt-in diagnostic report content)
are encrypted at rest (AES-256-GCM) before being stored.
- Passwords are never stored in plain text — they are hashed with
bcrypt before storage.
- Access to administrative functions is restricted by role-based access
control and is itself audit-logged. See our Security & Privacy Overview.
6. Retention
See our Data Retention Policy for exact retention windows by data category. In brief: routine telemetry does not accumulate indefinitely, diagnostic reports are retained only as long as needed to resolve the associated support case, and account data is hard-deleted within 30 days of a verified deletion request.
7. Your Rights and Choices
Subject to applicable law, you may:
- Access the personal data we hold about you.
- Export a copy of your data in a portable format.
- Correct inaccurate account information.
- Delete your account and associated data — see our
- Withdraw consent for optional telemetry or diagnostic reporting at
any time via in-app Settings.
To exercise these rights, use the in-app data export/deletion tools where available, or contact us via the details in Contact Information.
8. Sharing and Disclosure
We do not sell personal information. We may share information with:
- Service providers who process data on our behalf under contractual
confidentiality obligations (e.g., cloud infrastructure hosting) — see our Third-Party Services Disclosure for the specific services currently in use.
- Law enforcement or regulators when required by valid legal process.
- A successor entity in connection with a merger, acquisition, or asset
sale, subject to this policy continuing to apply to previously collected data.
Our current third-party processors are listed in our Third-Party Services Disclosure; we will keep that list current as processors change.
9. Children's Privacy
The Service is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. We periodically review this section to confirm continued alignment with applicable children's privacy laws in the jurisdictions where the Service is offered.
10. International Data Transfers
Donnas-Bandwidth-Booster™ does not currently transfer personal data across international borders, because production hosting infrastructure has not yet been finalized. This section will be updated to identify specific hosting regions and any applicable cross-border transfer safeguards (such as Standard Contractual Clauses) once that infrastructure is in place.
11. Changes to This Policy
We will maintain a version history of this policy. When we make a material change, we will present the updated policy for your re-acknowledgment.
12. Contact
See Contact Information for how to reach us with privacy questions or requests.