Privacy Policy
Effective 13 September 2026
This is a translation of the Russian original, provided for convenience. If the two differ, the Russian version prevails.
This policy describes what personal data is processed when you use the Brouncher app for iPhone (the “App”) and the brouncher.ru website (the “Site”; together, the “Service”): why, on what legal basis, where and for how long it is kept, and how you can control it.
In short
- The App requires no registration, shows no ads and does not track you.
- Your list of mini-apps, the age you stated and the permissions you granted are stored only on your device.
- Our server receives technical request data and keeps it for no longer than 30 days.
- Data from a request or a report is used only to handle that request or report.
- All data is stored and processed in Russia.
1. General provisions
1.1. This policy is drawn up in accordance with Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (the “Law”) and sets out the Operator's policy on the processing of personal data.
1.2. We process data lawfully and fairly, only for purposes defined in advance, and only to the extent those purposes require.
1.3. This policy does not apply to mini-apps. They are published by companies, and each company is responsible for the data its mini-app processes (section 5).
2. Operator
The operator of personal data is the person specified in section 15 (the “Operator”, “we”). For any question about the processing of data, write to contact@brouncher.ru.
3. What data we process and why
3.1. The App on your device
The App stores on your device: the list of mini-apps you added; copies of their descriptions, icons and loading screens; the data mini-apps save themselves (cookies, local storage — each mini-app has its own, which no other mini-app can reach); the age group you stated; the language you chose; and a record that you accepted the Terms of Use.
This information is not sent to us or to anyone else. It is deleted together with the App, and a mini-app's data is deleted together with that mini-app.
3.2. Technical request data
- What data
- IP address, date and time of the request, the address requested and the request method.
- When
- The App loads the list of mini-apps, their icons and loading screens from our server; a browser opens pages of the Site; Safari opens the page for adding a mini-app to the Home Screen.
- Why
- To keep the Service working and secure: to repel attacks and attempts to guess access tokens, and to investigate failures.
- Legal basis
- The Operator's legitimate interest in the operation and security of the Service, which does not infringe your rights (clause 7, part 1, Article 6 of the Law).
- Retention
- No longer than 30 days, after which the records are deleted automatically. We do not link this data to your identity.
3.3. Reports about mini-apps
- What data
- The mini-app's number, the reason you chose, the text if you wrote one, the address of the mini-app page open at the time of the report, and the time it was sent. A report contains no name, contact details or device identifiers.
- Why
- Moderation: to check the report and block the mini-app if it violates the Terms of Use.
- Legal basis
- Performance of the Terms of Use, to which you are a party (clause 5, part 1, Article 6 of the Law).
- Retention
- For as long as the report is needed for moderation and for resolving disputes, and no longer than 3 years.
Do not include personal data — yours or anyone else's — in a report unless it is necessary.
3.4. Requests from companies
- What data
- The organisation's name and INN; the contact person's first and last name; a work email address; a phone number, website address and comment, if given; the language of the page the request was sent from; the date and time it was sent.
- Why
- To consider the request, contact the contact person, and prepare and conclude an agreement with the organisation. A confirmation of the request is sent to the email address given.
- Legal basis
- The contact person's consent (clause 1, part 1, Article 6 of the Law), given with a separate checkbox in the request form on the terms of the Consent to the Processing of Personal Data.
- Retention
- Until the purpose is achieved, but no longer than 3 years from the last contact, or until consent is withdrawn. If an agreement is concluded with the organisation, section 3.5 applies from then on.
3.5. Company dashboard
- What data
- The organisation's name, INN and email address; information about its mini-apps; a hash of the access token (the token itself is not stored and cannot be recovered); a service session cookie.
- Why
- Performance of the agreement with the organisation: running the dashboard, placing mini-apps, and communication about them.
- Legal basis
- The Operator's legitimate interest in performing the agreement with the organisation the data subject represents (clause 7, part 1, Article 6 of the Law).
- Retention
- For the term of the agreement and 3 years after it ends.
3.6. Correspondence
- What data
- Email address, name and whatever you tell us in your message.
- Why
- To answer your message, including a request about personal data or a complaint.
- Legal basis
- The Operator's legitimate interest in answering a message you sent (clause 7, part 1, Article 6 of the Law); for requests about personal data, the Operator's obligations under the Law (clause 2, part 1, Article 6).
- Retention
- No longer than 3 years from the last message.
4. What we do not do
- We show no ads and do not use the device's advertising identifier.
- We do not track you across other apps and websites, and we do not share data with data brokers.
- We do not collect analytics about how you use the App, and we do not embed third-party analytics SDKs in it.
- We put no visitor counters, pixels or third-party cookies on the Site. The Site's fonts are served from our own server.
- We do not sell personal data or use it to make decisions that have legal effects for you.
5. Mini-apps
5.1. Mini-apps are companies' web services. An open mini-app exchanges data directly with its company's servers; the Operator does not receive that data.
5.2. So that mini-apps open faster, the App may load the pages of the mini-apps you added in advance and keep recently opened ones in the background. The company's servers then receive technical request data, as they would when any website is opened.
5.3. The processing of data in a mini-app is governed by the privacy policy of the company that published it: the company is the independent operator of that data. Only add mini-apps from sources you trust.
6. Access to device features
6.1. A mini-app may ask for access to the camera, microphone, location, contacts, photos, Bluetooth, Face ID, the clipboard and notifications — and only to what the company declared when it placed the mini-app. The App asks for your permission separately for each mini-app; a permission given to one does not extend to others.
6.2. Only the contact and the photo you pick yourself in the system picker are passed to the mini-app.
6.3. Face ID biometric data is processed only by iOS. Neither the App nor a mini-app has access to it; they receive only the result of the check.
6.4. Mini-app notifications are created on the device itself; the Service does not receive push notification tokens.
6.5. A mini-app's access ends when you delete it. The App's own access to device features can be revoked in iOS Settings.
7. Cookies on the Site
The Site uses only two first-party cookies:
lang— the Site language you chose, kept for 1 year;__Host-portal_session— the sign-in session for the company dashboard, 12 hours; set only after you sign in.
There are no third-party or analytics cookies. If you turn cookies off in your browser, the Site will not remember your language, and you will not be able to sign in to the dashboard.
8. Who receives data
8.1. We do not share personal data with third parties, except in the cases below.
8.2. Email. Messages to and from contact@brouncher.ru — request confirmations, notifications, correspondence — are stored and transmitted through the VK WorkSpace email service provided by VK LLC (Leningradsky Prospekt 39, bldg. 79, Moscow, 125167, Russia). The service's servers are located in Russia.
8.3. Hosting. The Service's server is located in a data centre in Moscow. The hosting provider supplies equipment and connectivity and does not use the Service's data for its own purposes.
8.4. Apple. The App is distributed through the App Store. Downloads and purchases in the App Store are processed by Apple under its own privacy policy; we receive only anonymised statistics from Apple.
8.5. Public authorities — in the cases and in the manner provided by law.
8.6. Personal data is not transferred across borders.
9. Where data is stored
All data the Operator processes is recorded, stored and processed in databases located in Russia, including when it is collected (part 5, Article 18 of the Law). If you use the Service from another country, your data is processed in Russia.
10. Retention and deletion
10.1. Data is kept no longer than the purposes of processing require (the periods are given in section 3), unless a longer period is required by law.
10.2. When the purpose is achieved, the period expires or consent is withdrawn, the data is destroyed within 30 days, unless the Operator has another lawful basis to continue processing it. Server backups are overwritten within 14 days.
11. Data protection
We take the legal, organisational and technical measures provided for by Articles 18.1 and 19 of the Law, including:
- the Site and the App connect to the server only over HTTPS;
- dashboard access tokens are stored as an irreversible hash, and repeated attempts to guess a token are blocked;
- only authorised persons of the Operator have access to the data;
- the server process is isolated from the rest of the system and cannot open outgoing connections itself, and the server is protected by a firewall;
- technical logs are limited in size and retention.
12. Your rights
12.1. You have the right to:
- receive information about the processing of your personal data (part 7, Article 14 of the Law);
- demand that data be corrected, blocked or destroyed if it is incomplete, outdated, inaccurate, unlawfully obtained or not necessary for the stated purpose;
- withdraw your consent to processing;
- appeal against the Operator's actions or inaction to Roskomnadzor (the Russian data protection authority) or in court.
12.2. To exercise a right, write to contact@brouncher.ru. Tell us how to address you and give details that let us find your data — for example, the request number and the address it was sent from. We may ask you to confirm that the request really comes from you.
12.3. We respond within 10 working days. This period may be extended by no more than 5 working days, in which case we will tell you why.
12.4. The App has no accounts, so technical request data usually cannot be linked to a particular person.
13. Children
The Service does not collect children's data. The request form is intended for representatives of organisations. The age group you state in the App is stored only on your device. If we learn that we have received a child's data without the consent of a legal representative, we will delete it.
14. Changes to this policy
A new version is published on this page with its date and takes effect when it is published. We announce material changes on the Site or in the App.
15. Operator details
- Name
- to be specified
- OGRN
- to be specified
- INN
- to be specified
- Address
- to be specified
- contact@brouncher.ru