W
Warsha Everything Mobile
Documentation / BLE Studio / Privacy Policy
Browse documentation

Legal

Included with Warsha BLE Studio

v0.9.9

Privacy Policy — Warsha BLE Studio

Effective date: August 30, 2026
Controller: Yahia Hassan, trading as Warsha.dev
Contact: yahia.hassan@warsha.dev or https://warsha.dev/contact
Address: c/o MDC#1413, Welserstraße 3, 87463 Dietmannsried, Germany

This policy explains how I handle personal data when you use Warsha BLE Studio, visit its pages on warsha.dev, purchase Pro access, or contact support.

At a glance

Warsha BLE Studio keeps scripts, GATT definitions, project data, and settings on your device. There are no Warsha accounts in version 1. I do not sell personal data, show advertising, or collect advertising identifiers.

Crash diagnostics and product analytics are optional and disabled by default. The first-run privacy prompt lets you enable either category independently. You can change either choice later under Settings → Privacy.

Some features communicate with another system because you ask them to: the LAN editor connects to a browser on your local network, URL import contacts the URL you enter, and scripts with networking permission contact their configured destinations.

On Android, subscription synchronization and purchases use RevenueCat and Google Play.

On macOS, purchases use Polar, and the app checks the Warsha update feed.

Data kept on your device

The app stores scripts, libraries, GATT definitions, project metadata, settings, consent records, local diagnostic state, and commerce or license state needed to provide the app. This data remains on your device unless you export it, enable a network feature, make a purchase, enable optional telemetry, or contact support.

You can delete individual projects in the app. Uninstalling the app or erasing its application data removes locally stored data, subject to device backups and operating-system behavior.

Bluetooth and foreground operation

The Android app requests Bluetooth advertising and connection permissions when you use an on-air BLE run. It uses a foreground-service notification while a peripheral or LAN editor must remain active. These permissions are not used to infer location or create an advertising profile.

When a peripheral is running, the app processes connection state and data sent by connected BLE centrals. That data is used locally to run and inspect the peripheral and is not intentionally sent to Warsha. You are responsible for having permission and a lawful basis for any personal data you configure or receive.

LAN editor

When you enable the LAN editor, the app starts a local HTTP server so a browser on your network can edit and inspect the project. It processes the pairing PIN, session tokens, script source, library metadata, and live inspector state required for that connection.

LAN-editor traffic is not encrypted. Use it only on networks and devices you trust. Someone able to observe the local network may be able to read this information in transit. Warsha does not receive LAN-editor traffic.

URLs and script networking

“Import from URL” contacts the URL you provide. A script using the optional networking capability contacts the destinations defined by you or by that script. The destination receives ordinary request information such as your IP address, technical request headers, and the content sent in the request. Those recipients operate under their own privacy terms.

Optional crash diagnostics

Firebase Crashlytics is disabled until you enable Crash diagnostics in the first-run privacy prompt or in Settings. If enabled, Google processes crash and non-fatal diagnostic reports, which can include stack traces, app version, device model, operating-system version, locale, Firebase and Crashlytics installation identifiers, loaded binary information, and technical exception details.

Warsha excludes script source, script titles, GATT layouts, characteristic values, URLs selected by you, license keys, and other authored project content from its own diagnostic fields. You can withdraw consent at any time under Settings → Privacy; this stops future collection. Google states that Crashlytics retains crash traces and associated identifiers for 90 days before beginning removal from live and backup systems. See Firebase privacy and security information.

The legal basis is your consent under Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG.

Optional product analytics

Google Analytics for Firebase is disabled at build time and remains disabled until you enable Product analytics. If enabled, the app sends a fixed catalog of coarse events, such as whether a run started on a simulated or on-air target, an import succeeded, a paywall appeared, or a commerce action reached checkout or a normalized outcome. Commerce events may include a canonical source, action, and product token such as monthly, yearly, or 1.x; they never include an offer token, purchase token, order identifier, license key, price, currency, tax amount, or transaction payload. Event parameters use closed vocabularies and coarse count or duration buckets.

Warsha does not include script source or titles, GATT layouts, service or characteristic UUIDs, Bluetooth or device names, URLs, IP addresses, pairing PINs, filenames, license keys, order identifiers, email addresses, free-text exception messages, or hashes of those values in product events. No User-ID or custom user property is set. Advertising-identifier collection is disabled. Google Analytics assigns an app-instance identifier and processes standard app, device, operating-system, language, and coarse country information.

Warsha configures aggregated analytics retention to two months and raw event-export retention to 90 days. Withdrawing consent stops future collection, resets local analytics state, and causes the SDK to create a different app-instance identifier if you opt in again. It does not retroactively erase aggregate reports already created. You may contact me to exercise a deletion right.

The legal basis is your consent under Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG.

Operational configuration

Firebase Remote Config is enabled to deliver operational configuration, safety switches, supported-version rules, and public links. It receives a Firebase installation identifier and ordinary technical information such as app version, platform, language, country, IP-derived request information, and request timestamps. It does not receive scripts, project content, analytics events, purchase details, or contact information.

Remote Config is used for app reliability and safety, and the app continues with packaged defaults if it is unavailable. The legal basis is the provision of requested app functionality under Article 6(1)(b) GDPR and my legitimate interest in secure and reliable operation under Article 6(1)(f) GDPR. Google states that Firebase installation identifiers are retained until deletion is requested through Firebase’s mechanisms. See Firebase privacy and security information.

Purchases and license activation

Google Play

Android subscriptions are purchased and managed through Google Play. For users in Germany and the rest of the EEA, Google is the merchant of record for that purchase and is the controller of the transaction data it collects. Google processes payment, account, order, tax, fraud-prevention, and related information under the Google Privacy Policy. The app stores a bounded canonical entitlement record locally; Warsha does not operate a separate Android receipt server in version 1.

RevenueCat

RevenueCat, Inc. processes Android subscription synchronization and entitlement status on Warsha’s behalf. It receives an automatically generated anonymous app-user identifier, device/operating-system technical information, last-seen time, Google purchase token, product and subscription status, and ordinary HTTPS information such as IP address. This is needed to provide, restore, reconcile, and support Pro access under Article 6(1)(b) GDPR and to prevent incorrect or fraudulent entitlement grants under Article 6(1)(f). The app does not send RevenueCat an email address, Warsha account, Firebase installation ID, analytics identity, authored project content, or custom attribution metadata; automatic device-identifier collection and optional analytics integrations are disabled. RevenueCat controls service-side retention under its Privacy Policy. Requests concerning data Warsha controls can be sent to the contact below; the anonymous RevenueCat identifier may be needed to locate a record.

Polar and direct macOS licenses

Polar Software, Inc. acts as merchant of record and authorized reseller for direct macOS purchases. Polar processes checkout, identity, contact, payment, tax, fraud-prevention, order, and license information under its Privacy Policy and Buyer Terms.

When you activate, validate, or deactivate a macOS license, the app sends Polar the license key, Warsha organization identifier, a generic “Warsha on Mac” activation label, the eligible major-version condition, and—after activation—the activation identifier. Polar also receives ordinary HTTPS request information such as IP address and technical headers. The activation identifier and license state are stored in the macOS Keychain. Polar controls provider-side retention under its published terms; Warsha retains purchase or support records only where needed to provide the license, handle disputes, or meet legal obligations.

Processing a purchase and providing, restoring, or deactivating the entitlement you bought is performance of that contract and steps taken at your request before it, under Article 6(1)(b) GDPR. Detecting fraud, abuse, and unlawful reuse of a license rests on my legitimate interest in protecting the product and paying customers under Article 6(1)(f) GDPR. Purchase and accounting records kept for the periods set by tax and commercial law rest on Article 6(1)(c) GDPR.

macOS update checks

The macOS app uses Sparkle to request a signed update feed hosted on warsha.dev through Cloudflare. The request includes the installed app version and ordinary HTTPS request information, such as IP address, user agent, and request timestamp. Sparkle’s optional anonymous system-profile submission is explicitly disabled. Cloudflare may process request logs for content delivery, abuse prevention, and security under its Privacy Policy.

The legal basis is the provision of secure app updates under Article 6(1)(b) GDPR and my legitimate interest in app security and reliability under Article 6(1)(f) GDPR.

Website and support

The Warsha website is delivered through Cloudflare. Warsha does not use advertising trackers, website analytics, or non-essential cookies on the BLE Studio documentation pages. Cloudflare processes ordinary web-request information for delivery and security as described in its Privacy Policy.

If you submit the contact form or email support, I process your name, email address, subject, message, attachments, and related correspondence to answer and resolve the request. The contact form uses Resend to deliver the message. Resend states that email and log data for standard plans is retained for 30 days; see Resend’s GDPR information.

Ordinary support correspondence is retained for 12 months after the request is closed, then deleted unless it is still needed to establish, exercise, or defend legal claims or meet a legal obligation. Do not send secrets, full license keys, or unredacted project data unless specifically requested through an appropriate channel.

The legal basis is taking steps at your request or performing the support relationship under Article 6(1)(b) GDPR and my legitimate interest in answering requests and protecting legal rights under Article 6(1)(f) GDPR.

Recipients and international transfers

Personal data is disclosed only to the providers identified above, recipients you select through app features, professional advisers where necessary, or public authorities where required by law. Those providers may process data outside Germany or the European Economic Area. Where required, processing is based on an adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism described in the provider’s terms.

To obtain a copy of the safeguards that apply to a specific transfer, or to find out where they are available, email yahia.hassan@warsha.dev naming the provider you are asking about.

Retention and deletion

Local data remains until you delete it, erase the app’s data, or uninstall the app, subject to backups and operating-system behavior. Provider-held data follows the periods and controls described above. Purchase and accounting records may be retained for the periods required by tax and commercial law.

The app has no Warsha account to delete. Removing local data does not delete records held by a purchase provider, a URL host, or another recipient you chose. To request deletion of data controlled by Warsha or exercise another privacy right, email yahia.hassan@warsha.dev.

Your rights

Where GDPR applies, you may have rights to access, correct, delete, restrict, or object to processing; receive portable data; and withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal. You also have the right to complain to a supervisory authority. The supervisory authority responsible for private-sector controllers in Bavaria is the Bavarian State Office for Data Protection Supervision (BayLDA).

I do not use personal data covered by this policy for automated decisions that produce legal or similarly significant effects.

Right to object

You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data that is based on Article 6(1)(f) GDPR. In this policy that legal basis covers the processing identified above as relying on legitimate interests, including operational configuration and the handling of support correspondence.

If you object, I will stop processing your data for that purpose unless I can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing serves to establish, exercise, or defend legal claims. An objection costs nothing and needs no particular form. Send it to yahia.hassan@warsha.dev or through https://warsha.dev/contact.

No processing described in this policy is carried out for direct marketing, so there is no marketing profiling to object to.

Children

Warsha BLE Studio is a developer tool and is not directed to children. In Germany a person must be at least 16 years old to consent to optional data processing on their own; below that age, consent must be given or authorized by a parent or guardian. Crash diagnostics and product analytics must not be enabled without that consent. Both remain off until someone enables them, so no telemetry is collected from a device where nobody has answered the prompt.

Changes

The current policy is published at https://warsha.dev/docs/ble-studio/privacy-policy. I will update the effective date when this policy changes and provide additional notice where required for a material change.