Privacy Policy

BERP — TestFlight beta
Effective date: 26/08/2026
Version: [1.0]
Last updated: 26/08/2026

1. Who we are

Birmingham City University ("BCU", "we", "us"), an exempt charity under the Charities Act 2011, with administrative offices at Curzon Building, 4 Cardigan Street, Birmingham, B4 7BD, owns and operates BERP (the "App") and is the data controller for the personal data described in this notice.

The App has been developed for BCU by V Formation Limited, who act as our data processor. They process personal data only on our documented instructions, under a written data processing agreement.

This notice sits alongside BCU's general privacy information and gives the detail specific to the App. Where the two differ in relation to the App, this notice applies.

2. Scope

The App is a private journalling and reflection tool distributed only through Apple TestFlight to a limited group of invited testers. It is not publicly available.

It is provided for personal, informational and educational use. It is not a clinical system, not a medical device, and must not be used for medical purposes or as a substitute for advice from a qualified professional. It should not be relied on for formal record keeping, assessment, supervision or compliance purposes, and your employer's or placement provider's own record-keeping and confidentiality rules continue to apply to anything you write.

Features and data handling may change during the beta. We will tell testers when they do.

Age: the App is intended for users aged [18 / 16] and over.

3. What personal data we collect

Account data

You can create an account in one of two ways:

  • Sign in with Apple — Apple provides a unique identifier and an email address. If you choose to hide your email, Apple supplies a private relay address (@privaterelay.appleid.com) instead of your real one. We never receive your Apple ID password.
  • Email address and password — your password is stored only as a cryptographic hash by our authentication provider. We cannot see it or recover it.

The authentication system also records your user ID, account creation date and sign-in timestamps.

Profile data

You provide, and we store:

  • Name
  • Occupation
  • Job role
  • Age band

Journal entries

Your journal entries are encrypted on your device before they leave it, using AES-256-GCM. The encryption key is generated on your device and held in the iOS Keychain. Only the encrypted text is transmitted and stored.

This means that neither BCU, nor V Formation, nor our hosting providers can read your entries. Nor could anyone who obtained unauthorised access to the database.

We do hold unencrypted technical information about each entry — the date it was created and last edited, and the account it belongs to — so that the App can list and synchronise entries.

Please note: because we do not hold your key, we cannot recover your entries if you lose access to it. If you lose your device and your recovery phrase, your entries cannot be restored by us or by anyone else.

Voice notes

You can record a voice note as a journal entry, either instead of or alongside typed text.

  • BERP accesses your device's microphone only while you are actively recording. It does not listen in the background, and iOS shows an indicator whenever the microphone is in use. You will be asked for permission the first time, and you can withdraw it at any time in iOS Settings.
  • Voice notes are encrypted on your device before they are uploaded, using the same key and method as your written entries. We store only the encrypted audio file. Neither BCU, nor V Formation, nor our hosting providers can listen to your recordings.
  • To play a recording back, BERP decrypts it temporarily on your device and removes the decrypted copy immediately afterwards.

We store unencrypted metadata about each recording — its length, format, file size and the date it was made — so that BERP can list and play your entries.

A recording of your voice is personal data in its own right, and reveals more than the words spoken. It may also capture other people who happen to be nearby. Please record somewhere you will not be overheard, and take care not to capture the voices or identifying details of others. If a recording were processed for the purpose of identifying you from your voice it would be biometric data — we do not do this, and we do not use voice for authentication, identification, or any form of analysis.

The same warning applies to voice notes as to written entries: because we do not hold your key, a recording cannot be recovered by us if you lose access to your device and your recovery phrase.

Dictation

You can dictate a written entry using the microphone key on the standard iOS keyboard. This is a feature of your device provided by Apple, not by BERP. When you use it, your speech is handled by Apple under Apple's privacy policy and its terms for Siri and Dictation — BCU does not receive the audio and has no control over how Apple processes it. The text that appears in the entry is then encrypted and stored exactly like anything you type. You can turn dictation off in iOS Settings under General → Keyboard.

Technical and log data

Our hosting provider automatically records IP addresses, timestamps and technical details of requests made by the App, for security and fault diagnosis. These are retained for 7 days and then deleted.

Apple separately collects data about TestFlight installations, crashes and beta feedback under its own privacy policy.

Feedback

If you send us feedback about the App, we hold your message and contact details in order to respond and to improve the App. Feedback is separate from your journal entries — we do not access, read or use your entries as feedback, and the intellectual property licence you grant over feedback in the End User Licence Agreement does not extend to the content of your journal.

What we do not do

We do not use your data for advertising, do not sell it, do not use it for automated decision-making or profiling, and do not use advertising identifiers or location tracking.

4. Why we process it, and our lawful basis

As a university, BCU processes most personal data in the performance of a task carried out in the public interest — our teaching, research and related functions.

  • Creating and securing your account. Account data. Lawful basis: Art 6(1)(e) public task.
  • Storing and synchronising your entries. Encrypted entries, entry metadata. Lawful basis: Art 6(1)(e) public task.
  • Understanding who is testing the App so we can evaluate and improve it across different roles. Profile data. Lawful basis: Art 6(1)(e) public task.
  • Protecting the service and diagnosing faults. Technical and log data. Lawful basis: Art 6(1)(e) public task.
  • Corresponding with you about the beta and responding to feedback. Account data, feedback. Lawful basis: Art 6(1)(e) public task.
  • Evaluating how well BERP worked, to inform further development and research (see section 6). Usage data, profile data — never entry content. Lawful basis: Art 6(1)(e) public task.

[IF THIS IS A RESEARCH STUDY: add the ethics approval reference and confirm whether Art 89 research safeguards apply.]

5. Sensitive information in your entries

Journal entries are free text. Yours may include information about your health, beliefs or personal circumstances — special category data, which receives extra protection in law.

Because entries are encrypted on your device, we do not process their content. Our condition for storing them in encrypted form is your explicit consent under Article 9(2)(a) UK GDPR, given when you create your account. You may withdraw consent at any time by deleting your entries or your account; withdrawal does not affect processing carried out beforehand.

Please do not record information that identifies other people — patients, service users, students or colleagues by name or by details that would make them recognisable. You are responsible for ensuring that what you write complies with your professional obligations and your employer's confidentiality requirements.

6. Evaluating the pilot

After the pilot ends, BCU will evaluate how well BERP worked, in order to decide whether to develop it further and to share what we learn with others. This evaluation may inform internal reports, conference presentations or published research.

We will not analyse the content of your journal. Your written entries and voice notes are encrypted on your device and are unreadable to us. Nothing you write or record will be read, listened to, quoted, coded or analysed by BCU, V Formation, or anyone else.

What we will analyse is usage data — how the App was used, not what was said in it:

  • how many entries were created, and how often
  • whether people chose written entries, voice notes, or both
  • how long testers continued using the App
  • which features were used and which were not
  • how these patterns varied by occupation, job role and age band
  • technical performance, including errors and crashes

Analysis is carried out on an aggregated and anonymised basis. Before analysis, we remove names, email addresses and account identifiers, and we report findings only at the level of groups, never individuals. Where a group is too small for its members to remain unidentifiable, we combine it with another or leave it out.

Once data has been anonymised in this way it is no longer personal data, and we may keep and use it indefinitely — including after your account and entries have been deleted. Anonymised evaluation data cannot be traced back to you, which also means it cannot be withdrawn or deleted at your request once it has been aggregated.

You can object to your usage data being used for evaluation before that point by contacting us at informationmanagement@bcu.ac.uk and we will exclude your records.

7. Who your data is shared with

We do not sell your data or share it for anyone else's purposes. The following organisations process it on our behalf:

  • V Formation Limited — Developer and technical operator, acting as processor. All data listed below, to the extent needed to build and maintain the App.
  • Supabase Inc. — Database, authentication and hosting (sub-processor). Account data, profile data, encrypted entries, logs.
  • Amazon Web Services — Underlying infrastructure (sub-processor). As above.
  • Apple Inc. — TestFlight distribution; Sign in with Apple. Account identifier, email or relay address, crash and feedback data.

We may also disclose personal data where we are required to by law, or to establish, exercise or defend legal claims.

8. Where your data is stored

The database is hosted in the [EU (Ireland) / London] region. Supabase Inc. is incorporated in the United States and its personnel may access the infrastructure from outside the UK. Any such transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards — including the fact that journal content is encrypted and unreadable in transit and at rest.

9. How long we keep it

  • Journal entries and profile data — while your account is active
  • Voice notes — while your account is active
  • Account data — deleted when you delete your account
  • Technical logs — 7 days
  • Feedback correspondence — 21 days

You can delete individual entries at any time within the App. Deleting your account removes your entries, profile and account record within 30 days, allowing for removal from routine backups.

At the end of the beta, all tester accounts and associated data will be deleted unless we have told you otherwise and you have separately agreed to your data being carried forward. We will give at least [14] days' notice and an opportunity to export your entries first.

Anonymised evaluation data, as described in section 6, is retained after this point. It contains no journal content and no information that identifies you.

10. Your rights

You have the right to ask us to:

  • give you access to a copy of your personal data
  • correct data that is inaccurate
  • erase your data
  • restrict how we use it
  • stop processing it, where we rely on public task, by objecting on grounds relating to your situation
  • provide your data in a portable format
  • honour your withdrawal of consent in relation to journal entries

Some of these you can exercise directly in the App. For anything else, contact informationmanagement@bcu.ac.uk. We will respond within one month.

We can only supply journal entries in encrypted form, as we cannot decrypt them. Exporting from within the App produces readable text.

If you are dissatisfied with how we have handled your data, you may complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would ask that you raise it with our Data Protection Officer first.

11. Security

  • Journal entries are encrypted on your device before transmission; keys are held in the iOS Keychain and never sent to us
  • All traffic between the App and our servers uses TLS
  • Data is encrypted at rest by our hosting provider
  • Row-level security policies restrict each account to its own records
  • Administrative access is limited to one named individual and protected by multi-factor authentication

No transmission over the internet is completely secure, and we cannot guarantee the security of data in transit. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO and, where required, you.

12. Changes to this notice

We may update this notice as the App develops. Material changes will be notified to testers by email or within the App before they take effect. The version number and date above show the current revision.

13. Contact

Birmingham City University
Curzon Building, 4 Cardigan Street, Birmingham, B4 7BD
innovate@bcu.ac.uk

Data Protection Officer: informationmanagement@bcu.ac.uk