Privacy policy
2026-07-25
RTK Pulse is a diagnostic tool for correction streams. It handles two genuinely sensitive things — NTRIP credentials and your position — so this page states plainly what happens to each.
Who is responsible
The controller is Zorbano s.r.o., ID 09257730, registered at Martinská čtvrť 1702, 744 01 Frenštát pod Radhoštěm, Czech Republic, registered with the Regional Court in Ostrava. RTK Pulse is part of the Corfuse product family.
Contact for anything in this document, including data-subject requests: info@corfuse.com.
What this covers
The RTK Pulse mobile app for iOS and Android, this website (rtkpulse.app), and the account backend at api.rtkpulse.app.
What never leaves your device
- NTRIP usernames and passwords. They are held in the platform secure storage (iOS Keychain / Android Keystore) and are sent only to the caster you chose to test, over that connection.
- The raw diagnostic run — the correction stream itself is decoded on the device.
- If you use the app without an account, everything: profiles, history, results.
Location
The app asks for location to sort nearby mountpoints by distance. That use alone stays on the device.
There is a second use you should know about before you accept: connecting to a network-RTK mountpoint (VRS, MAC, FKP — flagged nmea=1 in the caster’s sourcetable) requires the client to send its position to the caster as an NMEA GGA sentence. The caster operator — a third party you choose — therefore receives your approximate position, and the virtual reference station it returns is computed at that position.
We disclose this before the first test rather than mid-flow, and you can choose to send a coarsened position. Your position is never uploaded to our own servers.
If you create an account
An account is optional. Sign-in runs through Zitadel, an OIDC provider we self-host in the EU, with Apple, Google or email and password. Apple and Google receive only what their sign-in flow needs; we receive an identifier and, if you allow it, your email address.
- Stored on our servers: your account identifier, profile metadata (caster host, port, mountpoint, label), and session results.
- Never stored on our servers: NTRIP passwords and precise position.
- Free accounts get an encrypted backup and restore for one active device; Pro adds live sync across devices.
Purchases
Subscriptions are sold by Apple or Google. We never see your card details. Entitlements are handled by RevenueCat, Inc. acting as our processor: it receives an app-generated user identifier and the store receipt so that Pro can be validated server-side. Nothing else about your diagnostics is sent there.
Support reports
When you send a report from the app, the engine builds the text with credentials and position removed. That redaction is a tested property of the decoding core, not a filter in the interface, and it applies to the full log, shared reports and support mail alike.
Analytics and tracking
As of this version the app ships with no advertising SDKs and no third-party analytics. This website is static: no cookies, no trackers, no fonts or scripts loaded from third parties. Our servers keep short-lived access logs (IP address, user agent, requested path) for security and abuse handling.
How long we keep things
Account data lives until you delete the account, after which backups age out within 30 days. Uninstalling the app removes everything held locally. Access logs are rotated within 30 days.
Your rights
Under the GDPR you may request access to your data, correction, erasure, portability, restriction of processing, and you may object to processing. Write to info@corfuse.com; we answer within one month. You can also lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz).
Transfers and children
Our servers are in the EU. RevenueCat and the app stores may process data outside the EU under standard contractual clauses. The app is a professional tool and is not directed at children.
Changes
Material changes are reflected here with a new date at the top, and in the app store data-safety labels. The current version is dated above.