Privacy policy
2026-08-01
RTK Pulse is a diagnostic tool for correction streams. It handles two genuinely sensitive things — NTRIP credentials and your position — so this page states plainly what happens to each.
Who is responsible
The controller is Zorbano s.r.o., ID 09257730, registered at Martinská čtvrť 1702, 744 01 Frenštát pod Radhoštěm, Czech Republic, registered with the Regional Court in Ostrava. RTK Pulse is part of the Corfuse product family.
Contact for anything in this document, including data-subject requests: info@corfuse.com.
What this covers
The RTK Pulse mobile app for iOS and Android, this website (rtkpulse.app), and the account backend at api.rtkpulse.app.
What never leaves your device
- NTRIP usernames and passwords. They are held in the platform secure storage (iOS Keychain / Android Keystore) and are sent only to the caster you chose to test, over that connection.
- The raw diagnostic run — the correction stream itself is decoded on the device.
- If you use the app without an account, everything: profiles, history, results.
Location
The app asks for location to sort nearby mountpoints by distance. That use alone stays on the device.
There is a second use you should know about before you accept: connecting to a network-RTK mountpoint (VRS, MAC, FKP — flagged nmea=1 in the caster’s sourcetable) requires the client to send its position to the caster as an NMEA GGA sentence. The caster operator — a third party you choose — therefore receives your approximate position, and the virtual reference station it returns is computed at that position.
We disclose this before the first test rather than mid-flow. By default the app rounds the position to about a kilometre before it goes upstream — enough for the network to build a virtual reference station, not enough to place you — and you can switch that off on the Test position screen if you would rather send the exact figure. Your position is never uploaded to our own servers.
You can also set the position yourself instead of using the phone’s — type coordinates, drop a pin on a map, or take a mountpoint’s published position. That is useful when there is no fix indoors, or when you are checking a caster in a region you are not in. A position you set is stored only on the phone, and it is treated exactly like a measured one: it still goes to the caster in the GGA sentence, and it is still left out of a shared report unless you switch it on.
If you create an account
An account is optional. Sign-in uses Apple, Google, or email and password, and happens entirely in the app — no browser. Your identity is kept in our own account service at api.rtkpulse.app, hosted in the EU; we do not hand it to a third-party single sign-on. Apple and Google receive only what their sign-in flow needs; we receive an identifier and, if you allow it, your email address.
- Stored on our servers: your account identifier, profile metadata (caster host, port, mountpoint, label), and session results.
- Never stored on our servers: NTRIP passwords and precise position.
- An account gives you an encrypted backup and restore of your profiles and session history; live sync across devices is planned for Pro.
Purchases
Subscriptions are sold by Apple or Google. We never see your card details. Entitlements are handled by RevenueCat, Inc. acting as our processor: it receives an app-generated user identifier and the store receipt so that Pro can be validated server-side. Nothing else about your diagnostics is sent there.
Support reports
A report identifies the stream you tested: it includes your NTRIP username, so the provider can find the account, but never your password. Your own position is left out unless you turn it on when you send it — off by default. If the test ran from a position you set rather than a measured fix, the report says so instead of presenting it as where the phone was.
For a single physical base, the base station’s published coordinates are shown; those are public — the caster broadcasts them to every client. For a network-RTK (VRS) mountpoint the virtual base sits at your location, so its position is treated as yours and withheld unless you opt in. The report is built on your device and is never uploaded to our servers.
Analytics and tracking
As of this version the app ships with no advertising SDKs and no third-party analytics. This website is static: no cookies, no trackers, and fonts bundled with the page rather than fetched from anyone. The single script it loads from another host is the contact form described below, from our own service. Our servers keep short-lived access logs (IP address, user agent, requested path) for security and abuse handling.
The form on this site
The “I am interested in RTK Pulse” form asks for your name, your email address and an optional message, and nothing else. It is rendered and stored by SellBoost at sellboost.corfuse.com — our own product, on our own infrastructure, under the same controller as the rest of this site. It is not a third-party form service, and it sets no cookies on this page.
We use what you send to reply and to invite you to the beta. We do not add you to a mailing list and we pass it to nobody. Write to info@corfuse.com and we delete the entry.
How long we keep things
Account data lives until you delete the account, after which backups age out within 30 days. Uninstalling the app removes everything held locally. Access logs are rotated within 30 days. Entries from the form on this site are kept while the beta programme runs, and we delete them sooner on request.
Your rights
Under the GDPR you may request access to your data, correction, erasure, portability, restriction of processing, and you may object to processing. Write to info@corfuse.com; we answer within one month. You can also lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz).
Transfers and children
Our servers are in the EU. RevenueCat and the app stores may process data outside the EU under standard contractual clauses. The app is a professional tool and is not directed at children.
Changes
Material changes are reflected here with a new date at the top, and in the app store data-safety labels. The current version is dated above.