1. Overview

BuzuRadar is a public transparency tool that allows Rio de Janeiro residents to monitor the city bus fleet in real time. We are committed to providing this service with the utmost respect for user privacy.

This policy covers the buzuradar.com.br website and the BuzuRadar app for iPhone and Apple Watch. It describes the categories of data we process, when we use cookies or identifiers for advertising or analytics, and how we comply with Brazil's General Data Protection Law (LGPD, Federal Law No. 13,709/2018).

We minimize data and do not maintain user accounts.

BuzuRadar does not maintain user accounts. Your name, email address, subject, and message are requested only when you choose to use the contact form. Technical data such as IP addresses and headers may also be processed for operation, security, rate limiting, logs, and the third-party services described below.

2. Data collection

What the website does not request

On the website, outside the contact form, BuzuRadar does not request the following user data. The app has its own rules, described in section 3.

  • Phone numbers or identity documents
  • Your geographic location (the website does not use browser geolocation)
  • Individual browsing history, user profiles, or personal behavior
  • Login or authentication data (there are no user accounts)
  • Payment or financial data (in the app, purchases are processed by Apple)

Temporary technical data

Like any web server, our system temporarily processes technical information needed to respond to HTTP requests, such as IP addresses and browser headers. This data is used exclusively to:

  • Deliver requested content to the correct browser
  • Apply request rate limits to protect the service
  • Keep minimal technical logs for security, availability, and diagnostic purposes
  • Generate aggregate usage and performance metrics when Cloudflare Web Analytics is enabled

Technical logs maintained by BuzuRadar are not associated with user profiles. They may include an IP address, HTTP method, requested path, response status, and request duration. Retention must be limited to what is necessary for security, operational investigations, and compliance with legal obligations. Cloudflare Web Analytics metrics are aggregated and described in the next section.

Contact form data

When you send a message through the contact page, we process your name, email address, selected subject, and message to receive, review, and respond to your request. Submission is voluntary, and this data is delivered through Web3Forms, which provides the form service under its own privacy policy.

Bus fleet data

BuzuRadar displays public bus fleet data provided by the SMTR, the Rio de Janeiro Municipal Department of Transportation. This public-domain data does not contain personal information about passengers or drivers.

Summary by category

  • Contact form: name, email address, subject, and message submitted voluntarily; used to receive and respond to requests; delivery processed by Web3Forms.
  • Public fleet data: displayed for public transparency; sourced from SMTR; does not identify website users.
  • Technical logs: IP address, path, method, status, and duration; used for security, rate limiting, and diagnostics under the legal bases of legitimate interest and service delivery.
  • Aggregate analytics: loaded only after consent when enabled on the website; used for usage and performance metrics.
  • Advertising, cookies, and identifiers: used only under applicable consent and permissions; processed by Google and, when active, Media.net and Meta under their own policies.
  • iOS app technical events: when sent by the app, they may include version, build, approximate operating system, device class, component, technical reason, and limited diagnostic metadata.
  • App Attest: the backend may retain a key identifier, public key, monotonic counter, and technical dates to validate app integrity and prevent abuse.

3. iOS and watchOS app

The BuzuRadar app for iPhone and Apple Watch does not require an account or login. In addition to what applies to the website, the app processes the data below. The in-app controls are under Settings › Privacy and local data inside BuzuRadar.

Location

The app uses your location only if you grant permission in iOS. With While Using, it shows your position on the map, nearby routes, stops and buses, and suggests a route origin. Always is requested only when you start tracking a trip, to keep tracking and the Live Activity up to date while the app is off screen; if you keep While Using, tracking only works with the app open. Tracking ends when you finish, cancel or re-plan the trip.

  • To find nearby buses, the app asks the BuzuRadar backend for vehicles in a small area (a coordinate rectangle) around your position or the map region.
  • For walking legs of a route, the app sends the leg’s start and end coordinates (which may be your position, origin or destination) to the BuzuRadar backend. If the backend does not respond, Apple MapKit is used. Address searches also use Apple services.
  • These requests are not linked to an account, name or identifier of yours, and are not used for tracking or advertising.
  • Positions collected continuously during a trip, on iPhone or Apple Watch, are processed on the device and are not sent to the backend.

Legal basis: consent, given through the system permission. You can change or revoke it in iOS Settings › Privacy & Security › Location Services › BuzuRadar. Without location, the app keeps working with manual search.

App usage data (PostHog)

With “Share usage data” turned on, the app sends usage events to PostHog so we can understand which screens and flows work (for example: onboarding steps, route planning, opening a stop, trip start and end, app opens, and interactions with ads and Premium).

This option is pre-selected during onboarding.

On the privacy step of first use, “Share usage data” appears selected. If you continue without changing it, sharing is turned on. You can choose “Do not share now” on that same step, or turn it off at any time in Settings › Privacy and local data › Share usage data in the app. Nothing is sent to PostHog before that choice, and new events stop being sent as soon as you turn it off.

  • What is sent: the event name and properties from a closed list, bucketed when possible (for example, route duration ranges and transport modes), app and OS version, device model, and a random installation identifier created by the PostHog SDK. As with any network connection, PostHog receives the request’s IP address.
  • What is not sent: search text, addresses, free-text origin and destination, precise coordinates, names of your places, stop names, and vehicle identifiers. Session replay, screen and tap capture, surveys, and feature flags are turned off.
  • No personal profile: the app does not associate these events with a name, email or account, and does not use them for advertising or cross-app tracking.
  • Legal basis and retention: consent, revocable at any time; events follow PostHog’s retention policy.

Separately, diagnostic data (crashes, performance and other technical diagnostics) is sanitized to reduce the risk of personal data, kept in a local queue for up to 7 days, and sent to the BuzuRadar backend to keep the app stable. It may be associated with an installation identifier, is not used for tracking, and does not go to PostHog. Legal basis: legitimate interest in the security and stability of the service.

Purchases and Premium subscription

Premium purchases and subscriptions are made through the App Store and processed by Apple (StoreKit). BuzuRadar does not receive your name, email, or card details; the app only checks with Apple whether the purchase is active to unlock features. To manage or cancel, use iOS Settings › [your name] › Subscriptions.

Widgets, Live Activity and Apple Watch

Widgets and the Live Activity show data the app already has on the device, through a space shared between the app and its extensions; they do not collect new data. The Apple Watch app works on its own and, when the iPhone is nearby, syncs favorites, preferences and trip state over Apple’s device-to-device connection. On the watch, location is used only during a trip you started or resumed.

iCloud sync

If an iCloud account is available on the device, the app syncs across your devices favorite routes, saved destinations and favorite trips (which may include a custom name, address and coordinates), alert definitions, preferences, and onboarding progress. This data lives in BuzuRadar’s private storage in your iCloud account, managed by Apple, and is not sent to BuzuRadar servers. Search terms and ad consent choices are not synced. You can turn off iCloud for the app in iOS Settings.

Ads in the app (AdMob, UMP and ATT)

Free-plan users may see Google AdMob ads, which may mediate demand from Media.net and Meta Audience Network. When applicable, the app first shows Google’s consent form (UMP) and then Apple’s tracking request (ATT). Declining does not block the app. Details are in section 6. Premium subscribers do not see ads.

4. Retention and deletion

We retain technical data for the shortest period compatible with service operation, security, failure investigation, and legal obligations. The windows below may be reduced through operational configuration but must not be extended without a new necessity review.

  • Contact messages: retained only as long as needed to respond, follow up on the request, and meet applicable legal obligations; Web3Forms applies its own retention policy.
  • Technical observability events: standard operational retention of up to 90 days.
  • App Attest: inactive keys may be removed after 365 days without use; compromised keys may be revoked or removed sooner.
  • Server technical logs: retained only for the period needed for security, diagnostics, and service continuity.
  • Public fleet data: preserved while needed for transparency, civic auditing, and the operation of the public history.

Where applicable, deletion requests are assessed in light of the technical nature of the data, its security purpose, and whether the record can be reliably identified without collecting unnecessary additional data.

5. Usage analytics

BuzuRadar may use Cloudflare Web Analytics to measure page views, traffic sources, and real-world browser performance in aggregate, and PostHog on the server to measure completed actions and diagnose exceptions. PostHog usage inside the app is described in section 3.

How it works

When enabled and after you consent, the website loads a small JavaScript beacon hosted at static.cloudflareinsights.com with the public token for the Web Analytics property. Because BuzuRadar's domain is proxied through Cloudflare, we use a manual installation in the website code and keep Cloudflare's automatic setup disabled to avoid counting page views twice.

On the website, PostHog runs only on the server and does not install browser scripts, cookies, or local storage. Product events are sent without person profiles, search terms, license plates, or vehicle identifiers; the IP address is removed before sending.

Data processed

These metrics help us understand product health and performance, including visited pages, referrers, browser type, operating system, approximate country or region, and Web Vitals. They also cover completed route searches, line page views, licensing lookups, audit analyses, and generated reports. BuzuRadar does not use these metrics to create individual profiles, sell data, or identify users.

Cloudflare Web Analytics does not rely on BuzuRadar's own cookies. Cloudflare may process technical data needed to provide the service under its own privacy policy.

Your controls

You can block the Cloudflare beacon through your browser settings or privacy extensions. You can also reject or revoke consent on this page. The map and public pages remain available even if the beacon is blocked.

6. Advertising and cookies

To keep BuzuRadar free and operational, we may display non-intrusive ads provided by advertising networks. On the website, ads appear in no more than two units per page, only on allowlisted product and published-analysis pages, and never block the main content; legal, institutional, operational, archive, and error pages carry no ads. When advertising is enabled, its script is loaded only after consent to non-essential features.

iOS app, IDFA, and ATT

In the iOS app, Google AdMob measures and serves ads and may mediate demand from Media.net and Meta Audience Network. Before allowing tracking across apps and websites, BuzuRadar presents the applicable privacy choices and requests Apple's AppTrackingTransparency (ATT) permission. Permission is optional: if you decline, the app remains available and may show only permitted contextual ads, without using the IDFA for tracking or personalization.

When authorized, partners may use the IDFA and technical device signals to personalize, limit frequency, prevent fraud, and measure ads and impression revenue. BuzuRadar does not include search text, a viewed transit line, precise location, its own device identifier, or an ad response identifier in these measurement events.

Advertising cookies

Advertising networks may use cookies and similar technologies to measure or display ads. These cookies are managed by the advertising networks, not BuzuRadar. They may include:

  • Session cookies: expire when you close your browser
  • Persistent cookies: remain for a defined period to personalize ads
  • Tracking pixels: used to measure ad effectiveness

How to manage cookies

You can control and disable cookies in your browser settings:

You can also opt out of personalized advertising through the Digital Advertising Alliance or the Network Advertising Initiative.

Consent in this browser

You can accept or reject non-essential features. Your choice is stored only in this browser and can be changed at any time.

7. Advertising partners

The website may use Google AdSense, while the iOS app uses Google AdMob. AdMob may mediate Media.net and Meta Audience Network when those partnerships are active.

How Google AdSense works

Google AdSense may use cookies and similar technologies to measure ads, limit frequency, and personalize displayed ads according to Google and user settings. On BuzuRadar, AdSense loads only with consent when advertising is enabled.

Data processed by partners

BuzuRadar does not send account, login, or user-submitted data to Google AdSense. Google Media.net, and Meta may independently process data through their own technologies under their privacy policies:

Disable personalized Google ads

You can disable Google's use of cookies for personalized advertising in Google Ads Settings. On iOS, you can also decline or revoke tracking in Settings > Privacy & Security > Tracking without losing access to the app.

Advertising data security.

BuzuRadar uses only the public Google AdSense Publisher ID in the website code. No secret key or API credential is exposed in client-side code.

8. LGPD compliance

BuzuRadar is committed to complying with Brazil's General Data Protection Law (LGPD, Federal Law No. 13,709/2018), which governs the processing of personal data in Brazil.

Legal basis for data processing

Because BuzuRadar does not maintain user accounts, we limit processing to what is necessary to operate the service and respond to voluntarily submitted messages. Contact details, IP addresses, technical logs, and third-party cookies or identifiers may be personal data under the LGPD, so we follow these practices:

Purpose

Temporary technical data is used exclusively to operate the service.

Necessity

We collect only the minimum needed for the service to function.

Transparency

This policy clearly and accessibly describes our data practices.

Security

We use technical measures to protect data processed by the service.

Cookies and consent

Cloudflare Web Analytics does not rely on BuzuRadar's own cookies. Cookies used by Google AdSense and other third-party identifiers may, however, constitute personal data processing under the LGPD. BuzuRadar does not treat continued browsing as consent to load these non-essential features.

You can withdraw consent at any time using the controls on this page, disabling cookies in your browser settings, or using the opt-out tools mentioned in the previous section.

9. Your rights

Under the LGPD, you have the following rights regarding your personal data:

  • Confirmation and access: learn whether we process your data and access it
  • Correction: request correction of incomplete or inaccurate data
  • Deletion: request deletion of unnecessary or unlawfully processed data
  • Portability: receive your data in a structured format
  • Withdrawal of consent: withdraw consent at any time
  • Objection: object to data processing in certain circumstances

Because BuzuRadar does not maintain user accounts, requests related to contact form messages should include the email address used for submission so the record can be located. For rights related to Google AdSense cookies, see the Google Privacy Policy. For technical data processed by Cloudflare, see the Cloudflare Privacy Policy.

10. Contact

If you have questions about this Privacy Policy or BuzuRadar's data processing, email [email protected].

For privacy and data protection matters, you may also contact Brazil's National Data Protection Authority (ANPD) through its website at www.gov.br/anpd.

Updates to this policy.

This policy may be updated periodically. We recommend reviewing it regularly. The date of the latest update appears at the top of this page.