Skip to main content
Be Native Be Native

Privacy Policy

Last updated: October 2025

Be Native is committed to protecting your privacy while delivering an outstanding learning experience for Apple developers. This Privacy Policy explains how we handle your personal information when you use our apps for iPhone, iPad and Mac, our websites, and related services (collectively, the “Services”). If you have any questions, please contact us at info@benative.dev.

Privacy in Short

Be Native declares every type of data it collects in two places you can read before you install anything: the privacy label on the App Store product page, and the privacy manifest that ships inside every build of the app. Two of those data types are linked to your identity, and they appear only if you choose to create an account: the identifier of that account and your email address. Without an account, neither of them is collected. The other two — a device identifier and product interaction data — are used for usage statistics and are declared as not linked to your identity.

There is no tracking in Be Native. The privacy manifest declares NSPrivacyTracking as false, and every declared data type is marked as not collected for tracking. There is no advertising, no advertising identifier, and no data is sold or shared with any company for advertising or profiling. This is also why the app never shows the App Tracking Transparency request: that system prompt exists to ask for your permission to track you, and Be Native has nothing to ask for. The app contains no tracking code, so there is no permission to request.

Three other things are worth saying at the top. There is no password: signing in uses passkeys or Sign in with Apple, the private key never leaves your device, and we hold no authentication secret that could be stolen or reused. The features built on Apple Intelligence — semantic search and the explanation of source code — run entirely on your device: your question, the code on screen and the generated explanation never leave it. And subscriptions are processed by the App Store, so we never see or store your payment details.

The rest of this policy is the detail behind those statements: what we hold, why we hold it, on what legal basis, who processes it on our behalf, how long we keep it, and how you can ask us to delete it.

Who We Are and How to Reach Us

The controller of the personal data described in this policy is BN CODING SL (“Be Native”, “we”, “us”, “our”), a company incorporated in Spain, with registered office at Anabel Segura 10, Planta 3, 28108 Alcobendas (Madrid), Spain, tax identification number ESB19487933, contactable at info@benative.dev. Be Native is the product; BN CODING SL is the company behind it.

For any question about how we process personal data, or to exercise your rights, write to info@benative.dev.

We blend deep platform expertise with a principled approach to privacy: every feature begins with a data-minimisation review, and we continually evaluate new Apple frameworks to keep our implementation aligned with their latest protections. We design our Services with privacy and security as first-class features and limit the data we collect to what is strictly necessary to deliver and improve the experience.

This policy is written against the EU General Data Protection Regulation (GDPR). If you are in the United Kingdom, the same protections apply to you under the UK GDPR and the Data Protection Act 2018, which the United Kingdom retained on leaving the European Union, with the same article numbering used throughout this policy. The supervisory authority for the United Kingdom is the Information Commissioner’s Office (ICO), not the Spanish Agencia Española de Protección de Datos referred to below.

Device and Session Identifiers

The first time you open the app, your device generates a cryptographic key through Apple’s App Attest service. We store the identifier of that key (the “key ID”) together with the attestation record. The key ID is not your name and does not by itself reveal who you are, but it persists for as long as the app stays installed and it lets us tell one installation from another. We therefore treat it as personal data in pseudonymised form, and everything this policy says about your rights applies to it. On Mac, the app uses the equivalent device-trust mechanism available on that platform, which produces its own installation key identifier and is handled in the same way, and for the same purposes, described here.

We use the key ID for three purposes only: to verify that requests to our servers come from a genuine, unmodified copy of the app; to issue per-session DRM licences for video playback; and to enforce the limit of one simultaneous video playback per installation. The attestation payload is encoded with CBOR (RFC 8949) and transmitted over TLS; CBOR is an encoding format, not an encryption method, and we mention it only to describe the format. Session tokens are short-lived, expire automatically, and are associated with the key ID for the duration of the session.

Legal basis: our legitimate interest in protecting our content and our systems against fraud and unauthorised access (Article 6(1)(f) GDPR). You can object at any time under Article 21 GDPR, bearing in mind that video playback cannot be provided without attestation.

Using Be Native Without an Account

You can use the app without creating a Be Native account. Signed out you can read the articles, watch the videos, listen to the podcasts and the newsletters, explore sample lessons, use on-device semantic search, and keep up to ten notes on your device. What an account adds is unlimited notes, synchronisation across iPhone, iPad and Mac, and your subscription.

While you stay signed out we hold neither your email address nor an account identifier, so neither of the two data types linked to your identity is collected. The installation key identifier described above still exists, because it is what lets our servers tell a genuine copy of the app from an unauthorised one.

Creating an Account

If you choose to register, you may sign in with Sign in with Apple or create a passkey account. These methods rely on unique credentials managed by Apple and may use Apple’s private email relay: if you use Hide My Email, what we store is the forwarding address Apple gives us, not your own. The only attributes you can optionally provide are your display name and email address, and these are stored solely to give you control over your account. Your identity in our systems is always tied to the unique Sign in with Apple or passkey credential identifier. At any time you can revoke the credential in Apple settings, and our servers will automatically reject future logins until you decide to reconnect.

The account identifier and the email address are the two data types that the App Store privacy label declares as linked to your identity. They exist so that your account, your synchronised content and your subscription work across your devices. We do not use them for analytics, advertising or profiling.

Legal basis: performance of the contract you enter into with us when you create an account and use the Services (Article 6(1)(b) GDPR).

Content and Progress Synchronisation

Registered users can sync their progress across devices, including podcast playback, video lessons, article reads, course milestones, mini tracks, snippets, tips, and completion status. Digital notebooks, notes and favourites lists are also synced. This information is encrypted in transit and at rest on our servers, and is linked only to your Sign in with Apple or passkey credential.

Notes you delete are moved to a trash so that you can recover them, which means a deleted note stays on our servers until the trash is emptied or its retention period expires. You can delete your account at any time from the app to remove this synchronised data, and the deletion is propagated to our backups as those backups are overwritten.

Legal basis: performance of the contract (Article 6(1)(b) GDPR).

Subscriptions and Purchases

Subscriptions are sold and processed by the App Store. We have no payment gateway of our own, so we never receive or store your card details, your billing address or any other payment information. To confirm that you are entitled to the content you have paid for, our servers verify the purchase with Apple and store the transaction identifiers Apple returns, the identifier of the original transaction, the status of the subscription, and its renewal or expiry dates.

Legal basis: performance of the contract (Article 6(1)(b) GDPR) for verifying your entitlement, and compliance with a legal obligation (Article 6(1)(c) GDPR) for the accounting and tax records we are required to keep.

Media Delivery and DRM

Training videos inside Be Native are protected with Apple FairPlay Streaming DRM. Each playback request generates a one-time licence using the attestation data described above, and the resulting content key context (CKC) is issued per session so it cannot be reused outside that request. We operate the DRM pipeline through our media partner Axinom GmbH (Fürth Office, Kurgartenstrasse 37, 90762 Fürth, Germany). Axinom hosts the encrypted video segments, the accompanying captions and transcripts, and the image assets that power our catalogue, all within the European Economic Area.

Axinom acts as a processor on our behalf: it handles the DRM entitlement request and the IP address it is made from, it follows our instructions, and it may not use that data for its own purposes. We do not send Axinom your name, your email address or your account identifier.

Legal basis: performance of the contract, so that we can deliver the video you asked to play (Article 6(1)(b) GDPR), and our legitimate interest in protecting the content against unauthorised copying (Article 6(1)(f) GDPR).

Analytics and Diagnostics

We collect product interaction metrics — which features are opened, and how often — and performance diagnostics, so that we know what to improve and can keep the app stable. These records are associated with a device identifier, not with your name and not with your account: they are pseudonymous, not anonymous. We do not join them to your account, which is why the App Store privacy label declares both the device identifier and the product interaction data as not linked to your identity. We aggregate these records and then delete the per-installation ones; from that point on only aggregate figures remain, and those cannot be traced back to anyone. That aggregation happens weekly.

Legal basis: our legitimate interest in understanding how the app is used and in keeping it stable (Article 6(1)(f) GDPR). You can object at any time by writing to info@benative.dev.

On-Device Intelligence

Semantic search and the “explain this code” feature run entirely on your device, using Apple Intelligence and Apple’s Foundation Models framework on the Neural Engine. Your query, the code you are looking at and the generated explanation never leave your device and are never sent to our servers or to any third party. We do not receive them, we do not store them and we cannot see them. These features require a device compatible with Apple Intelligence; where it is unavailable, the feature is simply not offered.

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. Explanations generated on your device are produced automatically, may be incomplete or incorrect, and are offered for learning purposes only.

Notifications

Push notifications are optional. If you turn them on, your device gives us a notification token that we store for as long as notifications stay enabled, and we use it to send broad updates such as new content releases or community events. Notifications are never personalised based on analytics, advertising profiles or behavioural targeting. You can turn them off at any time in system settings, and you can ask us to delete the token by writing to info@benative.dev.

Legal basis: your consent, given when you accept the system permission (Article 6(1)(a) GDPR). You may withdraw it at any time, and withdrawing it affects nothing else about your account.

Our Website

benative.dev serves our public pages and this policy. We run no analytics on the website. The typefaces used across the site are served from benative.dev itself, so loading a page does not report your visit to any third party. One third-party resource is loaded, and it is covered in the sections on processors and on international transfers below: the contact page loads Cloudflare Turnstile, which checks that the form is being submitted by a person and processes your IP address and signals about your browser in order to do so.

If you write to us through the contact form, we receive the name, email address, subject and message you type, together with the language version of the site you used, and we use them only to answer you. Legal basis: our legitimate interest in replying to the request you sent us (Article 6(1)(f) GDPR), and, for Turnstile, our legitimate interest in protecting the form against automated abuse.

App Store Privacy Label

The privacy manifest that ships inside the app — the same one in the iPhone, iPad and Mac versions — declares four types of collected data. That is what the App Store product page shows, and this policy uses the same words:

  • User ID — linked to you. The identifier of your account. Collected only if you create one, and used for app functionality.
  • Email address — linked to you. Collected only if you create an account, and used for app functionality.
  • Device ID — not linked to you. Used for analytics.
  • Product interaction — not linked to you. Used for analytics.

The app also declares its use of the UserDefaults API with reason AC6B.1, the declaration Apple requires for reading and writing an app’s own settings: it means the app stores your preferences on your own device. No data type is declared as collected for tracking, and none is used for advertising.

Who Else Processes Your Data

We do not sell or rent personal data, and we do not share it for advertising or profiling. We do rely on a small number of providers that process data on our behalf and on our instructions, and that may not use it for their own purposes:

  • Axinom GmbH (Germany, European Economic Area) — hosting of the encrypted video, captions, transcripts and artwork, and delivery of DRM licences. Processes DRM entitlement requests and the IP address they are made from. To deliver the video itself, Axinom relies on a content delivery network operated by Microsoft (Azure) as its sub-processor: when you play a lesson, your device connects to that network, which receives your IP address in order to serve the video to you.
  • Apple Inc. and Apple Distribution International (United States and Ireland) — Sign in with Apple, App Attest, FairPlay Streaming, push notifications, and App Store purchases and subscription verification. Processes credential identifiers, device tokens and transaction identifiers.
  • Cloudflare, Inc. (United States) — anti-abuse verification (Turnstile) on the contact form at benative.dev. Processes your IP address and signals about your browser.
  • DigitalOcean — hosting of our application servers and databases, and therefore of all account and synchronisation data.

We also disclose data where we are legally required to do so — for example, in response to a binding request from a competent authority.

International Transfers

Our video infrastructure and our application servers are located in the European Economic Area, in Germany (Frankfurt). Some of our providers are established in the United States, so using the Services involves transfers of personal data outside the EEA: Apple (Sign in with Apple, App Attest, push notifications, App Store purchases) and Cloudflare, Inc. (anti-abuse verification on the contact form at benative.dev).

These transfers rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), combined with supplementary technical measures. You can request a copy of the safeguards in place by writing to info@benative.dev.

If you are in the United Kingdom, the same transfers are restricted transfers under the UK GDPR. The transfer of your data to our servers in Germany does not need an extra safeguard, because the UK Government’s data protection adequacy regulations recognise the European Economic Area as offering an adequate level of protection. For the transfers to Apple and Cloudflare in the United States, we additionally rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission’s Standard Contractual Clauses, both issued by the Information Commissioner’s Office, combined with the same supplementary technical measures. You can request a copy of these safeguards by writing to info@benative.dev.

How Long We Keep Your Data

We keep each type of data only for as long as we need it for the purpose it was collected for:

  • Attestation key ID and attestation record: while the app remains installed.
  • Session tokens: they expire automatically at the end of the playback session.
  • Account data (credential identifier, optional display name and email address): while the account exists, and deleted without undue delay once you request deletion.
  • Synchronised progress, notebooks, notes and favourites: while the account exists, and deleted with the account. Notes moved to the trash are kept until you empty it.
  • Backups containing account data: until the backup is overwritten, which happens every week.
  • Support correspondence, including messages sent through the contact form: as long as needed to handle your enquiry and any follow-up.
  • Analytics: per-installation records are deleted after aggregation; aggregate figures, which cannot be traced back to anyone, are kept indefinitely.
  • Subscription status and App Store transaction identifiers: for as long as the subscription lasts and afterwards for as long as accounting and tax law requires — six years under Article 30 of the Spanish Commercial Code.

Your preferences are stored by the app on your own device and are removed when you delete the app.

Security

We protect your information with encryption in transit (TLS) and at rest, strict access controls, hardware-backed key management and device attestation. There is no password to steal: authentication uses passkeys or Sign in with Apple, the private key never leaves your device, and our servers only ever hold the public key. We review our safeguards regularly, keep them aligned with Apple’s platform requirements, and log and investigate anomalous access to our systems.

No system is completely secure. If a breach affects your personal data and is likely to result in a high risk to your rights, we will notify you and the competent supervisory authority as required by Articles 33 and 34 GDPR.

Your Rights

You have the rights of access, rectification, erasure, restriction of processing, objection and data portability, and the right not to be subject to a decision based solely on automated processing. Where our processing is based on your consent, you may withdraw it at any time, as easily as you gave it, without affecting the lawfulness of the processing carried out before the withdrawal.

In practice, you can:

  • Use the app without creating an account.
  • Delete your account at any time from the app to remove synchronised data.
  • Disable push notifications through system settings.
  • Request a copy of your synchronised data, or ask us to correct or delete it, by contacting info@benative.dev.
  • Object to the processing we base on our legitimate interest, including analytics.
  • Request full account erasure, which will deactivate credentials and remove your synchronised content.
  • Ask us to close your account and stop providing the Services to you. This is a separate matter from any right of withdrawal in respect of a subscription, which is exercised through Apple as described in our Terms of Use.

How to exercise them. Write to info@benative.dev from the email address associated with your account, or use the account deletion option inside the app. We will answer within one month of receiving your request. If the request is complex, or if we receive several from you, we may extend that period by two further months and we will tell you why within the first month. Exercising these rights is free of charge. If we cannot identify you with reasonable certainty, we may ask for additional information solely to confirm your identity; we will not use it for anything else.

Complaints. If you believe we have not handled your data correctly, you have the right to lodge a complaint with a supervisory authority. In Spain that authority is the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es). You may also complain to the supervisory authority of the European Union Member State where you live or work. If you are in the United Kingdom, the equivalent authority is the Information Commissioner’s Office (Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk), which oversees compliance with the UK GDPR and the Data Protection Act 2018.

Children and the Age of Digital Consent

Be Native is designed for adult professionals and for people learning to develop software. We do not knowingly collect personal data from children below the age at which they can consent to the processing of their own data, and that age is set by the law of the country where the child lives, not by us.

In the European Union it ranges from 13 to 16 under Article 8(1) GDPR: 13 in Portugal, Denmark, Sweden and Finland; 14 in Spain and Italy; 15 in France; and 16 in Germany, the Netherlands and Poland. It is 13 in the United Kingdom, and 13 in the United States under COPPA. Two of our markets sit outside that range: in India, the Digital Personal Data Protection Act, 2023 requires verifiable parental consent for anyone under 18; in mainland China, the Personal Information Protection Law requires the consent of a parent or guardian for anyone under 14. If a different age applies where you live, that is the age that applies to you.

If you are below that age, please do not create an account unless the holder of parental responsibility over you gives or authorises that consent. If you believe a child has provided us with personal data, write to info@benative.dev and we will delete it.

Changes to This Policy

We may update this Privacy Policy to reflect changes in the Services or in the law. When we do, we will update the “Last updated” date and, where the change is significant, tell you in the app or by email before it takes effect. This policy informs you about how we process personal data: it is not a contract, and continued use of the Services is not treated as your acceptance of it. Where a change requires your consent under data protection law, we will ask you for it separately, and you remain free to refuse.

Contact Us

If you have questions, requests or concerns about this Privacy Policy or how we handle your data, email us at info@benative.dev, or write to BN CODING SL, Anabel Segura 10, Planta 3, 28108 Alcobendas (Madrid), Spain. We are committed to working with you to resolve any issues quickly and transparently.