Privacy Policy

Last updated: 20 July 2026

Pharos is a personal safety app: when you press your button (or the app), it alerts the emergency contacts you choose and shows them your location. This policy explains what data we handle, why, and the control you have over it. We built Pharos to share as little as possible. Your data is for your people, not for us.

Pharos is not a medical device and does not detect medical events. It is not a substitute for emergency services. In a life-threatening emergency, always contact your local emergency number.

Who we are

Pharos ("we", "us") provides the Pharos app and the relay service it connects to. For any privacy question or to exercise your rights, contact us at [email protected]. We are the data controller for the data described below.

What we collect

We do not collect advertising identifiers, we do not sell or share your data with advertisers or data brokers, and there is no call centre reading your alerts.

How we use it

SMS

On Android, the SMS backup channel is sent from your own phone using your mobile plan. The message and your contact's number do not pass through our servers. Standard carrier rates may apply.

Legal basis (GDPR)

We rely on: your consent, which you give when you create your account and which you can withdraw at any time; and the performance of the service you asked us to provide. For the sensitive health-related aspect of a medical/seizure profile, we rely on your explicit consent. Withdrawing consent (for example by deleting your account) stops future processing but does not affect anything done beforehand.

Who can see your data

Your alerts, location and status are visible only to the emergency contacts you add and who accept. We use Google Firebase to deliver push notifications to phones. Traffic between the app and our relay is encrypted in transit (HTTPS). We never make your data public.

Where it is stored, and self-hosting

Data is stored on our secure relay and reachable only over an encrypted connection. Pharos can also be self-hosted: you can run the relay yourself, in which case your data lives entirely on infrastructure you control and this policy applies only to the app itself.

How long we keep it

Your rights

You can, at any time:

To make a request we can't fulfil in the app, email [email protected].

How we protect it

Passwords are stored only as salted hashes; your auth token is held in the Android Keystore on your device; connections to the relay are encrypted and certificate-pinned; and login attempts are rate-limited. No system is perfectly secure, but we design Pharos to minimise what is collected and who can reach it.

Children

Pharos is not directed at children under 16. If a child uses Pharos, it should be set up and managed by a parent or guardian who consents on their behalf.

Changes

We may update this policy as Pharos evolves. We will change the "last updated" date above and, for significant changes, notify you in the app.

Contact

[email protected]