Pharos is a personal safety app: when you press your button (or the app), it alerts the emergency contacts you choose and shows them your location. This policy explains what data we handle, why, and the control you have over it. We built Pharos to share as little as possible. Your data is for your people, not for us.
Who we are
Pharos ("we", "us") provides the Pharos app and the relay service it connects to. For any privacy question or to exercise your rights, contact us at [email protected]. We are the data controller for the data described below.
What we collect
- Account details: your name, username and email address. Your password is never stored in readable form; we keep only a salted hash of it.
- Your emergency contacts: the name, and the phone number and/or email, of each person you add so we can reach them when you need help.
- Location: your location is collected and shared only during an active alert (including a short trail of updates so contacts can find you, and any alert that a missed check-in escalates to). A check-in on its own carries no location. Pharos does not track your location the rest of the time.
- Your safety profile: the mode you choose (for example medical, danger, lone-worker or wellbeing) and the specific alarm you set. Because a medical or seizure profile can reveal information about your health, we treat it as sensitive and process it only with your explicit consent (see "Legal basis").
- Device push token: an identifier from Google so we can deliver alert notifications to your phone.
- Check-in and alert activity: records of alerts and check-ins (sent, missed, confirmed, acknowledged) and their timestamps, plus a periodic "phone is alive" heartbeat, so you and your contacts can see what happened and that your phone is reachable.
- Enquiries you send us: if you use the "register interest" or contact form on our website, we keep the name, email and message you submit so we can reply. These are automatically deleted after 30 days.
We do not collect advertising identifiers, we do not sell or share your data with advertisers or data brokers, and there is no call centre reading your alerts.
How we use it
- To deliver your alert, with your location, to the contacts you chose, and to let them acknowledge that they are responding.
- To run your check-ins and, if you miss one, to notify your contacts as you configured.
- To operate and secure your account (sign-in, email verification, keeping the service running).
SMS
On Android, the SMS backup channel is sent from your own phone using your mobile plan. The message and your contact's number do not pass through our servers. Standard carrier rates may apply.
Legal basis (GDPR)
We rely on: your consent, which you give when you create your account and which you can withdraw at any time; and the performance of the service you asked us to provide. For the sensitive health-related aspect of a medical/seizure profile, we rely on your explicit consent. Withdrawing consent (for example by deleting your account) stops future processing but does not affect anything done beforehand.
Who can see your data
Your alerts, location and status are visible only to the emergency contacts you add and who accept. We use Google Firebase to deliver push notifications to phones. Traffic between the app and our relay is encrypted in transit (HTTPS). We never make your data public.
Where it is stored, and self-hosting
Data is stored on our secure relay and reachable only over an encrypted connection. Pharos can also be self-hosted: you can run the relay yourself, in which case your data lives entirely on infrastructure you control and this policy applies only to the app itself.
How long we keep it
- Closed alerts, their location trails and check-in logs are automatically deleted after 30 days.
- Account data and your contacts are kept until you delete them or delete your account.
- An active (unresolved) alert is kept until it is resolved or expires.
Your rights
You can, at any time:
- Access and correct your account details in the app.
- Delete your account and all associated data from Settings → Danger zone → Delete my account (this permanently erases your alerts, trails, contacts, check-ins and tokens).
- Clear your incident history from the Incidents screen.
- Withdraw consent by deleting your account.
- Request a copy of your data, or lodge a complaint with your local data protection authority (in Romania, the ANSPDCP).
To make a request we can't fulfil in the app, email [email protected].
How we protect it
Passwords are stored only as salted hashes; your auth token is held in the Android Keystore on your device; connections to the relay are encrypted and certificate-pinned; and login attempts are rate-limited. No system is perfectly secure, but we design Pharos to minimise what is collected and who can reach it.
Children
Pharos is not directed at children under 16. If a child uses Pharos, it should be set up and managed by a parent or guardian who consents on their behalf.
Changes
We may update this policy as Pharos evolves. We will change the "last updated" date above and, for significant changes, notify you in the app.