This Privacy Policy explains what personal data the AlertOS mobile application
(identifier tech.oxoft.SOS, the “App”) processes, how that data is used, with whom it is
shared, and what rights you have as a user.
The data controller is OXOFT, OBRT ZA INFORMATICA USLUGE I TRGOVINU, VL. ANDRII POLYVACH, ZAGREB, VRBIK III. 17, OIB: 89219595864 (“OXOFT”, “we”, “us”). For any privacy-related questions, contact alertos@oxoft.tech.
AlertOS is not an emergency response service. The App helps notify your loved ones, but it does not replace calling 112 / 911 / emergency services and does not guarantee that a signal is delivered. See the Terms of Service for details.
We collect only the data needed for the App to function.
| Category | Details | When |
|---|---|---|
| Account | Email, display name, user identifier. When signing in with Apple or Google — the data the provider supplies (email, name). | At sign-up and sign-in |
| Location | Precise coordinates at the moment an SOS is sent | Only when SOS is pressed (see §2) |
| Family connections | Family composition, roles (sender / loved one), QR-code invitations | When creating or joining a Family |
| Care and routines | Care notes, reminders, and status entries about a loved one that you enter manually | When using care features |
| Notifications | Device push token (APNs) | When you grant notification permission |
| Subscription | Premium subscription status and expiry. Payment is handled by Apple — we do not receive card data. | When you subscribe |
| Technical data | Device/installation identifiers, anonymized usage analytics and crash diagnostics | While the App runs |
We do not request or store bank card numbers, passport data, or other identity documents.
Location is sensitive data, so we process it in the most limited way possible:
| Purpose | Legal basis (GDPR) |
|---|---|
| Account creation and authentication | Performance of a contract (Art. 6(1)(b)) |
| Sending an SOS signal and sharing location with loved ones | Performance of a contract; protection of vital interests (Art. 6(1)(b), 6(1)(d)) |
| Voice calls within the Family | Performance of a contract (Art. 6(1)(b)) |
| SOS push notifications | Performance of a contract (Art. 6(1)(b)) |
| Subscription processing | Performance of a contract (Art. 6(1)(b)) |
| Analytics and crash diagnostics | Legitimate interest — service stability and improvement (Art. 6(1)(f)) |
The App is built around a “Family” — a group of connected users. Data is shared with:
We do not sell your personal data and do not share it for third-party advertising.
To operate the App we use the following trusted providers. Each processes data on our behalf and under its own privacy policy:
| Service | Purpose | Data processed |
|---|---|---|
| Google Firebase (Auth, Firestore, Cloud Functions, Cloud Messaging, Analytics) | Authentication, data storage, server logic, push notifications, analytics | Account, family connections, notes, SOS location, push tokens, identifiers |
| Agora | Real-time voice calls | Call audio stream (end-to-end encrypted, see §6) |
| RevenueCat | Subscription management | User identifier, subscription status |
| Apple (App Store, Sign in with Apple, APNs) | Subscription payments, sign-in, notification delivery | Purchase data, Apple identifier, push token |
Voice calls within the Family are protected by end-to-end encryption (AES-256-GCM with a unique key per session). Call content is not accessible to us or to the connectivity provider and is not stored on servers.
You can delete your account directly in the App: Settings → Delete account. To prevent accidental deletion, the button is enabled after 10 seconds, and the action is irreversible.
Deletion triggers the server-side deleteMyAccount function, which removes your account
and associated personal data. Some technical records may be retained for a limited time where required
by law (for example, for tax accounting of purchases).
If you are located in the EEA, you have the following rights:
To exercise your rights, contact alertos@oxoft.tech. Many of these actions can be performed yourself within the App.
We apply encryption in transit (TLS) and at rest, end-to-end encryption of calls, access controls at the server-rules level, and the principle of data minimization. Nevertheless, no method of transmission or storage can be guaranteed to be 100% secure.
The App is not intended for independent use by children below the age set by applicable law (generally 16 in the EU). We do not knowingly collect such children’s data. If you believe we have processed a child’s data without appropriate consent, contact us for deletion.
Our providers may process data on servers outside your country, including in the United States. In such cases, transfers are carried out on the basis of legally provided mechanisms (for example, the EU Standard Contractual Clauses).
We may update this Policy. We will notify you of material changes within the App or by other reasonable means. The current version is always available at this address with the update date shown.
OXOFT, OBRT ZA INFORMATICA USLUGE I TRGOVINU, VL. ANDRII POLYVACH
ZAGREB, VRBIK III. 17 · OIB: 89219595864
Email: alertos@oxoft.tech