Skip to content
RESCUEN logoRESCUEN
Trust & Security

Your data, locked down

We treat your safety data with the seriousness it deserves. Here’s exactly how we protect it — in plain language, no jargon.

Encrypted in transit & at rest

All data travels over TLS and is encrypted at rest in Firebase — strong transport and storage protection (we don’t claim end-to-end encryption).

Passwordless sign-in

Google Sign-In + phone OTP via Firebase, verified server-side. No password to phish, leak or reuse, plus a 60-day change-lock on emergency numbers.

Backend-only secrets

API keys and credentials are stored as Firebase secrets and injected at runtime — never inside the app bundle or the browser.

No data selling

No ad-trackers, no data brokers. Your location is never used for ads — only shared with your contacts and nearby rescuers when you trigger SOS.

App Check & strict rules

Firebase App Check plus default-deny Firestore/Storage rules require an authenticated user for every read and write.

Hardened platform

Server-side proximity filtering, a write-only evidence vault, rate-limiting and strict security headers reduce the attack surface.

Responsible disclosure

Found a security issue? We welcome responsible reports and will work with you to fix it quickly. Please don’t exploit or disclose it publicly before we’ve resolved it.

Email our security team →

Your part in staying secure

  • • Never share your OTP with anyone — we’ll never ask for it.
  • • Keep your phone locked and your number secure.
  • • Review your trusted contacts regularly.
  • • Report anything suspicious to us right away.