Your data, locked down
We treat your safety data with the seriousness it deserves. Here’s exactly how we protect it — in plain language, no jargon.
Encrypted in transit & at rest
All data travels over TLS and is encrypted at rest in Firebase — strong transport and storage protection (we don’t claim end-to-end encryption).
Passwordless sign-in
Google Sign-In + phone OTP via Firebase, verified server-side. No password to phish, leak or reuse, plus a 60-day change-lock on emergency numbers.
Backend-only secrets
API keys and credentials are stored as Firebase secrets and injected at runtime — never inside the app bundle or the browser.
No data selling
No ad-trackers, no data brokers. Your location is never used for ads — only shared with your contacts and nearby rescuers when you trigger SOS.
App Check & strict rules
Firebase App Check plus default-deny Firestore/Storage rules require an authenticated user for every read and write.
Hardened platform
Server-side proximity filtering, a write-only evidence vault, rate-limiting and strict security headers reduce the attack surface.
Emergency numbers (India)
In a real emergency, call these first.
Responsible disclosure
Found a security issue? We welcome responsible reports and will work with you to fix it quickly. Please don’t exploit or disclose it publicly before we’ve resolved it.
Email our security team →Your part in staying secure
- • Never share your OTP with anyone — we’ll never ask for it.
- • Keep your phone locked and your number secure.
- • Review your trusted contacts regularly.
- • Report anything suspicious to us right away.