Who sees your safety data?
Privacy and responsible data stewardship in community safety.
When you use a safety app and something actually happens, you share real things — where you are, who to call, sometimes your health. It’s fair to want to know who sees that, and what happens to it afterward.
Most security providers don’t say much about it. We think you deserve a clear answer — because the people who trust us with their safety are trusting us with their information, too. The two aren’t separate.
The question worth asking
As communities adopt more safety technology, more sensitive personal information is being captured than ever — and the rules for governing it remain largely undefined across the industry. Evolving state privacy laws have made this a live issue, not a hypothetical one.
There’s a quieter gap, too. Most security companies do have a privacy policy — but read it closely and it’s mostly about their company: their website, their marketing, their employees. When it comes to your community’s actual information, the fine print usually treats that as someone else’s job. We don’t pass that off. Here’s how we handle yours.
Who sees your information
The app holds only what you choose to share: your contacts, your location when you ask for help, and any emergency or medical details you’ve added. Here’s who sees it — and who doesn’t:
- A trained operator — a real person — sees what they need to help you, in the moment you need it. Not a stranger, not your neighbors, not an advertiser — and never staff from another community. Your information is walled off by community and by role.
- A validator checks the response, not you. They confirm a responder was on the incident and that it’s properly documented before it’s closed — without ever seeing your private or medical details. Oversight on the response, not a window into your information.
- We never sell your information, and never use it to build a picture of you. It exists to enable a response — that’s the only reason we hold it.
- You control your profile — and the record of a response stays a record. The information you enter — your contacts, your details, your preferences — is yours to see, update, or remove anytime. What happened during an actual emergency response is kept as a permanent record — not to hold onto you, but because a safety record you could quietly erase wouldn’t be worth anything to anyone, including you.
What we hold — and how it’s handled
| What we hold | What it is | Who sees it | How it’s handled |
|---|---|---|---|
| Profile & contacts | The people to reach, your access permissions and preferences | You, and the operator helping you when it’s needed | You control it — update or remove it anytime |
| Location & check-ins | Where you are when you ask for help or check in | The operator handling your request; a validator, to confirm the response | Used only to send help — not tracked over time, never sold |
| Emergency & medical details | Health information you’ve added; what happened during a response | The operator and the responders helping you | Medical-grade confidentiality; shared only as needed for your care |
| Operator communications | Calls and messages during a response | The operator helping you; supervisors, for safety and quality | Recorded in a log that can’t be edited or deleted — access tied to safety use only |
The architecture underneath
A promise is only as good as what’s holding it up. Here’s what’s underneath — not policy language, but how the system itself is built:
- Your location lives in the moment, not over time. When you ask for help, it’s used to send help — then it’s done. There’s no quiet history of your movements building up in the background; it’s tied to the request you made, and locked to it.
- Health information runs only on covered infrastructure. Anything that could carry protected health information stays on HIPAA-compliant, BAA-covered systems — the same kind of formal data-protection agreement a hospital requires of its vendors, and the same standard your own doctor is held to. Where a channel isn’t covered for that purpose, it isn’t used for it. Protection comes before the feature, not after.
- Every access is written to a log that can’t be edited or deleted. By the design of the database itself, each access is permanent — not editable by an operator, an administrator, or us. Every one carries a name and a time. That’s the accountability behind every promise here.
- Training is gated, not assumed. No operator responds to you until they’ve been trained on all of this. The system enforces it rather than trusting it happened.
The test worth running
Anyone can say their operators are trained. The sharper questions are the ones to put to your current provider:
Ours are trained to protect your privacy on every call — security or medical — and to handle health information the way HIPAA requires. Most providers don’t train for privacy at all.
When a response involves a photo or video, ours is captured inside the system and scoped to the people helping you — never a feed someone watches when nothing’s wrong. Ask whether theirs is.
Every access to your information carries a name and a time that no one — not even us — can erase. Most providers’ privacy policies are about their company. Ours is about your information.
Three straight questions. You should get a clear answer to all three. Most can’t give you one.
You shouldn’t have to wonder who sees your safety data. The answer should be simple, and it should be the same every time: the people helping you, using it only for that — and nothing else.
That’s the standard we hold ourselves to, and the one every community deserves.
Sources: SafeHome.org, 2026 Home Security Industry Report (survey of 2,435 U.S. adults); Mordor Intelligence and Grand View Research, 2026 smart-home security market reports (evolving privacy and data-residency requirements).