Dead Man Switch
📑 Quick Navigation Outline (15 Sections) ▼
DOC ID: DMS-POL-2026 REV: v2.9.0 CONTROLLER: QUYETNV

Privacy Policy & Data Safety

Effective Date: September 9, 2026 • Compliance: Google Play Data Safety & Apple App Privacy Standards • Contact: quyetnv.mlhn@gmail.com
Covers all mobile clients, account records, local biometric guards, and emergency alert dispatch systems.

SECTION 01

Core Privacy Philosophy & Terms Integration

At Dead Man Switch (operated by quyetnv), our architecture is engineered around the principle of Privacy by Design and Minimum Necessary Data. We believe your emergency text messages, safety check-in parameters, and contact configurations should be accessible strictly by you and your authorized recipients — never by advertisers, data brokers, or unauthorized third parties.

📌 NOTICE & LEGAL CROSS-REFERENCE

This Privacy Policy is an integral part of and strictly subject to the full Disclaimer of Warranties (“AS IS”), Limitation of Liability ($50 USD / 12-month spend cap), Mandatory Individual Arbitration, and Class Action Waiver set forth in our Terms of Service.

SECTION 02

Information We Collect & Storage Architecture

2.1. Account Authentication Data

When you register, we collect your email address, unique account identifier (UUID), and authentication provider metadata (Google Sign-In, Sign in with Apple, or Email Magic Link). We do not store plain-text passwords.

2.2. Switch Timing Metadata

We store switch configuration parameters: switch title, countdown duration (hours/days), grace period duration, recipient email addresses, and active/paused state.

2.3. Emergency Text Messages & PostgreSQL Row-Level Security (RLS)

We want to be entirely transparent regarding how your emergency messages and switch settings are safeguarded:

  • PostgreSQL Row-Level Security (RLS): All switch metadata, recipient email lists, and emergency text messages are protected by PostgreSQL Row-Level Security policies. RLS ensures that only authenticated database requests belonging to your specific user ID can view, edit, or delete your switch configurations.
  • No File Attachments or Media Storage: The Application stores text-only emergency messages and configurations. We do not support, store, or process file attachments, photos, videos, audio recordings, or binary media uploads.
  • Infrastructure Protection: Database storage volumes are encrypted at rest via AES-256 server encryption, and all API calls and database sessions are encrypted in transit via TLS 1.3.

2.4. Geolocation Data (Trigger-Only)

NO CONTINUOUS BACKGROUND TRACKING: The Application DOES NOT track, log, or store your historical movements. Foreground location access is requested only when a switch timer lapses and triggers an alert, appending single-point GPS coordinates to the dispatch email.

2.5. Zero Biometric Transmission

The Application supports biometric locking (Face ID / Touch ID / Android BiometricPrompt) via platform APIs (`local_auth`). Biometric verification executes entirely within your device’s Secure Enclave / TrustZone. ZERO BIOMETRIC DATA IS EVER TRANSMITTED TO OUR SERVERS.

2.6. Production Analytics

In production, we use Firebase Analytics to understand feature usage, purchase flow outcomes, app version distribution, language, theme, subscription status, and biometric-lock preference. Events are associated with a Firebase user identifier when the user is signed in. We do not use this data for targeted advertising or sell it to third parties. Analytics collection is disabled in development and debug builds.

SECTION 03

How We Process Your Data

Data is processed strictly to perform essential life-safety and contingency features:

  • Evaluating deadline expirations and resetting check-in countdowns when confirmed.
  • Transmitting transactional local and push reminders alerting you that a check-in is due.
  • Dispatching automated emergency email notifications containing your emergency text message and optional GPS location coordinates to your designated recipients when a deadline and grace period elapse without confirmation.
  • Monitoring delivery bounce rates and recipient abuse to enforce anti-spam policies.

WE DO NOT SELL, RENT, OR MONETIZE YOUR PERSONAL DATA. Firebase Analytics is used in production for product usage and reliability measurement, not for targeted advertising or data brokerage.

SECTION 04

Authorized Sub-Processors & Cross-Border Data Transfers

Sub-Processor Role & Function Location Transfer Legal Basis
Supabase PostgreSQL database, Authentication, Row-Level Security, Cloud Functions Global / EU / US Standard Contractual Clauses (SCCs), SOC2 Type II
Transactional Email Provider (Resend / SMTP) Emergency alert email delivery United States Standard Contractual Clauses (SCCs), TLS transit encryption
Apple & Google Binary distribution, Push Notifications (APNs/FCM), IAP Billing Global Direct platform agreement

Where personal data is transferred outside the European Economic Area (EEA), such transfers are governed by European Commission-approved Standard Contractual Clauses (SCCs) to ensure equivalent data protection.

SECTION 05

Strict Recipient Protections & Anti-Spam Enforcement

To protect third parties from unwanted harassment or unsolicited emails:

  • Users must only designate verified, consenting individuals as emergency contacts.
  • Every emergency alert email contains an authenticated opt-out mechanism allowing recipients to permanently block notifications from Dead Man Switch.
  • Accounts generating spam complaints or unverified bounces will be IMMEDIATELY TERMINATED AND BLACKLISTED in accordance with our Terms of Service.
SECTION 06

Location Policy: Non-Continuous, Trigger-Bound

We do not continuously track or record your location history. We request location permission to read GPS coordinates strictly at the moment of switch setup or single-point emergency trigger. If location permissions are denied by the user, the switch will execute its email dispatch without GPS coordinates.

SECTION 07

Google Play & App Store Account & Data Deletion Policy

In strict compliance with Google Play Store Data Safety and Apple App Store guidelines, users have the absolute right to permanently delete their account, switches, emergency text messages, and all associated personal data.

METHOD 1: IN-APP INSTANT SELF-SERVICE DELETION (RECOMMENDED)
  1. Open the Dead Man Switch app on your device.
  2. Navigate to Settings (gear icon).
  3. Select Account & Security → tap Delete Account.
  4. Confirm the prompt. Your account credentials, active switches, contacts, and emergency text messages are instantly and permanently purged from the database via cascading foreign keys.
METHOD 2: DIRECT WEB DELETION REQUEST VIA EMAIL

If you have uninstalled the application or cannot access your device, submit a formal deletion request:

  • Send an email from your registered email address to: quyetnv.mlhn@gmail.com
  • Subject Line: [DATA DELETION REQUEST] Dead Man Switch
  • Include your registered email address and user UUID (if known).
  • Processing Timeline: Direct email requests are verified and executed within 7 business days. All database rows, authentication tokens, and associated switch records are irreversibly wiped.
SECTION 08

EEA & GDPR Data Subject Rights

If you are a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, you possess statutory rights under the General Data Protection Regulation (GDPR):

  • Right of Access: You have the right to request a copy of the personal data we hold about you.
  • Right to Rectification: You can update or correct inaccurate profile and contact data at any time directly in the app.
  • Right to Erasure (“Right to be Forgotten”): You can erase your entire account, switches, and associated data via in-app deletion or by emailing us.
  • Right to Restriction of Processing: You may request that we restrict the processing of your data under certain statutory conditions.
  • Right to Data Portability: You may request an export of your personal data in a structured, commonly used, machine-readable format.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local Data Protection Authority (DPA).

To exercise any of these rights, submit your request to: quyetnv.mlhn@gmail.com.

SECTION 09

Post-Mortem Account Privacy

The Developer maintains strict post-mortem confidentiality:

  • We do not disclose switch contents or grant account takeover access to surviving spouses, family members, or estate executors without a formal subpoena or certified order from a court of competent jurisdiction.
  • Switches will only trigger if the pre-configured deadline and grace period expire without user check-in.
SECTION 10

Law Enforcement & Statutory Disclosures

We will only disclose user account metadata or stored text data to law enforcement or governmental authorities upon receipt of a valid, enforceable court order, subpoena, or search warrant issued by a court of competent jurisdiction in compliance with applicable statutory procedures.

SECTION 11

Data Security & Storage Architecture

We implement industry-standard organizational and technical safeguards:

  • Transport Security: All API communications and database queries are encrypted in transit via TLS 1.3.
  • Database Isolation: Supabase PostgreSQL Row-Level Security (RLS) ensures complete logical and cryptographic separation of user records.
  • Storage Encryption: Server storage volumes are encrypted at rest using AES-256.
SECTION 12

Data Retention, Purge Schedules & Account Termination

Active Accounts: Data is retained for as long as your account remains active.

Self-Service / Requested Deletion: Upon account deletion, all active switches, contacts, emergency text messages, and authentication records are deleted immediately from live database tables. Encrypted database backup snapshots cycle out and are permanently overwritten within thirty (30) days.

Account Termination vs. Deletion: If an account is terminated for spam or ToS violations, all scheduled switch handoffs are permanently revoked immediately. Minimal non-sensitive compliance markers (such as email hash) may be retained on our internal blacklist solely to prevent abusive re-registration.

Server Logs: Ephemeral server telemetry, network request logs, and edge function execution logs are automatically purged after ninety (90) days.

SECTION 13

Cookie & Tracking Technology Disclosure

This website and our policy pages DO NOT USE cookies, tracking pixels, local storage trackers, or behavioral analytics software. We do not profile visitors, serve third-party ads, or collect marketing analytics.

SECTION 14

Children’s Privacy (COPPA & GDPR Compliance)

Dead Man Switch is not directed at children under thirteen (13) years of age (or sixteen (16) in the European Economic Area). We do not knowingly collect or solicit personal information from minors. If we learn that we have inadvertently collected personal data from a child without verified parental consent, we will delete that data immediately.

SECTION 15

Language Precedence & Official Inquiries

This Privacy Policy is drafted in the English language. In the event of any conflict, divergence, or ambiguity between an English version and any translated text, the English version shall govern and control in all respects.

For privacy inquiries, GDPR rights requests, or data deletion requests, contact our Data Protection Officer:
quyetnv • Email: quyetnv.mlhn@gmail.com