AlertOS

Privacy Policy

Effective date: 22 July 2026 · Last updated: 22 July 2026

This Privacy Policy explains what personal data the AlertOS mobile application (identifier tech.oxoft.SOS, the “App”) processes, how that data is used, with whom it is shared, and what rights you have as a user.

The data controller is OXOFT, OBRT ZA INFORMATICA USLUGE I TRGOVINU, VL. ANDRII POLYVACH, ZAGREB, VRBIK III. 17, OIB: 89219595864 (“OXOFT”, “we”, “us”). For any privacy-related questions, contact alertos@oxoft.tech.

AlertOS is not an emergency response service. The App helps notify your loved ones, but it does not replace calling 112 / 911 / emergency services and does not guarantee that a signal is delivered. See the Terms of Service for details.

1. What data we process

We collect only the data needed for the App to function.

CategoryDetailsWhen
AccountEmail, display name, user identifier. When signing in with Apple or Google — the data the provider supplies (email, name).At sign-up and sign-in
LocationPrecise coordinates at the moment an SOS is sentOnly when SOS is pressed (see §2)
Family connectionsFamily composition, roles (sender / loved one), QR-code invitationsWhen creating or joining a Family
Care and routinesCare notes, reminders, and status entries about a loved one that you enter manuallyWhen using care features
NotificationsDevice push token (APNs)When you grant notification permission
SubscriptionPremium subscription status and expiry. Payment is handled by Apple — we do not receive card data.When you subscribe
Technical dataDevice/installation identifiers, anonymized usage analytics and crash diagnosticsWhile the App runs

We do not request or store bank card numbers, passport data, or other identity documents.

2. Location

Location is sensitive data, so we process it in the most limited way possible:

3. Purposes and legal bases

PurposeLegal basis (GDPR)
Account creation and authenticationPerformance of a contract (Art. 6(1)(b))
Sending an SOS signal and sharing location with loved onesPerformance of a contract; protection of vital interests (Art. 6(1)(b), 6(1)(d))
Voice calls within the FamilyPerformance of a contract (Art. 6(1)(b))
SOS push notificationsPerformance of a contract (Art. 6(1)(b))
Subscription processingPerformance of a contract (Art. 6(1)(b))
Analytics and crash diagnosticsLegitimate interest — service stability and improvement (Art. 6(1)(f))

4. Sharing with loved ones and third parties

The App is built around a “Family” — a group of connected users. Data is shared with:

We do not sell your personal data and do not share it for third-party advertising.

5. Third-party services (sub-processors)

To operate the App we use the following trusted providers. Each processes data on our behalf and under its own privacy policy:

ServicePurposeData processed
Google Firebase (Auth, Firestore, Cloud Functions, Cloud Messaging, Analytics)Authentication, data storage, server logic, push notifications, analyticsAccount, family connections, notes, SOS location, push tokens, identifiers
AgoraReal-time voice callsCall audio stream (end-to-end encrypted, see §6)
RevenueCatSubscription managementUser identifier, subscription status
Apple (App Store, Sign in with Apple, APNs)Subscription payments, sign-in, notification deliveryPurchase data, Apple identifier, push token

6. Calls and end-to-end encryption

Voice calls within the Family are protected by end-to-end encryption (AES-256-GCM with a unique key per session). Call content is not accessible to us or to the connectivity provider and is not stored on servers.

7. Retention periods

8. Account and data deletion

You can delete your account directly in the App: Settings → Delete account. To prevent accidental deletion, the button is enabled after 10 seconds, and the action is irreversible.

Deletion triggers the server-side deleteMyAccount function, which removes your account and associated personal data. Some technical records may be retained for a limited time where required by law (for example, for tax accounting of purchases).

9. Your rights (GDPR)

If you are located in the EEA, you have the following rights:

To exercise your rights, contact alertos@oxoft.tech. Many of these actions can be performed yourself within the App.

10. Security

We apply encryption in transit (TLS) and at rest, end-to-end encryption of calls, access controls at the server-rules level, and the principle of data minimization. Nevertheless, no method of transmission or storage can be guaranteed to be 100% secure.

11. Children

The App is not intended for independent use by children below the age set by applicable law (generally 16 in the EU). We do not knowingly collect such children’s data. If you believe we have processed a child’s data without appropriate consent, contact us for deletion.

12. International data transfers

Our providers may process data on servers outside your country, including in the United States. In such cases, transfers are carried out on the basis of legally provided mechanisms (for example, the EU Standard Contractual Clauses).

13. Changes to this policy

We may update this Policy. We will notify you of material changes within the App or by other reasonable means. The current version is always available at this address with the update date shown.

14. Contact

OXOFT, OBRT ZA INFORMATICA USLUGE I TRGOVINU, VL. ANDRII POLYVACH
ZAGREB, VRBIK III. 17 · OIB: 89219595864
Email: alertos@oxoft.tech