Privacy Policy
Last updated: August 2026
PanicButton is a silent panic button for your circle of trust. We handle the minimum information needed for your alert to reach the people you chose. We do not sell data to third parties, we show no ads, and we never share your location with advertisers.
What data we collect.
Account
Email and password (hashed), managed by Supabase Auth. The email is used only to sign in, recover your password and link you to your groups.
Profile
Display name and, optionally, medical data (allergies, blood type, medication, emergency contacts). This data is only shown to your trusted contacts when you trigger an alert.
Location
While you have an active alert, the app shares your location with your group members and your trusted contacts, updating it so they can follow your route. It starts when you press the button and stops when the alert is closed. Outside an emergency we never collect your location.
Groups and memberships
Which groups you belong to and your role in each.
Alerts and responses
Send time, category, optional message, status (active/resolved/canceled) and members' responses.
Push device token
An FCM/APNs identifier to deliver notifications.
App usage
A signal that the app was opened (date and time, version, whether it is Android, iOS or web) and six events at the steps where people get stuck: you finished the introduction, you opened the invite screen, you shared an invitation, someone opened it, creating a group or inviting failed, you added a trusted contact. Also whether you granted notification and location permission, so we know whether the button could reach anyone at all.
Location while the app is closed
During an active alert, PanicButton collects your location even when the app is closed or not in use. It serves one purpose only: so the people you chose can follow where you are for as long as the emergency lasts, even if you locked your phone or put it in your pocket.
- It starts only when you press the panic button, and stops when the alert closes.
- While it is active, your phone shows a persistent notice. You can choose what that notice says, including a coded phrase, in case you do not want whoever is looking at your phone to understand what is going on.
- It never turns itself on, not on a schedule and not by place.
- If you deny the permission, the app keeps working: the alert still goes out, but your contacts stop seeing your route once you lock the screen.
About usage measurement
It exists for a concrete reason: of the first real accounts, more than half never had anyone on the other side, and there was no way to know why. A panic button nobody hears is useless, and until now we could not tell someone who never found the invite button from someone who invited and was not accepted.
- Never content. No group names, no messages, no location, nothing you wrote. Only the name of the step and closed codes. The server rejects any event outside a list of six, and drops the detail if it exceeds 200 characters.
- Never on the alert path. Nothing is measured when you trigger, respond or escalate. Measurement cannot compete for the network with an SOS.
- The country, and only the country. It is resolved from the IP address of the connection at the moment of the call, and the IP is never stored: there is no column to write it to. The most precise thing kept is "AR", "BR", "ES". GPS is not used for this and no new permission is requested: precise location in this app belongs to the emergency, not to statistics.
- It can be turned off in Settings → My account → Account and sign-in, under the "Help me improve the app" switch. The server checks that switch before storing anything, so turning it off takes effect immediately, even on older versions of the app.
- The open signal is at most once per hour, and if you delete your account the events permanently lose their link to you.
- Asking for a language is not measurement. If you use the screen to request a missing language, that request is stored even with measurement turned off: it is something you deliberately asked for.
What we do NOT do
- We do not sell or rent your data.
- No advertising inside the app.
- We do not share your location in the background.
- We do not read your phone contacts.
- We do not listen to the microphone or access the camera (except while scanning a QR).
Who data is shared with
Your alert, location and message reach only the members of the group you chose and your trusted contacts. Technical data (push token, session) is processed by Supabase (infrastructure) and Google FCM / Apple APNs (push delivery).
How long data is kept
Alerts and responses are kept while your account exists or the group remains active. If you delete your account from Profile → Danger zone, we permanently delete your profile, tokens, alerts, responses, trusted contacts, memberships and sessions.
Usage events are the exception: they are not deleted, they are unlinked. The row is left with no reference to you and becomes an anonymous number inside a total. We say so because it is a real difference: if your account goes, the count of "how many people got stuck here" does not go with it.
Your rights
- Access and rectification: from your Profile.
- Deletion: Profile → Danger zone → Delete my account.
- Portability: write to us to export your data.
Contact
Privacy questions or requests: contact@atseacode.dev