Privacy Policy
Last updated: April 17, 2026 · Effective: April 17, 2026
- Who we are
- Scope
- Information we collect
- How we use your information
- Legal bases (GDPR/UK GDPR)
- How we share information
- Service providers (sub-processors)
- International data transfers
- Data retention
- Your rights
- California privacy rights
- Canadian privacy rights
- Security
- Children
- Contacts you add to Alert Arc
- Location data
- Push notifications
- Use of AI
- Changes to this policy
- Contact us
1. Who we are
Alert Arc (the "Service", "we", "us", or "our") is a critical-news alert application offered by Kristina Nemzer, an individual developer based in Canada ("Controller"). We are responsible as the data controller for the personal information described in this Privacy Policy.
If we incorporate a legal entity in the future, we will update this Policy accordingly and notify users of any material changes.
2. Scope
This Policy applies to personal information we collect through the Alert Arc mobile applications for iOS and Android, the alertarc.io website, and related services (together, the "Service"). It does not apply to third-party websites or services that the Service may link to, which have their own privacy practices.
3. Information we collect
3.1 Information you provide
- Account information: email address and password (hashed by our authentication provider). If you choose Sign in with Apple or Sign in with Google, we receive a verified email and a unique user identifier from those providers.
- Profile: optional display name.
- Contacts you add to Alert Arc: the alias/name and city you assign to each contact. See Section 15.
- Cities you monitor: the cities you choose to receive alerts for.
- Feedback and support: any messages, ratings, or feedback you send us in-app or by email.
- Payment information: if you purchase a subscription, payment is handled entirely by the Apple App Store or Google Play. We do not receive or store your card or bank details. We receive a transaction identifier and the subscription status.
3.2 Information collected automatically
- Device & push-notification identifiers: APNs (iOS) or FCM (Android) push tokens so we can deliver alerts; device model, OS version, app version, and language.
- Approximate or precise location: only if you enable the optional location-sharing feature. See Section 16.
- Log and diagnostic data: IP address (used transiently for security/abuse prevention and immediately discarded from application logs), request timestamps, and error diagnostics.
- Product analytics: aggregate, non-identifying usage counts (for example, number of alerts delivered, screen views) used to improve the Service.
3.3 What we do not collect
- We do not upload the contact list from your phone's address book. Only the contact entries you create inside Alert Arc (alias + city) are stored.
- We do not sell personal information.
- We do not use advertising identifiers or run ads.
4. How we use your information
| Purpose | Data used |
|---|---|
| Authenticate you and secure your account | email, password hash, provider IDs, IP |
| Deliver the core service (monitor cities, send alerts) | cities you monitor, contacts you add, push tokens |
| Optional location sharing between users you invite | location updates you choose to share |
| Process subscriptions and prevent fraud | store transaction IDs, subscription status |
| Customer support and responding to feedback | your messages and account identifiers |
| Security, abuse prevention, and legal compliance | IP, rate-limit events, diagnostic data |
| Improve the Service | aggregated, non-identifying usage metrics |
| Send essential service communications (security, billing, legal) | email address |
5. Legal bases for processing (EEA / UK)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data under the following legal bases under Articles 6 and 9 of the GDPR / UK GDPR:
- Performance of a contract (Art. 6(1)(b)) — to create your account, deliver alerts, and manage subscriptions.
- Consent (Art. 6(1)(a)) — for location sharing and optional push notifications. You may withdraw consent at any time in the app settings or your device settings.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent abuse, and improve features; balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — to comply with applicable laws (for example, tax and record-keeping for paid subscriptions).
6. How we share information
We share personal information only in the following circumstances:
- With service providers acting on our behalf under contract (see Section 7).
- Between users of the Service, but only to the extent you enable it. For example, if you accept a connection with another user and enable location sharing, your approximate or precise location is shared with that user until you disable it.
- For legal reasons — to comply with a lawful request, court order, or to protect rights, property, or safety of users or the public.
- Business transfers — if we merge, are acquired, or transfer assets, we will notify you and honor this Policy.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
7. Service providers (sub-processors)
We use the following processors to run the Service. Each is contractually bound to protect your information and to use it only for the purposes we specify.
| Provider | Purpose | Region |
|---|---|---|
| Supabase (Supabase Inc.) | Authentication, database, and backend services | US / EU (depending on project region) |
| Google Firebase (Google LLC) | Push notifications (FCM) | Global |
| Apple Inc. | Sign in with Apple, Apple Push Notification service, App Store purchases | US / Global |
| Google LLC (Sign in with Google, Play Billing) | Social sign-in, subscription billing for Android users | US / Global |
| OpenAI, L.L.C. | AI-assisted classification of public news items. See Section 18. | US |
| Vercel Inc. | Website hosting (alertarc.io) | US / Global CDN |
| Email delivery provider (for example, Mailgun/Postmark) | Transactional email (account verification, password reset) | US / EU |
8. International data transfers
Because we are based in Canada and our service providers operate globally, your personal information may be processed outside your country of residence, including in the United States and the European Union. Where required by law, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK Addendum, and equivalent mechanisms. You may request a copy of these safeguards by contacting us.
9. Data retention
- Account data is retained for as long as your account is active.
- When you delete your account, we delete or irreversibly anonymise your personal information within 30 days, except where we are required to retain it (for example, tax records for paid subscriptions for up to 6 years, or security logs for up to 12 months).
- Location updates are retained only for as long as needed to deliver the sharing feature; historical points older than 30 days are not stored.
- Diagnostic logs are retained for a maximum of 90 days.
10. Your rights
Depending on where you live, you have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you.
- Rectification — ask us to correct inaccurate or incomplete information.
- Deletion / erasure — ask us to delete your account and associated data. You can do this from the app's Settings screen (see our account deletion instructions) or by emailing us.
- Portability — receive a machine-readable copy of the personal information you provided.
- Restriction or objection — restrict or object to certain processing based on legitimate interests.
- Withdraw consent — at any time, without affecting the lawfulness of prior processing.
- Lodge a complaint with your local data protection authority. EEA users: see edpb.europa.eu. UK users: ico.org.uk.
To exercise any of these rights, email dev@alertarc.io. We will respond within 30 days (extendable by a further 60 days for complex requests, with notice). We may ask you to verify your identity before acting on a request.
11. California privacy rights (CCPA/CPRA)
If you are a California resident, in the 12 months preceding the "Last updated" date above we collected the categories of personal information described in Section 3 for the purposes described in Section 4. We do not sell or share personal information for cross-context behavioural advertising. You have the right to:
- Know what categories of personal information we have collected and the sources, purposes, and third parties with whom it is shared.
- Request deletion of personal information we collected from you.
- Request correction of inaccurate information.
- Limit use of sensitive personal information (we process precise location only for the feature you enabled).
- Not be discriminated against for exercising any of these rights.
You may submit a request by emailing dev@alertarc.io with the subject "California privacy request". An authorised agent may submit a request with your written permission.
12. Canadian privacy rights (PIPEDA / Québec Law 25)
Canadian residents have the right to access and correct their personal information and to withdraw consent, subject to legal or contractual restrictions. Québec residents have additional rights to data portability and to be informed of automated decision-making. We do not make solely-automated decisions that produce significant effects about individual users. Our privacy officer can be reached at dev@alertarc.io.
13. Security
We apply technical and organisational safeguards to protect your information, including:
- TLS encryption in transit between your device, our servers, and sub-processors.
- Encryption at rest for account and subscription data in our managed database.
- Password hashing using industry-standard algorithms (handled by our authentication provider).
- Access controls, principle-of-least-privilege, and audit logging.
- Rate limiting and abuse monitoring.
No system is perfectly secure. If we become aware of a personal-data breach likely to result in risk to your rights, we will notify affected users and the relevant supervisory authority without undue delay and, where feasible, within 72 hours, as required by applicable law.
14. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from anyone under that age. If you believe a child has provided us with personal information, please contact dev@alertarc.io and we will delete the account.
15. Contacts you add to Alert Arc
Alert Arc lets you build a list of people you care about and the cities they live in, so we can alert you when something critical happens there. Important points:
- We do not read or upload your phone's address book.
- Only the alias and city you type into Alert Arc are stored. Unless the person you add also installs Alert Arc and accepts a connection request, they are not a user of the Service and have no account with us.
- If you type another person's real name as the alias, you are responsible for ensuring you have a lawful basis for doing so. Please use a nickname if you are uncertain.
- If you are added by another user as one of their contacts, we do not create any account or data record for you until you install Alert Arc and sign up yourself.
16. Location data
- Location sharing is off by default. It is activated only when you explicitly enable it and grant the operating-system permission.
- When enabled, your location is shared only with users you have accepted a connection with. You can stop sharing at any time from the app's Location Sharing screen or by revoking the permission in your device settings.
- We use location solely to deliver the sharing feature and for city-matching for your own alerts. We do not use location for advertising or for any purpose unrelated to the Service.
- We do not retain historical location tracks beyond what is needed for the feature (see Section 9).
17. Push notifications
We use Apple Push Notification service (iOS) and Firebase Cloud Messaging (Android) to deliver critical-event alerts. You can disable notifications at any time from your device settings. Notification payloads are minimised and transmitted in encrypted form; however, these are delivered via Apple and Google platforms, which have their own privacy policies.
18. Use of AI
Our backend pipeline uses large-language-model services (including OpenAI) to classify public news content — for example, to determine whether a news item is critical and which city it refers to. We do not send your email, name, contacts' names, or other personal information to these models as part of that classification. Outputs are reviewed by deterministic filters before we decide whether to alert you. We do not rely solely on automated decision-making to make decisions that produce legal or similarly significant effects about you.
19. Changes to this policy
We may update this Policy from time to time. When we make material changes, we will revise the "Last updated" date at the top and, where required, notify you by email or in-app notice before the changes take effect. Your continued use of the Service after the changes take effect constitutes acceptance of the revised Policy.
20. Contact us
For any question, request, or complaint about this Policy or your personal information, please contact:
Kristina Nemzer — Alert Arc
Email: dev@alertarc.io
Website: https://alertarc.io
See also: Terms of Service · Delete account · Home