1. Who we are
Wardeny is operated by [LEGAL ENTITY NAME], registered in Spain under registration number [REGISTRATION NUMBER]. We are the data controller for the personal data described in this policy.
You can reach us at any time at privacy@wardeny.com.
2. What this policy covers
This policy explains how we collect and use personal data when you use Wardeny — including the web app, Android app and iOS app — and all features within it: SOS alerts, community alerts, group coordination, chat, kit management, explore and profile.
3. Data we collect
- Account data: email address and display name when you register. Guest sessions use only a temporary display name and a socket ID.
- Location data: GPS coordinates (coarse or precise) that you share during an active SOS alert or group session. We do not continuously track your position in the background and do not persist location beyond the session in which it was shared.
- Push notification data: VAPID endpoint URL, encryption keys and device user-agent, stored to deliver push notifications to your device.
- Communications: chat messages you send within a group. Walkie-talkie audio is relayed in real time and is not stored on our servers.
- Device and usage data: IP address, browser and operating-system user-agent, page loads and error logs, collected automatically when you access the service.
- Sensitive data: medical kit contents you choose to record in the Kit feature. Providing this data is entirely optional and voluntary.
We do not sell personal data. We do not run advertising.
4. Why we process your data (legal bases)
- Contract performance (GDPR Art. 6(1)(b)): account data, location during SOS/group sessions and chat messages are processed to provide the core service you signed up for. Without this processing the service cannot function.
- Legitimate interests (GDPR Art. 6(1)(f)): server logs, IP addresses and error data are processed to secure the platform, detect and prevent abuse, and debug failures. Our interest in operating a safe and reliable service is not overridden by your rights and freedoms, given the limited nature of the data and the security benefit.
- Consent (GDPR Art. 6(1)(a)): push notifications, precise location sharing and any optional analytics are only collected after you give explicit consent through our in-app consent banner. You can withdraw consent at any time without affecting prior processing (Art. 7(3)) — see §13 below.
5. How long we keep data
- Account data: retained while your account exists, then deleted within 30 days of account deletion (including backup purge).
- Location data: not persisted beyond the SOS or group session in which it was shared.
- Chat messages: retained for 30 days on our servers, then automatically deleted.
- Push subscriptions: retained until you revoke notification permission in your browser or OS, or until you delete your account.
- Server and security logs: retained for 90 days, then deleted.
- Walkie-talkie audio: relayed in real time only; never stored.
6. Who we share data with
We use the following sub-processors to operate the service. Each is bound by a data processing agreement to process data only as instructed and to maintain appropriate technical and organisational security measures.
- Supabase (EU region — AWS eu-west-1): Postgres database and authentication.
- Vercel: SPA hosting and global edge delivery network.
- Resend: transactional email delivery (e.g. password reset, account confirmation).
The full, current list of sub-processors is published at /legal/subprocessors.
We also share data with other Wardeny users in your group when you opt in to location or SOS sharing — this is the core purpose of the feature. We disclose data to competent authorities only when legally compelled.
We do not sell, rent or trade personal data with any third party for commercial purposes.
7. Your rights
As a data subject under the GDPR you have the following rights, exercisable at no charge:
- Access (Art. 15): obtain a copy of all personal data we hold about you.
- Rectification (Art. 16): ask us to correct inaccurate or incomplete data.
- Erasure (Art. 17): ask us to delete your data where there is no overriding legal ground to retain it.
- Restriction (Art. 18): ask us to pause processing while a dispute or objection is resolved.
- Portability (Art. 20): receive your data in a structured, machine-readable format (JSON) and transfer it to another controller.
- Objection (Art. 21): object to processing carried out on the basis of legitimate interests.
- Withdraw consent: for any processing based on consent (push notifications, precise location, analytics), withdraw at any time without affecting prior lawful processing (Art. 7(3)).
How to exercise your rights:
- Export your data (Art. 20): use the “Export my data” button in your profile, or call
GET /api/v1/me/export. You will receive a JSON file with every record we hold about you. - Delete your account (Art. 17): use the “Delete account” control in your profile, or call
DELETE /api/v1/me. Backups are purged within 30 days. - For anything else, email privacy@wardeny.com. We respond within 30 calendar days.
You also have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD) at www.aepd.es, or with the supervisory authority in your country of residence.
8. Cookies and similar storage
- Essential storage (cannot be disabled):
wardeny_consent_v1stores your consent choices;wardeny_siren_enabledstores your siren preference; a service-worker cache (wardeny-api-v1) caches public API responses so features work offline. These are strictly necessary and require no consent. - Optional analytics (consent required): if you consent, anonymous usage events may be collected to help us understand how features are used and how to improve them. No personally identifying data is sent to analytics. You can withdraw consent at any time via the button below.
No advertising cookies or cross-site tracking are used.
9. International data transfers
Our primary database runs on Supabase in the EU (AWS eu-west-1), so the majority of your data does not leave the European Economic Area. The following transfers outside the EEA do occur:
- Resend (US): transactional emails may transit through Resend servers located outside the EEA. These transfers are covered by Standard Contractual Clauses (SCC) approved by the European Commission under Article 46 GDPR.
- Vercel (US/global CDN): the static SPA is served from Vercel's global edge network. Vercel is certified under the EU–US Data Privacy Framework and these transfers are additionally covered by SCC.
Copies of the applicable SCCs are available on request at privacy@wardeny.com.
10. Children
Wardeny is not directed to children under 16. We do not knowingly collect personal data from anyone under that age. If you believe a minor has provided personal data without verifiable parental consent, please contact us at privacy@wardeny.com and we will delete it promptly.
11. Security
We use HTTPS for all data in transit, rate limiting on all public endpoints, Helmet security headers, authentication on admin-only broadcast endpoints and regular dependency audits to protect your data. No security measure is perfect — if you discover a vulnerability, please disclose it responsibly by following the process in SECURITY.md in our public repository.
12. Wardeny is not 112 / 911
Wardeny is a community-coordination platform. It does not dispatch emergency responders and does not guarantee message delivery. In any life-threatening emergency, call your official emergency services immediately — 112 in the EU, 911 in the US, 999 in the UK.
13. Changes to this policy
We will publish material changes at least 30 days before they take effect via an in-app banner. The date of the current version appears at the top of this page. Continued use of Wardeny after the effective date of a change constitutes acceptance of the updated policy. The latest version is always available at /legal/privacy.
14. Contact
Data controller: [LEGAL ENTITY NAME] — privacy@wardeny.com
Manage your consent
You may withdraw consent for optional processing (location, push notifications, microphone) at any time. Revoking your consent does not affect the lawfulness of processing carried out before the revocation (GDPR Art. 7(3)).