1. What This Policy Covers
This Data Policy describes how your personal data moves through Rakshya: how it is
collected, processed, stored, transferred, retained, and deleted. It works together with
our Privacy Policy, which explains your privacy rights
and how we protect your information.
2. Data We Collect
- Account data — Google account name, email, and avatar used for sign-in.
- Profile data — phone number and bio you add to your profile.
- Contact data — emergency contacts you add for notifications.
- Location data — GPS fixes collected during active tracking, background tracking, and SOS incidents.
- Incident data — SOS events, timestamps, and incident logs you create.
- Media data — audio and video recordings captured as evidence.
- Trip and ride data — routes, route deviations, and safe-zone alerts.
- Check-in data — scheduled check-ins, grace periods, and confirmations.
We do not collect any of this data passively for advertising or profiling.
3. How Data Is Collected
- By your explicit action — when you enter a contact, start a ride, schedule a check-in, or record video.
- By sensors you approve — GPS and microphone/camera access are always permission-gated and only used when you enable a feature.
- Through your account sync — on sign-in, Rakshya pulls your profile and encrypted backup blobs from your backend so data survives reinstalls.
4. How Data Is Processed and Stored
Rakshya stores sensitive data on-device and encrypts it with AES-256-GCM. Encryption keys
live only in the Android Keystore. The self-hosted backend stores only opaque encrypted
blobs and profile fields — it never receives or reads plaintext. SQLite is used for local
data, and the backend uses SQLite plus disk files for encrypted backups.
5. Where Data Is Stored
Data lives in two places:
- On your device — local database, encrypted files, and Android Keystore keys.
- On the backend you control — your own self-hosted Node.js backend stores encrypted blobs and profile fields. You choose and operate that backend.
Because the backend is self-hosted, you decide where it runs and who can access it.
6. How Data Is Shared
- Emergency contacts — see alerts and location only when you activate SOS or share live tracking.
- Emergency services — receive your call and whatever you disclose during an emergency call.
- Google — handles authentication; we receive only the account details you authorize.
- OpenStreetMap / Overpass — query for nearby safe places through a backend proxy.
Your plaintext data is never sold and never sent to the backend.
7. How Long Data Is Kept
- Profile and encrypted backup blobs are kept while your account is active.
- Incident logs, recordings, and location streams are kept as long as you choose to keep them.
- Location data not tied to an incident is stored only for the features that require it.
8. Deleting Your Data
You can delete your data in several ways:
- Delete individual records (contacts, rides, check-ins, recordings) from within the app.
- Stop and clear background tracking from the app's settings.
- Delete your profile and request removal of your encrypted blobs from the backend.
- Contact rakshyaapp@gmail.com to request account deletion.
After deletion, your encrypted blobs are removed from the backend and cannot be restored.
9. Data Security
- On-device AES-256-GCM encryption with keys in the Android Keystore.
- HTTPS for all network communication.
- Server-side verification of Google ID tokens and short-lived session JWTs.
- Opaque encrypted blobs on the backend mean plaintext is unreadable even if the backend is compromised.
10. Your Controls and Choices
- Grant or revoke location, microphone, and camera permissions at any time from Android settings.
- Choose which contacts are notified in an incident.
- Turn background tracking on or off.
- Export and decrypt evidence that belongs to you on your device.
11. Changes to This Policy
We may update this Data Policy as the app evolves. Revisions will be published here with a
new effective date and announced on rakshyaapp.github.io.
12. Contact Us
Questions about this Data Policy or your data can be sent to
rakshyaapp@gmail.com.