1. Overview
Rakshya is a personal safety app designed to help you alert the people you trust and share
your location in an emergency. Privacy is built into the app's architecture: sensitive data
is encrypted on-device before it ever leaves your phone. This policy describes what
information the app collects, why it is collected, and the choices you have.
2. Information We Collect
- Account information — when you sign in with Google, we receive your Google account name, email address, and profile picture so you can use the app.
- Profile information — information you choose to add, such as a phone number and bio.
- Emergency contacts — the contacts you add for emergency notification. These are encrypted on-device.
- Location data — GPS location while you use location features, background tracking you start, and SOS-flagged locations during an incident.
- Incident and SOS data — details of incidents you start, including timestamps and location shared to your trusted contacts.
- Audio and video recordings — recordings you capture as evidence during an emergency, encrypted on-device.
- Ride and check-in data — ride routes, route-deviation events, and safety check-ins you schedule.
3. How We Use Your Information
We use the information above to provide and operate the app, including: allowing sign-in and
data restore, sending SOS alerts and location to your emergency contacts, recording and
encrypting incident evidence, tracking rides and check-ins, discovering nearby safe places,
and maintaining the security, safety, and integrity of the service.
4. Encryption and On-Device Protection
Rakshya is built on a privacy-by-architecture model:
- All sensitive data is encrypted on-device with AES-256-GCM.
- Encryption keys are stored only in the Android Keystore on your device — they never leave your phone.
- Your self-hosted backend stores only opaque encrypted blobs and never receives plaintext data.
- Only you can decrypt your data, including videos recorded during emergencies.
5. Third-Party Services
- Google — Google sign-in via Credential Manager. Google handles authentication and provides basic account details you authorize.
- Self-hosted backend — a Node.js + Express + SQLite backend you control stores encrypted backup blobs and profile fields.
- OpenStreetMap / Overpass — used to discover nearby hospitals, clinics, police, and fire stations through a backend proxy.
These services run under their own privacy policies, and we limit what is shared with each to the minimum needed.
6. Sharing Your Information
Rakshya does not sell your personal information. We share information only in these cases:
- With your emergency contacts — when you activate SOS or share a live location, your chosen contacts see your alert and location.
- With emergency services — when you call emergency numbers (for example 112) from the app, your call and any details you choose to disclose go to those services.
- With service providers you operate — the self-hosted backend you run for backup and sync receives only encrypted blobs.
- To comply with law — where required by law, legal process, or to protect rights and safety.
7. Data Retention
Encrypted backup blobs and profile data are retained for as long as your account is active.
Recordings, incident data, and location streams tied to an incident are kept as long as you
choose to keep them. You can delete data in-app or by requesting deletion, details below.
8. Your Privacy Rights
- Access — request a summary of the data we hold.
- Correction — update your profile data in-app at any time.
- Deletion — delete your data in-app, or request account deletion and removal of backend blobs.
- Data portability — your encrypted blobs can be exported and decrypted on your device.
- Withdrawing consent — stop location sharing, tracking, and recording at any time from the app.
To exercise any of these rights, contact us at rakshyaapp@gmail.com.
9. Children's Privacy
Rakshya is intended for people who need personal safety support and is not directed at
children. We do not knowingly collect personal information from children. If you believe a
child has provided us with personal information, contact us and we will delete it.
10. Security
We use strong technical safeguards: AES-256-GCM on-device encryption with keys in the
Android Keystore, HTTPS for all network communication, server-side verification of Google
ID tokens, and session JWTs. The backend stores only opaque encrypted blobs, so even if it
were compromised, your plaintext data remains unreadable.
11. Changes to This Policy
We may update this policy as the app evolves. Material changes will be reflected on this
page with a new effective date. Significant changes will also be announced through the app
or on rakshyaapp.github.io.
12. Contact Us
If you have questions about this policy or your data, contact:
rakshyaapp@gmail.com.