Legal

Privacy Policy

Effective date: September 25, 2026. This policy explains how the Rakshya app collects, protects, and handles your information.

1. Overview

Rakshya is a personal safety app designed to help you alert the people you trust and share your location in an emergency. Privacy is built into the app's architecture: sensitive data is encrypted on-device before it ever leaves your phone. This policy describes what information the app collects, why it is collected, and the choices you have.

2. Information We Collect

  • Account information — when you sign in with Google, we receive your Google account name, email address, and profile picture so you can use the app.
  • Profile information — information you choose to add, such as a phone number and bio.
  • Emergency contacts — the contacts you add for emergency notification. These are encrypted on-device.
  • Location data — GPS location while you use location features, background tracking you start, and SOS-flagged locations during an incident.
  • Incident and SOS data — details of incidents you start, including timestamps and location shared to your trusted contacts.
  • Audio and video recordings — recordings you capture as evidence during an emergency, encrypted on-device.
  • Ride and check-in data — ride routes, route-deviation events, and safety check-ins you schedule.

3. How We Use Your Information

We use the information above to provide and operate the app, including: allowing sign-in and data restore, sending SOS alerts and location to your emergency contacts, recording and encrypting incident evidence, tracking rides and check-ins, discovering nearby safe places, and maintaining the security, safety, and integrity of the service.

4. Encryption and On-Device Protection

Rakshya is built on a privacy-by-architecture model:

  • All sensitive data is encrypted on-device with AES-256-GCM.
  • Encryption keys are stored only in the Android Keystore on your device — they never leave your phone.
  • Your self-hosted backend stores only opaque encrypted blobs and never receives plaintext data.
  • Only you can decrypt your data, including videos recorded during emergencies.

5. Third-Party Services

  • Google — Google sign-in via Credential Manager. Google handles authentication and provides basic account details you authorize.
  • Self-hosted backend — a Node.js + Express + SQLite backend you control stores encrypted backup blobs and profile fields.
  • OpenStreetMap / Overpass — used to discover nearby hospitals, clinics, police, and fire stations through a backend proxy.

These services run under their own privacy policies, and we limit what is shared with each to the minimum needed.

6. Sharing Your Information

Rakshya does not sell your personal information. We share information only in these cases:

  • With your emergency contacts — when you activate SOS or share a live location, your chosen contacts see your alert and location.
  • With emergency services — when you call emergency numbers (for example 112) from the app, your call and any details you choose to disclose go to those services.
  • With service providers you operate — the self-hosted backend you run for backup and sync receives only encrypted blobs.
  • To comply with law — where required by law, legal process, or to protect rights and safety.

7. Data Retention

Encrypted backup blobs and profile data are retained for as long as your account is active. Recordings, incident data, and location streams tied to an incident are kept as long as you choose to keep them. You can delete data in-app or by requesting deletion, details below.

8. Your Privacy Rights

  • Access — request a summary of the data we hold.
  • Correction — update your profile data in-app at any time.
  • Deletion — delete your data in-app, or request account deletion and removal of backend blobs.
  • Data portability — your encrypted blobs can be exported and decrypted on your device.
  • Withdrawing consent — stop location sharing, tracking, and recording at any time from the app.

To exercise any of these rights, contact us at rakshyaapp@gmail.com.

9. Children's Privacy

Rakshya is intended for people who need personal safety support and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

10. Security

We use strong technical safeguards: AES-256-GCM on-device encryption with keys in the Android Keystore, HTTPS for all network communication, server-side verification of Google ID tokens, and session JWTs. The backend stores only opaque encrypted blobs, so even if it were compromised, your plaintext data remains unreadable.

11. Changes to This Policy

We may update this policy as the app evolves. Material changes will be reflected on this page with a new effective date. Significant changes will also be announced through the app or on rakshyaapp.github.io.

12. Contact Us

If you have questions about this policy or your data, contact: rakshyaapp@gmail.com.