Overview
Beacon (“we”, “us”, or “our”) operates the Beacon mobile application (available on iOS and Android) and the Beacon administration portal. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data.
By using Beacon, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the app or services.
Data we collect
Account information
- Email address — used to create and authenticate your account.
- Display name — shown to other users in chat and incident reports.
- Profile photo — optional, uploaded by you.
- Campus affiliation — the campus you select during registration.
- Role — student/staff, safety officer, or campus administrator.
Location data
Beacon requests access to your precise location, including background location access on devices where you grant it. See the Location data section below for full details.
Health and medical data
You may optionally provide medical information to assist first responders during an emergency. See the Health & medical data section for details.
Emergency contacts
- Names and phone numbers of people you designate as emergency contacts.
- These are stored securely and only surfaced to authorized safety officers during an active emergency.
Communications
- Chat messages — messages you send through Beacon’s safety chat feature, including text and any files or images you attach.
- Incident reports — descriptions, photos, and location data you submit when reporting a safety incident.
- Virtual escort sessions — route and duration data while an escort session is active.
Device and technical data
- Push notification token — a device-specific identifier used to deliver emergency alerts to your device.
- Device type and OS version — collected for app compatibility and crash reporting.
- App version — to ensure you are running a supported version.
- Session and login timestamps — for security and to show your last active time to campus administrators.
- Crash reports and error logs — collected automatically via Sentry and Firebase Crashlytics to help us fix bugs. These may include device state at the time of a crash but do not include message content.
Usage analytics
We collect anonymised usage events (for example: “emergency reported”, “map viewed”, “notification tapped”) via Firebase Analytics to understand how the app is used and where to improve it. These events are not linked to personally identifiable information.
Information we do NOT collect
- We do not collect payment information.
- We do not track your contacts list — we only access it temporarily on-device when you choose to add an emergency contact from your phonebook, and we do not upload your contacts to our servers.
- We do not collect biometric data (face ID, fingerprints).
- We do not build advertising profiles.
How we use your data
- Providing the service — authenticating you, showing campus-relevant content, enabling safety chat and incident reporting.
- Emergency response — sharing your location and medical profile with authorised safety officers when you activate an emergency or when an incident is reported near you.
- Push notifications — sending you emergency alerts, campus announcements, and chat replies relevant to your campus and role.
- Safety and security — detecting and preventing abuse, fraudulent accounts, and violations of our Terms of Service.
- App improvement — anonymised analytics and crash reports help us identify and fix problems.
- Communication — sending you important service announcements (account changes, policy updates). We do not send marketing emails.
- Legal compliance — responding to lawful requests from law enforcement or courts where required.
Data sharing & third parties
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
Within your campus
Authorised campus safety officers and administrators at your institution can see incident reports you submit, your active location during an emergency session you initiate, and basic profile information (name, photo, role). They cannot see your medical information unless you activate an emergency that triggers disclosure.
Service providers
We use the following third-party services to operate Beacon. Each acts as a data processor under applicable law and is contractually required to protect your data:
- Supabase (United States) — our primary database, authentication, and file storage provider. Your account data, messages, incident reports, and uploaded files are stored on Supabase infrastructure hosted on AWS. Supabase is SOC 2 Type II certified. Supabase Privacy Policy.
- Google Firebase / Firebase Cloud Messaging (FCM) (United States) — used exclusively to deliver push notifications to your device. FCM receives your push notification token and the notification payload. Firebase is operated by Google and is subject to Google’s Privacy Policy.
- Expo / EAS (United States) — the platform used to build, distribute, and deliver over-the-air updates to the Beacon mobile app. Expo may process device identifiers during the update process. Expo Privacy Policy.
- Cloudflare (United States) — used as a secure relay for push notification delivery. Cloudflare processes notification content and push tokens in transit but does not store them. Cloudflare Privacy Policy.
- Sentry (United States) — crash reporting and error monitoring for the mobile app and admin portal. Sentry Privacy Policy.
- Google Firebase Analytics & Crashlytics (United States) — anonymised usage analytics and native crash reporting. Firebase Privacy.
Legal requirements
We may disclose your information if required to do so by law, court order, or government authority, or if we believe disclosure is necessary to protect the safety of any person.
Business transfers
If Beacon is acquired or merges with another organisation, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
Location data
Location access is central to Beacon’s safety mission. Here is exactly what we collect and why:
- While using the app (“When in Use”): We collect your precise location to show nearby incidents and threats on the campus map, and to provide directions to safe zones during emergencies.
- Background location (“Always”): On devices where you grant Always permission, we access your location in the background to provide real-time safety updates during active emergency or escort sessions, and to alert you to threats near your location even when the app is closed. We only process background location when an active emergency or escort session is in progress, or when a campus-wide alert has been issued.
Location data associated with a specific session is retained for the duration of that session and deleted within 90 days unless it forms part of an incident report required for safety investigation.
You can revoke location permission at any time in your device Settings. Revoking location access will limit some safety features but will not prevent you from using the app.
Health & medical data
Beacon allows you to optionally store sensitive health information in your profile — including blood type, known allergies, current medications, and other details relevant to emergency medical response. This is entirely optional.
- Medical data is encrypted at rest and in transit.
- It is only accessible to you and to authorised safety officers when you activate an emergency that makes disclosure appropriate.
- It is never used for analytics, advertising, or shared with third parties beyond emergency responders at your campus.
- You can view, edit, or delete your medical profile at any time from the app’s Profile settings.
Push notifications
Beacon uses push notifications to deliver emergency alerts, campus announcements, and chat replies. To do this, we store a push notification token for each device on which you have enabled notifications.
- Push tokens are specific to your device and Beacon account. They are deleted when you sign out or delete your account.
- Notifications are delivered via Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS).
- You can disable notifications at any time in your device Settings or in the Beacon app. Emergency alerts may still display as in-app banners when the app is open.
Contacts access
Beacon requests access to your device contacts solely to make it easier for you to add emergency contacts from your phonebook. This access is used on-device only — we do not upload, store, or transmit your contacts list to our servers. We only store the specific name and phone number of contacts you explicitly choose to designate as emergency contacts within the app.
You can deny contacts access and manually enter emergency contact details instead. Denying contacts access does not affect any other app functionality.
Data storage & security
All personal data is stored on Supabase infrastructure hosted on Amazon Web Services (AWS) in the United States. We use the following security measures:
- All data is encrypted in transit using TLS 1.2 or higher.
- Sensitive data (medical information, passwords) is encrypted at rest.
- Database access is controlled by Row-Level Security (RLS) policies — each user can only access their own data unless they hold an authorised administrative role.
- Administrative access to the Beacon admin portal requires multi-factor authentication.
- We conduct regular security reviews and apply security patches promptly.
No method of electronic transmission or storage is 100% secure. While we take every reasonable precaution, we cannot guarantee absolute security. If you discover a security vulnerability, please report it responsibly to security@beaconresponseplatform.app.
Data retention
- Account data — retained until you delete your account.
- Chat messages and incident reports — retained for up to 12 months after the session or incident closes, or as required by your institution’s safety record-keeping obligations.
- Location session data — deleted within 90 days of the session ending unless part of an open incident report.
- Push tokens — deleted immediately on sign-out or account deletion.
- Crash reports and analytics — retained for 90 days in Sentry and Firebase, then automatically deleted.
- Deleted account data — upon account deletion, your profile and associated data are removed from our live systems within 30 days. Anonymised aggregate data (e.g. incident counts) may be retained in analytics systems indefinitely.
Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — correct inaccurate or incomplete data. You can update most of your profile information directly in the app.
- Deletion — request deletion of your personal data. You can delete your account directly in the app (Profile → Delete Account) or by contacting us. Deletion removes your profile, messages, and associated data from our live systems within 30 days.
- Portability — request an export of your data in a machine-readable format.
- Objection — object to certain processing of your data, including analytics.
- Withdrawal of consent — where processing is based on consent (e.g. location access, medical data), you may withdraw consent at any time.
To exercise any of these rights, contact us at privacy@beaconresponseplatform.app. We will respond within 30 days.
If you are in the European Economic Area (EEA), you also have the right to lodge a complaint with your local data protection authority.
Children’s privacy
Beacon is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at privacy@beaconresponseplatform.app and we will delete that information promptly.
For users between 13 and 18, we recommend that a parent or guardian review this Privacy Policy. Campus deployments of Beacon for institutions with minor students should ensure appropriate institutional consent procedures are in place.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Last updated” date at the top of this page.
- Send a push notification to all active users if the change affects how we use personal data.
- For significant changes, require you to review and acknowledge the new policy before continuing to use the app.
Continued use of Beacon after changes take effect constitutes acceptance of the updated policy.
Contact us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Email: privacy@beaconresponseplatform.app
- General inquiries: hello@beaconresponseplatform.app
- Security disclosures: security@beaconresponseplatform.app
We aim to respond to all privacy-related enquiries within 30 days.