This Privacy Policy explains how Brilicept Limited ("Amara", "we", "us") collects, uses, and protects your information when you use the Amara app and related services.
Amara is built around a simple principle: collect the least we need to keep you safe, and never sell your data. Everything below describes what the app actually does.
1Information we collect
Account details
- Your name: first and last, used to identify you in the alert your contacts receive.
- Email address: from the sign-in method you choose (email and password, Google, or Apple).
- Country and time zone: confirmed at setup. Country drives phone-number formatting and the region your alerts are sent from; time zone drives when your check-ins fire.
- Your plan: which Amara plan you are on, and how many contacts you have enrolled.
We do not ask for your date of birth, your home address, or your phone number.
Check-in settings
- Your check-in times, your mode (Off, Standard, or Interval) and interval length, and your sleep window.
- Your escalation timings: how long Amara waits at each step before moving to the next.
Your security codes
Your check-in code and your duress (panic) code are hashed: put through a one-way function - and only the hashes are stored, in a record your own device cannot read. We never store, log, or transmit either code in plain text, and we cannot recover them. We also keep a short-lived count of failed attempts so we can rate-limit guessing.
Your emergency contacts
- Phone contacts: the name, phone number, and relationship you enter for someone you enroll by phone number.
- Linked contacts: where your contact is also an Amara user, the link between your two accounts and their display name.
- Invitations: when you invite someone to be a linked contact, we store a single-use invite link, your display name, and when it was created, used, or revoked.
If you use your phone's contact picker to add someone, Amara receives only the name and number of the person you actually select. We do not read, upload, or store your address book.
Optional information you choose to add
- Health profile: free text you write yourself (for example allergies, a condition, or a blood type). Off by default.
- Emergency instructions: free text telling your contacts what to do or where to look, such as where a spare key is kept. Off by default.
- Location: your last known position. Off by default.
Health notes and emergency instructions are encrypted before they are stored, using a key held in Google Cloud KMS. Leave them blank and there is nothing to share.
Device and technical data
- Push notification tokens: the addresses your devices need in order to receive check-in prompts and alarms.
- Device region: a two-letter country code derived from your phone's settings, used only to decide which sponsor messages are eligible to show you. It is kept separately from your account country.
Amara contains no third-party analytics, advertising, or crash-reporting SDK. We do not track you across other apps or websites, and there is no advertising identifier in the app.
Records created as you use Amara
- Check-in history: each check-in cycle, whether you responded, and when.
- Escalation records: when an escalation ran, which contacts were notified, and whether it was cancelled.
- Access records: if a contact opens your emergency instructions during an escalation, we record who viewed them and when, and tell you.
- Security records: a log of significant account actions, such as changing your codes or deleting your account, so we can investigate problems.
- Sponsor message events: if a sponsor message is shown or tapped, we record the campaign, the country, the time, and your account identifier so we can report on it. These records contain nothing about your check-ins, contacts, health, or location.
2How we use your information
We use your information to run the check-in service, deliver reminders and alarms, escalate to your contacts when you miss a check-in, let you cancel a false alarm, keep your account secure, show country-relevant sponsor messages on non-safety screens, and diagnose and improve the Service.
We do not use your information to build advertising profiles, and we do not make automated decisions about you with legal or similarly significant effects.
3What your contacts can see
This is the part that matters most, so it is worth being precise. On any ordinary day, your contacts see nothing at all.
When an escalation reaches them, a contact receives a message containing your name, the fact that you have not responded, and, only if you turned them on, the time of your last check-in, a link to your last known location, and your health notes. A duress alert is marked so it is treated with the appropriate urgency.
- Emergency instructions are not included in that message. A linked contact can retrieve them only while your escalation is actually active, and only if they are still one of your contacts. You are notified whenever this happens, and told who did it.
- Your location is never shared continuously and is never visible to a contact outside an escalation.
- Your codes are never shared with anyone, in any circumstance.
You can remove a contact at any time, which ends their access.
4Device permissions
- Notifications: required, so Amara can prompt you and raise the alarm.
- Location: optional. When granted, your position is read when you open the app and around your check-in time, so a recent position is available if an escalation happens. Amara does not follow you in the background.
- Contacts: optional, on Android only, and only at the moment you use the contact picker to add someone.
You can withdraw any of these in your phone's settings, and turn location and health sharing off inside Amara at any time.
5When we share information
- Your emergency contacts: as described in section 3.
- Google Cloud Platform and Firebase: our hosting, database, authentication, encryption, and push notification provider. Your data is stored on servers in Europe.
- Our SMS provider: Termii by default, who deliver the text messages sent to phone contacts. They receive the contact's phone number and the content of the alert.
- Legal: where required by law or to protect someone's safety.
6Security
Your codes are hashed and verified only on our servers, never on your device, and attempts are rate-limited. Health notes and emergency instructions are encrypted with a managed key. Your account is protected by your sign-in credentials, and our database rules prevent one account from reading another's data. We use encryption in transit and at rest and restrict internal access to personal data.
7Data retention
We keep your information for as long as your account is active. When you delete your account, your sponsor message events are deleted along with everything else.
8Deleting your account
You can delete your account at any time from Settings → Manage account → Delete account. This erases your profile, your code hashes, your contacts, your check-in and escalation history, your health profile, your emergency instructions, and your sponsor message events, and cancels any pending escalation. It is immediate and cannot be undone. Step-by-step instructions are on our account deletion page.
We retain a minimal record that an account was deleted and when, and anything the law requires us to keep.
9Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal data, to object to certain processing, and to complain to your local data protection authority. To exercise these rights, contact us using the details below.
10Children's privacy
Amara is intended for adults and is not directed to children under 18. We do not knowingly collect data from children.
11Changes and contact
We may update this policy from time to time; material changes will be communicated in the app. Questions or requests? Contact us at amara@brilicept.com.
