MYGUARDIANTM

Privacy Policy

MyGuardian is built to protect you. The same principle applies to your information. This policy explains what we collect, how we handle it, and the rights you have. It is written in plain language, with the precise terms that the law and the app stores require.

Effective April 21, 2026

01Our privacy commitment

MyGuardian, Inc. ("MyGuardian," "we," "us," or "our") provides a personal-safety application that lets you capture evidence, alert trusted contacts, access informational legal guidance, and broadcast your status when you need help. This Privacy Policy applies to the MyGuardian web app and any native iOS or Android app published under the MyGuardian name (together, the "Service").

We designed MyGuardian to work with as little information as possible. Whenever we can keep your data on your device, we do. When information must leave your device — for example, to notify a trusted contact or to back up an evidence bundle to your own cloud drive — we try to make sure it is encrypted in transit and under your direct control at the destination.

In one sentence The evidence you record stays on your device unless you choose to share it with the people you designate or back it up to your own Google Drive or iCloud. We do not sell your information, and we do not collect it to train advertising models.

02Information we collect

We collect the information below. Some of it is provided directly by you, some is generated by the Service when you use it, and some comes from the device's sensors and the operating system.

Account information

If you create an account with an email and password, your password is verified via Firebase Authentication using industry-standard salted hashing. MyGuardian never sees, stores, or has access to your plain-text password, and we cannot recover it. If you sign in with Google, Apple, or your phone number using Firebase Authentication, we receive the identifier and basic profile information that you approve at sign-in (typically name, email, and a provider-specific user ID).

Trusted contacts

You choose the people who receive alerts when you trigger an SOS, arrive-safely timer, or other broadcast event. For each contact you add, we store the name, relationship label, phone number or email address, and any role or notes you provide. We use that information only to deliver the messages you initiate, and only when you initiate them.

Evidence you capture

When you use the Service to record audio, record video, transcribe a conversation, or generate an incident bundle, the resulting media and metadata are created on your device. Unless you opt to back them up to your cloud drive, they remain on your device and are never uploaded to MyGuardian servers. Incident metadata typically includes the timestamp, approximate GPS coordinates (if you have granted location access), the language the transcript was captured in, a SHA-256 hash chain used to detect tampering, and a short plain-language summary you or the Service generates.

Device permissions and sensor signals

To perform its core functions the Service asks for access to your microphone (for audio evidence and transcription), camera (for video evidence), location (for geotagging and live-broadcast coordinates), and — where supported by your browser or operating system — your battery status and network type. These are requested only when a feature needs them, and you can revoke them in your browser or system settings at any time.

Diagnostic and crash information

To keep the app working reliably we may receive error logs containing a timestamp, the app version, a coarse device type (for example, "iPhone" or "Chrome desktop"), and the stack trace of the error. We do our best to strip personally identifying information from these logs.

What we do not collect

We do not use advertising SDKs. We do not sell your contact list. We do not build a behavioral profile of you for marketing. We do not read or scan the evidence you record. We do not collect biometric identifiers such as face-print or voice-print templates for identification purposes.

03How we use your information

We use the information we collect to provide, maintain, and improve the Service. That includes: authenticating you when you sign in; letting you create, view, and manage your trusted contacts and evidence; delivering the messages, share links, and alerts you initiate; responding to your questions and support requests; investigating abuse, fraud, or security incidents; and complying with our legal obligations.

If we ever want to use your information for a materially new purpose — for example, product analytics beyond crash reporting — we will update this policy and, where the law requires it, ask you to opt in before the new use begins.

04Where your information lives

MyGuardian is designed around a device-first architecture. Most of what you do lives on your device, in your browser's or app's secure local storage. Three additional destinations are possible, each only when you opt in.

Your Google Drive

If you connect Google Drive, the Service can upload your incident bundles to a folder named "MyGuardian Evidence" in your Drive. We request the narrowest OAuth scope required to write those files (drive.file), which grants us permission only to files the Service creates on your behalf. We cannot read the rest of your Drive, and you can revoke access at any time at myaccount.google.com/permissions.

iCloud and other drives you choose

On iOS and Android, you can use the system share sheet to save your evidence bundles to iCloud Drive, Dropbox, or any other destination you have installed. When you do that, the file leaves MyGuardian and becomes subject to the privacy policies of those services.

Firebase Authentication

If you sign in with Google, Apple, or phone number, we use Firebase Authentication (provided by Google LLC) to verify you. Firebase receives and stores your email address, provider-specific user ID, and authentication metadata. Firebase does not receive your evidence — only your identity. Firebase's data handling is governed by Google's Firebase Privacy and Security documentation.

05How we share your information

We share the categories of information above only in the following circumstances.

With people you designate

When you send an SOS, an arrive-safely check-in, a share link for an incident bundle, or any other outgoing message, we deliver it to the specific recipients you name. You control the recipient list in the Trusted Contacts screen, and you can remove anyone at any time.

With service providers who help us run MyGuardian

We use a small set of vendors — for example, a cloud-hosting provider for our marketing site, an email provider for transactional messages, and Firebase Authentication for identity. These vendors process information only on our behalf and under contractual confidentiality obligations. We do not sell, rent, or disclose your information to third parties for their own marketing purposes.

For legal and safety reasons

We may disclose information if we are required to do so by a valid subpoena, court order, or other legal process, or if we have a good-faith belief that disclosure is necessary to protect life, prevent serious injury, investigate fraud, or enforce our Terms of Service. We aim to give affected users notice of such requests where the law allows us to, and we aim to challenge requests that we believe are overbroad.

In a business transaction

If we are involved in a merger, acquisition, financing, or sale of some or all of our assets, your information may be transferred as part of that transaction. If that happens we will tell you and, where the law requires, give you a meaningful opportunity to object or delete your information before the transfer.

We do not sell or "share" your personal information

We do not sell personal information as "sale" is defined under the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), or comparable laws. We do not share personal information for cross-context behavioral advertising.

06Your California privacy rights

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") gives you specific rights. We honor these rights for all of our users, regardless of residency, to the extent practical.

What we collect, in CCPA categories

In the past twelve months we may have collected the following categories of personal information about California residents: identifiers (email, phone number, account ID); customer records (name, contact information); commercial information (subscription plan); internet or electronic network activity (session logs for the app); geolocation data (if you grant location permission); audio and visual information (if you record evidence); professional or employment information (if you provide a relationship label such as "colleague"); and inferences we draw from the above (for example, which features you rely on most). We collect these for the purposes described in Section 3.

Your rights

You have the right to know what personal information we hold about you and to receive a copy of it in a portable format. You have the right to request that we correct inaccurate information or delete information we hold about you, subject to the exceptions the law allows (for example, records we need to keep for legal or security reasons). You have the right to opt out of the "sale" or "sharing" of your personal information — we do not sell or share it, but we honor the right in any event. You have the right to limit our use of sensitive personal information to what is necessary to provide the Service, and we already do so by design.

How to exercise your rights

Email hello@myguardianinc.com with the subject line "California Privacy Request." Tell us what you would like us to do (for example, "send me a copy of my data" or "delete my account"). We will acknowledge your request within ten business days and substantively respond within forty-five days, as the CCPA requires. To protect your information we may ask you to verify your identity by confirming facts only you and we would know.

Authorized agents and non-discrimination

You can designate an authorized agent to make a request on your behalf. We will verify the agent's authority before we act. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercise a privacy right.

Shine the Light

California Civil Code §1798.83 permits California residents to request certain information about the disclosure of personal information to third parties for direct-marketing purposes. We do not disclose personal information to third parties for their direct-marketing use.

07Data retention

We keep your account information for as long as your account is active. If you delete your account, we delete or de-identify the account record within thirty days, except for records we are legally required to retain (for example, fraud and abuse logs, which we keep for no more than two years). The evidence you record lives on your device and, if you enabled backups, in your cloud drive — those files are not ours to delete. You can remove them directly from your device or from your Drive.

08Security

We take security seriously. Passwords are handled by Firebase Authentication using industry-standard salted hashing — MyGuardian never touches plain-text passwords. We serve the Service over HTTPS with a strict Content Security Policy. We request the minimum OAuth scopes required for each integration and authenticate users through industry-standard providers. No system is perfectly secure, but we work to keep ours at the current bar of good industry practice and we will publish a prompt, honest disclosure if a breach ever occurs.

How the hash chain works

Every incident recording is protected by a sequential SHA-256 hash chain so that any tampering with the evidence file is detectable. The chain is computed as follows: the genesis value H0 is 64 hex zeros. For each MediaRecorder data chunk that arrives in sequence, a chunk hash is computed as SHA-256(chunk bytes), then the chain is advanced: Hn = SHA-256(Hn−1 ∥ chunkHash), where ∥ denotes concatenation of the raw 32-byte values. The final HN is stored with the incident as a 64-character lowercase hexadecimal string. Any independent party with access to the original recording file can recompute the chain and compare it against the stored value. A mismatch indicates the file was altered after it was sealed.

09Children

MyGuardian is not directed to children under the age of thirteen, and we do not knowingly collect personal information from them. If you believe a child under thirteen has provided us with personal information, please contact us at the address below and we will delete it. For users between the ages of thirteen and seventeen, a parent or guardian should review this policy and our Terms of Service before the user signs up.

10Your choices and controls

You can remove a trusted contact at any time from the Trusted Contacts screen. You can revoke Google Drive access at myaccount.google.com/permissions. You can revoke microphone, camera, and location permissions in your browser or operating system settings. You can delete your account and all locally stored data by choosing Settings → Delete account in the app. You can reach a human at hello@myguardianinc.com for any of the above.

Export your data. You can request a complete copy of everything we have stored about you by choosing Settings → Privacy → Export my data in the app. Within approximately thirty seconds you will receive a downloadable archive containing your account information, every incident you have recorded (audio, video, transcript, GPS coordinates, hash chain), your trusted-contact list, your settings, and any Cloud Function usage logs. The export is for your records only — we do not retain a copy of the export file after you download it.

11Changes to this policy

If we change this policy we will update the effective date at the top of the page and, for material changes, give you notice inside the app and by email (if you have provided one) at least thirty days before the change takes effect. Your continued use of the Service after a change means you have accepted the update, but you can always delete your account if you do not agree.

12How to reach us

You can reach us by email at hello@myguardianinc.com. We read every message. Please include the word "privacy" in the subject line if your question is about this policy so that it reaches the right person quickly.

MyGuardian, Inc.
a Delaware corporation
Attn: Privacy
hello@myguardianinc.com