Privacy Policy
Last updated: July 28, 2026 — covers v1.18.0
Dawnwren ("the App") is a wellness check-in application designed for aging adults and their caregivers. Your privacy is important to us. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
Account Data
- Email address and password — used for authentication via Firebase Auth. Passwords are hashed and never stored in plain text.
- Display name — optional, shown to caregivers.
Check-in Data
- Check-in timestamps and status (ok / help) — stored in Google Cloud Firestore to track your wellness history and trigger caregiver notifications.
- Streak data — calculated from check-in history.
Health Data (Android only, optional)
- Heart rate, steps, activity data — read from Android Health Connect with your explicit permission. Used only to verify wellness and detect potential emergencies.
- BLE smartwatch readings — heart rate from paired Bluetooth devices. Stored locally only.
- Health data is never sold, shared with advertisers, or used for profiling.
Emergency Contacts
- Names, phone numbers, email addresses, and relationships — the primary copy is stored on your device (SharedPreferences), and is also mirrored to our secure Firestore database so that, if you miss check-ins and escalation reaches its final stage, our backend can email your emergency contacts on your behalf (and, for premium users, send them an SMS text message via our messaging provider). The Help button itself still sends SMS / Telegram from your own device.
Device Data
- FCM token — Firebase Cloud Messaging token for push notifications. Stored in Firestore, deleted on sign-out.
- Last seen timestamp — used for device-offline detection to alert caregivers if your device may be off.
- Timezone — used for sleep-aware escalation scheduling. Stored in Firestore.
- Crash and error logs — collected via Firebase Crashlytics to diagnose stability issues and improve reliability.
Notifications and Transition History
- In-app notifications — when you (or your care recipient) misses a check-in, an alert document is written to your inbox in Firestore. You can read it under Settings → Notifications, mark it as read, or delete it.
- Escalation history — every state-machine transition (for example, OK → GRACE, FINAL_WARNING → ESCALATED) is recorded in a per-user audit trail under Settings → Escalation History. This is so you can always see exactly when an alert fired and who was notified.
- Read notifications older than 30 days and transitions older than 90 days are automatically deleted by an automated cleanup task.
2. How We Use Your Data
- Wellness monitoring — check-in tracking, streak calculation, and health status display.
- Caregiver notifications — if you miss a check-in, your linked caregivers receive push notifications through a rule-based escalation system, AND an in-app notification record they can read in their Notifications inbox.
- Emergency alerts — when you press the Help button, your emergency contacts are notified via SMS or Telegram from your device's native share sheet (your phone sends those). Separately, if you miss check-ins and escalation reaches its final stage, our backend may email your emergency contacts and caregivers on your behalf (via our email provider), and for premium users may also send them an SMS text message (via our messaging provider), so they can reach you.
- Health alerts — abnormal health readings trigger caregiver notifications via Cloud Functions.
- Audit trail — every state transition (caregiver alert fired, your status changed) is logged so you can review what happened under Settings → Escalation History.
3. Data Storage and Security
- Account and check-in data is stored in Google Cloud Firestore (Google Cloud Platform), protected by Firebase security rules.
- Emergency contacts are stored on your device (primary copy) and mirrored to Firestore so the backend can notify them on escalation; the cloud copy is protected by Firebase security rules.
- All network communication uses HTTPS/TLS encryption.
- Authentication is handled by Firebase Auth with industry-standard security.
4. Data Sharing
- We do not sell your data to third parties.
- We do not use your data for advertising or profiling.
- Your check-in status is shared only with caregivers you explicitly link via email.
- Health alert notifications are sent only to your linked caregivers.
5. Third-Party Services
- Firebase (Google) — authentication, database, cloud functions, push notifications, analytics.
- Adapty — subscription management (processes purchase data only).
- Android Health Connect — health data access (data stays on device and in our Firestore).
6. Your Rights
- Access — you can view all your data in the app (check-in history, settings, contacts).
- Export — use Settings > Backup & Restore to export all your data as JSON.
- Delete — contact us to request full account and data deletion.
- Revoke permissions — you can revoke Health Connect permissions at any time in Android Settings.
7. Children's Privacy
The App is designed for adults and is not intended for children under 13. We do not knowingly collect data from children.
8. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.
9. Contact
For privacy questions or data deletion requests, contact us at: support@getstillokay.com