Privacy Policy
This Privacy Policy explains how Bailout collects, uses, and protects your information in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
Policy sections
Important Safety Notice
- 911 (USA, Canada)
- 112 (European Union, UK)
- 999 (UK, Ireland)
- 000 (Australia)
- Your local emergency services number
Our emergency alert feature is designed to notify your personal contacts and should not be relied upon as your sole safety measure. Always prioritize contacting official emergency services when you are in danger.
Who we are
Bailout is a personal safety application that schedules and places phone calls on your behalf. We act as the data controller for personal data you provide and the data processor for information handled when you use connected services.
Legal Entity: Bailout App
Contact Email: bailout_supp@gmail.com
Data Protection Officer: Available upon request at the email above.
Data we collect and legal basis
We collect data based on the following legal bases under GDPR Article 6:
Performance of Contract (Art. 6(1)(b))
- Account data: Email, password hash, and display name to create and manage your account.
- Phone number: Required to place scheduled calls to you.
- Scheduled calls: Call timing, caller name preferences, and scenarios.
- Subscription data: Plan type, usage limits, and billing cycle.
Consent (Art. 6(1)(a))
- Guardian contact: Name and phone number of your emergency contact (only if you enable emergency alerts).
- Location data: Geolocation coordinates (only if you enable location sharing in emergency alerts).
- Safety codeword: A secret word to trigger emergency alerts during calls.
Legitimate Interest (Art. 6(1)(f))
- Device data: Browser type, app version, and device identifiers for security and fraud prevention.
- Usage analytics: Aggregated, anonymized usage patterns to improve the service.
Third-party processors
We use the following trusted third-party services to operate Bailout:
- Supabase (Database & Auth): Stores your account data, alarms, and profile information. Data is encrypted at rest and in transit. Servers located in EU.
- Twilio (Voice & SMS): Places phone calls and sends SMS alerts. Processes your phone number and guardian's phone number when emergency alerts are triggered.
- Stripe (Payments): Processes subscription payments securely. We do not store full card details; Stripe handles all payment data.
- OpenAI (AI Conversations): Generates dynamic call conversations for premium users. No personal data is stored by OpenAI; only call scenarios are processed.
All processors are bound by Data Processing Agreements (DPAs) and comply with GDPR requirements.
How we protect your data
- Encryption: TLS 1.3 for data in transit; AES-256 encryption at rest for stored data.
- Access controls: Role-based access with multi-factor authentication for administrative access.
- Audit logging: All data access is logged and monitored for unauthorized access.
- Local encryption: Guardian contact and emergency settings are encrypted locally on your device.
- Regular backups: Automated backups with disaster recovery procedures.
- Security testing: Regular vulnerability assessments and penetration testing.
Data retention periods
- Account data: Retained until you delete your account or request deletion.
- Scheduled alarms: Automatically deleted 30 days after the alarm date passes.
- Call logs: Retained for 90 days for troubleshooting, then anonymized.
- Guardian alerts: Retained for 30 days, then automatically deleted.
- Payment records: Retained for 7 years as required by tax regulations.
- Local device data: Remains on your device until you clear the app data.
You may request deletion of your data at any time. We will process deletion requests within 30 days unless retention is required by law.
Your GDPR rights
Under GDPR, you have the following rights:
- Right of Access (Art. 15): Request a copy of all personal data we hold about you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete information.
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten").
- Right to Restrict Processing (Art. 18): Limit how we use your data.
- Right to Data Portability (Art. 20): Receive your data in a machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent for optional features at any time.
To exercise any of these rights, email us at bailout_supp@gmail.com. We will respond within 30 days.
International data transfers
Our primary data storage is within the European Economic Area (EEA). When data is transferred outside the EEA, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): Used for transfers to processors outside the EEA.
- Adequacy decisions: For countries recognized by the EU as providing adequate protection.
- EU-US Data Privacy Framework: For certified US processors.
Cookies and local storage
Bailout uses minimal cookies and local storage:
- Essential cookies: Authentication tokens required for the service to function.
- Local storage: Language preferences, encrypted guardian contact info, and emergency settings stored on your device.
We do not use advertising or tracking cookies. No third-party analytics cookies are used.
Contact and complaints
For privacy questions, data requests, or concerns, contact us at:
Email: bailout_supp@gmail.com
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority (DPA). For EU residents, you can find your DPA at edpb.europa.eu.