Last updated: December 2025

    Privacy Policy

    This Privacy Policy explains how Bailout collects, uses, and protects your information in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.

    Policy sections

    Who we are

    Bailout is a personal safety application that schedules and places phone calls on your behalf. We act as the data controller for personal data you provide and the data processor for information handled when you use connected services.

    Legal Entity: Bailout App
    Contact Email: bailout_supp@gmail.com
    Data Protection Officer: Available upon request at the email above.

    Data we collect and legal basis

    We collect data based on the following legal bases under GDPR Article 6:

    Performance of Contract (Art. 6(1)(b))

    • Account data: Email, password hash, and display name to create and manage your account.
    • Phone number: Required to place scheduled calls to you.
    • Scheduled calls: Call timing, caller name preferences, and scenarios.
    • Subscription data: Plan type, usage limits, and billing cycle.

    Consent (Art. 6(1)(a))

    • Guardian contact: Name and phone number of your emergency contact (only if you enable emergency alerts).
    • Location data: Geolocation coordinates (only if you enable location sharing in emergency alerts).
    • Safety codeword: A secret word to trigger emergency alerts during calls.

    Legitimate Interest (Art. 6(1)(f))

    • Device data: Browser type, app version, and device identifiers for security and fraud prevention.
    • Usage analytics: Aggregated, anonymized usage patterns to improve the service.

    Third-party processors

    We use the following trusted third-party services to operate Bailout:

    • Supabase (Database & Auth): Stores your account data, alarms, and profile information. Data is encrypted at rest and in transit. Servers located in EU.
    • Twilio (Voice & SMS): Places phone calls and sends SMS alerts. Processes your phone number and guardian's phone number when emergency alerts are triggered.
    • Stripe (Payments): Processes subscription payments securely. We do not store full card details; Stripe handles all payment data.
    • OpenAI (AI Conversations): Generates dynamic call conversations for premium users. No personal data is stored by OpenAI; only call scenarios are processed.

    All processors are bound by Data Processing Agreements (DPAs) and comply with GDPR requirements.

    How we protect your data

    • Encryption: TLS 1.3 for data in transit; AES-256 encryption at rest for stored data.
    • Access controls: Role-based access with multi-factor authentication for administrative access.
    • Audit logging: All data access is logged and monitored for unauthorized access.
    • Local encryption: Guardian contact and emergency settings are encrypted locally on your device.
    • Regular backups: Automated backups with disaster recovery procedures.
    • Security testing: Regular vulnerability assessments and penetration testing.

    Data retention periods

    • Account data: Retained until you delete your account or request deletion.
    • Scheduled alarms: Automatically deleted 30 days after the alarm date passes.
    • Call logs: Retained for 90 days for troubleshooting, then anonymized.
    • Guardian alerts: Retained for 30 days, then automatically deleted.
    • Payment records: Retained for 7 years as required by tax regulations.
    • Local device data: Remains on your device until you clear the app data.

    You may request deletion of your data at any time. We will process deletion requests within 30 days unless retention is required by law.

    Your GDPR rights

    Under GDPR, you have the following rights:

    • Right of Access (Art. 15): Request a copy of all personal data we hold about you.
    • Right to Rectification (Art. 16): Correct inaccurate or incomplete information.
    • Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten").
    • Right to Restrict Processing (Art. 18): Limit how we use your data.
    • Right to Data Portability (Art. 20): Receive your data in a machine-readable format.
    • Right to Object (Art. 21): Object to processing based on legitimate interests.
    • Right to Withdraw Consent: Withdraw consent for optional features at any time.

    To exercise any of these rights, email us at bailout_supp@gmail.com. We will respond within 30 days.

    International data transfers

    Our primary data storage is within the European Economic Area (EEA). When data is transferred outside the EEA, we ensure appropriate safeguards are in place:

    • Standard Contractual Clauses (SCCs): Used for transfers to processors outside the EEA.
    • Adequacy decisions: For countries recognized by the EU as providing adequate protection.
    • EU-US Data Privacy Framework: For certified US processors.

    Cookies and local storage

    Bailout uses minimal cookies and local storage:

    • Essential cookies: Authentication tokens required for the service to function.
    • Local storage: Language preferences, encrypted guardian contact info, and emergency settings stored on your device.

    We do not use advertising or tracking cookies. No third-party analytics cookies are used.

    Contact and complaints

    For privacy questions, data requests, or concerns, contact us at:

    Email: bailout_supp@gmail.com

    If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority (DPA). For EU residents, you can find your DPA at edpb.europa.eu.