Privacy Policy
Nirapod is a community-powered safety intelligence platform. Users report incidents, the system aggregates those reports into geographic risk zones, and people nearby receive safety alerts. This policy explains what data we collect, why we collect it, how long we keep it, who it is shared with, and how you can access or delete it.
1. Information We Collect
1.1 Information you provide
- Account details — name, email address and, optionally, a phone number and profile photo. If you sign in with Google or Apple, we receive the name and email address released by that provider (Apple users may choose to hide their real email address, in which case we only receive Apple's private relay address).
- Incident reports — the category, title, description, GPS coordinates, derived address and any photo you attach.
- Community content — posts, comments and likes on the community wall.
- Verification activity — your confirm or flag votes on other users' reports.
1.2 Information collected automatically
- Location data — your device's location is used while the app is in the foreground, to show nearby reports, centre the map and warn you when you enter a high-risk area. Nirapod does not track your location in the background. Your live location is used on the device and for queries; it is not published as part of your profile.
- Approximate area subscriptions — a coarse geographic cell identifier (a geohash prefix, roughly neighbourhood-level) is stored on your account so we can send you alerts for your area via push topics.
- Push notification token — a Firebase Cloud Messaging device token used to deliver alerts.
- Usage and diagnostic data — Firebase Analytics events (screens viewed, feature usage), device model, operating system version, app version and crash information.
- Trust score — a numeric reputation value derived from the accuracy of your reports and votes, along with timestamps such as account creation and last-seen.
1.3 Anonymous reports and posts
2. Why We Use Your Data
| Purpose | Data used |
|---|---|
| Create and secure your account, and authenticate you | Email, name, provider identifiers, password credential held by Firebase Authentication |
| Show incidents and risk zones near you | Device location, report locations, geohash |
| Send safety alerts, broadcasts and activity notifications | Area geohash topic, push token, notification records |
| Aggregate reports into risk zones | Report location, category and severity weighting |
| Verify report credibility and rank contributors | Confirmation and flag votes, trust score |
| Moderate content and prevent abuse | Report and post text, user ID, submission rate, moderation queue records |
| Improve performance and fix defects | Analytics events, crash and diagnostic data |
| Meet legal obligations and respond to lawful requests | Account and submission records |
Where applicable law (such as the GDPR) requires a legal basis, we rely on: performance of our contract with you (operating your account and the reporting features), your consent (device location permission, push notifications, optional profile details), our legitimate interests (safety, abuse prevention, service improvement) and compliance with legal obligations.
3. What Is Publicly Visible
- Incident reports — including category, title, description, photo, approximate location and time — are visible to other users of the app, including users browsing as guests.
- Community posts and comments are visible to other users.
- Your display name and profile photo are shown next to your non-anonymous content.
- Risk zones are aggregate, cell-level statistics and do not identify individual reporters.
- Your email address, phone number, precise live location, push token and trust score are not shown to other users.
Please avoid including personal information about yourself or others — names, licence plates, house numbers, faces — in report text or photos unless it is necessary for the safety warning.
4. Sharing and Disclosure
We do not sell your personal data and we do not share it with advertisers. We share data only with:
- Google Firebase (Google LLC) — authentication, database, file storage, push messaging, analytics and serverless functions. Firebase processes data on our behalf as our infrastructure provider.
- Apple and Google — only for the sign-in flow, when you choose Sign in with Apple or Google Sign-In.
- Map and geocoding providers — map tiles are requested from OpenStreetMap and place lookups from the Nominatim geocoding service. These providers receive the map area being viewed or the search term, as part of a normal web request, but do not receive your account identity.
- Law enforcement or regulators — where we are legally required to disclose information, or where disclosure is necessary to prevent imminent harm.
Our backend is hosted in Google Cloud's us-central1 region. If you use Nirapod from
outside the United States, your data will be transferred to and processed there.
5. Data Retention
- Account data — kept while your account is active, and deleted when you delete your account (see section 7).
- Reports and community content — retained as part of the public safety record. When you delete your account, this content is detached from your identity rather than removed, so that safety history and risk statistics remain accurate.
- Risk zones — scores decay automatically every 24 hours and a zone is removed once its score reaches zero, so stale incidents stop influencing the map.
- Notifications and votes — deleted with your account.
- Analytics and crash data — retained according to Firebase's default retention settings.
6. Security
- All traffic between the app and our backend is encrypted in transit (TLS), and data is encrypted at rest by Google Cloud.
- Passwords are handled and stored by Firebase Authentication; we never see or store your plaintext password.
- Database and file access is restricted by server-side security rules; sensitive fields such as trust score and risk zones can only be written by our server-side functions.
- Deleting your account requires you to re-authenticate first, so a lost or unattended device cannot be used to erase your data.
No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to or from the app.
7. Your Rights and Choices
- Access and correction — view and edit your name, phone number and profile photo in the app under Profile → Edit Profile.
- Deletion — delete your account and associated personal data at any time from Profile → Edit Profile → Delete Account. Full details are in our Data Deletion Policy.
- Location — you can revoke location permission in your device settings at any time. Nearby reports, the red-zone warning and location-based alerts will stop working, but the rest of the app remains usable.
- Notifications — you can disable push notifications in your device settings.
- Browsing without an account — guests can read reports and community posts without registering; posting, commenting and voting require an account.
- Depending on where you live, you may also have the right to object to or restrict processing, to request a copy of your data in portable form, or to lodge a complaint with your data protection authority. Contact us using the details below to exercise these rights.
8. Children's Privacy
Nirapod is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
9. Changes to This Policy
We may update this policy as the app evolves. Material changes will be announced in the app or by notification, and the "last updated" date above will change. Continuing to use Nirapod after an update means you accept the revised policy.
10. Contact Us
AlphaCue Technologies
Email: rxalphatech@gmail.com
We aim to respond to privacy requests within 30 days.
NIRAPOD