Privacy
What matters to you
We collect only what safety requires. Your sign-in identifier, the contacts you choose, and — when you activate it — audio, location, and video if a camera is present.
No passwords stored. Sign-in is passwordless, so there's no credential for anyone to find or force out of you.
No ads, no tracking, no analytics, no profiling. We don't sell your information. Ever.
You control the record. Your capture belongs to you. Your organization (if you're enrolled with one) can access your events to help you — nobody else can.
Nothing goes to police or courts unless you say so, or unless legally compelled. Never a standing copy.
Every access is logged, and records are tamper-evident.
Text messages: we do not share or sell mobile numbers. Message frequency varies. Message and data rates may apply. Reply STOP to opt out, HELP for help.
You can delete. Remove contacts anytime, delete your account, or request your data.
-
BLACK BOX
Privacy Policy & Legal Position
Legal position, disclosure, and terms — full version, provided for transparency.
Effective: [DATE] · Last updated: [DATE] · Version 2.0 (DRAFT)
DRAFT — PENDING LEGAL REVIEW — NOT LEGAL ADVICE
1. Who We Are & What This Covers
BLACK BOX ("BLACK BOX," "we," "us," "our") operates a covert personal-safety application that lets a user ("you," the "Survivor") discreetly document a situation affecting their safety and notify contacts they choose. This Policy covers the BLACK BOX application and the website at blackboxsentinel.com, and explains what we collect, why, who owns it, who can access it, how long we keep it, and the choices and rights you have.
BLACK BOX complements and does not replace emergency services. It is not a monitored alarm service and does not guarantee dispatch. In an emergency, contact local emergency services directly (911 in the U.S.; 110/119 in Japan).
2. The Governing Principle: You Own Your Data
BLACK BOX is built around a single design commitment: the Survivor owns their Capture, and only the Survivor can authorize its release to anyone outside the immediate safety response. Everything else in this Policy — the access model, the retention schedule, the sharing rules — exists to enforce that commitment, not to describe an exception to it.
This is not a promotional claim. It is a specific, load-bearing architectural decision: the people who can operate on your data during an emergency (your organization's coordinator, if you're enrolled with one) are not the same people who can decide where that data goes afterward. Operating access and release authority are deliberately separated. See Section 5.
3. Information We Collect
We collect only what the safety function requires. We do not run advertising, behavioral analytics, tracking, profiling, or engagement optimization, and we do not build advertising profiles.
Information you provide
● Account identifier — sign-in is passwordless, using a device passkey and an optional recovery code. We do not create or store passwords.
● Designated Contacts — the name and delivery address (mobile number and/or messaging ID) of the people you choose to be notified.
● Organization enrollment — if you are enrolled with an organization, the association between your account and that organization's tenant, and nothing more.
Information created when you use the safety function
● Capture — audio and device location recorded when you activate the system, and video only when a camera is present and enabled.
● Event & delivery records — timestamps, event status, which channel was used, and whether a notification was actually delivered.
● Integrity & audit records — tamper-evidence data and access logs recording who accessed an event and when.
4. How We Use Information
● To operate the safety function: record Capture, notify your Designated Contacts, and surface a live response view to an authorized responder or organization coordinator where applicable.
● To deliver account, sign-in, and service messages.
● To secure the service, prevent abuse, and comply with law.
We do not use your information for advertising, and we do not sell it.
5. Data Custody & Access — Ownership, Operating Access, and Distribution Authority
Custody is deliberately narrow, and the roles within it are deliberately not interchangeable.
5.1 Survivor — owner
You hold your Capture. You control it. You are the only party who can authorize its release beyond the immediate safety response described below. Nothing in an organization's or a responder's operating access converts into a right to disclose your Capture to anyone else, including law enforcement, without your direction — except where valid legal process requires it (Section 6).
5.2 Organization / coordinator — operator, not owner
If you are enrolled with an organization, its authorized coordinators may access your event to coordinate a live response, scoped strictly to that organization and never visible to any other organization or user. This is operating access: the ability to see and respond to an active event. It is not distribution authority. A coordinator cannot forward, export, or hand your Capture to a third party — including an Authority — on their own decision. Only you can authorize that.
5.3 Operator — hands-off by design
We (the operator of the underlying infrastructure) hold what is necessary to run and deliver the service and to preserve its integrity — and nothing more than that. There is no browse-all interface over survivor data; there is no operator dashboard that lists survivors or lets staff read Capture content outside a specific, logged, break-glass action tied to a legitimate operational need (e.g., a support ticket you initiated). We are building toward an architecture in which the operator holds only encrypted content it cannot itself read. Client-side / zero-knowledge encryption is on our roadmap and is identified here as planned, not yet deployed — we will not claim it is active until it has shipped and been independently reviewed.
5.4 Authorities — recipients, never holders
Law enforcement, emergency responders, and courts receive your Capture only at your direction, or where required by valid legal process. No Authority holds a standing copy of your data. Access, once granted, is scoped to the specific event and expires (Section 7).
Summary of the access model: Survivor decides where data goes. Organization operates the live event, it does not distribute the data. Operator stores and secures, it does not read or distribute. Authorities receive only what the Survivor releases, or what law compels — never a standing feed.
6. How We Share Information
● Contacts you designate — your alert and status information is delivered to the people you choose, on the channels you choose.
● Your organization — authorized coordinators of your enrolled organization, scoped to that organization only, for the duration needed to coordinate a response.
● Service providers (sub-processors) — vendors that deliver messages and host the service on our behalf (for example: SMS and messaging providers, cloud hosting and storage), under agreements limiting their use of data to providing the service.
● Authorities — only at your direction, or where required by valid legal process. Where we receive valid legal process, we will respond as required by law and, where lawful and feasible, notify you. [COUNSEL to finalize the legal-process response and notice policy.]
We do not sell personal information, and we do not share it for third-party marketing.
7. How We Protect Information
● Data is encrypted in transit (TLS) and protected at rest.
● Access is scoped and least-privilege; there is no browse-all interface over survivor data, and any operator access is limited, exceptional, and logged.
● Capture records are tamper-evident (hashed and chained), and every access is recorded in an audit log available to you.
● Access to a resolved event expires automatically and is not held open indefinitely (Section 9).
● The architecture is designed to degrade safely and not depend on any single provider for your protection.
8. Recording, Consent & Lawful Use
Activation is immediate and unconditional. BLACK BOX does not evaluate your location, the nature of the situation, or local consent law before recording — a personal-safety tool that pauses to check jurisdiction before protecting you has failed at its one job.
Laws governing the recording of audio and video vary by location, including "all-party consent" requirements in some U.S. states and requirements under the laws of Japan, India, and other countries. By using the Service, you acknowledge that BLACK BOX's built-in behavior does not adapt to those laws at the moment of activation, and that some jurisdictions may treat non-consensual recording as a criminal offense in circumstances outside the safety purpose this Service is designed for.
The Service is a tool for a person to document a threat to their own safety. It is not intended for unlawful surveillance, harassment, or covert recording of others outside that purpose. Consent law affects two distinct things, not one: whether a recording can later be offered as evidence in court, and whether the act of recording itself could expose you to liability independent of any court case. [This recording-consent posture is under review by counsel and will be finalized in the reviewed version of this document. See the companion Legal Position document for the full jurisdictional analysis.]
9. Data Retention
Retention is layered, not uniform, because no single period satisfies every legitimate demand on this data — grant-compliance rules, evidentiary needs, and data-minimization duties pull in different directions. [Specific periods below are the current working design and require confirmation by counsel per jurisdiction.]
Data
Default retention
Why
Capture (audio/video/location content)
Deletable by you after an event
You control your own risk; minimization
Sealed original / evidence vault
36 months, write-once
Exceeds the federal grant-records floor (3 years, 2 CFR §200.334) with margin; supports later evidentiary use if you choose to pursue it
Audit metadata (who accessed what, when — not content)
7 years
Covers most applicable statute-of-limitations windows without holding the recording itself
You may request deletion of your Capture at any time, subject to any active-safety hold or legal-hold limitation described to you at the time.
10. Your Choices & Rights
● Add, edit, or remove your Designated Contacts at any time in the app.
● Opt out of SMS by replying STOP to any message.
● Request access to, correction of, or deletion of your information, subject to applicable law and any active-safety or legal-hold limits.
● Delete your account, subject to retention of limited audit records as described in Section 9.
Depending on where you live, you may have additional rights under applicable privacy law, including Japan's Act on the Protection of Personal Information (APPI), India's Digital Personal Data Protection Act, and various U.S. state privacy laws. [Counsel to tailor jurisdiction-specific rights.]
11. Children
BLACK BOX is a safety tool that may be configured by or for members of a household, including minors, at the direction of a responsible adult. We do not knowingly use children's information for any purpose other than the safety function, and never for advertising. [Treatment of minors under COPPA and applicable law to be confirmed with counsel.]
12. International Users & Data Transfers
BLACK BOX may process information on infrastructure located in countries other than where you live. Where required, we apply appropriate safeguards for such transfers under APPI, India's DPDP Act, and other applicable law.
For users in India specifically: because India's DPDP Act treats precise location as more sensitive personal data than the equivalent U.S. or Japanese frameworks do, BLACK BOX defaults to region- or city-level location granularity for India deployments rather than exact coordinates, with the option to enable precise location for an active event. [Transfer mechanisms and default-granularity policy under review by counsel.]
13. Changes to This Policy
We may update this Policy; material changes will be posted with an updated effective date. Revisions move in the direction of greater user protection and transparency.
14. Contact
Questions or requests: [CONTACT@blackboxsentinel.com]
DRAFT FOR LEGAL REVIEW. This document is provided for transparency and is not legal advice. Bracketed items marked for counsel are pending review. Where this document and any plain-language summary differ, this document is the more complete statement.