Privacy Policy
Effective date: September 13, 2026
Senior Companion is designed to help seniors use simple safety and everyday assistance tools on their own phone. This policy explains what information the app uses, where it is stored, and when it may leave the device.
Information Stored on the Device
Senior Companion may store the following information locally:
- Emergency contact name and phone number
- Trusted contact names, phone numbers, and optional contact photos
- Important dates, important notes, caregiver PIN, and home screen preferences
- Daily check-in reminder and local check-in state
- Onboarding progress and optional usage-analytics preference
This information is used to provide app features. Most setup information stays on the device unless the user chooses a sharing action or enables cloud-backed automatic check-in alerts.
Contacts
The app can request access to contacts so the user or caregiver can select an emergency contact or trusted family contact. The app saves only the selected contact details needed for app features and never uploads the user's full address book. If the user explicitly consents to Family Monitoring or caregiver pairing, selected contact names, phone numbers, and optional photos can be encrypted and uploaded to Supabase so paired caregivers can view and manage them. Without that consent, selected contacts remain on the device except when the user chooses to call, text, or share them. Family Monitoring also collects a separately entered caregiver name or label and email address.
Location
The app can request location permission for safety and weather features. Location may be used to add a location link to SOS or location text messages, support "I Am Lost" and location-sharing features, and request local weather information from Open-Meteo.
Location is not continuously tracked by the developer. The app does not run a background location tracking service.
Camera and Photos
The app can request camera permission for the magnifier and flashlight features. Camera images are not uploaded to the developer. The app can request photo library permission if the user chooses to add a contact or family-card photo. With Family Monitoring, those optional photos are resized, stored in a private cloud bucket, and shared only with the paired caregiver; otherwise contact photos remain on the device.
Messages, Phone Calls, and Sharing
The app can open the phone dialer, SMS composer, or a one-to-one WhatsApp conversation. When the user taps WhatsApp, the selected contact's phone number is passed to WhatsApp through a user-initiated link. WhatsApp handles the conversation under its own terms and privacy policy. Senior Companion does not read WhatsApp messages or calls. Other user-initiated calls and messages are handled by the chosen phone or messaging app and recipient; the developer does not receive their content.
Automatic Check-In Monitoring
If the user enables automatic check-in alerts, Senior Companion creates an anonymous Supabase user ID and stores cloud monitoring settings. This may include the daily check-in deadline, timezone, grace period, cloud check-in date and time, missed/resolved alert events, email quota state, and an encrypted caregiver email address. This cloud data is used so the system can detect a missed check-in even when the app is closed.
The caregiver must verify the email address with a six-digit code. Resend sends verification, missed-check-in, and late resolved emails and reports delivery, bounce, complaint, suppression, and failure events. Hard bounces, complaints, and suppressions pause delivery. The caregiver can confirm an opt-out from an email link, and either user can disable monitoring in the app. Monitoring is limited to 200 alert emails per calendar month.
Companion Button Prototype
When an explicitly provisioned Companion Button is used with Family Monitoring, it sends a random device identifier, firmware version, connectivity timestamps, and hardware-originated check-ins to Supabase. The server stores only a hash of the device authentication token. A paired caregiver can see that a check-in came from the button and when it last connected. Wi-Fi network names and passwords remain in locally configured prototype firmware and are not sent to Senior Companion's cloud service. Revoking the device stops new check-ins, and deleting cloud monitoring data removes the device registration.
Caregiver Mode
A family member can install Senior Companion on their own phone and connect it to the user's phone with a one-time pairing code that the user shows on their screen. A connected family member's device can view the user's daily check-in status and history, alert history, the monitoring schedule, and the user's phone battery level. Family Monitoring can also synchronize encrypted senior settings, family messages, optional photos, shared care tasks, viewed/completion events, and push-notification tokens. Photos are stored in a private cloud bucket and push notifications contain only a generic update notice. The battery level is collected from the user's device when monitoring is enabled, only to show it to the connected family member. Either side can disconnect at any time, which removes this access. The pairing code is stored only in protected form and expires after 10 minutes.
Purchases and Subscriptions
Senior Companion uses RevenueCat and Google Play Billing or Apple's App Store to manage optional Family Monitoring subscriptions and historical purchase records, including earlier Senior Companion Plus purchases. Former Plus phone tools are free in the updated app and do not require a billing or family-access check. RevenueCat and the applicable app store may process purchase history, subscription status, device/app identifiers, and related purchase data needed to provide and restore paid access. For automatic email alerts, the server checks Family Monitoring subscription status before sending verification or alert emails. RevenueCat's privacy information is available at https://www.revenuecat.com/privacy.
Optional Usage Analytics
In versions that offer this choice, usage analytics is off by default. You can choose it on the welcome screen or under “Demo and privacy choices” on either phone. Declining does not restrict any app feature. This consent is separate from family sharing, monitoring, and purchase processing. No earlier actions are backfilled when you turn analytics on.
If you opt in, Supabase receives predefined milestones such as completing the demo, choosing a phone role, pairing, viewing subscription or trial terms, purchase attempts and their outcomes, server-confirmed check-ins, displaying a check-in on the family phone, email verification, and enabling alerts. Each event includes its time, app version, platform, language, phone role, setup version, plan type and an enumerated outcome. Campaign participation is identified only as campaign or standard, never by code.
These records use a pseudonymous app account identifier; they are not anonymous. For measuring a check-in arriving on both phones, the server associates the event with the existing family link and check-in record ID. This cross-phone measurement is used only when both participants consent. Analytics events do not contain contact details, pairing or promotional codes, messages, location, battery readings, payment details, or free-text errors. Operational Family Monitoring data described above is separate.
Access to analytics reports is limited to authorized administrators. Raw events are deleted after 90 days by a scheduled retention job. The app keeps at most 100 pending events for up to seven days when offline. Turning analytics off immediately stops collection and clears its local queue and pending purchase-measurement context. It requests deletion of your stored analytics and associated cross-phone display records when online; if offline, that request is retried on reconnection or next app opening. A minimal consent record is retained to honor your choice and reject older requests. Cloud-data deletion also revokes analytics and removes these event records.
The purpose is to understand where optional setup is confusing and improve the app, not advertising or tracking across other companies’ apps. Billing history, trial-to-paid results, renewals, cancellations, and refunds remain managed by RevenueCat and the app stores independently of this optional analytics choice. Infrastructure providers may separately process normal security and request logs under their own retention arrangements.
Website Hosting
The senior-companion.eu website is hosted on a DigitalOcean server. Connection information, including your IP address, is processed to deliver and protect the website. This is separate from optional in-app analytics. The website does not add advertising trackers, analytics scripts, or cookies.
Our website access logs record the time, request method, page path, response status, and response size, without IP addresses, query strings, referrers, or browser identifiers. Access logging is disabled for the email opt-out page. Diagnostic error logs may contain technical request details and IP addresses. Server logs are rotated daily, with up to 14 rotated files kept. DigitalOcean may process separate infrastructure and security logs under its own retention arrangements. See DigitalOcean's privacy policy.
Data Sharing
Senior Companion does not sell personal information.
The app may share information for app functionality or optional analytics you consent to:
- With RevenueCat and the applicable app store for purchase and subscription processing
- With Supabase for anonymous identity, cloud check-ins, monitoring settings, encrypted synchronized settings, family messages, tasks, media, activity events, push tokens, and registered Companion Button identifiers and connectivity data
- With Resend for caregiver verification and automatic alert email delivery
- With Supabase for optional, pseudonymous usage analytics when enabled by the user
- With Open-Meteo when weather is requested
- With contacts chosen by the user through SMS, phone, or sharing actions
Data Security
Data sent between the app and cloud services is encrypted in transit. Sensitive setup values are stored locally on the device, and some values use secure device storage where supported. Cloud caregiver email addresses and synchronized senior content are encrypted at rest, and family/contact photos are held in private cloud storage. Users should protect their phone with a screen lock because anyone with access to the unlocked phone may be able to view saved emergency, contact, important date, and note information.
Data Deletion
Users can delete or change saved information inside the app where those features are available. Uninstalling the app removes local app data from the device according to Android system behavior. One-time purchase history and subscription records are handled by the applicable app store and RevenueCat.
Cloud check-in, alert, verification, family-card, task-completion, and activity history is automatically deleted after 90 days. Companion Button registration and its latest connectivity timestamps remain while the device is registered. The caregiver setup includes actions to disable automatic alerts and delete cloud monitoring data, including synchronized settings, family cards, tasks, media, activity events, push tokens, and the device registration.
Children's Privacy
Senior Companion is intended for adults and seniors. It is not directed to children.
Emergency Disclaimer
Senior Companion is a convenience and safety-assistance app. It does not replace emergency services, caregiver supervision, or local emergency response systems. Email delivery can be delayed or fail. In an emergency, users should contact local emergency services.
Contact
For privacy questions, contact: contact@dudna.sk.