Privacy Policy

    Raxha — Personal Safety Guardian
    Last Updated: August 20, 2026

    Our core principle: Privacy by design. We collect only the minimum data necessary to keep you safe. Your microphone is used only to listen for signs of danger, and by default that listening happens in real time on your device, where the audio never leaves it. Sending any of your speech to our speech-processing providers is off unless you turn on Cloud Voice Detection. If you do turn it on, it happens only at moments when your vitals and your voice together suggest distress, which can be before any SOS is raised, and it is used only to detect a call for help. Sensor data is processed on your device; the resulting health and location data are stored encrypted in our secure cloud, hosted by trusted third-party infrastructure providers, and used only to protect you and your family. You choose who can see your live location: share it with your family group in real time, or keep it private and share it only during an emergency. Either way, the moment an SOS is triggered your location is shared instantly so people can reach you.

    1. Who We Are

    The Raxha personal safety application and associated services are provided by Raxha, Inc., a Delaware corporation ("Raxha", "we", "our", "us"). Raxha, Inc. is the data controller responsible for your personal information described in this policy. This privacy policy explains how we collect, use, and protect your information when you use the Raxha app.

    2. Data We Collect

    • Health & Biometric Data — Health data (such as heart rate, heart rate variability, and a derived stress level) collected during active safety monitoring, stored in our cloud database. Your live health stats (such as your current heart rate and stress level) are private by default. They are shared with your family group only if you turn on live health-stats sharing, and you can turn it off again at any time. Your full vitals history (for example, your heart-rate timeline over time) is likewise private by default and shared only if you separately turn on history sharing. During an active SOS, your live health stats are shared with your family regardless of these settings so they can help you. We retain your health data to provide the service, including your personalized safety baseline, and you can delete it at any time (see Data Retention and Your Rights).
    • Audio — When safety monitoring is active, your microphone is used to listen for signs of distress, such as a call for help or a scream. What happens to that sound depends on a single setting, and that setting is off by default. By default, everything stays on your watch: audio is analyzed in real time by on-device models, including the one that recognizes a spoken word for help. Nothing is recorded, nothing is uploaded, and the words you speak are never stored. Only the resulting safety signal is acted upon. Cloud speech analysis is off unless you turn it on, under Settings → Protection. If you turn it on, then at moments when monitoring sees abnormal vitals together with signs of distress in your voice, a few seconds of audio may be sent to our speech-processing providers to transcribe what is said, and that text may then be analyzed by an AI language-processing provider to judge whether it is a call for help. Be clear about when this happens: it can happen before any SOS is raised, because an elevated-risk moment is exactly what it is meant to catch. It never happens continuously, it never happens while the setting is off, and you can turn the setting off again at any time. On a profile managed by a parent or guardian, only that adult can turn it on. While cloud speech analysis is off, no audio and no words leave your watch. The app may still send measurements of how your voice sounds, such as pitch and tremor, which contain nothing of what you said, and our servers refuse to process even those unless you have turned the setting on. Separately, during an SOS countdown a few seconds of audio may be passed from your watch to your own paired iPhone and transcribed there by Apple's on-device speech recognition, so that what you say can stop an alert that should not go out. That audio and its text stay on your devices, are deleted as soon as the decision is made, and are never sent to us.
    • Motion & Activity — Movement readings from your watch (such as acceleration and the activity type your watch reports, for example walking or exercise) are processed on the device to recognize a possible fall, impact, or other sign of distress. Improving fall detection: when a movement-triggered SOS countdown appears and is then resolved (because you cancelled it, marked it a false alarm, or let it send), we upload roughly the preceding ninety seconds of accelerometer readings from your watch, labeled with that outcome, so that we can make fall detection more accurate. These snippets contain no location, no audio, and no health data; they are stored under your account in our secure cloud storage, are limited in number per day, and are deleted automatically after 30 days (see Data Retention). They exist because a detector only improves if it learns which alarms were real.
    • Location — Your live location is collected continuously while monitoring is active, including when the app is in the background. You control who can see it. In the default mode, members of your family group can see your live location in real time. If you choose "share location only during an emergency," your live location is hidden from your family group and is revealed to them only while an SOS is active; the moment the emergency ends, it becomes private again. Regardless of this setting, during an SOS your latest location is always sent automatically to your emergency contacts and family so they can reach you. Your live location normally comes from your Apple Watch; if you turn on "Use my phone's location when my watch is off," your iPhone will also share its own location with your family group when your watch is unavailable (for example, if you leave it at home). This phone-location option is off by default and you can turn it off at any time. We also store the routes of trips you record. If you set up Safe Zones, we store the name you give each zone, its centre coordinates and radius, and whether the family member it applies to is currently inside or outside it. This is what lets us tell a guardian when a family member whose profile they manage arrives at or leaves a place. Safe Zone alerts go to that guardian, not to the wearer, and they apply only to managed profiles. Safe Zones are places the guardian chooses to save, such as home or school, and they can delete a zone at any time. Location data is stored in our cloud database to provide the service. Choosing emergency-only sharing is a visibility control: it hides your live location from your family group except during an SOS; it does not delete data. We retain your data while your account is active and you can delete it at any time (see Data Retention and Your Rights).
    • Your Routine, and Check-ins (optional, off unless you turn it on) — If you turn on check-ins, we build a private picture of what is ordinary for you, so that we can notice when something is not and ask whether you are all right. That picture is made of approximate places you are often in (stored as fuzzy areas, not a movement trail), the hours of the day you are usually active, and your usual resting range for heart-rate variability. It is calculated periodically from data we already hold, kept as a single file tied to your account, and updated as your routine changes. When at least two unusual signals occur together, the watch may ask "Everything okay?", and we record that moment: which signals fired, the time, your heart rate and heart-rate variability at the time, the activity your watch reported, your location rounded to roughly 100 metres, and your answer if you give one. This is behavioral profiling, used only to ask you a question about your safety: it can never start an emergency on its own, it is off until you turn it on, it can be turned off at any time, and it is not available on profiles for people under 18.
    • Account Data — Phone number or sign-in credentials for authentication, your name, an optional profile photo you choose to help family recognize you during emergencies, the language(s) you speak (used to understand a spoken call for help), and a record of which version of our Terms of Service and Privacy Policy you accepted and when, including the choices you made about sharing and the time our servers recorded them. All of this is stored in our cloud database.
    • Device Data — To deliver alerts to the right devices, we store a push-notification token for each phone you sign in on, together with the device model and the operating-system and app versions, when we last saw it, and your notification preferences. This is what stops alerts being sent to a phone you no longer use.
    • Emergency Contacts — Name and phone number of contacts you designate. We do not access or upload your full contact list.
    • Emergency Records — When an SOS is raised we keep a record of the emergency itself: when it opened, how it was resolved, and when it ended. If someone alerted about your emergency sends one of the short fixed replies (for example that they are calling you or on their way), we record that choice and the time our servers received it, and show it to you and to the others alerted about the same emergency. We record only the choice and the time, never their location, and nothing they type. These replies exist for the duration of the emergency; when it ends they stop being visible and are deleted shortly afterwards. They are not kept as a browsable history.
    • Safety Telemetry — To verify that protective features work reliably, we record event metadata about the safety system itself: for example, when monitoring turned the microphone on or off and why, whether an SOS countdown was shown and cancelled, and quality metrics of danger analysis (scores, timings, and outcomes). When an SOS is sent we also record, for each person we tried to alert, who they were, whether we reached them by push notification or SMS, whether it succeeded, and when. This is what lets us answer "did my alert actually go out?" when someone says they never received one. It records the attempt, never the message content. This telemetry never contains audio, transcripts, or the words you speak, and is stored in our cloud database tied to your account.
    • App Improvement Data — Diagnostic logs and usage information tied to your account, used to improve app performance and fix bugs. Logs are compressed and uploaded to our secure cloud storage; because they describe the app's operation, they can include operational details such as sensor readings and approximate location coordinates recorded at the time. Email addresses and phone numbers in log content are redacted before transmission, and diagnostic logs are automatically deleted after 30 days.

    3. Data We Do NOT Collect

    • We do not keep recordings of your audio and we do not store the words you speak. On-device audio is analyzed in real time and never leaves your device. (The one exception is described in the Audio section above: if, and only if, you have turned on cloud speech analysis, a few seconds of speech may be sent to our speech- and AI language-processing providers at an elevated-risk moment, which can occur before any SOS. That setting is off by default and can be turned on or off under Settings → Protection. Even then, we keep no audio and no transcript: what we retain is the resulting danger assessment and measurements about it, such as how many words were spoken, never the words themselves.)
    • We do not keep a continuous movement trail for the check-in feature, only the fuzzy areas that make up your routine, and the approximate location of a check-in moment
    • We do not sell your personal data
    • We do not share data with advertisers or use advertising identifiers
    • We do not scan or upload your full contact list
    • We do not keep an image, scan, or copy of any identity document presented to verify a parent or guardian (see Section 9a)

    4. How We Use Your Data

    • Safety monitoring — Detect emergencies and maintain session history
    • Live location sharing — Share your live location with your family group, continuously or only during an emergency, as you choose
    • SOS alerts — Automatically send your latest location and alert details to your trusted contacts in real time during an emergency, and show you who has been reached and who has replied
    • Family safety — Share your monitoring status with your family group, plus (if you opt in) your live health stats (such as heart rate and stress level) and your live location, based on your sharing choices
    • Noticing when something is unusual — If you turn on check-ins, learn your routine so we can ask whether you are all right at unusual moments
    • Authentication — Verify your identity to secure your account
    • Verifying a parent or guardian — Confirm that an adult consenting for a child is an adult, and that the same identity document is not used for more than one account
    • Improving detection — Use labeled movement snippets around a safety event, and quality measurements of past detections, to reduce false alarms and missed emergencies
    • App improvement — Improve app performance and reliability
    • Safety, abuse prevention, and legal obligations — Investigate misuse of the Service (such as false emergencies or misuse of Community Help), enforce our Terms, and meet legal requirements

    5. Data Sharing

    We share your data only in these limited circumstances:

    • Trusted contacts — Your safety status is shared with the contacts you designate; during an SOS your latest location is sent to them automatically in real time. You choose who these contacts are and can change them at any time
    • Family members — Your monitoring status is shared within your family group. Your live health stats (such as heart rate and stress level) and your full vitals history are each private by default and shared only if you explicitly opt in to that specific sharing; your live location is shared based on your separate location choice. You control who is in this group and what you share with them: live health stats, vitals history, and whether your live location is visible outside of an emergency. You can change any of these or leave the group at any time. During an active SOS, your live health stats and location are always shared with your family so they can help, regardless of these settings
    • Guardians of a managed profile — Where a parent or guardian manages a profile for a child or dependent adult, that adult holds the account and can see what the profile shares, including its location and, if they enable it, its live health stats. The person using a managed profile cannot change these settings themselves. Parents of a managed child are sent a periodic reminder of who can currently see that child, a notification that contains first names only, and no location or health data
    • People alerted about your emergency — The short reply someone chooses during your emergency (for example "on my way"), and the time it was received, are shown to you and to the others alerted about the same emergency
    • Community Help (optional, off by default) — If you turn on "Alert nearby Raxha users during my SOS", triggering an SOS sends your first name, your location at that moment, and your distance to up to 20 nearby Raxha users, within a few hundred metres, who have themselves opted in to help. No health data is ever included, and helpers cannot follow your location afterwards. We keep a record of which users were notified of which SOS (identities, distance, and time) for safety, abuse prevention, and accountability; you can request this record from us. If you opt in to help others, you may receive time-sensitive emergency alerts when a nearby Raxha user has an SOS. Both settings are off until you enable them, are available only on adult accounts you manage yourself, and can be changed anytime in the app.
    • Service providers — We use trusted third-party infrastructure providers for authentication, data storage, app improvement, notification delivery, and speech and AI language processing during elevated-threat moments (off by default; you can turn it on under Settings → Protection). These providers act as our processors under data-processing agreements that require them to safeguard your data and to process it only on our instructions.
    • Legal requirements — We may disclose data when required by applicable law, court order, or subpoena

    We do not sell your personal data. We do not share data with advertisers.

    6. Data Storage & Security

    • On-device data — Certain data remains on your device and is protected by built-in device encryption. This includes the models that analyze audio and motion on your watch, and a cached copy of your routine if you have turned on check-ins.
    • Cloud data — Account information, Terms of Service and consent records, optional profile photos, emergency contacts, family groups, health data, location data, trip routes, Safe Zones and their arrival/departure state, your routine file if check-ins are on, check-in events, safety events and emergency records, replies from people alerted, safety telemetry, records of SOS alerts we attempted to deliver, movement snippets used to improve fall detection, compressed diagnostic log archives, device records and push notification tokens are stored in our cloud database and storage, which are hosted by trusted third-party infrastructure providers, with encryption at rest and in transit.
    • Parental consent and verification records — Where a parent has verified themselves to activate a child's profile, the consent record and the minimal verification details listed in Section 9a are stored in our cloud database. The retained document reference is additionally sealed with a public key whose matching private key is held offline, outside our systems: our servers can write that reference but cannot read it back, so it is not readable by our staff or by anyone with access to the database.
    • Where your data is held — Our infrastructure providers store and process data on servers that may be located outside the country you live in, including in the United States and elsewhere. Wherever it is held, your data remains subject to this policy and to the contractual obligations we impose on our providers.

    7. Data Retention

    • Health data, location data, trip routes, and safety events — Retained as long as your account is active. Deleted upon account deletion.
    • Privacy settings control sharing, not deletion — Your privacy choices (live health-stats sharing, vitals-history sharing, emergency-only location) control who can see your data, not whether we keep it. We retain your data while your account is active to provide the service and your personalized safety baseline, and we do not automatically erase it. You can delete your data at any time (see Your Rights).
    • Account data — Retained as long as your account is active. Deleted upon account deletion.
    • Replies from people alerted about an emergency — Kept only for the emergency they belong to; deleted shortly after it is resolved, and in any case within a small number of days.
    • Movement snippets used to improve fall detection — Automatically deleted after 30 days, and immediately upon account deletion.
    • Diagnostic logs — Retained for up to 30 days, then automatically deleted.
    • Your routine and check-in events — Retained while check-ins are on and your account is active; deleted upon account deletion. Turning check-ins off stops new events being recorded.
    • Parental consent records — Retained while the consent is active and, unlike the categories above, kept after consent is withdrawn and after the associated accounts are deleted, as evidence that valid consent existed at the time information was processed. A child's own data (profile, health, location, family membership) is deleted with their profile; only this record remains, and it contains no name, date of birth, photograph, or full document number. See Section 9b.

    8. Your Rights

    You have the right to:

    • Access your data — view what we store about you
    • Export your data — where the app offers it, you can generate a machine-readable copy of your account records yourself. That copy deliberately leaves out a few categories: your location history, your vitals history, detection telemetry, and diagnostic logs. They are left out because they are very large and, in the wrong hands, a complete movement history is dangerous to the person it describes. You can ask us for any of those at any time using the contact details below, and we will verify who you are before we send them.
    • Delete your account and all associated data — open About → Delete Account in the app. Deletion is permanent and erases your profile, monitoring history, location, family group membership, emergency contacts, stored photos, movement snippets, and diagnostic archives from our cloud database and storage. If your closure is scheduled for a future date, signing back in before that date cancels it. If you are a parent who gave consent for a child's profile, the consent record itself is kept afterwards as evidence that consent existed (see Section 9b). If you created a family group, deleting your account also deletes that group and any child profiles managed within it; other adults in the group keep their own accounts and data.
    • Correct your data — update your profile details in the app, or contact us
    • Withdraw a consent — every optional feature described in this policy (live health-stats sharing, vitals history, cloud audio detection, check-ins, Community Help, phone-location fallback) can be switched off in the app at any time, without losing the rest of the Service
    • Revoke permissions — disable health data, location, microphone, or contacts access at any time in your device settings
    • Opt out of app improvement data collection — contact us to disable this for your account
    • Object or complain — you may object to our processing, and you may complain to your local data-protection authority

    9. Children's Privacy

    A Raxha account of one's own is for adults, and a person under 18 cannot create one. A child uses Raxha only as a profile created and managed by a parent or guardian who has completed the identity check described in Section 9a, inside that adult's own family group. The parent holds the account and every privacy and safety setting on it: the child cannot change what is shared, cannot switch protections off, cannot remove themselves from the guardian's family group, and cannot alter these choices from their own device. Community Help and check-ins are not available on a child's profile. Right now, only parents with Indian government ID can create and monitor a child's profile, because the identity check described below relies on it. We are working to extend this to other countries. The parent remains the account holder, gives every consent on the child's behalf, and can remove the profile at any time. Removing it deletes the child's account and their data. Parents are sent a periodic reminder of who can currently see their child. Outside a parent-managed profile created this way, we do not knowingly collect personal information from anyone under 18. If you believe a child's information has reached us another way, contact admin@raxha.app and we will delete it promptly. We show no ads and do not sell personal information.

    9a. Verifying parents and guardians

    The adult presents a government-issued identity document in the app. Our systems read the document's machine-readable data (name, date of birth, gender, address, and photograph) solely to confirm that the document is genuine, by checking the issuing authority's digital signature, and that the person it was issued to is an adult. This check runs entirely on our own systems: the document's contents are not sent to the issuing authority or to anyone else, are used for no other purpose, are never written to logs, and are discarded as soon as the check completes. We do not store the document or the personal details printed on it: we keep no image, scan, or copy of the card, and we take no name, date of birth, gender, address, photograph, or full document number from it. The only things kept from the check are the four items listed below. To be clear about what this establishes: it confirms that a genuine identity document belonging to an adult was presented. It does not by itself prove that the person presenting it is that individual, and it does not verify the family relationship. That the adult is the child's parent or guardian is their own declaration, which they make when creating the profile.

    What we keep from that check is deliberately minimal:

    • the last four digits of the document number, together with the date the document was generated;
    • a one-way cryptographic code derived from the document, which cannot be reversed to reveal the document number or any personal details. Its only purpose is to prevent the same identity document from being used to verify more than one account;
    • the verification result and when it happened; and
    • the consent record itself: which terms and privacy-policy versions the parent accepted, and when consent was granted or withdrawn.

    9b. Retention of consent records

    You withdraw your consent by deleting the child's profile from your family group; doing so stops the profile from operating and deletes the child's account and their data. The consent record described above is retained after withdrawal, and after the associated accounts are deleted, because we must be able to show that valid consent existed at the time information was processed; it contains no identity document images and no full document number. You may ask us to delete it using the contact details below, and we will do so except where we are required to keep it.

    10. Third-Party Services

    Raxha uses a small number of trusted service providers for authentication, data storage, app improvement, notification delivery, and speech and AI language processing during elevated-threat moments. These providers act as our processors under data-processing agreements that require them to protect your data and process it only on our instructions, in accordance with applicable privacy regulations.

    Categories of Providers We Use

    • A cloud infrastructure provider — Secure hosting, database, and edge computing for your account, health, and location data.
    • Notification delivery providers — Delivery of push notifications and SMS messages, including emergency alerts, to the devices and phone numbers of the people you have chosen.
    • Speech-to-text providers — Transcription of a short audio clip during an elevated-threat moment; the audio is used only to detect a call for help.
    • An AI language-analysis provider — Analysis of the resulting transcript text to assess whether it indicates danger or a call for help; the transcript is used only for that purpose.

    Sub-Processor Scope

    The transcription and AI-analysis providers are used only when cloud audio detection is enabled (off by default; you can turn it on under Settings → Protection) and only during elevated-threat moments. A current list of our sub-processors is available on request using the contact details in Section 12.

    11. Changes to This Policy

    We may update this privacy policy from time to time. We will notify you of material changes by updating the "Last Updated" date at the top of this page and, where the change is material, by asking you to review it in the app. Continued use of Raxha after changes constitutes acceptance of the updated policy.

    12. Contact Us

    If you have questions about this privacy policy or your data, contact us at: