1. Who we are
AcuteAlert (“we”, “us”) operates the AcuteAlert mobile apps and acutealert.com. Contact: privacy@acutealert.com.
2. Information we collect
Account information
Name, email address, optional phone number, timezone, locale, appearance preference, and authentication identifiers from Apple or Google when you use those sign-in methods. We never receive your Apple or Google password.
Health information
On your device, the app reads the categories you explicitly grant in Apple Health or Health Connect (for example heart rate and blood oxygen). Raw, continuous health history stays on your device. Our servers receive (a) privacy-minimized alert payloads when one of your rules triggers: metric type, triggering value, your configured threshold, duration and timestamp; and (b) the single most recent reading per metric, so your dashboard can display it. You can disconnect a health source at any time and revoke permissions in the operating system.
Acute Card information
Emergency contacts, allergies, medications, conditions, blood type, preferred hospital, physician, insurance, notes and instructions that you choose to enter. Every field is optional. These fields are encrypted at the application layer in addition to encryption at rest. You control which fields are visible through your QR card and to which Circle members.
Circle relationships
Names, relationships, emails and phone numbers of the people you invite, invitation status, priorities and the permissions you grant them. Members see only what you grant.
Notification information
Push tokens for your devices and delivery status of notifications we send (push, email, SMS). Lock-screen notification text never includes readings by default.
Location (optional)
Only when you explicitly choose to share your location during an active alert or a Watch Me session. Location is shared with the Circle members you have granted location permission, expires automatically, and can be stopped at any time. We do not collect background location.
Payment
Web subscriptions are processed by Stripe; app subscriptions by Apple or Google. We receive subscription status and identifiers, never full card numbers.
Technical and analytics data
Device type, app version, coarse error diagnostics, and categorical product events (for example “invitation sent”). Analytics never include health readings, medication names, conditions, precise location, Circle member names or incident content. We do not use advertising SDKs.
3. How we use information
- Provide the service: evaluate your rules, create incidents, notify you and your Circle, display your Acute Card.
- Secure the service: authentication, rate limiting, abuse prevention, audit logs.
- Communicate: verification, sign-in links, invitations, alert notifications, account notices.
- Billing and legal compliance.
We do not use health data for advertising, ad targeting, insurance or employment eligibility, or unrelated profiling.
4. Sharing
- Your Circle: only the information and permissions you grant to each member.
- QR card viewers: only the fields you chose to share, at the link you control.
- Processors: hosting (Vercel), database (Neon), email (Resend), SMS (Twilio, if enabled), push (Apple, Google, Expo), payments (Stripe, Apple, Google), scheduling (Upstash). Processors act on our instructions.
- Legal: when required by law or to protect safety.
We do not sell personal or health information.
5. Retention
- Account data: until you delete your account.
- Incident history: 30 days (Free) or 1 year (paid), and you can delete individual incidents sooner.
- Location shares: expire automatically within hours and are deleted with the incident.
- Revoked invitation and card tokens are invalidated immediately.
- Payment and audit records: retained only as long as legally required, without linkage to your deleted profile.
6. Your controls
- Export all your data (Dashboard → Settings → Export).
- Delete your account from the app or the web dashboard; deletion is immediate.
- Revoke Circle members, invitation links, card links and device sessions at any time.
- Disconnect health sources and revoke OS permissions.
- Choose notification channels per member.
7. Security
TLS in transit, encryption at rest, application-layer encryption for Acute Card fields, high-entropy unguessable tokens for links, server-side authorization on every sensitive operation, structured logging with redaction, and rate limiting. AcuteAlert is designed with privacy and security in mind; we do not currently claim HIPAA, SOC 2 or FDA status.
8. Children
AcuteAlert is not directed to children under 13 (or the applicable age in your region), and we do not knowingly collect their data.
9. International transfers
Data is processed in the United States. Where required, we rely on appropriate safeguards for transfers.
10. Changes
We will post updates here and, for material changes, notify you in the app or by email.
11. Contact
privacy@acutealert.com · security@acutealert.com · support@acutealert.com