1. Scope and who we are
NWatch is an emergency-alert service for trusted groups. This policy covers the NWatch mobile app, manager portal, public website and support interactions. NWatch is operated by Robert Evans (ABN 94 037 705 984) under the RME Solutions Technology brand ("NWatch", "we", "us" or "our").
We collect only the information needed to authenticate people, manage groups and licences, deliver and investigate alerts, secure the service, provide support and meet legal obligations. We do not sell personal information, run advertising profiles or use cross-app tracking.
2. Information we collect
| Category | Examples | Why we need it |
|---|---|---|
| Account and identity | Firebase user ID, email address, display name and sign-in provider. If email sign-in is used, we also process the address needed to send and complete a one-time secure sign-in link. | Sign-in, account recovery, member identification and access control. |
| Group and role data | Group membership, role, status, invite use, group name and coarse group zone. | Route alerts, enforce seat limits and let managers administer their groups. |
| Device and security data | Push token, platform, app version, public encryption key and key identifier. We may also keep a one-way identifier derived from a verified sign-in identity, together with platform suspension and privileged-access bootstrap state. Private encryption keys remain in the device's secure storage. | Deliver notifications, encrypt an alert separately for each intended recipient, prevent a suspended identity from evading a safety restriction by creating a new account, and prevent privileged access from being automatically granted twice. |
| Alert records | Sender and group identifiers, timestamps, status, recipient-specific encrypted envelopes, delivery outcomes and resolution notes. | Send, display, recover, investigate and audit safety alerts. |
| Optional address and precise location | An address you enter and, only when you enable it for an alert, GPS coordinates. These leave the device only inside an encrypted alert envelope. | Tell your trusted group where help may be needed. |
| Delivery and security diagnostics | Whether an alert was received, opened or sounded; platform and OS details; alarm volume/DND/channel state; key identifiers; error details and client timestamp. | Detect the safety-critical failure case where an alert did not sound or decrypt. |
| Billing and enterprise records | Billing email, licence/seat entitlement, Stripe customer and subscription IDs, payment amount/status and invoice link. | Provision and administer paid licences, invoices and support. Stripe, not NWatch, handles full card details. |
| Support and audit information | Messages you send us, operational actions, actor identity and relevant group/incident references. | Respond to requests, investigate misuse and maintain security accountability. |
Our public "find a group" form prepares an email in your own email application; the website does not submit that form to an NWatch server. Information is sent only if you choose to send the email.
3. Address and location
Your saved address is kept in local app storage on your device. NWatch does not continuously track your location. The optional GPS control is off by default and requests foreground location permission only when you choose to include GPS in an alert.
You can send an alert without GPS, and you can edit or clear the saved address in the app. Device operating systems may separately process permission and location information under their own policies.
4. Encrypted alerts and authorised access
Alert location content is encrypted on-device using ML-KEM-768 key encapsulation and AES-256-GCM. NWatch attempts to create a separate envelope for each intended recipient key; only successfully sealed envelopes, each bound to its incident and recipient, are uploaded. Transport is also protected by HTTPS.
Current clients include a service-recovery envelope when the configured recovery key is available. This lets an authorised administrator who is also permitted for the relevant group recover or re-wrap an incident when a member rotates keys, and supports incident management. Plaintext decryption is access-controlled and written to the audit log. This means the content is strongly protected, but we do not describe it as information that the operator can never decrypt.
No technical system can promise absolute security. If we become aware of a data breach, we will investigate and notify affected people and regulators where required.
5. How we use and disclose information
We use the information above to provide app functionality, authenticate and authorise users, deliver alerts, maintain encryption keys, administer groups and subscriptions, provide support, monitor delivery reliability, prevent misuse and comply with law.
Information is disclosed only to intended group recipients, authorised managers/administrators, the service providers below, professional advisers or authorities where required or permitted by law. We do not use alert content, location, identity or diagnostics for advertising or data-broker activity.
Where European privacy law applies, our processing is based on providing the service you request, our legitimate interests in safety, reliability and fraud prevention, consent for optional precise location, and legal obligations.
6. Service providers and overseas processing
We use specialised providers to operate NWatch:
- Google Firebase and Google Cloud for authentication, Firestore and Firebase Cloud Messaging.
- Apple for Sign in with Apple and Apple Push Notification service.
- Microsoft for Microsoft account authentication when that sign-in option is used.
- Cloudflare for API and web hosting, access control and security.
- Stripe for manager subscriptions, invoices and payment processing.
These providers may store, process or permit support access to information outside the country where you live, including in Australia and the United States, and in other locations identified in their current subprocessor and service documentation. This is overseas processing for users in New Zealand and Canada and may also be overseas processing for users elsewhere.
We use contractual commitments, access controls, encryption in transit and at rest where supported, recipient-specific encryption for alert content, audit logging and data minimisation to protect information handled across borders. Privacy laws and government-access rules in another country may differ from those where you live. Contact our Privacy Officer if you want current information about a provider or processing location relevant to your data.
7. Retention and account deletion
Account, membership, device and active encryption-key records are kept while needed to operate your account. Invalid push tokens may be removed automatically. Ordinary local app storage is removed when you clear it, delete the account in-app or uninstall the app. Operating-system secure storage has different uninstall and reinstall behaviour, especially on iOS; use the in-app sign-out or deletion flow to purge NWatch key material from that device.
Account deletion removes the active user profile, device tokens, public encryption keys, memberships and that user's incident envelopes. A deletion tombstone, one-way identity-security identifier and its suspension or privileged-bootstrap state, former-member record, incident metadata, delivery/security logs, audit records and billing records may be retained where reasonably necessary for safety investigations, fraud and access-control prevention, accounting, legal claims and regulatory obligations. The identity-security record does not retain the raw provider subject or email in that identifier. We limit access to retained records and delete or de-identify them when they are no longer needed.
When a manager archives a group, we retain its group record, membership and invitation records, licence and billing references, incidents, encrypted envelopes, notes and audit history where needed for safety, support, recovery, accounting or legal purposes. Archiving disables new operational activity; it is not automatic deletion and does not cancel billing. Access to retained records is limited, and records are deleted or de-identified when they are no longer reasonably needed.
For an Apple-linked account on iPhone, in-app deletion first obtains one-time deletion authorisation from Apple. The NWatch service then attempts to cancel active self-serve Stripe subscriptions immediately and stops without deleting service data if cancellation cannot be confirmed. This ends the related entitlement immediately and may forfeit unused time, subject to non-excludable refund rights. After service deletion, the app attempts Apple authorisation revocation and local/Firebase cleanup; any unconfirmed cleanup is reported separately and does not mean service deletion is still pending. Managers must still hand over or archive any group for which they are the only active manager. Enterprise or manually provisioned entitlements may require support to transfer or close them. See Account deletion for the in-app and web request paths.
8. Your choices and rights
- Use the app without sharing GPS and revoke location permission in device settings.
- Review notification and emergency-alert permissions in the app's Settings screen and your device settings.
- Request access to or correction of personal information we hold about you.
- Delete your account in the app, or request deletion through our web deletion page if you no longer have the app.
- Object to or restrict processing, or request portability, where applicable law gives you that right.
We may need to verify that a request comes from the account holder. Some records cannot be removed immediately where retention is required for security, safety, billing or law; we will explain any such limitation.
9. Children
NWatch accounts are for people aged 13 or older. The Service is not directed to children under 13, and a manager must not invite or create an account for a child under 13. A parent, guardian or responsible organisation should decide whether a person aged 13 to 17 may join a group and supervise how emergency alerts are used. If you believe a child under 13 has provided information, contact our Privacy Officer so we can investigate and delete it where required.
10. Changes to this policy
We may update this policy when the product, providers or law changes. The effective date above will change, and we will provide additional notice in the app or portal for material changes where appropriate.
11. Contact, access requests and complaints
Contact the NWatch Privacy Officer at [email protected] with the subject "NWatch privacy request". Please do not include alert content, passwords, private encryption keys or precise location in an unencrypted email.
We will acknowledge and investigate privacy complaints, explain the outcome and tell you about further review options. Depending on where you live and the issue, you may also contact the Office of the Australian Information Commissioner, the New Zealand Privacy Commissioner, the Office of the Privacy Commissioner of Canada, or the relevant United States state privacy regulator or Federal Trade Commission.