Privacy Policy for ImmaShap
Last Updated: 2 October 2026
Effective Date: 27 May 2026
This privacy policy governs your use of the software application ImmaShap (“Application”), developed by Axiom Array. ImmaShap is a wellbeing and safety utility designed to act as a silent safety net by sending automated alerts if a user misses a scheduled check-in.
1. Data Collection and Usage
To provide its core safety features, the Application requests and processes the following information:
- Google Account Information: Your name and email address, obtained via Google Sign-In, used to identify your account and personalise safety alerts.
- Emergency Contact Information: The name and email address of one or more people you designate as your emergency contacts.
- Check-in Settings: Your configured check-in frequency, reminder preferences, and check-in history. This data is stored locally on your device.
- Device Token (FCM Token): A unique device identifier generated by Firebase Cloud Messaging, used solely to deliver push notifications to your device.
- Location Data (Manual Emergency Alerts and Share My Location Only): ImmaShap uses your location in only two situations, both started by you, and only if you have granted location permission. ImmaShap does not continuously track, log, or monitor your location at any other time.
- Manual emergency alerts: ImmaShap takes a single, one-time snapshot of your device’s GPS coordinates at the moment you manually trigger an emergency alert (long-press). This is attached to that specific alert so your emergency contact can locate you. This does not apply to automatic missed check-in alerts, which never include location data. Granting or denying this permission never blocks or delays an emergency alert from being sent. If your location has not yet been captured when your contact views the alert, they may choose to wait up to five minutes for it to arrive before acknowledging the alert; this is optional and applies only to that specific alert.
- Share My Location: When you tap Share My Location on the Emergency Numbers page, ImmaShap obtains your current location once (or, if a fresh GPS fix is not available within about 15 seconds, the most recent location your device already holds) and passes a Google Maps link containing it to Android’s share menu. You choose which app (for example, a messaging app) and which person receives it. ImmaShap does not store this location or send it to Axiom Array; once shared, it is handled by the app and recipient you chose, under their own terms and privacy policies.
- Country Detection (Emergency Numbers Page): To show the emergency numbers for the country you are in, the Emergency Numbers page reads the country code of the mobile network your device is connected to, falling back to your SIM card’s country and then your device’s region setting. This is a two-letter country code only — not your location — and it is used solely on your device to choose which country’s list to display. It is not stored or sent anywhere.
- Device Identifier (Free-Tier Fair-Use Enforcement): To prevent abuse of the free tier — for example, repeatedly deleting and reinstalling the Application to obtain additional free alerts — the Application reads your device’s built-in Android ID, a non-resettable identifier that survives app reinstalls (it only changes if the device is factory reset). This identifier is used solely to enforce free-tier usage limits, is never used for advertising, tracking, or profiling, and is never shared with any third party. It does not apply to, and never limits, users with an active paid subscription.
- Subscription and Purchase Data (Paid Users Only): If you purchase a paid subscription, Google Play processes your payment directly — Axiom Array never receives or stores your payment card, bank, or billing address details. We receive and store only a Google Play purchase-verification token and your subscription status (e.g. active, cancelled, expired), used solely to confirm your entitlement to paid features and to keep that status in sync with Google Play’s own records.
- Performance and Diagnostic Data: The Application includes Firebase Performance Monitoring, which automatically collects technical information about how the Application runs — such as start-up times, screen rendering performance, network request timing, and basic device information including device model, operating system version, and application version. This information is technical in nature, is used only to identify and fix performance problems, and is not used to identify you personally.
Purpose of Collection: This data is used strictly for the Application’s core functionality: the Emergency Check-in system, fair enforcement of free-tier usage limits, and verification of paid subscription entitlement. If a user fails to respond to scheduled reminders, the Application uses these details to send push notification alerts to designated contacts via Firebase Cloud Messaging.
Legal Basis: We process this information because it is necessary to provide the safety service (and, where applicable, the paid subscription service) requested by the user, and because the user voluntarily provides the information required to use the Application.
2. Data Storage and Transmission
- Local Storage: Check-in settings and preferences are stored locally within the Application’s private sandbox on your device.
- Cloud Storage (Firestore): Your name, email address, and FCM device token are stored in Google Firestore, a cloud database provided by Google Firebase. This is necessary to enable push notifications and contact management between users. Records of the alerts you send, your emergency contact connections, and your free-tier and subscription usage counters are also stored there. If you send a manual emergency alert with location permission granted, the one-time GPS coordinate snapshot described above is stored as part of that alert record in Firestore, so your emergency contact can access it. Alert records and their acknowledgement records are automatically deleted seven days after they are created.
- Subscription Verification Data: Purchase-verification tokens and subscription status are also stored in Firestore, and are readable only by Axiom Array’s backend systems (Cloud Functions) — never directly by any user, including you, through the Application interface.
- Transmission: All data transmitted between the Application and Firebase is protected using HTTPS/TLS encryption. We do not use any other backend services for data transmission.
- International Processing: Your information may be processed or stored on secure servers located outside your country of residence through Google Firebase. Appropriate safeguards are used to protect your information during this processing.
- Not Stored: Locations shared using Share My Location, and the country code used by the Emergency Numbers page, are never written to Firestore or sent to Axiom Array.
- No Third-Party Email Services: The Application does not use any external email delivery services (such as Brevo or SendGrid). All alerts are delivered exclusively via Firebase Cloud Messaging push notifications.
3. Data Security and Encryption
We take the security of your information seriously:
- In-Transit: All data transmitted between the Application and Firebase is protected using HTTPS/TLS encryption to prevent unauthorised interception.
- At Rest: Your data is stored in Google Firestore, which applies Google’s infrastructure-level encryption at rest.
- On-Device: Data stored locally is protected by the Android operating system’s security architecture.
- Access Control: Firestore security rules restrict access to your data. Your alerts, emergency contact connections, alert allowance, and device notification token are readable only by you and, where relevant, by the emergency contacts an alert was actually sent to. Your name and email address can be read by another signed-in ImmaShap user only where the Application needs to display them to that user — for example, showing your name on an alert they have received from you. The user list itself cannot be searched, queried, listed, or downloaded by any user.
4. Third-Party Services and Advertising
- Google Firebase: We use Firebase Authentication, Cloud Firestore, Cloud Functions, Firebase Cloud Messaging (FCM), Firebase Performance Monitoring, and Firebase App Check — the last of which uses the Google Play Integrity API to confirm that requests come from a genuine, unmodified installation of the Application. Firebase is operated by Google LLC. For more information, see Google’s Privacy Policy.
- Google Play Billing: If you purchase a paid subscription, payment is processed entirely by Google Play Billing. We do not collect, see, or store your payment card, bank, or billing address details. For more information, see Google Play’s Terms of Service.
- Google AdMob: Free-tier use of the Application is supported by advertising through Google AdMob, operated by Google LLC. AdMob uses the Google Advertising ID (AD_ID) and related device identifiers, which are shared with Google for advertising purposes, including personalised advertising and advertising measurement. You can opt out of personalised advertising in your Android device settings under Google → Ads. Users with an active paid subscription are not shown ads.
- No Data Selling: We do not sell, rent, or trade your personal or emergency contact information to third parties for marketing purposes.
5. User Accounts and Data Deletion
ImmaShap requires a Google account to use the Application. Your account is managed through Google Sign-In.
- Control: You can modify or remove your emergency contacts at any time within the Application’s Settings menu.
- Sign Out: Signing out of the Application clears your check-in settings and preferences from your device. Two non-personal display flags are kept — recording that you have already seen the first-launch safety disclaimer and the onboarding screens — so that those screens are not repeated every time you sign in.
- Full Deletion: You can delete your account and all associated data directly from within the Application by tapping the gear icon → scrolling to the bottom → Delete Account. This immediately and permanently removes your ImmaShap sign-in account, your profile information (name and email address), your device notification token, every alert you have sent — including any location attached to a manual alert — all emergency contact connections in both directions, all connection notices, all alert acknowledgement records, and your alert allowance record. Your email address is also removed from the alert history of anyone who listed you as an emergency contact. Any Google Play purchase-verification token we hold is stripped of everything that links it to you — see the purchase record exception below. If you are unable to access the Application, contact us at the email address below and we will process your deletion request within 30 days.
- Limited Retention Exception — device usage record: To prevent abuse of the free-tier alert allowance — for example, deleting and recreating an account in order to obtain additional free alerts — one device-level usage record is retained after account deletion. It is keyed to the device identifier described in Section 1 and contains the number of free alerts used on that device, the date on which its 30-day period ends, and the email address most recently associated with that device. This record is deleted automatically once its 30-day period ends, and in any event no later than 30 days after the last free alert sent from that device. It is never used for advertising, tracking, or profiling, is never shared with any third party, and is not restored or linked to any new account you create.
- Limited Retention Exception — purchase record: If you had a paid subscription, the Google Play purchase-verification token is retained after account deletion, but your account identifier and your email address are permanently removed from it. What remains is the token itself and the number of manual alerts already used within the billing period you are currently paying for. This is kept for two reasons. First, deleting your ImmaShap account does not cancel your Google Play subscription — Google bills your Play account, not us — so if you sign in again, the subscription time you have already paid for is restored to you rather than lost. Second, without the usage figure, deleting and recreating an account would reset the monthly alert allowance for a paid subscriber. This record is deleted automatically 30 days after the billing period it relates to ends. It is never used for advertising, tracking, or profiling, and is never shared with any third party.
- Retention: Your data is retained only for as long as necessary to provide the Application’s services, or until your account is deleted (subject to the limited retention exceptions above). Data associated with deleted connections is removed immediately upon deletion.
6. Background Processing
ImmaShap monitors your check-in schedule in the background. It does not run continuously. Instead, it asks Android to wake it at short intervals (approximately every five minutes) using the device’s built-in alarm system. Each time it wakes, it does one thing — compares the current time against your check-in deadline — and then stops again. This background monitoring:
- Runs only while you are signed in and check-in monitoring is active, and stops when you sign out or delete your account.
- Performs no processing at all between those short checks.
- Does not collect microphone input, camera access, or any other sensor data.
- Does not access or collect location data — location is only ever obtained directly by the app at the moment you manually trigger an emergency alert or tap Share My Location, as described in Section 1, and never by this background monitoring.
- Uses Android’s alarm system to schedule these checks. Android may deliver these wake-ups at approximate rather than exact times — particularly on newer Android versions or when battery saving is active — which may introduce a delay of several minutes.
While monitoring is active, ImmaShap displays an ongoing notification showing that it is running and when your next check-in is due. You can hide this notification through your device’s notification settings for ImmaShap, though we recommend leaving it visible so you can confirm at a glance that monitoring is active.
7. Children’s Privacy
ImmaShap is not designed for children and is not directed at children. The Application is intended for use by adults aged 18 or over, as set out in our Terms of Service and End User Licence Agreement. We do not knowingly collect personal information from children. If you are a parent or guardian and believe that a child has provided us with personal information, please contact us at the address below so that we can delete it.
8. Privacy Rights and Data Protection Compliance
ImmaShap is distributed in South Africa, Namibia, and Botswana. Axiom Array, based in South Africa, is the responsible party (data controller) for the personal information described in this policy.
We apply the same standard of protection to every user, regardless of which of these countries they are in:
- South Africa — we process personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA). You may lodge a complaint with the Information Regulator of South Africa.
- Botswana — Botswana’s Data Protection Act applies to services offered to individuals in Botswana. You may lodge a complaint with Botswana’s Information and Data Protection Commission.
- Namibia — Namibia does not currently have a comprehensive data protection statute in force; the right to privacy is protected under Article 13 of the Namibian Constitution. We voluntarily apply the same POPIA-standard protections described in this policy to Namibian users, and will comply with Namibia’s data protection legislation once it comes into force.
In all three countries, we ensure that:
- We only process personal information that is necessary to provide the safety service you have requested (data minimisation).
- Users are responsible for obtaining consent from their emergency contacts before entering their details into the Application.
- We maintain the integrity and confidentiality of all personal information processed.
- You have the right to access, correct, or request deletion of your personal information at any time by contacting us.
- You have the right to object to our processing of your personal information, and to lodge a complaint with the relevant authority listed above if you believe your personal information has been handled unlawfully.
9. Emergency Services Disclaimer
ImmaShap is designed to help you notify your chosen emergency contacts when you need assistance. It is not a substitute for emergency services, medical care, or professional assistance.
If you are in immediate danger or require urgent assistance, contact your local emergency services immediately.
The Emergency Numbers page in the Application lists public emergency, private ambulance, and support line numbers for South Africa, Namibia, and Botswana for your convenience. Tapping a number opens your phone’s dialler with the number filled in; ImmaShap does not place calls itself. See our Terms of Service (Section 3) for the limitations of this list.
Emergency alerts depend on factors outside ImmaShap’s control, including your device, battery level, internet or network availability, and your contacts’ devices. Alerts may be delayed, not delivered, or not seen in time.
By using ImmaShap, you acknowledge these limitations and agree to use ImmaShap at your own risk.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the updated Privacy Policy on this page and updating the “Last Updated” date. Continued use of the Application after changes are posted constitutes acceptance of the updated policy.
If you have any questions regarding privacy or the data handled by ImmaShap, please contact the developer at:
Axiom Array
ImmaShap@AxiomArray.co.za
© 2026 Axiom Array. All rights reserved.