1. Prominent Disclosures: Sensitive Device Permissions
To provide proactive family safety, real-time danger avoidance routing, and anti-stalker detection, Project Roam requires specific hardware and operating system permissions. In accordance with Google Play Developer Policies and Apple App Store Review Guidelines, we disclose the explicit reasons and runtime behaviors for these permissions:
2. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically during app operation, and information received from authorized third parties.
A. Information You Provide Directly
- Account Details: Full name, email address, password hash (encrypted via bcrypt), phone number (if provided for SMS verification), and profile avatar.
- Family Circle Data: Contact lists and group identifiers created when you establish a family circle or invite trusted members.
- Safety Feedback & Reports: User-submitted hazard reports, road condition notes, or customer support communications.
- Calendar Information: Optional scheduled events and trip itineraries synced to plan safe departure times.
B. Information Collected Automatically
- Precise Geolocation & Telemetry: GPS coordinates, altitude, travel bearing, speed, and timestamps recorded during active trips and background monitoring.
- Bluetooth Peripheral Data: Cryptographic advertising payloads, RSSI signal strength, and anonymized peripheral identifiers of nearby BLE tracking beacons detected during anti-stalking scans.
- Device & Technical Information: Device hardware model, operating system version, unique device identifiers, IP address, network carrier, and crash/diagnostic logs.
3. How We Use Your Information
We process your personal information strictly to operate, maintain, and enhance the safety services of Project Roam:
- Dynamic Risk-Avoidance Routing: Comparing your trajectory against our real-time database of municipal crime records, police dispatch reports, and severe weather warnings via our routing engine.
- Anti-Stalking Heuristics: Running correlation algorithms on BLE beacon sightings across multiple locations to identify and alert you to suspicious tracking devices.
- Family Circle Visibility & Peer Permissions: Delivering encrypted location updates exclusively to contacts you explicitly authorize through our peer-to-peer permission model.
- Emergency SOS Dispatch: Relaying high-priority alert packets and exact coordinates to your designated emergency guardians and contacts.
- Device Presence & Offline Monitoring: Running periodic heartbeat checks to detect disconnected or powered-down devices in high-risk zones.
- Service Improvement & Security: Monitoring platform performance, preventing fraud, verifying subscriptions, and debugging technical issues.
5. Our Zero-Sale Data Commitment
Project Roam NEVER sells, rents, trades, or monetizes your Personal Identifiable Information (PII), real-time location data, family contact lists, or private communications to data brokers, ad networks, or commercial marketing companies.
Any statistical or mobility research we conduct (such as macro-level traffic trends or municipal safety indices) is strictly aggregated, de-identified, and stripped of all personal and device identifiers.
6. Children's Privacy & Family Circles
Project Roam is designed to help parents and legal guardians protect their families. For users under the age of 13 (or under the applicable age of digital consent in your jurisdiction), accounts must be created with explicit parental consent or added directly by a parent or legal guardian within a family circle.
Parents and legal guardians maintain granular control over their children's accounts, including the ability to review, modify, or delete their child's location history and permissions at any time.
7. Data Retention & Security Standards
We implement rigorous defense-in-depth technical and organizational security measures:
- Encryption in Transit: All communication between the mobile client and our API servers is encrypted using modern TLS 1.3 encryption.
- Encryption at Rest: Database volumes, S3 buckets, and sensitive user fields are encrypted at rest using AES-256 standards.
- Authentication & Token Rotation: Stateless 15-minute JWT access tokens with revocable 30-day cryptographically hashed refresh tokens.
- Location History Lifecycle: High-frequency granular telemetry coordinates are automatically pruned after their analytical retention window.
8. Account & Data Deletion (Google Play & Apple Compliance)
You have the absolute right to delete your Project Roam account and permanently erase all associated personal and location data at any time.
Method 1: In-App Instant Deletion
If you have the mobile app installed, you can delete your account instantly:
- Open the Project Roam app.
- Navigate to Settings (gear icon) → Account & Security.
- Tap Delete Account and confirm your password.
- Your account, profile, family circle memberships, and location history are immediately scheduled for permanent database purging.
Method 2: Web Deletion Request Form (No App Reinstall Needed)
If you have uninstalled the app or cannot access your mobile device, submit your deletion request below. Our team will verify and permanently delete your account and all associated telemetry within 30 days:
You can also email your request directly to support@projectroamhq.com with the subject line "Account and Data Deletion Request".
What Data Is Deleted Upon Request:
- Personal identifying information (name, email, password hash, avatar).
- Historical GPS coordinates, trip records, route polylines, and worry scores.
- Anti-stalking Bluetooth scan logs and diagnostics.
- Private chat messages, group memberships, and peer permission grants.
- Device tokens and push notification registrations.
9. Your Privacy Rights & Choices
Depending on your geographic location (including California under CCPA/CPRA, and the European Union / UK under GDPR), you possess the following rights:
- Right to Access & Portability: Request an export of the personal data we hold about you in a structured, machine-readable format.
- Right to Rectification: Update or correct inaccurate account details.
- Right to Erasure: Request the deletion of your personal data as described above.
- Right to Restrict or Object: Limit the processing of specific telemetry data.
- Non-Discrimination: We will never discriminate against you for exercising your privacy rights.
10. International Data Transfers & Compliance
Project Roam operates primary server infrastructure within the United States. If you use our Services outside the United States, your information will be transferred to and processed in the United States in accordance with Standard Contractual Clauses and this Privacy Policy.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect improvements to our app, changes in technology, or updated legal requirements. When significant revisions are made, we will notify you through a prominent in-app notification or by email prior to the changes taking effect.
12. Contact Us & Data Protection Officer
If you have questions, feedback, or concerns regarding this Privacy Policy, our data practices, or your privacy rights, please reach out to our privacy and security team:
Project Roam Inc.
Attn: Privacy & Data Protection Officer
Email: privacy@projectroamhq.com
Support: support@projectroamhq.com
Website: https://app.projectroamhq.com