Your privacy and data security are fundamental to our mission of keeping you safe.
Last updated: December 2024 β’ Effective Date: December 1, 2024
On-device routing means we never see your location, routes, or travel patterns. Alerts are proximity-based on downloaded maps, not GPS tracking.
Your data is never sold to advertisers or data brokers. End-to-end encryption and industry-standard security practices.
Access, correct, export, or delete your data anytime. No questions asked, no hoops to jump through.
Full compliance with EU and California privacy laws. Privacy by design, not an afterthought.
We believe in data minimization. We only collect what is absolutely necessary to provide disaster monitoring services and process transactions. We do not track your location, movements, or browsing behavior beyond what you explicitly provide.
When you create an account, we collect only the essentials:
App Store Sign-In: When you sign up through the iOS App Store (Sign in with Apple) or Google Play (Sign in with Google), we receive: your email address (or Apple's private relay email), unique user identifier, and subscription status. We do not receive your full name, contacts, or any other device data unless you explicitly grant permission.
You control how you receive disaster alerts. Alerts are proximity-based on the geographic areas (maps) you've downloaded - we don't monitor or track your location. We store only what's necessary for your chosen notification methods:
Privacy advantage: Alerts are triggered based on disasters occurring in your downloaded map regions, not by tracking where you are. If a wildfire starts in "Los Angeles" and you have that map downloaded, you get an alert - regardless of whether you're currently in LA, at work, or on vacation.
Your choice: You can choose any combination: app-only, email-only, SMS-only, or all three. Change your preferences anytime in account settings.
We store only the geographic areas (maps) you choose to download. These downloaded map regions determine which disaster alerts you receive (proximity-based, not location-based). Key privacy features:
Example: If you download a map of "Los Angeles," we store "Los Angeles area downloaded" β not your home address, not your GPS coordinates, just the general region. You'll receive LA disaster alerts whether you're at home, at work, or traveling abroad.
Routing privacy: When you request emergency evacuation routes, all route calculations happen on your phone/tablet using the downloaded map data. Your start point, destination, and route are never sent to our servers. This means we can't provide real-time traffic data (beyond official road closure notices from authorities), but it also means your movements remain completely private.
To help families coordinate offline map downloads and improve disaster preparedness, we collect privacy-preserving metadata about which maps you've downloaded and approximately how many pins/destinations you have in each region.
This is an extension of existing functionality: We already track which maps you've downloaded for delivering proximity-based disaster alerts. The new feature adds aggregate counts (e.g., "15 pins in California map") to enable smart family recommendations without compromising location privacy.
Example: "User has 15 pins in California map" - this reveals nothing about where those pins actually are within the 300,000+ square kilometer region.
Zero-knowledge architecture: Map tiles are HUGE geographic areas. Knowing you use "California" reveals nothing about your home, work, or travel patterns.
Unlike typical family tracking apps that monitor your exact location 24/7, our system only knows:
Privacy by design: Server aggregates map names for recommendations but can never reverse-engineer your actual locations because coordinates are never sent.
Purpose: This metadata enables the "Family Map Suggestions" feature, which recommends useful maps based on what your family members have downloaded, helping everyone stay prepared without revealing anyone's actual locations or travel plans.
For paid subscriptions, we must retain:
We collect minimal technical data to keep the service running:
When you contact support, we store:
Privacy tradeoff: Because we use on-device routing instead of server-side routing, we cannot provide real-time traffic congestion data. However, we do provide official road closure notices from authorities, and your privacy remains intact - your movements are never tracked or analyzed.
We use your information only for the specific purposes you provide it. We do not repurpose your data for marketing, profiling, or any use beyond disaster monitoring services.
You can opt out of non-critical emails anytime in your account settings or via unsubscribe links.
Your personal information is not a product. We do not sell, rent, or trade your data to advertisers, data brokers, or marketing companies.
We share minimal data with these trusted service providers only to deliver our service. They cannot use your data for their own purposes.
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Your password is hashed using industry-standard bcrypt with high-cost factors.
We use enterprise-grade cloud infrastructure with redundant backups, access controls, and continuous monitoring.
Employee access to user data is strictly limited, logged, and granted only on a need-to-know basis for support and maintenance.
We conduct regular security audits, penetration testing, and vulnerability assessments with third-party security firms.
Under GDPR, CCPA, and other privacy laws, you have the right to access, correct, export, or delete your personal data. Use our dedicated privacy request page to exercise these rights.
Submit Privacy RequestYou can view all your personal data through your account dashboard. For additional details, contact our support team.
Update your account information, email address, and monitoring locations anytime through your account settings.
Export your data in machine-readable formats (JSON, CSV) through your account settings or by contacting support.
Delete your account and all associated data anytime. We'll remove your personal information within 30 days, keeping only anonymized data for service improvement.
Active Accounts
Indefinite - data retained while account is active
Deleted Accounts
30 days - personal data removed within 30 days after deletion request
Event and Alert Data
Plan-dependent: Demo (7 days), Basic (30 days), Pro/Family (2 years)
Database Backups
90 days - automated backups retained for disaster recovery
System and Audit Logs
1 year - security and debugging logs retained for system integrity
Transaction and Payment Records
7 years - retained for tax compliance and financial audit requirements
Legal Compliance Data
As required by law - may be retained longer for legal obligations, in anonymized form when possible
Keryx Maps is operated from the United States, and your data is stored on servers located in the United States. If you are accessing our service from outside the United States (including the European Union), your data will be transferred internationally to our US servers.
We ensure appropriate safeguards for international transfers:
We use minimal cookies and tracking technologies:
Required for login, session management, and core functionality. These cannot be disabled.
Help us understand how users interact with our platform. These are anonymized and can be opted out.
Remember your settings like theme preferences and dashboard layout.
Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us immediately and we will delete such information.
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information:
Right to Know
You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions (e.g., completing transactions, fraud prevention, legal compliance).
Right to Opt-Out of Sale
We do not sell your personal information. We have never sold personal information and do not have plans to do so in the future.
Right to Non-Discrimination
You have the right to not receive discriminatory treatment for exercising your CCPA rights. We will not deny service, charge different prices, or provide different quality of service for exercising your privacy rights.
California residents can exercise these rights by:
For California residents, we collect the following categories of personal information:
If you are located in the European Union (EU) or European Economic Area (EEA), the General Data Protection Regulation (GDPR) provides you with comprehensive rights regarding your personal data:
Right of Access (Art. 15)
You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data and receive information about how it is processed.
Right to Rectification (Art. 16)
You have the right to have inaccurate personal data corrected and to have incomplete data completed.
Right to Erasure / "Right to be Forgotten" (Art. 17)
You have the right to request deletion of your personal data under certain circumstances, such as when the data is no longer necessary or you withdraw consent.
Right to Restriction of Processing (Art. 18)
You have the right to restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability (Art. 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON, CSV) and to transmit it to another service provider.
Right to Object (Art. 21)
You have the right to object to processing of your personal data based on legitimate interests, direct marketing, or processing for scientific/historical research purposes.
Rights Related to Automated Decision-Making (Art. 22)
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not use automated decision-making for critical functions.
Right to Withdraw Consent
Where we process your data based on consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before withdrawal.
We process your personal data based on the following legal grounds:
EU/EEA residents can exercise these rights by:
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local data protection authority (supervisory authority) in the EU member state where you reside, work, or where the alleged infringement occurred.
Find your local authority: EDPB Member List
While not required for our current scale of operations, we have designated a privacy contact for GDPR matters:
Privacy Contact: privacy@keryxmaps.com
Subject Line: "GDPR - [Your Request Type]"
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
If you have questions about this Privacy Policy or our data practices, please contact us:
Email: privacy@keryxmaps.com
Subject Line: Privacy Policy Inquiry
Response Time: Within 72 hours