How ByStander collects, uses, shares, and protects your information — including live incident media, location, and health readings.
This Privacy Policy describes how ByStander Inc. (“ByStander,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use the ByStander mobile application and the website at https://bystander.life (together, the “Services”).
ByStander is a personal-safety service. It lets you alert trusted contacts and trained advocates during emergencies, share live video, audio, and location during active incidents, schedule recurring safety check-ins, run dead-man’s-switch timers, and monitor heart-rate and blood-oxygen readings from connected wearables for the purpose of detecting potential medical emergencies. Because of what the app does, we handle information that is personal, sensitive, and occasionally urgent. This policy explains how.
During an active incident that you trigger, the app collects and streams:
CheckPoint response window. While you have an unresolved scheduled check-in (the app has prompted you to confirm you are safe and you have not yet responded), ByStander uploads your location to your private profile approximately every 60 seconds. This continues until you confirm you are safe, you dismiss the prompt, or the response window expires. The purpose is to give your emergency contacts the most recent possible location in the SMS sent if the window expires without your response. Updates stop automatically as soon as the response is resolved. On Android the app shows a persistent notification while this is active because the platform requires it for background-location use.
Scout (dead-man’s-switch) timer. When you start a Scout timer, ByStander does not stream live media. It tracks the timer locally and shares your location with your pre-configured contacts only if the timer expires without your check-in.
None of the data described in this section is collected when no incident, CheckPoint window, or Scout timer is active. Location tracking, camera, and microphone all stop automatically when the relevant flow ends.
We use information for these purposes, and no others:
We do not use your information to serve advertising, to build advertising profiles, or to sell to third parties.
When you add an emergency contact, we send them a one-time SMS asking them to opt in. Until they opt in, they receive no further messages. Once opted in, they receive SMS and push notifications about incidents you trigger and can view your live video, audio, and location through a secure link. They can opt out at any time by replying STOP.
Advocates are independent contractors and trained volunteers who help users during incidents. When you request an advocate, the system matches you with one or more nearby approved advocates based on language, availability, and distance. Matched advocates receive:
Advocates are bound by a confidentiality agreement and platform conduct rules. They do not see your account history, your payment information, or any information from past incidents they were not part of. You can block an individual advocate at any time; blocked advocates will never be matched to you again.
We may disclose information when we believe in good faith that disclosure is necessary to: comply with law or valid legal process; protect the rights, safety, or property of any person; investigate fraud or abuse of the Services; or enforce our Terms.
Emergency contacts who have completed the SMS opt-in and who are themselves ByStander users can view your last known location from within the ByStander app, but only when you have explicitly enabled the “Share my location” toggle for that specific contact in your in-app Contacts screen. If you have not enabled sharing for a contact, the contact still receives incident alerts via SMS but cannot view your location in their app outside of an active incident.
You can revoke a contact’s ability to view your location at any time by disabling the per-contact sharing toggle or by removing them as an emergency contact. The change takes effect on their next refresh (typically within 10 seconds).
ByStander reads heart rate and blood-oxygen saturation from connected wearables through Apple HealthKit (iOS) and Android Health Connect, for the sole purpose of detecting potential medical emergencies and dispatching alerts to your emergency contacts and (on supported tiers) a trained advocate. See Section 5 for the Android Health Connect-specific terms and the approved use case. These platforms require your explicit permission before we can read anything.
We use health data only to: (a) detect cardiac, respiratory, or fall events that may indicate an emergency; (b) dispatch the resulting alert to your chosen emergency contacts and any matched advocate; and (c) include recent readings in an incident if one is triggered. We do not share health data with advertisers and we do not sell it. We do not use it for fitness tracking, wellness coaching, sleep tracking, training analytics, gamification, ML or AI training, insurance scoring, profiling, or any other purpose you did not enable.
On Android devices, ByStander integrates with Health Connect under the Medical care — Emergency response and first aid approved use case. The integration is gated behind an in-app permission screen and is available only on paid Standard-tier subscriptions; we do not request Health Connect permissions at install time or on any free tier.
We read the following data types from Health Connect, for the purposes described:
What we never derive from these signals.
ByStander never uses Health Connect data for fitness tracking, workout coaching, exercise monitoring, performance analytics, step-count gamification, daily-activity scoring, training analytics, social features, leaderboards, advertising, profiling, ML or AI training, insurance scoring, or third-party sharing of any kind. We do not sell Health Connect data and do not share it with advertisers.
Storage and deletion. Routine heart-rate and SpO2 readings are deleted from our backend 7 days after capture. Readings flagged by the anomaly detector as clinically significant are retained 365 days to support emergency-incident follow-up, then deleted. Sleep state and step counts are not persisted at all. You can revoke ByStander’s access in Health Connect at any time, disable health monitoring in the in-app Settings screen, or permanently delete every stored reading by deleting your account.
We use the following service providers to operate the Services. Each is contractually required to handle your information only as needed to provide their service to us.
| Provider | Purpose | Data they process |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime sync, serverless functions | Account data, incident data, media files, location history, health readings |
| Twilio | SMS verification and incident SMS notifications | User and emergency-contact phone numbers, SMS content |
| Apple Push Notification Service | Push notifications (iOS) | Push tokens, notification payloads |
| Firebase Cloud Messaging (Google) | Push notifications (Android) | Push tokens, notification payloads |
| Agora | Live audio and video streaming during incidents, cloud recording of incident streams | Live media stream, session metadata; recorded MP4 written to our storage |
| RevenueCat | Mobile in-app subscription management (App Store and Google Play) | User ID, subscription tier, transaction history (payment card data is processed by Apple and Google and never reaches RevenueCat or ByStander) |
| Stripe | Web-portal subscription payments at bystander.life | Payment card data (processed by Stripe; we do not store card numbers) |
| Apple HealthKit / Google Health Connect / Samsung Health | Provide heart-rate, blood-oxygen, and (on Android) sleep-state readings from your wearable | Health readings (with your permission) |
| Google Maps | Map rendering in the app | Location data used to render maps (subject to Google’s privacy policy) |
Data hosting location. Our backend (Supabase) is hosted in the us-west-2 region (Oregon, United States). All account data, incident records, location history, health readings, emergency-contact records, and stored media reside there. If you access the Services from outside the United States, your information is transferred to and processed in Oregon. Where required by law, we rely on Standard Contractual Clauses (or the UK and Swiss equivalents) as the lawful basis for these transfers.
We will update this list if we add or change sub-processors. If we ever introduce analytics or crash-reporting tools beyond what is described here, we will update this section and the app’s consent flow accordingly.
ByStander sends SMS messages for two purposes:
You or your emergency contact can opt out of non-verification SMS at any time by replying STOP. Reply HELP for help. Message and data rates from your carrier may apply. We do not sell or share your phone number with third parties for their own marketing.
| Category | Retention |
|---|---|
| Account data (name, email, phone, etc.) | Until you delete your account |
| Incident recordings (video, audio, chat transcripts) | 30 days on the Free tier; 60 days on Standard; retained while the account is active on Pro / LifeSupport. Items you star in the in-app Evidence Gallery are kept regardless of tier until you unstar or delete them. |
| Health readings (routine) | 7 days, then automatically deleted |
| Health readings flagged as clinically-significant anomalies | 365 days, then automatically deleted |
| Location data outside of incidents and CheckPoint windows | Not retained beyond the current session |
| Push tokens | Until you uninstall, sign out, or disable notifications |
| SMS opt-in / opt-out records | Retained as required for compliance |
You can delete your ByStander account at any time from inside the app (Settings → Account → Delete Account), which requires you to type your name to confirm. Deletion removes your profile, contacts, incident history, stored health readings, and evidence from active systems within 30 days. We may retain minimal records required by law (for example, transaction logs for financial reporting).
We protect your information with:
No system is completely secure. If we ever become aware of a security incident affecting your personal information, we will notify you as required by applicable law.
Regardless of where you live, you can:
We respond to verified requests within 30 days.
If you are a California resident, the California Consumer Privacy Act gives you the following rights. We will not discriminate against you for exercising them.
To exercise any of these rights, email info@bystander.life with the subject line “California Privacy Request.” You may designate an authorized agent to make a request on your behalf; we will require reasonable verification.
If you are in the European Economic Area, the United Kingdom, or Switzerland, ByStander Inc. is the data controller for your personal information. The lawful bases on which we process data are:
You have the rights to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time. To exercise these rights, email info@bystander.life. You also have the right to lodge a complaint with your local data-protection authority.
Your data is transferred to and processed in the United States (Supabase, us-west-2 / Oregon, and the other US-based sub-processors listed in Section 6). Where required, we rely on Standard Contractual Clauses (or the UK and Swiss equivalents) with our sub-processors, together with supplementary measures (TLS-encrypted transit, AES-256 encryption at rest, role-scoped access, audit logging) to protect your data during transfer and processing.
ByStander operates in and is headquartered in Illinois. We do not collect, capture, purchase, or otherwise obtain biometric identifiers as defined by the Illinois Biometric Information Privacy Act (BIPA). Specifically:
ByStander is intended for individuals 13 years of age or older. Users between 13 and 18 must have verifiable parental consent to use the app in jurisdictions that require it. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us at info@bystander.life and we will delete the account and related information.
For users under 18, we recommend reviewing this policy together with a parent or guardian. Parents and guardians who wish to review, modify, or delete their minor child’s account information may contact us at info@bystander.life.
ByStander is operated from the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States and in any other jurisdiction where our sub-processors operate (see Section 6). By using the Services, you consent to such transfers.
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. For material changes, we will provide notice through the app or by email at least 30 days before the change takes effect. Continued use of the Services after the effective date of an updated policy constitutes acceptance of the update.
For any privacy question, request, or concern, contact us at:
ByStander Inc.
683 83rd Street, Bolingbrook, Illinois 60440
Email: info@bystander.life
Website: https://bystander.life