Privacy Policy
Effective date: 2026-06-14 · Last updated: 2026-06-14
1. Who we are
IWasKidnapped.com ("the App") is a personal-safety application for adults. It is operated by FIBER LLC, a limited liability company organised in the State of Texas, United States ("we", "us"), which is the controller of the personal data described in this policy. When you trigger an emergency alert, the App sends information you have set up to the emergency contacts you have chosen. This policy explains what we collect, why, how long we keep it, who receives it, and your choices.
Our mailing address is 2943 Parkway Blvd, Unit #297, West Valley, UT 84119, United States; written requests can be sent there or by email.
Privacy Officer: the person accountable for the protection of personal data at FIBER LLC can be reached at Support@IWasKidnapped.com. Write to that address for any privacy question, access request, correction, or complaint.
2. Summary (plain language)
- We do not collect your audio, photos, or live location until you trigger an alert.
- When you trigger an alert, that data is sent only to the emergency contacts you chose.
- Some account and security data (email, IP address) is collected so the App can work and stay secure.
- Your PINs never leave your device. Your password is stored only as a secure hash.
- All data is encrypted in transit. We do not sell your data and do not share it with advertisers.
- You can delete your account and request deletion of your data at any time.
3. Data we collect
3.1 Account data
- Email address — to create and manage your account. Required.
- Password — stored only as a secure hash (bcrypt) on our server. We never see your plain password.
- PIN codes — your normal and panic PINs are hashed on your device and stored only in the device secure storage. They are never sent to our servers.
3.2 Content you add
- Files you upload (e.g. ID or passport scans) — stored so they can be sent to your emergency contacts if you trigger an alert. Optional.
- Emergency contacts — the email address (required) and optional name, relationship, and phone number of each contact you add. Optional.
3.3 Data collected only during an alert
When (and only when) you trigger an alert — by entering your panic PIN, by repeated wrong PIN entries, or by an automatic dead-man-switch — the App may collect:
- Audio recording (about 30 seconds).
- Photos from the front and back camera (if you granted camera permission).
- Precise and approximate location, updated about every 10 minutes during the alert.
- Device battery level and online status.
Audio, photos, and camera require the relevant device permissions; if you do not grant them, that data is simply not collected.
3.4 Optional tracking outside an alert
- Location history — collected outside of an alert only if you turn on "location history" (off by default).
- Battery history — collected outside of an alert only if you turn on "battery history" (off by default).
3.5 Security and diagnostic data
- IP address — recorded at key account events (registration, login, session refresh, alert activation) for security and fraud prevention. Always collected for those events.
- IP address at routine check-ins — recorded only while the "IP history" setting is on (on by default; you can turn it off). During an active alert it is always recorded.
- Push token — if you enable notifications, so we can notify you about your alert. Optional.
- Crash / error diagnostics — only if you opt in. These are anonymous (tied to a random install ID, not to your account); email, user ID, files, and PINs are excluded.
We do not collect: payment card numbers (subscriptions are handled by the app store), government ID numbers as identifiers, face-recognition biometrics, or the contact list from your phone.
4. Who we share data with
- Your emergency contacts — when you trigger an alert, we email the contacts you chose. The message can include your uploaded documents (as attachments or secure download links), the audio clip and photos, your location as Google Maps links and a live tracking-map link, and your battery status. You choose the contacts; nothing is sent until you trigger an alert.
- Law enforcement — IP address and related forensic data may be disclosed only on a valid official request connected to a triggered alert. This is never shared with your contacts or the public.
- Service providers (processors) who operate the service on our behalf: email delivery, database hosting, push notifications, and subscription billing. They process data only to provide the service.
- We do not sell your personal data, and we do not share it with advertisers.
5. How long we keep data
- Account data and uploaded files: while your account exists; deleted when you delete your account.
- Alert media (audio and photos) and the alert record: kept for up to 1 year after the alert ends, then deleted.
- Location history: 30 days on a rolling basis. If an alert is triggered, the related history is frozen for 1 year from the alert.
- IP history: 30 days on a rolling basis; frozen for 1 year if an alert was triggered.
- Battery history: 30 days on a rolling basis; frozen for 1 year if an alert was triggered.
- Alert links sent to contacts (maps / evidence downloads): remain usable while the alert is active and for about 30 days after it ends.
- Anonymous crash diagnostics: up to 180 days.
Why alert data is kept for a year. An alert is a record of a possible crime against you. That record is often the only evidence of where you were, what was happening around you, and who was notified — and it may be needed by you, by your lawyer, or by the police long after the event. Keeping it for a year also lets us trace, in reverse, whether someone impersonated you or acted in your account. We therefore keep alert records and alert media for one year rather than deleting them immediately.
You can always ask us to delete it sooner — deletion on your request is not conditional on the year passing. Because this is a safety product, we first take reasonable steps to confirm that the request really comes from you and not from someone who has taken control of your account or your device, and that you are not making the request under duress. Once we are satisfied of that, we delete the data.
6. Security
- All traffic is encrypted in transit (HTTPS/TLS).
- Passwords are stored as bcrypt hashes; session tokens are stored only as hashes on our server.
- On your device, authentication tokens and PIN hashes are kept in the operating-system secure storage (iOS Keychain / Android Keystore). Your PINs never leave your device in any form.
- Optional encrypted backups are encrypted on your device before upload — we store opaque data we cannot read.
During recording, your operating system shows standard indicators (a recording dot, a notification). This is required by Android/iOS and cannot be hidden.
7. Your choices and rights
You can:
- Access the data we hold about you and correct inaccurate data.
- Delete your account and data — in-app ("Delete account") or by emailing support (see Data Deletion).
- Turn off optional location history, battery history, and IP history; revoke camera/microphone/location permissions in your device settings.
U.S. residents (including under the California CCPA/CPRA): you have the right to know, access, delete, and correct your personal information, and not to be discriminated against for exercising these rights. We do not sell or "share" personal information as those terms are defined under U.S. privacy law. To exercise your rights, email us (Section 10).
8. International users and transfer of data to the United States
The App is available in more than one country. Wherever you use it, your data is processed and stored on our servers in the United States, and our database provider hosts it in the United States as well. Uploaded files are stored on our own server; we do not copy them to third-party storage. By using the App you understand that your data is transferred to and held in the United States, where the legal protections may differ from those in your country, and that U.S. authorities may in principle request access under U.S. law.
We remain responsible for your data after that transfer: we use it only for the purposes described in this policy, require comparable protection from the service providers we use, and answer your access, correction, and deletion requests wherever you live.
8.1 Canada (PIPEDA and Quebec Law 25)
If you are in Canada, the following applies in addition to the rest of this policy:
- Your data is processed and stored outside Canada — in the United States, by FIBER LLC and its service providers. While it is there, it is subject to U.S. law, including lawful access requests by U.S. authorities.
- We stay accountable for it. FIBER LLC remains responsible for personal information transferred to a third party for processing and uses contractual means to require a comparable level of protection.
- Named contact. The person accountable for our privacy compliance — the Privacy Officer referred to in Section 1 — can be reached at Support@IWasKidnapped.com. You may also complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d'accès à l'information.
- Your rights. You may access, correct, and request deletion of your personal information, withdraw your consent to optional collection (location, IP and battery history) at any time in the App, and ask us how we handled your data. We answer within the time limits set by applicable Canadian law.
8.2 Other countries
If your country gives you additional rights over your personal data, we honour them. Send your request to Support@IWasKidnapped.com and tell us where you live so we can apply the right rules.
9. Children
The App is intended only for adults 18 and older and is not directed to children. We do not knowingly collect data from anyone under 18, and we ask the app stores to keep users they have determined to be minors from downloading it. If you believe a minor has used the App, contact us and we will delete the data.
10. Recording laws and contact
You are responsible for following the recording laws in your location — they differ from country to country and, in the United States, from state to state; see our Terms of Service (Recording of third parties).
Privacy questions and requests — FIBER LLC, a limited liability company organised in the State of
Texas, United States:
Email: Support@IWasKidnapped.com
Mailing address: 2943 Parkway Blvd, Unit #297, West Valley, UT 84119, United States
11. Language
This policy may be published in several languages. The English version is the controlling version; if a translation differs from it, the English text prevails, except where the law of your country requires otherwise.
12. Changes
We may update this policy. We will post the new version here and update the dates above. Material changes will be highlighted in the App.