Privacy Policy
Last updated: March 2026
We take the protection of your personal data very seriously. This privacy policy informs you about how we handle your data when you use our app Still OK.
Were you entered as someone's emergency contact and do not use Still OK yourself? Then section 15 is written for you — it explains in one place what we store about you, why, and how you can object.
1. Data Controller
The data controller responsible for data processing is:
Nicolas Autzen
Heinrich-Vogeler-Weg 18
27726 Worpswede
Germany
Email: contact@still-ok.com
2. Data We Collect
We collect and process the following data:
- Your name (for personalized notifications)
- Your check-in times
- Your check-in interval settings
- Emergency contact names and email addresses
- Device token for push notifications
- Language preference
- Anonymous device identifier (UUID)
- Account creation date
- Your GPS location (only if you explicitly enable location sharing)
- Emergency contact phone numbers (used for WhatsApp and SMS notifications)
- Custom notification messages (if you configure personalized messages for your contacts)
- Subscription and purchase data (processed by your app store and our subscription management provider)
- Phone number type (mobile, landline, or VoIP — determined via our messaging provider to select the appropriate notification channel)
- WhatsApp availability status per contact (cached temporarily to optimize message delivery)
- Emergency profile information (Premium only) — safety details you voluntarily provide, such as medical conditions, allergies, blood type, dependents, pet care needs, home access details, and key contacts. This data is included in emergency notifications sent to your contacts.
- Account credentials (optional) — if you create an account via Apple Sign-In or Google Sign-In, your email address and authentication provider are stored to enable account recovery and multi-device access. The app works fully without an account.
- Contact status page data (optional) — if you enable the status page for a contact, a unique access token is generated and stored. When someone visits the status page, we record the time of the visit. During an active alert, the status page displays your name, check-in status, emergency profile (if set), and GPS location (if enabled). This data is accessible to anyone with the status page link — no login required.
- Delivery test records (optional) — when you send a test message to a contact, we store the time of the test, the result for each channel (email, WhatsApp, SMS) and a single-use confirmation token. If your contact presses the confirmation button, we additionally store the time of that press and which channel they confirmed. There is one record per contact, overwritten by the next test — no history is built up. The record itself contains no IP address, no browser information and no location. Independently of that, our hosting provider logs technical request data when the confirmation page is opened — see section 4.
3. Purpose and Legal Basis
We process your data for the following purposes:
a) Core App Functionality
- To provide the deadman's switch functionality
- To send reminder notifications before your check-in deadline
- To notify your emergency contacts via email, WhatsApp, and/or SMS if you miss a check-in
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) - this processing is necessary to provide the service you requested.
b) App Improvement
- To improve our app through crash reports (Firebase Crashlytics)
- To analyze app usage patterns (Firebase Analytics)
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) - we have a legitimate interest in improving our app and fixing bugs.
c) Ad-Free Experience
Still OK is completely ad-free — both the free and premium versions. We do not display advertisements or share data with advertising networks.
privacySection3cLegal
d) Location Sharing (Optional)
If you enable location sharing, your GPS location is recorded during each check-in and stored securely. In an emergency, this location is included in notifications (email, WhatsApp, and SMS) sent to your contacts to help them find you.
If you grant "Always" location permission, the app uses low-power background location monitoring (iOS: significant-change location service; Android: balanced-accuracy location updates) to keep your location current even when the app is closed. This data is stored exclusively on EU servers and is only used for emergency notifications.
Legal basis: Consent (Art. 6(1)(a) GDPR) - you explicitly opt in to location sharing. You can withdraw your consent at any time by disabling location sharing in the app settings, which will also delete your stored location data.
e) Premium Features and Messaging
If you subscribe to premium features, we process your subscription status to unlock premium functionality such as flexible check-in intervals, WhatsApp and SMS notifications, GPS location sharing, SOS alerts, unlimited contacts, and an emergency profile. The emergency profile lets you store structured safety information (medical details, dependents, pet care, home access) that is automatically included in alert emails sent to your contacts. Your contacts' phone numbers are transmitted to our messaging provider for WhatsApp and SMS delivery, and to determine the phone number type (mobile, landline, or VoIP) for automatic channel selection. WhatsApp messages are delivered via the Meta/WhatsApp Business Platform through our messaging provider.
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) - this processing is necessary to provide the premium services you purchased.
f) Optional Account (Social Login)
The app works without an account (anonymous mode). If you choose to create an account via Apple Sign-In or Google Sign-In, we receive your email address and an authentication token from the provider. This data is processed by Firebase Authentication to enable account recovery and multi-device access. We do not receive or store your Apple or Google password.
Legal basis: Consent (Art. 6(1)(a) GDPR) - you explicitly choose to create an account. You can disconnect your account at any time in the app settings.
g) Contact Status Page (Optional)
If you enable the status page for a contact, a unique token-based URL is created that allows the contact to view your current check-in status without logging in. In normal mode, the page shows your name, last check-in time, and 7-day check-in history. During an active alert, the page additionally displays your emergency profile and GPS location (if available), and allows the contact to confirm they are checking on you. Visit timestamps are recorded to notify you when someone checks on you. You can disable the status page for each contact individually, which immediately revokes access. The status page URL is not indexed by search engines.
Legal basis: Two different people are affected here, and they are covered separately. For displaying your data (name, check-in status, emergency profile, location): consent (Art. 6(1)(a) GDPR) — you explicitly enable the status page per contact and can disable it at any time in the contact detail view, which immediately revokes access. For the visit and confirmation timestamps of your contact: legitimate interest (Art. 6(1)(f) GDPR) — your consent cannot cover another person's data, so this processing rests on your interest in knowing whether someone has checked on you. Right to object (Art. 21 GDPR): your contact can object to this at any time at contact@still-ok.com.
h) Delivery Test and Confirmation (Optional)
You can send a test message to a contact at any time to check whether your safety net really holds. The test goes out over the same channels that would carry a real alert. Every test message contains your name and a note that it is a test. Only the email additionally contains a link to this privacy policy and a button your contact can press to confirm that the message arrived — a text message has no room for a link, and the WhatsApp templates are fixed and cannot carry one. Contacts who reach us only by phone therefore find the information about them in section 15 of this policy. Confirming is possible by email only. Only the press of that button is stored as a confirmation — opening or previewing the message is not. Before confirming, your contact is told what it means. Afterwards the app shows you "last confirmed" instead of just "sent". The confirmation expires after 12 months; from then on the app shows "never confirmed" again rather than claiming something it no longer knows.
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — the provision expressly also covers the interest of a third party, here yours: you have a legitimate interest in knowing whether your emergency contacts can actually be reached, and without a response from the recipient that cannot be verified. Your contact acts voluntarily: without a press on the button no confirmation is stored. What the confirmation adds is a single timestamp and the channel, for one recipient, with no profiling. Your contact can object to this at any time — see section 15.
4. Third-Party Services
We use the following third-party services:
Firebase (Google)
For data storage, authentication (including optional Apple/Google Sign-In), push notifications, crash reporting, and analytics. Your data is stored exclusively in European data centers (EU).
Email Service (Resend)
Emergency notifications and test emails are sent via Resend. Although Resend Inc. is a US-based company, our sending domain is configured to use the EU (Ireland, eu-west-1) region — emails are routed and processed in European data centers. The emails contain your name and are sent to the email addresses you specified as emergency contacts. During an alert, the email may additionally include your emergency profile and location, depending on your settings. Email delivery data is retained by Resend for up to 30 days. As an additional safeguard against any potential data access by Resend's US parent company, the processing is covered by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs).
Messaging & Phone Lookup (Twilio)
WhatsApp messages, SMS messages, and phone number lookups are processed via Twilio, a US-based communications platform. Twilio is used for: (1) delivering WhatsApp notifications via the Meta/WhatsApp Business Platform, (2) delivering SMS notifications, and (3) determining the phone number type of your contacts (mobile, landline, or VoIP) to select the appropriate notification channel. The data transmitted includes your contacts' phone numbers, your name, an alert message, and optionally your location. Phone type results and WhatsApp availability are cached for up to 30 days to avoid repeated lookups. Message contents are retained in Twilio's accessible logs for up to 30 days and may persist for up to 30 additional days in internal backup systems before being permanently deleted. Twilio processes this data under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs).
Subscription Management (RevenueCat)
In-app subscriptions and purchases are managed through RevenueCat, a US-based subscription management platform. RevenueCat processes your anonymous app user ID, subscription status, purchase history, and app store country. No personal data such as your name or email is shared with RevenueCat. RevenueCat processes this data under Standard Contractual Clauses (SCCs) to ensure GDPR compliance.
Feedback Categorization (Google Gemini)
When you send in-app feedback, the free text you write is sent to Google's Gemini API to automatically categorize it (for example bug, feature request, question, or praise) so we can respond faster. Only the feedback text and its language are sent — never your email address, your name, or your device ID. We use the paid Gemini API: Google does not use the transmitted content to train its AI models and acts as a data processor on our behalf; Google logs inputs and outputs only for a limited period to detect abuse and maintain security. Because the Gemini API is a global service, this text may be processed on Google infrastructure outside the EU; this transfer is covered by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs). Please do not enter health data or other sensitive information in the feedback field.
Internal Notification (Telegram)
When new feedback arrives, we receive an internal notification via Telegram so we notice it quickly. This notification contains only the category, a short auto-generated summary of the topic, and technical metadata (platform, app version, language) — it does not contain your feedback text and not your email address. Your actual feedback is stored and read in our European database. Telegram is operated by Telegram FZ-LLC (United Arab Emirates).
Website Hosting and Server Logs (GitLab Pages)
Our website is hosted on GitLab Pages. As with any web server, the host records technical data for each page request: IP address, browser identification, time, and the address of the page requested. We cannot switch this off and we do not receive these logs. This matters here for one specific reason: the pages we send your emergency contacts to — the status page and the delivery confirmation page — are part of that website, and the address of those pages contains the access token and, for the confirmation page, your first name. The pages themselves load nothing from outside: no analytics, no external fonts, no cookies, no browser storage.
5. Local Data Storage
In addition to cloud storage, we store the following data locally on your device for offline access: your name, check-in settings, emergency contacts, and device ID. This data remains on your device and is deleted when you uninstall the app or delete your account.
6. Data Retention
Your data is stored as long as you have an active account. When you delete your account, all your data is permanently removed from our servers within 30 days. Delivery test records are kept for a maximum of 12 months; when you delete the contact they belong to, they are removed within 24 hours by a daily clean-up job. The confirmation link in a test message expires after 30 days and works only once. Provider-specific retention: Firebase Crashlytics 90 days, Firebase Analytics 2 months (default), Twilio SMS/WhatsApp message data up to 30 days in accessible logs plus up to 30 additional days in internal backup systems, Resend email delivery data up to 30 days. Once a notification has been delivered to a recipient (via SMS, WhatsApp, or email), the message remains in their inbox or chat until they delete it — that storage is outside our control.
7. Data Transfer to Third Countries
Your data stored in Firebase Firestore and Cloud Functions remains in European data centers (Frankfurt, Germany), and our Resend email infrastructure is configured to the EU (Ireland) region. However, some services involve data transfer to the USA: Twilio (SMS, WhatsApp delivery, phone type detection), Meta/WhatsApp (sub-processor for WhatsApp delivery), RevenueCat (subscription management), Firebase Crashlytics/Analytics, and GitLab (website hosting, see section 4). These providers — as well as Resend's US parent company as an additional precaution — operate under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission, July 2023) and have additionally implemented Standard Contractual Clauses (SCCs) approved by the European Commission. Additionally, when you submit in-app feedback, the feedback text is processed via Google's global Gemini API and may be processed outside the EU; this is covered by the same EU-U.S. Data Privacy Framework and Standard Contractual Clauses. Our internal Telegram notification about new feedback contains no personal data and therefore does not involve a transfer of your personal data to a third country.
8. Your Rights
Under GDPR, you have the following rights:
- Right to access your personal data (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure - 'right to be forgotten' (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
You can exercise these rights directly in the app (Settings > Data Export / Delete Account) or by contacting us.
If you are an emergency contact and do not use Still OK yourself: these rights apply to you in exactly the same way, even without an app and without an account. Write to us at contact@still-ok.com and tell us the email address or phone number stored for you — without it we cannot find your data, because it is filed under the account of the person who named you. You can also simply ask that person to remove you as a contact; that deletes everything stored about you and is usually the fastest route.
9. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR. You can choose: the authority where you live, where you work, or where you believe the infringement took place. As we are based in Germany, the authority responsible for us is:
Die Landesbeauftragte für Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
www.lfd.niedersachsen.de
10. Data Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, or manipulation. All data transmission is encrypted using TLS. Data at rest is encrypted using industry-standard encryption.
11. Minimum Age
This app is intended for users aged 16 years or older. We do not knowingly collect personal data from children under 16. If you are under 16, please do not use this app without parental consent.
12. Automated Decision-Making
The app does not use automated decision-making or profiling that produces legal effects or significantly affects you. The sending of notifications is based solely on whether you checked in within your specified interval.
13. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any significant changes through the app. The current version is always available at this URL.
14. Contact
If you have questions about this privacy policy, please contact us at:
Nicolas Autzen
Heinrich-Vogeler-Weg 18
27726 Worpswede
Germany
contact@still-ok.com
15. Information for Emergency Contacts
This section is for you if someone has entered you as their emergency contact and you do not use Still OK yourself. Everything above is written from the perspective of the person using the app. Here you will find, in one place, what we store about you and what you can do about it.
We did not receive your data from you, and not from any public source: a person who uses Still OK entered you. From them we have your name and, depending on what they entered, your email address and/or your phone number, plus the language in which you should be contacted. In addition we store what is technically needed to reach you: whether your number is a mobile or landline number and whether it can receive WhatsApp, and — once a test message or an alert has gone out to you — when that happened, over which channel, and whether you confirmed it.
Why we may do this: legitimate interest under Art. 6(1)(f) GDPR. The provision expressly also covers the interest of a third party — here the interest of the person who entered you: they want someone to be notified if something happens to them, and that only works if we can actually reach you. This covers both a real alert and a test message. Your data is not used for anything else: no advertising, no profiling, and no disclosure beyond the delivery providers named in section 4.
We store your data for as long as the person who entered you keeps you as a contact. If they remove you, or delete their account, your data goes with it. Delivery test records are capped at 12 months on top of that.
You have the same rights as anyone else whose data we process — access, rectification, erasure, restriction and portability (section 8). Write to contact@still-ok.com and tell us the email address or phone number stored for you: without it we cannot find your data, because it is filed under the account of the person who entered you. Often the fastest route is to ask that person directly to remove you as a contact. You can also lodge a complaint with a supervisory authority at any time (section 9).
Your right to object (Art. 21 GDPR). You can object to us processing your data at any time, with effect for the future, and you do not have to give a reason. One message to contact@still-ok.com is enough. We will then delete your data. Please be aware of what that means: from that point on you will no longer be notified if the person who entered you misses a check-in.