Privacy Policy

Last updated 25 September 2026

CyShield works without an account, without ads and without tracking. Most of your information never leaves your phone. This policy explains exactly what is processed, where and why.

1. Who is responsible

The data controller is Garbis Tapacian. Contact: boogieapps.help@gmail.com.

2. What stays on your phone

  • Your location, used to show your position, find nearby shelters and calculate distances. CyShield doesn't track your location or send it to our servers, except when you choose to send a flooded-road report or a shelter check (see section 3).
  • Emergency contacts you choose, the medical information you enter and the places you save (such as home or work).
  • Your settings, saved offline maps, cached warnings and the shelter database.

We cannot see this information. It is deleted when you delete the app. If you export a backup, you decide where it goes.

3. What we store on our servers

Our backend is hosted by Supabase in Frankfurt, Germany (EU).

  • Notifications. If you allow notifications, we store your device's push token, platform (iOS or Android), app language and your alert choices (warning types, earthquake level, whether alerts are on, whether critical alerts are on, and whether you limited alerts to an area, but not the area or your location), so we can send official alerts. The alerts are delivered through Apple's push service on iPhone and through Google's Firebase Cloud Messaging on Android. Purpose: sending the alerts you asked for. Legal basis: your consent (Art. 6(1)(a) GDPR). Kept while notifications are active. Tokens not refreshed for 12 months are deleted automatically.
  • Shelter reports. If you send a report, we store the shelter, the problem category, your optional text, the time and a random identifier created for this installation. The identifier prevents duplicate reports and abuse. It is not linked to your name, phone number, email or location. Legal basis: our legitimate interest in keeping shelter information reliable and forwarding problems to the authorities (Art. 6(1)(f) GDPR). The random identifier is removed from a report after 30 days. Report contents are kept while they are useful for correcting shelter data, and for no more than 3 years.
  • Random installation identifier. Created without any personal details, so the backend can apply rate limits. It is deleted after 12 months without use.
  • Technical logs. Our hosting provider keeps short-lived server logs (such as IP address and time of request) for security and troubleshooting.
  • Shelter checks. If you send a check, we store the shelter, the date of your visit, the time we received it, your checklist answers, your optional text, your phone's position at the moment of sending (if location is allowed), any photos, and the random identifier for this installation. Legal basis: our legitimate interest in accurate shelter information (Art. 6(1)(f) GDPR). Checks are kept for up to 3 years; photos are deleted 12 months after the check is closed.
  • Photos. They are stored privately, seen only by us and the authorities we forward them to, and never published in the app. Compression on your phone removes the camera's embedded location and device data before upload.
  • Contributor nickname. Stored only if you choose one, and shown in the app next to your number of accepted checks. Legal basis: your consent (Art. 6(1)(a) GDPR). Removed whenever you ask, or if you delete your data in the app.
  • Flooded-road reports. If you report flooding or confirm a report, we store the location you marked, the time and the random identifier for this installation, and show the location (never who reported it) to other users. Legal basis: our legitimate interest in public safety information (Art. 6(1)(f) GDPR). Reports expire after a few hours and are deleted 7 days later.

4. Services your phone contacts directly

To work, the app connects directly to these providers. Like any website, they receive your IP address and technical request details.

  • Map data: the street map is OpenStreetMap data, served by CyShield through Cloudflare (USA) until you save it to your phone; after that it is read from your phone. Map fonts and icons come from the same place. No location or identifier is sent with these requests, although the parts of the map that load show roughly which area you are viewing.
  • Esri (USA): satellite imagery, only if you choose the satellite view. Esri receives which parts of the map are shown, as for any map service.
  • Photon by Komoot (Germany): online place search. Searches first run on your phone; when they need house numbers or find too little, your search text and your approximate position are sent to Photon to rank nearby results.
  • CyShield routing server (Hetzner, Germany): when you're online, the app sends your position and a shelter's position to our own routing server to show walking and driving distances along the streets and to find the shelter nearest on foot. Only the two points are sent, with no identifier; the server works out the route and keeps nothing: requests are not logged. Offline, distances are worked out on your phone in a straight line.
  • MeteoAlarm (EUMETNET, EU), EMSC (France) and NASA FIRMS (USA): public hazard feeds. No location is sent.
  • Apple (USA) and Google (USA): push notifications. Our server sends the alert to Apple's push service for iPhones, or to Google's Firebase Cloud Messaging for Android phones, and they deliver it to your phone. Android has no other way to reach a phone that is not running the app.
  • Apple or Google process support payments. We never receive your payment details.

Where a provider is outside the EU, transfers rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

5. What we never do

We do not use analytics, advertising or tracking SDKs. We do not sell or share your data for marketing. We do not build profiles. We do not ask for your name, email or phone number.

6. Sharing your location and medical ID

When you share your location or call for help, CyShield opens your phone's share sheet, messages, phone or maps app with the details filled in. Nothing is sent until you confirm, and it goes only to the people or apps you choose.

You can also share your medical ID, as a picture of the card or as text. It goes through the same share sheet, only to whoever you choose, and never to us. Anything on the card is in what you send, so send it only to someone you trust.

7. Permissions

Location (while using the app), notifications and critical alerts are optional. Contacts access is used only through the system picker to add the contacts you select. You can change permissions at any time in your phone's settings.

8. Your rights

Under the GDPR you have the right to access, correct and delete your data, to restrict or object to processing, to data portability and to withdraw consent at any time.

You can delete the data held on our servers for this installation directly in the app: Settings › Legal & privacy › Delete my data from CyShield servers. Because we do not know who you are, we may need your installation's report details to act on a request by email.

You can complain to the Office of the Commissioner for Personal Data Protection of Cyprus (dataprotection.gov.cy).

9. Children

CyShield is a general safety app and is not directed at children. We do not knowingly collect personal data from children under 14.

10. Changes

We update this policy whenever the app starts processing data differently. The date at the top shows the latest version. Important changes are shown in the app.