The short version
Porchlight collects what a check-in needs and nothing else. There is no analytics SDK in the app, no crash reporter, no advertising identifier and no third-party tracker. Nothing is sold. Nothing goes to a data broker.
Nothing leaves the app's database except a notification on its way to a phone or a browser, because a notification has to be handed to a courier. The couriers are Expo's push service, and through it Apple or Google, or your browser's own push service. The list on this website is separate from the app: a signup there is also sent to Telegram. Each of these is named again below, with what it sees.
Most of what follows is not a promise about how we intend to behave. It is a constraint written into the database, which is a different kind of claim: the app is not granted the ability to do the thing, so there is no setting to leave switched on and nobody to talk into it.
What we collect
These are the fields, all of them, and the reason each one exists.
| What | Why it exists | Optional? |
|---|---|---|
| Email address | It is your sign-in. | No |
| Password | It is your sign-in. Stored hashed by Supabase Auth; we never see it. | No |
| Your name | So the people you named are told who is overdue rather than a row id. | No |
| Phone number | So the people you named have a number to call at the top of the ladder. Readable only by those who accepted. | Yes — set it to opt in, clear it to opt out |
| What you called the watch, and where you said you were going | The promise itself. | The destination is optional |
| A vehicle's plate and description | The case the feature exists for: nobody else knew the plate. | Yes — only if you send one |
| Your watch history and its events | The record of what happened. Append-only. | No, while the account exists |
| A position | Only from an alarm you pressed. See below — this is the answer people care about. | Yes |
| A sealed note | What you want a 911 dispatcher told if you ever do not check in. Opened only at the top of the ladder, only by a person you named who accepted, only while a watch of yours is open. Not part of the record. | Yes — write it to opt in, clear it to opt out |
| A bystander alarm | One of the people you named pressed the alarm for you, and a sentence about why. Seen by you and the people you named who accepted, and nobody else. It starts no watch and reads no position. | Yes — only if one of them presses it |
| A push token or Web Push subscription | The address an alarm is delivered to. | Yes — decline notifications and no such row exists |
| An installation ID, in the installed Android app | Google's Firebase Cloud Messaging makes one when it issues the push token. It names that copy of the app, not you, and it is held by Google, not in our database. | Yes — it comes with the push token, and not without it |
If you joined the list on this website rather than using the app, what we hold is the email address you typed and, if you chose to add them, a city, a phone number and a note. That table is insert-only: the website can write a signup and has no ability to read one back, because there is no read policy and no read grant on it. When you join, the same details are also sent once as a message to the project's own Telegram account, so that a person sees the signup. Telegram carries that message. To have an entry removed, write to the address at the bottom of this page.
Location, precisely
This is the question both app stores care about most, and the one most often overstated, so it is stated narrowly.
- Location is never collected in the background. The app asks only for when-in-use permission. Background location is switched off in the app's own configuration: not declined at runtime, but absent from what the app is built to be able to ask for.
- A watch does not track you. Starting a watch, running it, extending it and ending it read no position at all. A deadline is not a map. The database is split so that a person looking at your watch cannot see that a position exists, let alone what it is.
- One thing sends a position, and it is an act you took: an alarm you raised yourself. The phone reads where it is once, at the press, and that one fix goes to the people you named with the alarm. Nothing is left running, and there is no trail.
It is an exception on purpose. Pressing the alarm is asking to be found.
What we use it for
Running the product, and nothing else. No advertising. No marketing profiles. No personalisation. No analytics. No fraud scoring. No training a model on anything you wrote.
Who else sees it
- The people you named, which is the product. When a watch goes overdue, the people you named who accepted are told your name, what you called the watch, how late you are, and, if you raised an alarm, the position sent with it. They see nothing when there is nothing to know, and they never see where you are otherwise. In some of its messages the app calls a person who accepted a Guardian, which is the app's word for one of the people you named and nothing more.
- Supabase, the company whose service runs our database and sign-in. They are a processor: they hold the data so the product can work, and they do not get to use it for anything of their own.
- Expo, and through it Apple or Google, for a notification to the installed app. The database hands the alert to Expo's push service, run by 650 Industries, and Expo hands it to Apple for an iPhone or to Google's Firebase Cloud Messaging for an Android phone. Each sees the device token and the title and body of the alert as it passes, the same way any courier sees an envelope.
- Your browser's push service, for a notification to a browser. It belongs to whoever makes the browser, and it carries the alert to the browser that asked for it.
- Telegram, for a signup to the list on this website only, as described above. Nothing from the app goes to Telegram.
Nobody else. Not police, not advertisers, not a monitoring centre, not staff. There is no monitoring centre and no staff. We do not sell data, and we do not share it for anyone else's advertising.
One thing this page will not pretend away: it loads its two typefaces from Google Fonts, so Google sees the IP address of whoever opens porchlight.watch. That is a font service and not a tracker, and it is not something we use, but a page that asks you to trust its account of third parties should start by naming its own.
How long we keep it
Your account and its record stay until you delete them. Watch events are append-only for as long as the account exists: the app is granted no way to edit or remove one afterwards, not for you and not for the people watching, because a safety record you can quietly revise is not a record.
Deleting everything
You can delete your account from inside the app: open Your people, choose Account at the bottom, then Delete your account. It removes your profile, every watch and every event on it, the people you named and the people who named you, your push tokens and browser subscriptions, and your sign-in itself. It is not a request that goes into a queue; the account is gone when the screen returns you to sign-in.
It refuses in one situation, and it is deliberate. It will not delete while a watch is open, because deleting mid-watch would turn an alarm other people are waiting on into silence. End the watch first.
If you no longer have the app, Delete your account says how to do the same thing from any browser, or by writing to us.
How it is kept
- Everything is encrypted in transit, over HTTPS.
- Authorization lives in the database, not in the app. Every table is behind row-level security, and the key shipped inside the app grants nothing that those rules do not. Two test suites in the repository assert it: that a watch can only be opened on yourself, that the record cannot be rewritten, that a person looking at your watch cannot read a position.
- Push tokens and browser push endpoints cannot be reached through the API at all: security is on, and there is no policy and no grant that would let anything read them. They are written and read only by the database's own functions.
Children
Porchlight is not directed to children under 13, and we do not knowingly collect anything from them. Being straight about the mechanism: there is no age gate in the app. An account needs an email address, and an email address does not carry an age. If you believe a child under 13 has an account, write to us and it will be deleted.
Your choices
- Delete your account, and everything with it, from inside the app or from a browser.
- Add or clear your phone number at any time. Cleared means the people who could see it no longer can.
- Write or clear a sealed note at any time. Cleared means there is nothing to open.
- Decline notifications. The watch still runs, because the deadline lives on our server rather than on your phone, but the alert has no address to arrive at on that device.
- End a watch at any time.
- Remove one of your people, or stop watching over somebody who named you, at any time. Either side can end it, and neither needs the other to agree.
If you want a copy of what we hold, or something corrected, write to the address below and say so.
If this changes
The date at the top changes with it, and the change is written plainly rather than left to be discovered. If a change ever narrows what this page promises, whether a new thing collected or a new party it goes to, you will be told in the app before it takes effect, not after.
The terms of use are a separate page, and a shorter one.
Getting in touch
Write to support@porchlight.watch. Porchlight is a small independent project, so a reply comes from a person and can take a few days. What it is not is a monitoring service: nothing sent to that address raises an alarm, and nobody is reading it at 2am.
If you are in danger right now, call 911.