Privacy Policy

What we know, and what we don't.

Porchlight is a check-in with an alarm on it. It needs to know when you are due and who to tell. It does not need to know where you are, and mostly it is not able to find out.

Effective 27 September 2026. This is the second version. It adds the bystander alarm and the Android installation ID to what is collected, names Expo, Firebase and Telegram among those who carry something, says that an alarm is the only thing that sends a position, and says where Delete your account is found and how to ask for it without the app.
Porchlight is an independent project built in Kansas City, Missouri. It is not a monitoring company: there is no monitoring centre, no staff on call, and nobody watching a screen.

If you are in danger right now, call 911. Porchlight tells the people you named and nobody else. It never contacts police on your behalf.

The short version

Porchlight collects what a check-in needs and nothing else. There is no analytics SDK in the app, no crash reporter, no advertising identifier and no third-party tracker. Nothing is sold. Nothing goes to a data broker.

Nothing leaves the app's database except a notification on its way to a phone or a browser, because a notification has to be handed to a courier. The couriers are Expo's push service, and through it Apple or Google, or your browser's own push service. The list on this website is separate from the app: a signup there is also sent to Telegram. Each of these is named again below, with what it sees.

Most of what follows is not a promise about how we intend to behave. It is a constraint written into the database, which is a different kind of claim: the app is not granted the ability to do the thing, so there is no setting to leave switched on and nobody to talk into it.

What we collect

These are the fields, all of them, and the reason each one exists.

WhatWhy it existsOptional?
Email addressIt is your sign-in.No
PasswordIt is your sign-in. Stored hashed by Supabase Auth; we never see it.No
Your nameSo the people you named are told who is overdue rather than a row id.No
Phone numberSo the people you named have a number to call at the top of the ladder. Readable only by those who accepted.Yes — set it to opt in, clear it to opt out
What you called the watch, and where you said you were goingThe promise itself.The destination is optional
A vehicle's plate and descriptionThe case the feature exists for: nobody else knew the plate.Yes — only if you send one
Your watch history and its eventsThe record of what happened. Append-only.No, while the account exists
A positionOnly from an alarm you pressed. See below — this is the answer people care about.Yes
A sealed noteWhat you want a 911 dispatcher told if you ever do not check in. Opened only at the top of the ladder, only by a person you named who accepted, only while a watch of yours is open. Not part of the record.Yes — write it to opt in, clear it to opt out
A bystander alarmOne of the people you named pressed the alarm for you, and a sentence about why. Seen by you and the people you named who accepted, and nobody else. It starts no watch and reads no position.Yes — only if one of them presses it
A push token or Web Push subscriptionThe address an alarm is delivered to.Yes — decline notifications and no such row exists
An installation ID, in the installed Android appGoogle's Firebase Cloud Messaging makes one when it issues the push token. It names that copy of the app, not you, and it is held by Google, not in our database.Yes — it comes with the push token, and not without it

If you joined the list on this website rather than using the app, what we hold is the email address you typed and, if you chose to add them, a city, a phone number and a note. That table is insert-only: the website can write a signup and has no ability to read one back, because there is no read policy and no read grant on it. When you join, the same details are also sent once as a message to the project's own Telegram account, so that a person sees the signup. Telegram carries that message. To have an entry removed, write to the address at the bottom of this page.

Location, precisely

This is the question both app stores care about most, and the one most often overstated, so it is stated narrowly.

It is an exception on purpose. Pressing the alarm is asking to be found.

What we use it for

Running the product, and nothing else. No advertising. No marketing profiles. No personalisation. No analytics. No fraud scoring. No training a model on anything you wrote.

Who else sees it

Nobody else. Not police, not advertisers, not a monitoring centre, not staff. There is no monitoring centre and no staff. We do not sell data, and we do not share it for anyone else's advertising.

One thing this page will not pretend away: it loads its two typefaces from Google Fonts, so Google sees the IP address of whoever opens porchlight.watch. That is a font service and not a tracker, and it is not something we use, but a page that asks you to trust its account of third parties should start by naming its own.

How long we keep it

Your account and its record stay until you delete them. Watch events are append-only for as long as the account exists: the app is granted no way to edit or remove one afterwards, not for you and not for the people watching, because a safety record you can quietly revise is not a record.

Deleting everything

You can delete your account from inside the app: open Your people, choose Account at the bottom, then Delete your account. It removes your profile, every watch and every event on it, the people you named and the people who named you, your push tokens and browser subscriptions, and your sign-in itself. It is not a request that goes into a queue; the account is gone when the screen returns you to sign-in.

It refuses in one situation, and it is deliberate. It will not delete while a watch is open, because deleting mid-watch would turn an alarm other people are waiting on into silence. End the watch first.

If you no longer have the app, Delete your account says how to do the same thing from any browser, or by writing to us.

How it is kept

Children

Porchlight is not directed to children under 13, and we do not knowingly collect anything from them. Being straight about the mechanism: there is no age gate in the app. An account needs an email address, and an email address does not carry an age. If you believe a child under 13 has an account, write to us and it will be deleted.

Your choices

If you want a copy of what we hold, or something corrected, write to the address below and say so.

If this changes

The date at the top changes with it, and the change is written plainly rather than left to be discovered. If a change ever narrows what this page promises, whether a new thing collected or a new party it goes to, you will be told in the app before it takes effect, not after.

The terms of use are a separate page, and a shorter one.

Getting in touch

Write to support@porchlight.watch. Porchlight is a small independent project, so a reply comes from a person and can take a few days. What it is not is a monitoring service: nothing sent to that address raises an alarm, and nobody is reading it at 2am.

If you are in danger right now, call 911.