Privacy Policy
THIS SERVICE COLLECTS SENSITIVE INFORMATION, INCLUDING PRECISE LOCATION AND AUTOMATICALLY-CAPTURED AUDIO AND VIDEO, IN ORDER TO PROVIDE ITS EMERGENCY-RESPONSE FUNCTIONALITY. PLEASE READ THIS POLICY CAREFULLY.
1. Introduction
This Privacy Policy explains how Skuark Ltd ("Skuark", "we", "us", or "our") collects, uses, discloses, and protects information when you create an account and use the Skuark mobile application and related services (the "Service"). This Policy should be read together with our Terms of Service. By creating an account, you acknowledge that you have read and understood this Policy.
Because the Service is designed to facilitate emergency response, it necessarily involves the collection of sensitive information, including precise location and audio and video recordings. We have designed this Policy to explain that collection clearly, given its importance to your decision to use the Service.
2. Information We Collect
2.1 Account and Profile Information
- Name, email address, phone number, and password (or authentication credentials) provided when you create an account.
- A username, derived from your name and shown within the Service, and your sex/gender, which we collect for our records and for safety analytics.
- Your declared user category — member of the public, or a professional role such as medical, police, fire and rescue, security, or first aider — and, where you apply to be a Qualified Responder, the evidence document or photograph you upload to support that application (for example an ID card, warrant card, or certificate).
- Optional profile information, such as a profile photo, that you choose to provide.
- Organisational affiliation, where your account is provisioned by an employer, school, or event operator.
2.2 Location Data
- Precise, real-time location data (for example, GPS coordinates) collected when you activate an alarm, and, where you have enabled background location for the Service, at other times while the app is installed.
- Approximate location derived from network or device information, used to determine which Users and emergency services fall within a given notification radius.
2.3 Audio, Video, Transcripts, and Sensor Data
- Audio and video recordings automatically captured by your device upon alarm activation.
- Text transcripts of speech captured during an incident or during an evidence clip. The speech recognition is performed on your own device — no audio is sent to any third-party transcription service for this purpose — but the resulting transcript text is uploaded and stored as part of the relevant incident or clip record so that it is readable and searchable. During an active alert, transcripts from the raising device and from responding devices may be collated into a single incident transcript.
- Voice-characteristic analytics that the on-device recogniser may provide alongside a transcript, such as per-segment confidence and pitch (and related measures), used to distinguish one speaker's segments from another's and to gauge recognition quality.
- Motion, accelerometer, and other device-sensor data associated with an incident.
2.4 Incident and Usage Data
- Records of alarm activations, notifications sent and received, response statuses submitted (such as an intention to attend or monitor), chat messages exchanged through the Service in connection with an incident, and incident resolution requests.
- Device information (such as device model, operating system, and unique device identifiers), push-notification and calling tokens used to deliver alerts, messages, and incoming call notifications to your device, app usage data, log files, and crash reports.
2.5 Family and Child Accounts
- Where you are a parent or guardian, you may create and link a protected account for your child. For that account we collect the child's name, chosen username, and the information needed to operate their safety features.
- You may add a second parent or co-guardian to a child's account. To do so you may generate a code or link for the other parent to use, or send an invitation to an email address you provide; we process that email address in order to send the invitation. Where a child initiates the request, the prospective parent's name, phone number, and email address are shown to the existing parent so they can decide whether to approve the link, and no link is created unless and until they approve it. You should only invite people you intend to give this access to.
- Where adults link as family (your parent, or your adult son or daughter), you become mutual family contacts: private chat and calls, and a mutual family alert that shares live location between you only while an alert is active. Separately, either of you may choose to show your family your last known location, as described in section 2.11. Private display names you assign to your family members are stored and visible only to you. You may remove a linked family member at any time, which unlinks that member and ends the sharing between you.
- Family communications you send through the Service — chat messages, and photos and videos shared between linked family members — are processed in order to deliver them. Photos and videos shared in family chat are automatically deleted approximately one hour after they are first viewed.
- A child can send an SOS to their linked parent, and a parent can request the child's location. A child's location and device camera stream are shared with their linked, verified parents; with a grandparent only where a parent has expressly enabled location sharing or family alerts for that specific child and grandparent (each permission is separate and off by default); with the child's brothers and sisters only where a parent has turned that on for that child, in which case the parent's other children can see the child's last known location on their map (off by default, and the child is shown who can see them); and with nearby community responders only where a parent raises a public alert on the child's behalf, for the duration of that alert.
2.6 Location Requests by Parents and Authorised Administrators
- A linked parent may request the current location of their child's device for the child's safety, and a linked grandparent may do so only where the child's parent has expressly enabled location sharing for that grandparent. Authorised Skuark administrators may also request the current location of a device for safety and lawful-authority purposes.
- Where you have granted background ("always") location permission, such a request may be fulfilled while the app is closed and without a visible prompt on the device. A location obtained in this way is used only for these safety and lawful purposes and is never used for advertising.
- By creating and using an account (including on behalf of a child), you acknowledge and agree that your linked parent (for a child account) and authorised administrators may request the device's location for these purposes.
2.7 Home Location and Community Posts
- Where you use My Community, we collect the home location you set in order to determine your nearest local community. Your home location is not shown to other users; once set, it can only be changed after 30 days.
- Community posts you share — text and photos — are visible to other adult members of that community. Posts are automatically deleted approximately 48 hours after they are posted.
- Community content is automatically moderated. Records of moderation outcomes (such as warnings and strikes) are retained on your account for enforcement purposes as described in Section 7.
2.8 "Keep an eye out" Watches
- Where you use "Keep an eye out", you can ask one or more people you choose (from your linked family, or others the Service lets you select) to watch your live location for a limited period. During that period we process and share your live location with the watchers you have chosen.
- The watch ends automatically when the period you set expires, or when you end it, after which your location is no longer shared with those watchers. We keep a record that a watch took place for the operation and security of the Service.
2.9 Safe Places
- Where you use Safe Places, you (or, for a child account, a parent) may save named places — such as home, school, or a relative's house — by choosing a point on a map or searching for an address. We store the name you give the place and its coordinates.
- To tell you when someone arrives at or leaves a saved place, the Service compares the device's location against those places. Where you have granted background ("always") location permission, this comparison happens while the app is closed, and location is therefore processed at times when no alert is active and no watch is running. This is the only feature that processes location on an ongoing basis; you can stop it at any time by deleting the saved places, or by withdrawing background location permission in your device settings.
- We keep a history of arrivals and departures at your saved places — which place, and the time — so that it can be reviewed later by you and, for a child's places, by their linked parents and any grandparent a parent has expressly authorised. Where an expected arrival time is set for a place and no arrival is recorded by that time, we send a missed-arrival notification to those same people.
- To limit the amount of location processing, the Service reduces how often it checks position when the device is far from every saved place, and requires a person to remain inside or outside a place for a short settling period before an arrival or departure is recorded.
2.10 Activity Status and To-Do Lists
- You may set what you are currently doing ("what I'm up to"), either by choosing from a list the Service provides or by typing your own words. What you set is shown to your linked family and, where connected, a linked grandparent. It expires automatically after two hours or at midnight in your local time, whichever comes first, and you can clear it at any time. Adults can switch this sharing off entirely in settings; for a child account it is part of the safety features and is shared with the adults who look after them.
- When you are signed in and using the Service, we record the time you were last active. This is a single timestamp that is overwritten as you go, refreshed at most once a minute; we do not keep a history of it. Family members you exchange messages with are shown when you were last active, or that you are active now. While you are writing a message, the person you are writing to is shown that you are typing; that signal passes between devices in the moment and is not stored anywhere. Both follow the same setting as your activity status above, and neither is ever shown to an ex-partner.
- Where you type your own words rather than choosing from the list, we store that phrase so that the shared list of activities can be improved. Those phrases are reviewed by an automated process, and any resulting addition to the shared list is approved by a person before it appears. We do not publish what you typed: a phrase is only ever used to inform a general activity name, and text identifying a person, place, or private circumstance is not added to the list.
- To-do lists let you keep jobs for yourself, and let linked family members add jobs to one another's lists in the combinations the Service allows (for example, a parent to their child's list; between parents only where one has switched that on). We process the text of those jobs, who created each one, and when each was completed, in order to show the list to the people entitled to see it.
- Each morning the Service adds a few everyday jobs (such as making the bed or brushing teeth) and one surprise job to a child's to-do list, chosen from a fixed list. The choice uses only the date (school days, weekends and the time of year), whether the child has a brother or sister linked to the same parent, and any pets their parents have added, and which jobs the child had in the last week (so the everyday jobs change from day to day). A child can swap one of the day's jobs for another, or ask for an extra one once they have ticked one off, up to three of each a day; we keep which jobs they swapped or asked for, for a week, to keep to those limits and not give back a job they swapped away. A child's parent can switch these off, or leave any of them out, from their child's page.
- A parent can add their family's pets in their family settings: a name, and whether it is a dog, a cat or another animal. A pet is shared with the parent's partner, and its name is used only to word pet jobs on their children's lists, such as "Feed Biscuit"; a job walking a dog comes up only when there is a dog. Either of them can remove a pet at any time, which deletes it.
- A child earns stars when they complete a job a parent set and a parent confirms it is done; the parent chooses whether a job is worth one to five stars. A parent can also give a star, or take one away, and may pick a reason from a short list when they do. We keep a record of each change (how many stars, whether it was for a job, a star given or behaviour, the job's wording or the reason picked, which parent made it, and when). The child and their parents can see the total, the stage it has reached, and that record; nobody else can.
- A child also earns badges for jobs a parent set and confirmed: for how many they have done, what kind of job (such as making the bed or helping in the garden, worked out from the job's wording), days in a row, whole weeks with every job finished, the time of day or week, and the season; and for the pets, rides and homes they get for their avatar, worked out from what they have bought. To work these out we keep, with each job that earned stars, what kind of job it was, when it was set and when the child did it, and whether a parent typed it or the app added it as a daily or surprise job; and a record of each badge and when it was earned. Only the child and their parents can see their badges. A badge is never taken away, and none of this is used for anything but the badges.
- A child can build a 3D avatar, a cartoon character, from a fixed set of choices (a character, body type and height, face shape, eyes, nose, mouth, eyebrows, hair and its colour, and clothes). The avatar is made on the device from these choices; no photo of the child is used or taken. We keep the choices they made, any clothes they bought, and a small picture of the avatar that the builder draws when they save it, for their profile (and, when it wears a Halloween costume, a second small picture without the costume, shown outside October). We use the date of birth a parent entered for their child to choose which version of the Halloween costumes the avatar shows: from 11, the full costumes, with masks; under 11, gentler ones. Only that choice reaches the app, not the date. Some clothes are bought with the child's own stars, which shows in the star history like any other spend; nothing is random and nothing is sold for money. The child and their parents can see the avatar. Grown-ups can build their own avatar in the same way, with everything free; we keep their choices and its small picture in the same way. Only they see it, except that their own children see it in a game where it plays a part, such as the boss on a building site (see games, below).
- Where games are switched on for a child's family, the child can play job games in the Games tab: each career level they reach opens a game about that job, such as gardening or baking, played with their saved avatar on their device. Nothing is recorded from the camera or microphone. For each round we keep which game it was, when it started and ended, its score, for a game with levels the level played and whether it was passed, the purple stars it earned, and a few scores for the skills that game measures (such as measuring or memory); and for each game, how far the child has got, their best result, their totals, and a small save so they can carry on. The score, and whether a level was passed, are worked out by our servers from what happened in the round, not by the device. In a game with levels each level passed earns one purple star, and running out of time starts again at level 1; no game gives more than 5 purple stars a day. Where a game has a grown-up in it, such as the boss on a building site, it is the child's parent as their own avatar if a parent has built one (the first parent linked to the child who has), and otherwise a character of the game's own; the child sees only the avatar, nothing else of the parent's. Purple stars from games count towards the child's career level and are spent before other stars in the shop, but can never be swapped for pocket money. Parents choose how long their child may play each day and the hours games are closed (two hours a day, and nothing from 10pm to 7am, unless they change it), can switch games, or any one game, off, and see a summary of the last week: time played, rounds, purple stars and skills. Skill scores are shown only to the child, as encouragement, and to their parents; parents can switch them off and delete them, and they are never shared, sold, or used for anything else. Games have no adverts, chat, strangers or purchases. A child's parent can play the same games from their own profile, as their own avatar if they have built one. Each of their rounds is scored by our servers in the same way and earns 1 to 5 stars for how well the job was done; these are a record of their best, not stars to spend, and nothing a child has changes. For a grown-up we keep, for each game and level, their best stars and best score, how many times they have passed it and played it, and when they last played, and their results are shown only to them. Nothing else from their rounds is kept once a round is over, unless they have agreed to help us test the games: then we may also keep what happened in their rounds, to set how hard the games are, and, when a game stops unexpectedly, a short technical report (the type of device and its system version, its screen and graphics, and what the game was doing at the time), which is deleted after 90 days. We never keep what happened in a child's rounds for this. Where a parent has asked us to, to help test the games, their child's game sends the same short technical report when it stops unexpectedly (the type of device and its system version, its screen and graphics, and what the game was doing at the time; nothing the child typed and not where they are); it is sent only while that parent is still their guardian, is seen only by us, and is deleted after 90 days.
- A parent can stock a shop of rewards for their child, each with a price in stars, and may let their child swap stars for pocket money at a rate the parent sets. When the child asks for a reward or for pocket money, the stars are held until a parent says yes or no, and returned if the answer is no. Any pocket money is paid by the parent themselves, outside the Service: we never hold or move money, and only record what was asked for, the amount, and when a parent marked it given or paid. Stars cannot be bought and are not money; any value they have is what a child's parents choose to give for them.
- Activity status, last-active times and to-do lists are visible only to linked family members, never to the wider community or to responders, and are not used for advertising or profiling.
2.11 Sharing Your Location With Your Family
- If you are an adult, you may choose to share your location with your family by turning on "Share my location with my family" in your settings, under "Your details". It is off unless you turn it on, and a child account cannot turn it on: a child's location is shared only as described in sections 2.5 and 2.6. A child can see, on their own map, the adults who have chosen to share their location with them, and any brother or sister a parent has let them see.
- While it is on, your linked family members can see your last known location — the most recent position your device reported while the Service was open on it — together with how long ago it was reported and how precise it was, on their family map and on your profile in the Service. It is not a live stream, and turning it on does not make the Service collect your location in the background.
- "Your family" for this purpose means the people linked to you directly in the Service: your children, and a child's parents; your parents, and your adult sons and daughters; your partner; your children's other parent; your grandchildren and grandparents; and, for a grandparent, the other parent of their grandchild. Before you turn it on, the setting shows you by name who would see your location. An ex-partner never sees it, whether directly or through their family.
- You can also choose person by person: each family member's profile in the Service has its own switch, so you can share with some of your family and not others. The switch in your settings turns it on or off for everybody at once.
- You can turn it off at any time, and your family stops seeing your location straight away. Removing a linked family member, or separating from a partner in the Service, also ends that person's access to it, whatever you chose for them.
3. How We Use Your Information
We use the information described above to:
- Operate the core functionality of the Service, including determining your location upon alarm activation, generating a unique incident identifier, and notifying emergency services and nearby Users.
- Enable live audio/video streaming to authorised participants and preserve an encrypted copy of that content for evidentiary and safety purposes.
- Generate, using on-device speech recognition, a real-time text transcript of speech during an incident or evidence clip, and preserve that transcript (and any accompanying voice-characteristic analytics) as part of the incident or clip record so that what was said is readable and searchable for safety and evidentiary purposes.
- Dynamically calculate incident severity and adjust the notification radius in response to multiple, correlated alarm activations.
- Facilitate community responder coordination, including displaying response statuses and responder counts to relevant participants.
- Maintain, secure, and improve the Service, including diagnosing technical issues and developing new features.
- Communicate with you regarding your account, the Service, and, where you have consented, promotional or informational updates.
- Comply with applicable law, respond to lawful requests from public and government authorities, and protect the rights, safety, and property of Skuark, our Users, and the public.
4. How We Share Your Information
Given the emergency-response purpose of the Service, information may be shared with the following categories of recipients:
4.1 Emergency Services
Upon alarm activation, we share your location, incident identifier, and, where technically integrated, updated severity information with relevant emergency service systems, in order to facilitate a professional emergency response.
4.2 Other Users (Community Responders)
We share your approximate or precise location, incident details, and, where streaming is active, live audio/video, with other Users located within the applicable notification radius who are authorised to receive such notifications, together with any response statuses submitted by those Users.
4.3 Law Enforcement
We may disclose preserved recordings, transcripts, incident records, and associated metadata to law enforcement authorities: (a) in direct connection with an active incident, to facilitate response; (b) in response to a valid legal request such as a warrant, subpoena, or court order; or (c) where we believe in good faith that disclosure is necessary to prevent imminent harm to any person.
4.4 Service Providers
We share information with third-party service providers who perform functions on our behalf, such as cloud hosting, data storage, encryption, analytics, customer support, and payment processing, under contractual obligations to protect your information and use it only for the purposes we specify.
4.5 Corporate Transactions
If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a successor policy providing comparable protection.
4.6 Linked Parents and Family Members
Where you use a child account, we share your location, SOS alerts, and — during an active family alert — your device camera stream, with your linked, verified parents and, only where a parent has expressly enabled it for that pair, with a linked grandparent; and your last known location with your brothers and sisters only where a parent has turned that on for you. Where adults are linked as family, live location is shared between them only during an active family alert either of them raises; separately, an adult who turns on "Share my location with my family" shares their last known location with their linked family members, as described in section 2.11. If a family member raises a public alert on your behalf (or a parent on a child's behalf), your location is shared with nearby community responders in the same way as any public alert, for the duration of that alert. Family chat and call content is shared only between the linked family members involved in that conversation. Where you use "Keep an eye out", your live location is shared with the specific people you choose, only for the limited period of that watch. Where you invite a second parent or co-guardian, we send an invitation to the code, link, or email address you provide, and — for a child-initiated request — show that person's name, phone number, and email address to the parent who must approve the link.
We do not sell your personal information to third parties for their own independent marketing purposes.
5. Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area or the United Kingdom, we process your information on the following legal bases: performance of a contract (to provide the Service you have requested); consent (for example, for marketing communications, which you may withdraw at any time); legitimate interests (for example, to secure and improve the Service, subject to your rights and interests); and legal obligation (for example, responding to lawful requests from public authorities) or vital interests (for example, where processing is necessary to protect someone's life in an emergency).
6. Data Retention
We retain account information for as long as your account remains active, and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements. Incident-related recordings, transcripts, and metadata are retained on secure servers for 12 months following the closure of the relevant incident, or longer where required for an active legal, regulatory, or law-enforcement purpose, after which they are securely deleted or anonymised. While an evidence clip is itself encrypted, the transcript generated alongside it is stored in readable form so that it remains searchable by the account owner and authorised administrators.
Co-parenting records. Messages exchanged between two adults linked to one another as ex-partners, who share one or more children, are retained as a record: neither party can edit, delete or unsend them, photographs and videos sent in that conversation are kept rather than expiring, and the conversation is preserved even if one of the two closes their Skuark account. Where an account is closed, everything else held about that person is deleted as described above; only the co-parenting conversation is kept, because a record either parent could unilaterally destroy would not be a record. We rely on Article 17(3)(e) of the UK GDPR — retention necessary for the establishment, exercise or defence of legal claims — and we retain such a conversation until the youngest child shared by the two adults reaches the age of 19, after which it is deleted. Where the relevant date of birth is not known to us, we retain the conversation for seven years from the date of the message.
Photos and videos shared in family chat are automatically deleted approximately one hour after they are first viewed, except in a co-parenting record (see below), where they are retained with the messages. Community posts, including their photos, are automatically deleted approximately 48 hours after they are posted. A child's game rounds are deleted after 90 days; after that we keep only each game's totals (rounds, time played and purple stars earned), how far the child has got, a small save and, while the skill summary is on, their latest skill scores, and the stars themselves stay in the child's star record. All of it is deleted with the child's account. Invitations to add a family member (such as a second parent or co-guardian) expire after a short period if unused, and are consumed once accepted. Where an account is banned for serious or repeated misuse, we retain a record of the ban to prevent re-registration and further abuse.
7. Your Rights and Choices
Depending on your jurisdiction, you may have the right to: access the personal information we hold about you; request correction of inaccurate information; request deletion of your information, subject to our legitimate need to retain certain incident records and co-parenting records as described in section 6; object to or restrict certain processing; request a portable copy of your information; and withdraw consent, where our processing is based on your consent, at any time without affecting the lawfulness of processing before withdrawal.
You can exercise many of these rights directly within the Service's account settings, or by contacting us at support@skuark.com. We will respond to verified requests within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority.
Because a co-parenting record is retained even where you ask us to delete your information (see section 6), account settings provide a means of downloading that conversation in full at any time — every message with its timestamps and delivery status, together with the photographs and videos sent in it — in a portable, machine-readable format. Downloading a copy does not alter or remove the conversation held in the Service, which remains visible to both participants.
Enforcement action against misuse of the Service (such as a warning, suspension, or ban) may be applied automatically based on reports we receive. If your account is suspended or banned, you may submit an appeal through the Service's appeal process, which is reviewed by a member of our team.
8. Children's Privacy
The Service includes protected accounts for children under 16, which must be created, linked, and consented to by a parent or legal guardian. A child's personal information — including their location and SOS alerts — is used only to provide the child's safety features, and is shared only with their linked, verified parents, any grandparent a parent has expressly authorised for that child (communication, location sharing, and family alerts are each separate, parent-controlled permissions, off by default), their brothers and sisters where a parent has turned that on for that child (off by default), and the service providers described in this Policy. If a parent raises a public alert on the child's behalf, the child's location is shared with nearby community responders for the duration of that alert. The parent may access, manage, and delete the child's account and data at any time, and may exercise the rights described in Section 7 on the child's behalf. We design our children's features with regard to the ICO's Age Appropriate Design Code (the Children's Code). If you believe a child's account has been created without appropriate parental consent, please contact us at support@skuark.com and we will take steps to remove it.
9. Data Security
We implement technical and organisational measures designed to protect your information, including encryption of recordings and sensitive data in transit and at rest, access controls limiting who may view incident data, and regular security assessments. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. International Data Transfers
We may transfer, store, and process your information in countries other than your own, including countries that may not provide the same level of data protection as your home jurisdiction. Where we do so, we implement appropriate safeguards, such as standard contractual clauses or equivalent mechanisms, as required by applicable law.
11. Third-Party Links and Services
The Service may contain links to, or integrate with, third-party services, including mapping and navigation providers. This Policy does not apply to those third-party services, and we encourage you to review their respective privacy policies.
12. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. If we make material changes, we will provide reasonable notice, such as through the Service or by email, before the changes take effect.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:
Skuark Ltd
Email: support@skuark.com
