Privacy Policy
Last updated: July 15, 2026
The SAR21 Service is provided by H3LX Labs LLC, a California limited liability company ("H3LX Labs," "we," "our," or "us"), which is the data controller and party responsible for personal information processed through SAR21. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the SAR21 web portal and mobile applications (the "Service"). It should be read together with our Terms of Service.
1. Team Data vs. Account Data
Much of the information in SAR21 is added by teams about their members and about the subjects of their operations. Your team controls that information and decides what to collect and how to use it; we store and process it on the team's behalf and under its direction. If you are a team member, requests to access, correct, or delete data your team has entered about you should generally be directed to your team administrator. We handle account-level information (such as your login and billing) directly with you or your team.
2. Information We Collect
- Account & profile information — name, email address, phone number, SAR ID, profile photo, role and team affiliation, position title, certifications and expiration dates, skills, and mobile carrier (used for text-message delivery).
- Emergency contacts — contact names, phone numbers, and relationships you provide.
- Operational data — availability status, callout responses and ETAs, training and event attendance, equipment records, team posts, messages, meeting notes, and analytics derived from this activity.
- Location data — coordinates used for emergency-response coordination and mapping, including staging areas, home-base locations, and search points (such as last-known position and points of interest). On mobile, location may be accessed while you use the app or, where you enable it, in the background (see Section 5).
- Incident & subject data — information your team enters about the subjects of operations, which may include a missing person's name, physical description, photograph, clothing, medical information, and last-known location. This data is provided and controlled by teams and may relate to individuals who are not SAR21 users, including minors.
- Notification & device data — push notification tokens, device type, operating system, and app version, used to deliver alerts to your devices.
- Billing information — subscription and payment status. Card payments are processed by our payment processor (Stripe); we do not store full card numbers.
- Technical & usage information — usage data, error logs, and crash reports.
3. How We Use Information
- Coordinate search and rescue operations, callouts, and responses.
- Manage team member status, availability, trainings, certifications, and equipment.
- Deliver callout alerts and other notifications, and facilitate team communication.
- Process subscriptions and payments.
- Provide support, maintain security, improve the Service, and meet legal requirements.
4. Notifications and Communications
To deliver callout and other alerts, we and our providers may send you push notifications, SMS/text messages, and email, depending on your settings, device, and carrier. Delivery relies on third-party platforms and carriers and is not guaranteed. You can adjust most notification preferences in the app; however, critical callout and emergency alerts are core to the Service, and disabling them at the device or account level may prevent you from receiving time-sensitive information. See the Terms of Service for important information about notification reliability and backup systems.
5. Mobile App Permissions
Our mobile app may ask your permission to access certain device features. You control these in your device settings, and the app requests them only to provide the related features:
- Notifications & critical alerts — to deliver callout alerts and mission updates. Critical alerts can sound even when your device is silenced or in Do Not Disturb. You may disable them, but you may then miss time-sensitive callouts.
- Location — for emergency-response coordination and mapping and, where enabled, to help coordinate or locate team members during operations. Depending on your settings, location may be accessed while you use the app or in the background.
- Camera — to take profile photos and capture equipment or documentation images.
- Photos & media — to select images from your library for profiles, equipment, or documentation.
- Files & documents — to upload documents such as certifications.
- Calendar — to add trainings, meetings, and events to your device calendar.
- Microphone — if you use voice or in-app communication features.
- Contacts — if you choose to reach team members or emergency contacts from your device.
- Reminders — if you set reminders for trainings or equipment checks.
Denying a permission may limit the related feature but will not otherwise prevent use of the app, except that disabling notifications may prevent you from receiving callout alerts. Photos and images you capture are shared only with your team, not publicly.
6. How We Share Information
We do not sell, rent, or trade your personal information. We share information in the following limited ways:
- Within your team — members can see one another's availability, callout responses, and basic profile information; administrators have access to additional operational and member data.
- Service providers — we use trusted third parties to operate the Service, who process information only to provide their services to us, including: Google Firebase / Google Cloud (authentication, database, file storage, cloud functions, and push messaging); Apple and Google (mobile push delivery); Expo (mobile push delivery); Stripe (payment processing); Twilio and email-to-SMS gateway services (text messages); email delivery providers (e.g., Resend); and Caltopo (mapping).
- Emergency response — during active operations we may share information with emergency services, other SAR teams, or law enforcement to coordinate a response and protect safety.
- Legal — when required by law, subpoena, or legal process, or to protect the rights, property, or safety of any person.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
7. Data Security
We implement appropriate security measures, including encryption of data in transit and at rest, secure authentication, role- and team-based access controls, and incident-response procedures. Data is stored on Google Cloud (Firebase) infrastructure in the United States. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Data Retention
We retain information while your account or team is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and support safety and emergency response. Teams may delete much of their data within the Service; when an account or team is deleted, we delete or de-identify associated personal information within a reasonable period, except where retention is required by law.
9. Your Rights and Choices
Depending on your location, you may have the right to access, correct, delete, or export your personal information, and to opt out of non-essential communications. You can update much of your profile in the app, and you may request account deletion by contacting us. Because teams control member and subject data, we may direct certain requests to your team administrator or fulfill them on the team's instruction. To exercise a right, contact support@sar21app.com.
10. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you rights to know what personal information we collect, to request access to or deletion of it, to request correction, and to not be discriminated against for exercising these rights. We do not sell or "share" personal information as those terms are defined under California law. The categories of personal information we collect, our purposes for using it, and the parties we disclose it to are described in Sections 2, 3, and 6. To submit a request, contact support@sar21app.com; we will verify your request before responding.
11. Children's Privacy
The Service is intended for use by SAR team members and administrators; you must be at least 18 years old to create or administer an account, and the Service is not directed to children. We do not knowingly collect personal information directly from children under 13. Note that teams may enter incident or subject information that relates to minors (for example, a missing child); that information is provided and controlled by the team for emergency-response purposes.
12. International Users
The Service is operated in the United States. If you access it from outside the United States, your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your location.
13. Changes to This Policy
We may update this Privacy Policy periodically and will notify you of material changes through the app or by email. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
14. Contact Us
Questions about this Privacy Policy? Contact us at support@sar21app.com.
