WHAT CAN KILL ME

Privacy Policy — What Can Kill Me

Effective date: 26 August 2026

Contact: admin@whatcankillmeapp.com


The short version

What Can Kill Me collects the account details you give us, the hazard reports you choose to file, and the location data attached to them. We do not run advertising, we do not use analytics or tracking SDKs, and we do not sell or share your personal information with anyone for marketing.

Some of what you put into this app is deliberately public: a hazard report is meant to be seen by other people, and that is the point of filing one. Everything else — your contacts, your saved places, your check-ins — is yours.


What we collect, and why

Account

Hazard reports — public by design

When you file a report we store the hazard category, severity, your written description, any photo you attach, and the GPS coordinates, altitude and accuracy at the moment you filed it, along with the time.

Reports are visible to other people using the app, together with your username and trust score. Do not put anything in a description or photo that you would not want a stranger to read, and be aware that the coordinates on a report say where you were standing when you filed it.

Location

We ask for location only while the app is in use. It is used to:

We do not track your location in the background and we do not keep a history of where you have been.

Trusted contacts

Names and phone numbers you enter for check-ins are stored on our servers so they are there on your next device. We never send messages on your behalf — tapping "I'm Safe" or "Need Help" opens your own phone's messaging app with a message prepared, and nothing is sent until you send it. The message goes directly from your phone to your contacts and does not pass through us.

Places, Trip Packs and check-ins

Coordinates and radii for areas you watch, the contents of Trip Packs you save for offline use, and the time, status and location of check-ins you send.

Photos

Photos you attach to reports are uploaded to our storage and are visible with the report. Photos may carry information about where and when they were taken.

Membership

If you redeem a promotional code or hold a membership, we store which tier you have, how you got it, and when it expires. Payments, if and when they are offered, are handled by Apple; we do not receive or store your card details.


What we do not do


Other services the app talks to

The app requests public data from government and scientific sources. Each of these requests includes the area of the map you are looking at, because it has to in order to answer. It does not include your identity, your account, or your exact position.

These requests are proxied through our own servers where possible, which means those organisations generally see our server rather than your device. Their own privacy policies govern what they do with what they receive.

Our backend — database, authentication and file storage — is provided by Supabase.


Keeping and deleting your data

We keep your account data while your account exists.

To delete your account and its data, open Menu → Delete account in the app. It is immediate and permanent: your profile, contacts, places, trip packs, check-ins and badges are removed, and your login is destroyed. There is no recovery period.

Hazard reports are treated differently. Once other people have relied on a report, removing it silently could leave someone walking into a hazard nobody warned them about. On deletion we detach reports from your identity rather than erasing them, unless you ask us to remove a specific report and we agree it is appropriate.

You have the right to ask what we hold about you and to ask us to correct it. Depending on where you live you may have further rights, including under the California Consumer Privacy Act or the UK/EU GDPR. Write to us and we will honour them.


Children

This app is not directed at children under 13 and we do not knowingly collect their information. If you believe a child has created an account, contact us and we will remove it.


Security, honestly stated

Data is encrypted in transit. Access to your rows is enforced at the database level so one account cannot read another's private data. No system is perfectly secure, and we will not claim otherwise.


Changes

If we change this policy we will update the effective date above, and we will tell you in the app if the change is significant.


Contact

admin@whatcankillmeapp.com