Privacy

Last updated 27 July 2026.

CheckUpOnMe is a personal safety app. You start a check-in before something you want a second pair of eyes on, and if you do not confirm you are OK in time, the contact you chose is alerted. That means the app holds a small amount of unusually sensitive information: where you were, and why you were worried. This page says exactly what that is, who else ever sees it, and how long it lives.

It is written from what the app actually does. The retention numbers below are the numbers the server runs on, checked against the code by an automated test.

Who is responsible

CheckUpOnMe is operated by Robert Foppen, a sole trader in the Netherlands, who is the data controller for everything described here.

There is no data protection officer. At this size one is not required, and the address above reaches the person who makes these decisions.

In short

  • Nothing about a check-in is shown to another person unless it escalates.
  • Location is off until you turn it on, is captured only while a check-in is running, and is deleted 48 hours after that check-in ends.
  • Your contact sees your location only while an alert is live, only the latest fix, and not at all once you resolve.
  • A notification never contains your reason or your location.
  • Nothing is sold, and there is no advertising anywhere in the app or on this site.
  • This website sets no cookies, runs no analytics and loads nothing from anyone else.

What the app stores, and why

What is collected
WhatWhat it isLegal basis
Your accountYour email address and an account id. Signing in sends a one-time code to that address, so the address is the account. There is no password.Performance of the contract: there is no account without it.
Your name in the appThe display name you choose. It is what your contact sees when an alert is about you, so a first name is enough.Performance of the contract.
Your check-insWhen you started one, when you were due back, when it was resolved or escalated, and the reason you typed if you typed one. A reason can say something about your health, so it is treated as sensitive and the field is optional.Performance of the contract for the timer. Your explicit consent for the reason text, given by writing it.
Location fixesOnly while a check-in is running, and only if you turned the location switch on for that check-in. The switch is never on until you turn it on once. Each fix is a latitude, a longitude, an accuracy and the time your phone took it. The app never asks for background location and captures nothing between check-ins.Your explicit consent, given per check-in with that switch.
Who you are paired withThe pairing between you and each person you can alert, the invite code that created it, and the note you wrote for yourself while the invite was outstanding. A pairing is mutual: accepting one means each of you can alert the other, and either of you can end it.Performance of the contract.
Your phonesA push token per phone you sign in on, whether it is an iPhone or an Android phone, when it last registered, and whether it told us it may play a critical alert. An alert has to have somewhere to arrive.Performance of the contract.
What happened to an alertPer alert: that it was sent, whether the phone confirmed delivery, whether your contact tapped to say they are on it, and any error. This is what lets you see whether your alert actually landed.Performance of the contract.
Usage analyticsCounts, durations and yes-or-no flags: which screens were opened, that a check-in was armed and how long it ran, that an invite was accepted. The events cannot carry a reason, a location, a contact or an email address, because the app has no way to put one in them. You can turn this off in Settings.Legitimate interests in understanding whether the app works, balanced by the switch in Settings and by the events carrying nothing about you.
Crash reportsIf the app crashes, a report of where in the code it happened, plus the phone model and operating-system version. Crash reports are not linked to your account and carry no location.Legitimate interests in a safety app that does not crash.

Where the basis is your consent, you can withdraw it at any time: turn the location switch off before you arm, leave the reason blank, or turn the usage switch off in Settings. Withdrawing it does not undo what was lawful before, and it never affects the safety timer itself.

What your contact can see, and when

Choosing someone as your contact does not give them a window into your life. While a check-in is running, they cannot see that it exists. They are shown something only if it escalates, which happens when you have not confirmed you are OK by the deadline and the grace period after it.

Once it escalates, and only for as long as it stays escalated, they can see:

  • Your display name.
  • When you started the check-in, when you were due back, and when it escalated.
  • The reason you typed, if you typed one.
  • Your latest location fix, if you had location on for that check-in. The latest one only: they never see a trail, and the app shows how old the fix is, because it may be hours old.
  • Whether they have acknowledged the alert. You can see that too.

The moment you confirm you are safe, that access ends. It also ends by itself: an alert that is never resolved closes after 72 hours, so a check-in nobody ever answered cannot leave your last known location visible indefinitely.

Pairings are mutual. Accepting one means each of you can alert the other, and either of you can end it at any time. Ending it stops alerts in both directions. A pairing starts with an invite code, which works exactly once and stops working 7 days after it was created.

When your contact opens an alert, their phone asks its own operating system to turn the coordinates into a street name, the same way any map app would. That request goes to Apple or Google as part of their phone, not through us.

What a notification contains

An alert says who it is about and that they have not checked in. It never contains your reason or your location.

That is deliberate. A notification passes through three companies and then sits on a lock screen that anyone nearby can read, and it stays in notification history long after you have resolved. Details are fetched inside the app instead, where access ends when the alert does.

Usage analytics

The app records a small set of product events: which screen was opened, that a check-in was armed and for how long, that an invite was accepted. Their properties are counts, durations and yes-or-no flags. A reason, a location, a contact or an email address cannot appear in them, because the app has no way to put one there. Screen names come from the route, so a code or an id cannot leak into one.

You are identified in analytics only by your account id, which is a random identifier and nothing else. The analytics service is set to discard your IP address, and location is kept no finer than a country.

Turn it off in Settings, under "Share anonymous usage data". Nothing about the safety timer changes when you do.

Escalations themselves are deliberately not sent to analytics. The one event that matters most to us is the one we refuse to collect that way.

Who else processes your data

These are the only companies involved. None of them is allowed to use your data for anything except the job below, none of it is sold, and none of it is used for advertising.

Sub-processors
WhoWhat they doWhere
SupabaseThe database, sign-in, and the server that decides an escalation.European Union
Expo (Expo Application Services)Hands a notification to Apple or Google. Receives the push token and the notification text, never a reason or a location.United States
Apple (Apple Push Notification service)Delivers notifications to iPhones.United States and worldwide
Google (Firebase Cloud Messaging)Delivers notifications to Android phones.United States and worldwide
PostHog CloudUsage analytics, while the switch in Settings is on. Never receives a reason, a location or a contact.European Union
SentryCrash reports from the app.European Union (Germany)
VercelServes this website. Sees the ordinary server request log, which includes your IP address.Worldwide content network, United States company

Where your data sits

The database, sign-in, analytics and crash reports are hosted in the European Union, for every user, wherever in the world you are. There is no separate region for anyone.

Notifications are the exception, and they have to be: the push services that deliver them are run from the United States by Expo, Apple and Google. What crosses that border is a push token, your display name and the fact that a check-in was not confirmed. Never a reason, never a location. Those transfers rest on the European Commission's standard contractual clauses with each provider.

How long things are kept

Retention
WhatHow longFrom when
Location fixes from a check-in48 hoursafter the check-in is resolved or closed
A check-in that escalated and was never resolved72 hoursafter it escalated, at which point it closes itself
An invite code that is never used7 daysafter it is created, at which point it stops working

Location fixes are not deleted the instant a check-in ends. The window exists for one reason: if something turns out to have gone wrong after a check-in was resolved, there is a short period in which the trail can still be produced for you or for the emergency services. No app screen, yours or your contact's, can read it after you resolve.

Everything else is kept while your account exists. Delete your account and it goes, without installing anything.

What stays on your phone

Some things never leave it: whether you last had location sharing on, whether you chose light or dark, and whether the app has already offered you a permission once. Removing the app removes them.

Your rights

Under the GDPR you can ask us to:

  • Give you a copy of what we hold about you, and tell you where it came from.
  • Correct anything that is wrong.
  • Delete your account and its data.
  • Restrict or object to a use of it, including analytics.
  • Hand your data to you in a portable form.
  • Withdraw a consent you gave, at any time.

Write to hello@checkuponme.app from the address you signed in with, which is how we know the request is yours. Deletion has its own page, because Google asks for one: how to delete your account.

If you think we have handled your data badly, you can complain to your national data protection authority. Ours is the Autoriteit Persoonsgegevens in the Netherlands.

Age

CheckUpOnMe is not for anyone under 16. We do not ask for your date of birth, because storing one to enforce this would collect more than it protects. If you tell us an account belongs to someone younger, we will delete it.

Security

Everything travels over encrypted connections and is stored encrypted at rest. Access to your rows is enforced by the database itself, not only by the app: your contact's ability to read your location is a rule the server applies, which is why it can end the moment you resolve. There is no password to be stolen, because there is no password.

This website

This site sets no cookies, runs no analytics, and loads no fonts, scripts, images or styles from anyone else. There is nothing here to ask your consent for, which is why there is no consent banner.

The one exception is a deliberate act: on an invite page, tapping "View invite" sends the code in the link to our own server to look up who invited you. Nothing is sent until you tap it, so a link pasted into a chat reveals nobody.

The company that serves this site keeps an ordinary request log, which includes your IP address, for the usual operational reasons.

Changes to this policy

If this changes in a way that matters, the date at the top changes and the app says so before it takes effect. We will not quietly start doing something this page says we do not do.

Contact

hello@checkuponme.app, or the postal address at the top of this page. Support answers the same inbox.