Data VenA may use
- Name, phone number and optional email address to identify the person requesting help and facilitate contact if the user permits it.
- City, home address reference and location to show nearby alerts and local emergency numbers and, only if you explicitly choose it, approximately update your current area or share precise location during your own active alert.
- A push notification token to send help notifications.
- Optional department, category and notification preferences to filter weather alerts and local safety news.
- Firebase security signals, such as App Check and Auth, to help confirm that requests come from the legitimate app.
- Technical diagnostics and crash reports in production versions to detect errors and improve reliability.
- Optional help capabilities, such as first aid or available equipment.
- A pseudonymous invitation code and referral source when someone shares VenA from the app and the link recipient registers.
- A code word, access instructions and alert photo only if the user chooses to add them.
- The content of support or privacy enquiries sent from the app, together with a reply contact if the user enters one.
- Reduced community safety signals when operators or helpers confirm abuse or repeated false alerts.
Data use
The data is used to create a local support community, display nearby alerts, notify registered neighbours and allow alerts to be handled with better context.
Phone numbers, access instructions and photos are not automatically shown in every alert. The app requests confirmation before sharing sensitive data in a real alert.
Support enquiries are used to answer questions about the app, privacy or data deletion.
VenA may use Firebase Crashlytics in production versions to receive technical crash reports. This integration is used for reliability and does not add Firebase Analytics to the app.
Weather alerts and safety news are optional features. Country, department and category preferences are used to show regional information in the local language when a source is available. A news item does not replace an official alert or an emergency call.
Advertising is not enabled by default. If enabled in the future, it will be limited to the non-critical safety news section with a remote switch and will never appear during a help request, helper response, countdown, alert map, PIN entry, registration, authentication, widget use or opening a notification.
Before requesting an ad, VenA consults Google's consent platform. Where applicable, the app provides an Ad privacy action to review the choice. Only after that authorisation may Google Mobile Ads process the IP address to estimate a general area, interactions with the app or ad, diagnostics and device or advertising identifiers for advertising, analytics and fraud prevention. Transmission is encrypted in transit, and Android's advertising identifier controls remain available.
Invitations and referral attribution
When sharing VenA from the app, the link may include a random 16-character hexadecimal code and the source source=member_referral. The code does not directly contain the inviter's name, phone number or device identifier, but allows a registration to be pseudonymously associated with the inviting member's account. The link may remain in browser history or technical logs when requested.
The app keeps the code and its source in private device storage until replaced or app data is cleared. Deleting a VenA account does not automatically clear that local value. At registration, the app sends the code and source to the server to store the attribution. The specific server-side retention period for this attribution is not yet confirmed; no separate deletion deadline is claimed here. This section will be updated when the service owner confirms that period.
Location is transparent and under your control
During registration, you choose Yes or No separately for each of these modes. VenA explains the purpose before requesting Android permission. Granting permission does not enable a mode by itself, and declining one mode does not enable the other. You can change both decisions later in Privacy.
- Alerts near you: If enabled together with all-the-time location permission, a best-effort job obtains a rounded position about every 15 minutes and updates your current area to assign local alerts. It does not create a route history. Android may delay or batch this work to protect battery life.
- Live location during your own alert: If enabled, VenA first shares a usable position and then more accurate or newer positions only while an alert created by you remains active. This mode may use precise coordinates so help can find the location, and Android displays an ongoing service notification throughout.
- Offline help: This feature is in testing; availability depends on the installed version and server-side activation. Nearby-device permissions are requested only after enabling it. The 15-second check counts compatible VenA advertisements in memory only, rejects connections and stops when leaving the screen. If the version and server activation permit it, the channel starts separately and only through your action; Android maintains a visible notification with a stop option. It requires the official public key and a valid server authorisation; VenA packets are encrypted, signed, bounded and expire. General verification of offline SOS delivery is not yet available.
Approximate background location updates and live location are optional and can be disabled separately. In versions that offer this feature, when you confirm the normal closure of your alert with the PIN, the app stops location tracking for that alert. If you have configured a duress PIN and the server recognises it, the app does not perform that normal closure or request a tracking stop for that reason. Continued location updates depend on consent, permissions, and device and connection conditions.
Android may combine satellites, Wi-Fi, Bluetooth and mobile networks to calculate a position. VenA receives coordinates, time and accuracy; it does not request or store identifiers of Wi-Fi networks, cell towers or nearby Bluetooth/BLE devices.
Safety
- The Android app is native and does not use WebView to operate VenA.
- Cleartext HTTP traffic is disabled on Android.
- Local session data is stored encrypted on the device.
- API responses are protected by security headers and are not cached.
- Alert photos are served through authenticated access, not as directly public files.
- VenA does not request permission to read SMS messages or cell-tower identifiers. Offline help may request nearby Bluetooth and Wi-Fi permissions, but does not read or store network names, BSSIDs, device names or Bluetooth identifiers. It retains locally only an encrypted credential, minimal revocation state and a bounded queue of pending emergency packets.
Deletion
The app provides an action called Delete my data. When confirmed, VenA closes your active alerts, deletes visible personal data, clears the notification token and revokes the current session. Some historical security data may be retained in anonymised form to prevent abuse and review incidents.
Retention
VenA retains data only for the time needed to operate alerts, answer requests, protect the service and meet reasonable security obligations.
- After 30 days from the alert timestamp, personal metadata in closed alerts is anonymised: the account link, name, phone number, device, notes, exact coordinates and identifiers of helpers, recipients and rating authors are removed. Only the category, incident type, date and time, status and identifier-free rating values remain for aggregate statistics.
- Legacy-mode photos and their references in closed alerts are deleted after 30 days from the alert timestamp. Rear/front photo pairs have a regular retention period of 24 calendar months from the alert timestamp. Their expiry is recorded when attached and is not changed retroactively by configuration edits. An active investigation hold may suspend deletion.
- Support, privacy or deletion enquiries may be retained for up to 365 days to answer and document the request.
- Technical audit records of sensitive actions may be retained for up to 365 days to prevent abuse, investigate incidents and protect the community.
- Technical app diagnostics may be retained for up to 90 days to detect faults and improve reliability.
- Personal profile data is retained while the account is active or until the user requests its deletion.
- Invitation codes remain on the device until replaced or app data is cleared; account deletion does not automatically clear them. The server-side retention period for the corresponding attribution is pending confirmation.
- Live location stores only the latest state of an active alert, not a route history. That state is deleted when the alert is closed normally, expires or the account is deleted.
Some historical security data may be retained in anonymised or reduced form to prevent abuse and review incidents without keeping unnecessary personal information.
Minors
VenA is not directed at children. If you are a minor, use VenA only with guidance from a responsible adult or the appropriate local services.
Support and enquiries
For privacy, support or data deletion enquiries, use the support action in the app or email vena@modsbyben.net.
If you cannot access the app, include the name, city and phone number used in VenA in your message so we can identify the account without requesting unnecessary data.

