VenA Privacy

VenA helps nearby community members coordinate support during alerts. This page explains the location choices and data used by the native Android app.

Last updated: September 10, 2026

Location is transparent and under your control

During registration, you make a separate explicit Yes or No choice for each mode below. VenA explains the purpose before requesting Android permission. Granting a permission does not enable either mode by itself, and declining one mode does not enable the other. Both choices can be changed later in Privacy.

The two modes are optional and can be disabled separately. Live location stops when you close the alert with the normal PIN. A duress PIN intentionally does not stop it, so helpers can continue following the active alert under pressure.

Android may combine satellite, Wi-Fi, Bluetooth and mobile-network signals to calculate a position. VenA receives coordinates, capture time and Android-reported accuracy; it does not request or store Wi-Fi network identifiers, cell-tower identifiers or nearby Bluetooth/BLE device identifiers.

Offline help (Phase 1) is a separate optional readiness diagnostic. Only after opt-in, it advertises and discovers the VenA service over nearby Bluetooth/Wi-Fi for 15 seconds, counts compatible advertisements in memory, rejects every connection, sends no alarm or payload, and stops when the screen leaves the foreground. It is not an offline emergency channel yet.

Other data VenA may use

Security and sharing

Sensitive alarm details are not shown automatically in every alert. VenA asks for confirmation before sharing selected details in a real alert. Alert photos are served through authenticated API access and direct HTTP access to stored media is denied.

The Android app is native and does not use WebView to operate VenA. Cleartext HTTP is disabled and local session data is encrypted on the device. VenA does not request permission to read SMS messages. Optional nearby permissions are requested only for the explicit Phase-1 diagnostic, which stores no network names, BSSIDs, device names or Bluetooth identifiers.

Retention and deletion

VenA retains data only as long as reasonably needed to operate alerts, answer requests, protect the service and meet applicable obligations. Personal metadata in closed alerts is anonymized after 30 days: account links, name, phone, device, notes, exact coordinates, helper and notification-target identifiers, and rating-author identifiers are removed. Only category, incident type, time, status and identifier-free rating values remain for aggregate history. Closed-alert photos and their references are deleted after 30 days. Support and security audit records may remain for up to 365 days, and technical diagnostics for up to 90 days.

The app provides a Delete my data action. It closes the user's active alerts, removes visible personal profile data, clears the notification token and revokes the current session. Some reduced or anonymized security history may be retained to prevent abuse and review incidents.

Contact and authoritative language

For support, privacy or deletion questions, use the support action in the app or email vena@modsbyben.net.

The Spanish policy is available at Privacidad de VenA. If a translation differs, the Spanish policy describes the intended product behavior for the primary Paraguay release.