Privacy Policy
Last updated: June 4, 2026
"Protecting your privacy and your personal, intimate data (texts, photos, audio, video, drawings, and documents) is ImAlive's absolute commitment. This policy details in full transparency the nature of the data collected, the enhanced security measures applied, the strictly confidential handling of your information, and the rights you hold."
1. Data Controller
The controller of personal data collected via the ImAlive application and website is David Smith. For any inquiries regarding your data or to exercise your rights, you can contact him via: https://imalive.app or contact@imalive.app
2. Collected Data and Legal Basis
In fulfillment of our contract (our General Terms of Use), we collect only the data strictly essential for the Service's operation:
- Account Information (User): Full name/pseudonym, email address, encrypted password (or secure social login identifiers provided by Google, Apple, or Facebook), and subscription tier (Free or Premium).
- Notification Information (Loved Ones): Email address of the beneficiaries (Loved Ones) you choose to designate.
- App Content (Media & Messages): Texts of your messages, photos, audio files, videos, sketches/drawings, and imported documents (PDF/images from the safe).
Important Note: By default, this data is stored exclusively and locally on your own device. It is only transferred securely (encrypted in transit via HTTPS/TLS protocol) to our database and cloud storage if you actively enable the ImAlive service (button "Activate"). - Technical Operational Data: Push notification token (Push Token), device operating system (iOS/Android) and its version. This data is required to route security notifications to your device and ensure the technical compatibility of the application.
3. Absolute Security & End-to-End Encryption (Zero-Knowledge)
ImAlive integrates an ultra-robust "Zero-Knowledge" security architecture, guaranteeing the absolute confidentiality of your most intimate data (texts, photos, audio files, videos, drawings, and documents):
- Local Encryption Before Transfer (AES-256): Before leaving your device to be transferred to our storage servers, all your intimate data is encrypted locally on your phone using the military-grade AES-256 encryption algorithm. The encryption key is generated uniquely and randomly directly on your device.
- Impossible for Us to Read: Data stored in our databases and cloud storage spaces (Supabase) is entirely encrypted and unreadable. ImAlive's Publisher and hosting subprocessors are technically and physically completely unable to decrypt, read, or inspect your personal messages and files, having no access to the encryption keys.
- Exclusive Access for Your Loved Ones: The encryption keys required to open your messages and safes are transmitted to your designated beneficiaries (Loved Ones) only if the final alert protocol is triggered. Your loved ones will then receive an email containing a unique, secure, and confidential link. This link allows them to retrieve the encrypted data from the servers and decrypt it directly in their browser, ensuring no third party can intercept the content.
4. Purpose of Processing
Your data is collected exclusively for the following purposes:
- To facilitate the creation, securing, authentication, and management of your secure user account.
- To operate the "Proof of Life" mechanism and automate the transmission of your messages and files to your Loved Ones in case of prolonged absence or death.
- To manage paid subscriptions and access to the premium features of the application.
- To maintain the technical security of the application, monitor server performance, and prevent fraudulent activity.
The Publisher strictly prohibits: the resale or exchange of your personal data, any analysis of your texts or media for commercial, marketing, or advertising purposes, and any sharing with third parties beyond what is essential for technical service delivery.
5. Subprocessors, Security, and Data Localization
To ensure an ultra-secure environment that complies with the General Data Protection Regulation (GDPR), we employ trusted providers bound by strict contractual confidentiality obligations:
- Supabase, Inc. (Hosting): Your profile data and media files are hosted on cloud infrastructures located within the European Union (Region of Dublin, Ireland). Supabase complies with the most stringent security standards (SOC 2 Type II, ISO 27001 certifications). Databases and storage files are encrypted at rest (on disk) and protected by a strict authorization system (Row Level Security - RLS). Although the Publisher has technical administrative access for system maintenance, he formally commits to performing no human reading or inspection of your personal messages and files.
- Brevo (Email Routing): The email addresses of your beneficiaries and the emails containing the secure access links to your safes are processed and routed by Brevo (a GDPR-certified French company).
- RevenueCat, Inc. (Subscriptions): The management, synchronization, and validation of your Premium subscription status are processed in a pseudonymized manner by RevenueCat. No personal intimate data (messages, contacts) is transmitted to them.
- Expo (650 Industries, Inc.) (Push Notifications): The sending of daily "I am alive" reminders uses Expo's routing servers. Only your device's technical push token and the generic text of the security reminder transit through this service.
6. Retention Period (The "Black Box" Principle)
ImAlive's philosophy is to never retain your data longer than strictly necessary for the operation of your safety protocol:
- In Preparation Phase (Inactive Mode): Your media content and messages remain stored locally on your phone's physical memory. No sensitive personal data is present on our servers.
- During the ImAlive Activation Period (Countdown launched):
- If you show proof of life by clicking the "I am alive" button: the files and messages temporarily queued on our storage servers are immediately, permanently, and irreversibly destroyed.
- If the deadline expires and your Loved Ones are alerted: your messages and files are made available to your beneficiaries on a secure download portal for a strict duration of **90 days maximum**. After this 90-day period, all your files and messages are automatically and permanently purged from our servers, with no technical possibility of recovery.
- User Account Deletion: If you choose to delete your account via the app settings, all your data (profile, email addresses of loved ones, tokens, and any pending files) is instantly and permanently deleted from our databases.
7. Your Fundamental Rights (GDPR)
In accordance with European regulations (GDPR), you maintain full control over your personal information:
- Access and Portability: You can export and download all your locally stored data directly via the export tools within the application.
- Rectification: You can modify your personal information (pseudonym), the email addresses of your loved ones, as well as your password (if you signed up by email) instantly from the application settings or the reset interface.
- Right to Erasure (Right to be Forgotten): You can delete a specific media file, a designated loved one, or your entire account at any time.
- Withdrawal of Consent: You can disable the ImAlive service at any time to cut off the transmission of data to our servers.
8. Cookies and Analytics
Our showcase website (imalive.app) uses cookies essential for technical operations (security, routing, and session maintenance) and **Google Analytics** for the exclusive purpose of audience measurement.
Visitor Statistics: Google Analytics helps us analyze traffic on the showcase website to improve the app's presentation. These analytical cookies are only deposited **with your prior explicit consent** via the cookie banner. You can modify your preferences at any time from the website.
Absence of Advertising Trackers: No data is collected to profile users or display targeted advertisements. **No advertising tracking or analytical tool (such as Google Analytics) is integrated within the ImAlive mobile application.**