Privacy Policy
Effective date: July 11, 2026 · Last updated: August 19, 2026
Raretell ("Raretell," "the App," or
"the Service") is operated by Redoubtable LLC ("we,"
"us," or "our"), a Virginia limited liability company. This Privacy
Policy explains what personal information the App collects, how we use and share it, and the choices
and rights you have.
By using the App you agree to the collection and use of information as described here. If you do
not agree, do not use the App.
1. The short version
Raretell is a passive safety net for people who live alone. Your phone periodically sends the
server small signals that you are active (mainly step counts and a few device readings); the server
holds a timer, and if those signals go silent for a long time and you don't respond to a check-in, it
notifies the emergency contacts you chose. In plain terms:
- We collect the minimum to run the safety net: evidence-of-life signals (steps,
battery/charging, connectivity), your device's most recent location, and the contacts and observers
you add.
- We never keep a location trail. We store only your single most
recent location fix and overwrite it on every check-in. We never track you in real time and
never spin up GPS.
- We do not sell your personal information, and we do not use it for advertising.
There are no ad networks or third-party analytics SDKs in the App.
- Health data (steps) read via Apple HealthKit is used only to run the safety net
— never for advertising, marketing, or data mining, and never shared with third parties for those
purposes.
- We share information with only the processors needed to run the Service — our
cloud provider (Cloudflare), Apple's push-notification service, and Apple's in-app purchase billing —
plus the emergency contacts and observers you choose, which is
the whole point of the product.
The sections below are the complete and controlling detail.
2. Who this policy covers
The App has three kinds of people around a single account:
- Subjects — the monitored person who installs the App on their phone and owns the
account.
- Emergency contacts — people a Subject invites to be notified if the Subject goes
silent. A contact confirms by email and can opt out at any time.
- Observers — people a Subject shares a status link with, who can view a coarse
"all's well / away / trying to reach them" status.
This policy applies to all three. Where a right or practice is specific to one role, we say so.
3. Information we collect
3.1 Information you provide
- Optional display name. You may provide a first name or nickname used to
personalize your status page and alerts. It is optional; the App works without it.
- Optional backup email ("other ways to reach you"). A Subject may add their own
email address so an alert can also reach them if their phone is off, dead, or lost. Confirmed by a
one-click email link.
- Emergency contacts and observers you add. When you invite a contact or create an
observer link, we collect the email address and/or label you enter for that person, and we record
whether they have confirmed or opted out. Contacts are added by a double opt-in: we email them an
invitation and they must accept before they receive any alert or count as coverage.
- Purchase and sponsorship information. We record the
plan, payment provider, subscription status, renewal/expiration status, and which protected person is
covered. If someone sponsors coverage for another person, we record the payer-to-covered-person
entitlement. We do not collect full card numbers in the App.
- Support communications. If you contact us, we keep what you send us (e.g. your
message and email address) to respond.
3.2 Information collected automatically from your device
To run the safety net, the App sends the server a small "heartbeat" containing:
- Step activity — recent step counts and whether step data is available, read from
Apple HealthKit and/or the device motion sensor. (See Section 5 for our
HealthKit-specific commitments.)
- Device readings — battery level, whether the device is charging, the device's
time zone, and what woke the app (e.g. a background refresh, a step update, or a location change).
- Connectivity diagnostics — network path and interface state, the cellular radio
technology reported by iOS, and the previous server attempt's outcome, error code, and
request-to-callback completion time. The timing can include iOS suspension; it is not clean network
round-trip time. These fields contain no message content, Wi-Fi network name, browsing history, or
carrier account identifier.
- Location — your device's most recent cached location (latitude,
longitude, and its accuracy), when you have granted location permission. See Section 6 for exactly how
location is handled and how little of it we keep.
- A push notification token — an Apple-issued identifier that lets us deliver
check-in prompts and alerts to your device.
3.3 Identifiers
- Account identifier. Your account is keyed to a randomly generated
identifier created on your device and stored in the device keychain. We do not
require your name, email, phone number, or an Apple ID / login to create an account. The identifier is
not derived from any hardware identifier.
- Registration abuse ledger. On a sign-up attempt, we store the connecting IP
address and timestamp in our database to enforce rolling signup limits. The row is not attached to
the account record and cannot be removed by the in-app account-deletion control. Its deletion target
begins after 48 hours (the 24-hour limit window plus one day of cleanup slack).
- Technical logs. Like any internet service, our servers and hosting provider process
technical request data (including IP addresses and timestamps) to deliver and secure the Service.
Cloudflare retains these operational logs for no more than 7 days on the configured service; they
cannot be deleted individually before that fixed schedule.
3.4 What we do NOT collect
- We do not collect a location history or movement trail.
- We do not collect contacts from your address book automatically — only the
specific people you choose to add.
- We do not collect health data other than step activity used for liveness
detection.
- We do not use advertising identifiers, ad networks, or third-party
analytics/marketing SDKs.
4. How we use information, and our legal bases
We use the information above to:
We do not use your information for advertising, for building marketing profiles, or
for any automated decision-making that produces legal or similarly significant effects about you.
5. Apple HealthKit
The App reads step count data through Apple HealthKit to detect signs that you are
active. We commit that:
- HealthKit data is used solely to provide the App's safety features (detecting
activity and inactivity).
- We never use HealthKit data for advertising, marketing, or data-mining
purposes.
- We never sell HealthKit data or share it with third parties for advertising or
marketing.
- We do not store detailed health records. What reaches our server is a small
derived signal — recent step counts and a flag indicating whether step data is available — not your
Health app history.
You can revoke HealthKit access at any time in the iOS Settings → Privacy & Security →
Health screen. If you do, the App continues to run in a reduced mode using other signals, and it
will tell you it is doing so.
6. Location
Location is used to (a) help wake the app when you move, and (b) provide a last-known
location in an alert so your contacts know where help might be sent if you go silent.
Our handling is deliberately minimal:
- Latest-only, no trail. We store only your single most recent
location fix and overwrite it on every heartbeat. We do not keep a history of where
you have been.
- Cached fixes only; we never actively track you. The App reads the location iOS
already has cached; it does not turn on GPS to locate you in real time.
- You control precision. If iOS "Precise Location" is on, the cached fix is as
accurate as iOS has it; if you turn Precise off, fixes drop to approximately city-block/kilometer
scale, and the App's dashboard tells you so.
- Alerts include last-known location by default, and you can turn it off. In an
alert, your contacts see your last-known fix labeled with its age (never presented as "current"). You
can disable including location in alerts with an in-app toggle.
- Denying location does not break the safety net. The core inactivity detection
runs on step activity, not coordinates. If location permission is denied, we simply hold no location
and the location features are unavailable.
Where location is shown to a casual observer status page, it is not
included — observer pages are reassurance-only and do not reveal your location.
7. How we share information
We share personal information only as described here. We do not sell personal information,
and we do not share it for cross-context behavioral advertising.
7.1 With the people you choose
The purpose of the App is to notify people you designate. Accordingly:
- Emergency contacts you add receive alerts if you go silent, which may include
your display name, the nature of the alert, and (unless you opt out) your last-known location and its
age.
- Observers you share a status link with can view a coarse status ("all's well,"
"away," or "trying to reach them"). Observer status pages do not reveal your location, your activity
timestamps, or raw sensor data.
You control these relationships and can remove a contact or revoke an observer link at any time.
7.2 With service providers (sub-processors)
We use a small number of processors that handle data on our behalf under contractual confidentiality
and security obligations:
We do not use third-party advertising networks, data brokers, or third-party analytics providers.
7.3 For legal and safety reasons
We may disclose information if we believe in good faith it is necessary to comply with a law,
regulation, legal process, or governmental request; to enforce our Terms; or to protect the rights,
property, or safety of our users or others.
7.4 Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, personal information may
be transferred as part of that transaction. We will require the recipient to honor this Privacy Policy or
notify you of any material change.
8. Data retention
- Activity and event history (heartbeats, connectivity diagnostics, and
alert/escalation events) has a 90-day retention target and is deleted by the next
successful daily retention run after passing that age.
- Location is retained as your single most recent fix only,
overwritten on every heartbeat.
- Account data (your identifier, optional name, contacts, observer links, and
settings) is retained for as long as your account is active, and deleted when you delete your account,
subject to any retention required by law.
- Registration IP ledger rows have a deletion target beginning after
48 hours and are removed by a subsequent successful daily retention run. They are
outside the account graph and are not removed by account deletion.
- Operational logs are retained by Cloudflare for a fixed maximum of
7 days and cannot be purged individually before they age out.
- Support communications are kept as long as needed to resolve your matter and for
a reasonable period thereafter.
9. Security
We design for data minimization as a security control: keeping only the latest location fix and short
activity windows limits what a breach could expose. Data in transit is encrypted (HTTPS/TLS), and access
to production systems is restricted. No method of transmission or storage is perfectly secure, and we
cannot guarantee absolute security.
10. Your privacy rights
Depending on where you live, you may have some or all of the rights below. We honor these rights
regardless of where you live to the extent practicable.
10.1 Everyone
- Access the personal information we hold about you.
- Correct inaccurate information (e.g. your display name or a contact
address).
- Delete your account and account-linked personal information immediately. The
unlinked registration IP ledger and provider operational logs age out on the shorter schedules in
Section 8 rather than being removed by the account-deletion control.
- Withdraw consent for health or location processing at any time (via iOS
permissions and in-app settings); this does not affect processing already carried out.
10.2 California residents (CCPA/CPRA)
You have the right to know what personal information we collect and how we use and disclose it, to
request deletion, to correct inaccurate information, and to limit use of sensitive personal information.
We do not sell or share personal information as those terms are defined under the
CCPA/CPRA. We use sensitive personal information (step data and precise geolocation) only to provide,
secure, maintain the quality and safety of, and improve the Service itself. We do not use it to infer
characteristics about you, and never for advertising, marketing, profiling, or sale. We will not
discriminate against you for exercising your rights.
10.3 EEA, UK, and Switzerland residents (GDPR / UK GDPR)
Our legal bases are described in Section 4. In addition to the rights above, you have the right to
object to or restrict certain processing, the right to data
portability, and the right to lodge a complaint with your local data protection
authority. Where processing is based on consent, you may withdraw it at any time. The
data controller is Redoubtable LLC.
10.4 How to exercise your rights
Email privacy@raretell.com or use the account
deletion control in the App. We may need to verify your request. Because accounts are pseudonymous (keyed
to a device-generated identifier rather than your name or email), verification and fulfillment are
generally performed from the device that holds your account. We will respond within the timeframes
required by applicable law.
11. International data transfers
We are based in the United States, and our processors may store and process data in the United States
and other countries. If you use the App from outside the United States, you understand your information
will be transferred to and processed in the United States. Where required, transfers of personal data out
of the EEA/UK rely on appropriate safeguards such as the European Commission's Standard
Contractual Clauses.
12. Children's privacy
The App is not directed to children under 13, and we do not knowingly collect
personal information from children under 13. In the EEA/UK, the App is not directed to children under 16.
Our Terms require account holders to be adults. If you believe a child has provided us personal
information, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the
"Last updated" date and, where appropriate, notify you in the App or by email. Your continued use of the
App after an update means you accept the revised policy.
14. Contact us