Deleting your data

There is no account to delete

ShotDetect has no sign-in and no user account. There is no profile and no phone number held anywhere.

There is one email address, if you gave us one. This page previously said there was no email address held anywhere, and that has not been true since the early access test opened. If you asked for a place on it — on the early access page, or by writing to us — we hold the Google account address you gave, because Google Play matches testers by account and cannot install the app without one. Nothing you do inside the app creates that record, and the app never sends it: it exists only if you typed it into the form. It is the one thing here we can look up, and therefore the one thing we can delete on request. Section 01a says how.

Since August 2026 there is one server, and this page previously said there was none. It forwards alerts to a guardian who is not at the school. It holds no account and nothing that names you: an alert sits on it as encrypted bytes, addressed to a random token, and is discarded after twenty minutes whether or not it was collected. It has no key to read any of it. See the privacy policy, section 11.

One thing on that server is kept indefinitely, and this page previously implied nothing was. When your phone pairs, it registers a random sixteen-character routing token and the public key allowed to collect from it. That record has no expiry. It carries no name, no account and nothing derived from your phone or from you, and nothing on the server connects it to a person — but it is a record, it persists, and it can be deleted. Section 04 says how.

What we cannot do is look you up from the app. There is no account to find and no way for us to tell which routing token is yours — so a deletion request by email cannot reach the record the app made, however much we would like it to. That deletion route is the app's own, and it is described in section 04. The early access address above is the exception, and the one thing an email to us can act on.

Deleting your early access address

Email contact@shotdetect.com from the address you signed up with, or naming it, and say you want it deleted. We delete the record — the address, when you signed up, whether you confirmed, and the referral code attached to it — and reply to say it is done. There is no form to fill in and no account to close.

Two things worth knowing. Deleting is not the same as unsubscribing: every message we send carries a link that stops the mail while leaving your place on the test, which is usually what people want. And after a deletion, the confirmation link in any old message from us stops working — we keep a marker so that a link clicked, or fetched by a mail scanner, cannot quietly put you back. The marker holds a one-way hash of the address and the date, never the address, and it expires after about thirteen months. Signing up again clears it.

If you never confirm a signup, the place is released and the record deleted automatically after fourteen days. Nothing is kept about it.

What the app holds, and where

The timeline of what happened lives in your phone's memory while the app is running. It is not uploaded anywhere, and it does not survive the app being closed.

This page previously said the same of the people you have connected. That was true until August 2026. Pairings are now written to the phone, because a pairing that vanished when the app closed made two families pair again every time, and because a guardian's phone cannot be sent an alert it has forgotten how to address. Section 03 lists what a pairing record contains.

Sound is never part of this. It is examined in memory and overwritten within seconds, so there is no recording to delete at any point.

What is written to the phone

Three things. This page previously said none of them contains personal data, and that was true until August 2026 — the third now holds a name and a list of the people you paired with.

Since August 2026 that settings file also holds what pairing needs: the name you asked to be called, if you gave one; this phone's own pairing key pair and its routing token; and, for each person you paired with, the name they gave, whether they are a student or a guardian, the date you paired, and their public key and routing token. The private key is the most sensitive value in the file — whoever holds it can read that pairing's alerts.

The phone's own position is not among them, and neither is anyone else's. The app reads its own position while it is listening and while the app is open, puts it on the Bluetooth message described in the privacy policy, and — since August 2026 — sends it, sealed, to the people you paired with every few seconds while the app is on screen. Every one of those is held in memory for as long as it takes to send or to draw, and none is written to storage. The positions your paired people send you are the same: a dot on a map that is dropped after ninety seconds of silence, never a file. There is no location history to delete, on any phone or on our relay. The coordinates in the file above are the school's, which you chose yourself — not where the phone has been.

Nothing the app writes to storage contains audio. This page also said nothing it writes leaves the phone. That was true until August 2026. Two of the values above do: this phone's routing token and its public key are sent once to the relay when you pair, so that an alert can be addressed to you. The private key is not sent, and could not be.

How to remove everything

On a guardian's phone, do this first: stop the phone being a guardian. When it is no longer watching for a paired student — because you removed the last student you had paired with, or changed the phone's role — the app stops the relay watch, and stopping it is what asks the server to delete the token-and-key record described in section 01. The request has to be signed by the private key on that phone, which is why nobody else can delete your record and why we cannot delete it for you. If the phone has no network at that moment the request fails and the record survives; doing it again later tries again.

On a student's phone there is no equivalent, and this version does not pretend otherwise. That phone registers a routing token too, so that a guardian's phone knows how to reach it, and nothing in the app asks the server to unregister it. Uninstalling makes it unusable — a reinstall mints a new token, and nothing can be delivered to a token whose key no phone holds — but the record itself stays. The fix is a button in the app, not a sentence on this page, and until it exists this is where it is written down.

Then uninstall the app. That removes the cached map tiles, the map settings and the shotdetect.protection file — the key pair, the routing token, the pairings and the names among them — from the phone.

Uninstalling on its own does not clear the server record, and this page previously said nothing was left behind. An app that has been removed cannot ask the server for anything, so the record stays. It becomes useless — a reinstall mints a new token rather than reclaiming the old one, and nothing can be delivered to a token no phone is holding the key for — but useless is not deleted, and we would rather say so than let the word "uninstall" do work it cannot do. Turning the relay off before uninstalling is the difference.

To clear that storage without uninstalling, open Android Settings → Apps → ShotDetect → Storage → Clear storage. That also clears the armed flag and the listening hours, so the app will be off afterwards and a restart will not start it listening. It clears the pairing keys too, which means the phones you paired with must pair again — and, like uninstalling, it leaves the server record behind unless you turned the relay off first.

Two outside services see your device's IP address when the app asks them for a school address or a map tile: OpenStreetMap's Nominatim and the OpenStreetMap Foundation's tile servers. We hold nothing from those requests and cannot delete anything on their side; what they keep is governed by their own policies, linked from section 08 of our Privacy Policy.

Making a request

If you believe we hold data about you, email contact@shotdetect.com and we will respond within 30 days.

We will tell you honestly what the answer is, and the honest answer has changed twice. We hold no name and no account. We hold your email address if — and only if — you asked for an early access place with it; that one we can find, and we delete it on request, which is section 01a. Everything the app itself creates is different: the relay holds encrypted bytes under a random token for at most twenty minutes; a record that an alert was collected — a token and an opaque number, no content — for twenty-four hours; and the token-and-public-key record indefinitely. None of that is linked to a person, which is why there is no lookup we could perform on it even in principle: we cannot find it, and that also means we cannot delete it for you. Section 04 is the route that works for it. The reply to an email is a real one, not a form letter.

Retention

This section previously read "We retain nothing, because we receive nothing." That was true until August 2026. The relay now receives things, and retains three of them for three different lengths of time: an undelivered alert for twenty minutes, then discarded whether or not it was collected; a record that an alert was collected, a token and an opaque number with no content, for twenty-four hours; and the binding between a routing token and the public key allowed to collect from it, indefinitely, until the phone that owns it asks for it to go. We do not log request contents. We cannot read any of it.

The early access address is a fourth, and it sits outside all of that because the app never touches it. An address that confirmed is kept until the test ends or you ask us to delete it, whichever comes first. An address that never confirmed is deleted after fourteen days and its place released. An address that unsubscribed is kept and marked rather than deleted — deliberately, so that a later signup cannot quietly resume mail to somebody who asked us to stop — and is deleted on request like any other. The record holds the address, the dates, whether it confirmed, a referral code and where the signup came from. It holds no name, no phone number and nothing from the app.

On your own phone, the three items in section 03 are kept until you clear the app's storage or uninstall it.