Privacy Policy
How WardSafe handles information — in plain language first, then in detail.
Last updated 9 August 2026
The short version
Audio never leaves your iPhone. Sound and speech are analysed on the device and discarded immediately. No recording is ever saved to storage or uploaded to us or anyone else.
You do not need an account. Sound alerts, live captions, and your on-device history all work signed out, and nothing is uploaded. An account is optional.
If you create an account and turn on backup — it is off until you do — the results of the analysis sync to your private account so they survive a lost phone: word counts, the sound timeline, and daily summaries. Keeping the actual words is a separate setting, also off unless you turn it on.
You can delete everything, on the device and in the cloud, from inside the app at any time.
1. Who we are
WardSafe (“we”, “us”) publishes the WardSafe iPhone application. This policy covers the app and this website. For privacy questions, contact vittesh.taneja@gmail.com.
The data controller for the purposes of the UK and EU GDPR is WardSafe.
2. What happens to audio
This is the part most people want to know, so it comes first.
When listening is on, the microphone stream is analysed in memory, on your device, by two Apple frameworks that run locally:
- Sound Analysis classifies environmental sounds, such as a smoke alarm, a doorbell, or a dog barking.
- Speech Recognition transcribes speech with on-device recognition explicitly required. If a device or language cannot do this locally, the app disables transcription rather than sending audio to a server.
Audio buffers are discarded as soon as they are analysed. The app writes no audio file to disk, so there is no recording to upload, back up, hand over, or lose. What remains is derived data — a label such as “Smoke alarm”, a word such as “milk”, and counts.
3. What we collect
| Data | Why | Where it lives |
|---|---|---|
| Email address | To create and secure your account | Device and our servers |
| Display name (from Google or Apple, if used) | To show who is signed in | Device and our servers |
| The monitored person’s first name, and optionally a date of birth | To label the profile, and to show age-referenced ranges if you turn them on | Device and our servers |
| Vocabulary entries — individual words heard, with first/last heard dates and counts | To show vocabulary growth over time | Device and our servers |
| Sound events — label, urgency, confidence, timestamp, duration | To build the timeline and alert history | Device and our servers |
| Daily summaries — utterance counts, word counts, babble bursts, conversational turns | To show trends on the Insights screen | Device and our servers |
| Sentence transcripts (off by default) | Only if you switch on “Keep the actual words” in Settings | Device, and our servers only if enabled |
| Optional profile photo and history backup files | Only if you choose to add them | Our servers |
What we never collect
- Audio recordings. None, at any point, under any setting.
- Location, contacts, photos (beyond a profile photo you choose), or health records.
- Advertising identifiers. There is no advertising or tracking in the app.
We do not sell personal information, and we do not share it with third parties for their own marketing.
4. Children’s information
Read this if you are setting up a child profile
WardSafe accounts are for adults. You must be 18 or older, and the parent or legal guardian of any child you monitor, to create an account and enable a child profile.
By setting up a child profile you confirm you have the authority to consent to the collection described here on that child’s behalf.
In child mode the app derives information about a named child: the words they say, how often they speak, and their stage of pre-verbal babble. We treat this as sensitive.
- Children cannot create accounts or sign in.
- The data minimises by default — transcripts are off, so the app records that fourteen new words were heard without recording what was said.
- Age-referenced comparison ranges are off by default, and are presented as population context rather than as a test.
- A parent or guardian can delete all of a child’s data from within the app at any time, from both the device and our servers.
If you believe a child’s information has been collected without proper consent, email vittesh.taneja@gmail.com and we will delete it.
5. How we use information
- To provide the app’s features to you.
- To back up your history and keep it consistent across your devices.
- To respond when you contact support.
- To keep the service secure and to comply with legal obligations.
We do not use your data to train machine-learning models. The sound and speech models in the app are Apple’s, run locally on your device, and are not trained on your data by us.
We do not send your data to any third-party AI service. All sound and speech analysis happens on your iPhone using Apple’s on-device frameworks. No audio, transcripts, or derived data are transmitted to an external AI or machine-learning service for processing.
Under the UK and EU GDPR our lawful bases are: contract (providing the service you signed up for), consent (the microphone, optional transcript retention, and child-profile data), and legitimate interests (keeping the service secure). You can withdraw consent at any time by turning the relevant setting off or deleting your account.
6. Who else processes your data
We use Google Firebase (Google LLC) for authentication, the database, and file storage. Firebase acts as our processor and stores data on Google Cloud infrastructure. See the Firebase privacy documentation.
If you use Sign in with Apple or Sign in with Google, that provider authenticates you and tells us an account identifier and email address. Apple’s Hide My Email gives us a relay address instead of your real one, and the app works exactly the same either way.
We do not use analytics or crash-reporting SDKs that profile you, and there are no advertising SDKs in the app.
7. International transfers
Our processors may store and process data in the United States and other countries. Where data is transferred out of the UK or EEA, it is covered by the European Commission’s Standard Contractual Clauses or another approved safeguard.
8. How long we keep things
- Sound events on your device: automatically deleted after 30 days.
- Vocabulary and daily summaries: kept while your account exists, because their value is the long trend.
- Everything: deleted when you delete it in the app, or when you delete your account.
Backups held by our processors may persist for a short period after deletion before they are overwritten.
9. Your rights and controls
Inside the app, under Settings, you can at any time:
- Turn cloud backup on or off while staying signed in — it is off until you turn it on, and turning it on shows exactly what will be uploaded and to whom before anything is sent.
- Turn off transcript retention, and delete stored words.
- Delete everything on the device, and separately delete the cloud copy.
- Sign out, or delete your account entirely.
Depending on where you live, you also have the right to access, correct, export, restrict, or object to our processing, and to complain to a data protection authority. In the UK that is the Information Commissioner’s Office. California residents have rights under the CCPA/CPRA, including access and deletion; we do not sell or share personal information as those terms are defined there.
To exercise any right, email vittesh.taneja@gmail.com. We respond within 30 days.
10. Permissions the app asks for
- Microphone — required. Without it the app cannot detect any sound.
- Speech Recognition — optional. Decline it and sound alerts still work; only word tracking and captions are affected.
- Notifications — optional, but recommended. Without them you will only see alerts while the app is open.
You can change all of these in iOS Settings at any time.
11. Security
Data on the device is written with iOS file protection, so it is encrypted at rest while the device is locked. Data in transit uses TLS. Access to our stored data is restricted by security rules so that an account can only ever read and write its own records.
No system is perfectly secure. The strongest protection here is structural: because audio is never stored, there is no recording of your home that can be breached.
12. Changes to this policy
If we change this policy we will update the date at the top, and for significant changes we will tell you in the app before they take effect.
13. Contact
Privacy: vittesh.taneja@gmail.com
Support: https://wardsafe.app/support