Appearance
Privacy policy — Keryx for SafeCall
Status: DRAFT — not counsel-reviewed · 25 August 2026Planned public URL: {public_base}/keryx/privacy (not yet published)Owner: Thomas Minitsios (sourcectl)
This draft describes how Keryx for SafeCall (“Keryx”) handles information. It must match the data classification and related GTM architectures. English and Czech DRAFT bodies live in this file; Czech is not counsel-reviewed and public HTTPS publication remains #107.
Do not treat this page as live store legal text until counsel review and public HTTPS publication are complete.
1. Who we are
- Publisher: sourcectl
- Product: Keryx for SafeCall (launcher label: Keryx)
- Audience: adult administrators of a separately contracted SafeCall physical/building deployment — not a consumer self-service product
- Initial store availability (planned): Czech Republic
- Languages (planned public parity): English and Czech
Contact for privacy and support requests uses the existing SafeCall support channel (see support commitments). Monitored mailbox and phone values live in controlled organization records and are not duplicated here.
2. What Keryx is
Keryx is a free administrator companion. An authenticated SafeCall administrator selects friendly alert categories and scans a SafeCall-generated QR code on their own device. Keryx receives SafeCall alerts via a client-operated ntfy service. Ordinary administrators do not manually configure ntfy servers or topic names.
3. Roles
| Role | Party |
|---|---|
| App publisher / store privacy controller for the shipped app | sourcectl |
| SafeCall platform operator (alert generation / publish) | Contracted SafeCall deployment |
| ntfy host and optional APNs/FCM upstream processor | Client deployer |
| Local device and local copy controller | The administrator who installs and provisions Keryx |
4. Information we process on the device
Keryx processes data primarily on the administrator’s device:
| Category | Examples | Why |
|---|---|---|
| Provisioning config | ntfy HTTPS URL, selected topics/labels, optional debug flag; future per-QR subscribe credential (subscribe_auth) | Connect to the correct alert feed |
| Alert history | Title, body, tags, timestamps, topic metadata, raw ntfy JSON for recovery/debug | Show Active/Archive and recover cached alerts |
| App state | Pause flag, tombstones for deleted alerts | Pause delivery; avoid reintroducing deleted items from cache |
| Platform tokens (when implemented) | APNs / FCM device tokens registered with the client ntfy host | Wake the app for killed-state delivery |
Alert bodies may include device names, MAC addresses, asset identifiers, and operational or location-like information generated by SafeCall. sourcectl does not claim that alert content is free of personal or sensitive operational data.
5. Permissions
Keryx may request:
- Camera — scan the SafeCall QR
- Notifications — present alerts
- Network — subscribe/poll the ntfy host and receive push wakes
Keryx does not use an analytics or crash-reporting SDK at launch (P0-05).
6. Lock screen and notifications
Operating-system notifications may show the full alert title and body on a locked device. Administrators should use device passcodes and notification privacy settings appropriate to their workplace.
7. Storage, retention, and deletion
- Local config and history use platform preferences storage (SharedPreferences), including future
subscribe_auth, which must be treated as a secret. - Visible history is capped at the latest 200 messages; up to 500 deleted tombstones may remain to suppress cache reintroduction.
- Reset App clears local config and history. It does not revoke the ntfy subscribe credential. Offboarding requires revoke on the ntfy host, then local reset or uninstall.
- Device backups may include alert history and config secrets unless the administrator excludes the app from backup.
Details: data classification.
8. Network services and processors
- Client ntfy host: receives subscribe/poll traffic and caches messages under the client’s deployment.
- Upstream APNs/FCM (when configured): may receive wake/
poll_requestmetadata so the OS can wake Keryx; alert bodies remain on the client ntfy cache under the approved delivery architectures. - SafeCall server: publishes alerts; it does not receive APNs device tokens from Keryx under the approved iOS design.
- Apple / Google: may process push infrastructure traffic according to their platform terms when push is enabled.
9. Sharing
sourcectl does not sell Keryx user data. Sharing occurs as needed to operate the service (client ntfy, platform push, SafeCall support when the administrator contacts support). Support intake should redact secrets and minimize raw payloads.
10. International transfers
Client ntfy hosts and upstream push providers may be located outside the Czech Republic depending on the deployment. Administrators and client IT remain responsible for their chosen hosting geography and contracts.
11. Rights and requests
Depending on applicable law (including GDPR where it applies), administrators may have rights of access, rectification, erasure, restriction, objection, and complaint to a supervisory authority. For Keryx-on-device data, use in-app reset or uninstall; for subscribe-token revocation and SafeCall-side records, use the SafeCall administrator/support path. Contact the SafeCall support channel.
12. Children
Keryx is for adult administrators only. It is not directed to children and is not offered in kids/families store programs.
13. Regulatory position
Keryx is classified for store purposes as a Business administrator tool. It is not a medical device and is not a certified emergency dispatch system. Notifications are supplemental. Approved public safety-claim language is in safety claims.
14. Changes
Material changes will update this draft, and after publication the public URL. The change-control owner is Thomas Minitsios.
15. Related drafts
Czech (DRAFT)
Stav: NÁVRH — neověřeno právníkem · zrcadlo anglického textu · 26. srpna 2026
1. Kdo jsme
- Vydavatel: sourcectl
- Produkt: Keryx pro SafeCall (štítek na launcheru: Keryx)
- Publikum: dospělí správci samostatně smluvního fyzického nebo budového nasazení SafeCall
- Počáteční dostupnost (plánováno): Česká republika
- Jazyky: angličtina a čeština
Kontakt pro soukromí a podporu používá kanál podpory SafeCall (viz podpora).
2. Co je Keryx
Keryx je bezplatný doplněk pro správce. Správce SafeCall vybere kategorie upozornění a naskenuje QR kód na vlastním zařízení. Běžní správci ručně nenastavují servery ntfy ani topic názvy.
3–13. Další oddíly
Anglické oddíly 3–13 (role, data v zařízení, oprávnění, uzamčená obrazovka, retence, síť, sdílení, přenosy, práva, děti, regulace, změny) mají stejný význam v češtině: lokální zpracování na zařízení, doplňková upozornění, žádný prodej dat, GDPR práva přes kanál SafeCall, pouze pro dospělé správce, není zdravotnický prostředek. Plné znění pro publikaci projde právní revizí před HTTPS vydáním (#107).