Privacy Policy
Last updated 6 September 2026
Our role
For the personal data your organisation puts into the product — your members and your emergency contacts — you are the controller and we are a processor. We process it on your instructions to run the service.
For your billing contacts and the account data of the person who signs up, we are a controller in our own right.
What we hold
| Data | Why | Can we read it? |
|---|---|---|
| Member name, email, phone | Authentication, notification | Yes |
| Contact name, email, phone, role | Emergency notification | Yes |
| Secret values | Storage | No — encrypted on your devices |
| Secret titles, descriptions, tags | Search, audit visibility | Yes — do not put secrets in them |
| Audit events | Your compliance record | Yes |
| Message bodies | Delivery | Yes — see below |
| Public keys | Sharing key shares | Yes — they are public |
| Wrapped private keys | Sign-in from a second device | No — sealed with your password |
Emergency message bodies are not end-to-end encrypted, because they must reach people with no account and no keys, through carriers. Treat alert text accordingly. Secret values never appear in a notification.
Notification logs
We record every message sent: recipient, channel, template, timestamp and delivery status. The stored copy of the body is redacted — claim links and access codes are stripped before it is written, so the log alone cannot open anything.
Retention
Audit events are retained for the period your plan specifies (7 days on Free through 7 years on Enterprise) and then deleted in whole time windows. Other data is retained while your account is active and for 30 days after termination.
An SMS opt-out is retained indefinitely and survives contact deletion. Forgetting that someone said STOP would let a re-import resurrect permission they withdrew, so we keep the withdrawal specifically to honour it.
Sub-processors
Google Cloud (hosting and storage), Resend (email), Twilio (SMS and voice), Stripe (payments). Details, and what reaches each of them, are on our Trust & compliance page. None receive key material or plaintext secrets.
Your rights
Where we are the processor, direct access, correction and erasure requests to the organisation that holds your data — we will support them in responding. Where we are the controller, contact privacy@breakglass.business.
A note for emergency contacts
If you are listed as an emergency contact by an organisation, they uploaded your details, not us. You can opt out of text messages permanently by replying STOP to any message. To have your details removed entirely, contact the organisation that listed you; if that is not possible, write to us and we will help.