Privacy Policy

Last updated 6 September 2026

Draft — not yet reviewed by counsel. Accurate about the system’s actual behaviour; not yet reviewed by a qualified privacy lawyer, which it should be before launch. A GDPR-compliant DPA is a separate document and is not yet written.

Our role

For the personal data your organisation puts into the product — your members and your emergency contacts — you are the controller and we are a processor. We process it on your instructions to run the service.

For your billing contacts and the account data of the person who signs up, we are a controller in our own right.

What we hold

DataWhyCan we read it?
Member name, email, phoneAuthentication, notificationYes
Contact name, email, phone, roleEmergency notificationYes
Secret valuesStorageNo — encrypted on your devices
Secret titles, descriptions, tagsSearch, audit visibilityYes — do not put secrets in them
Audit eventsYour compliance recordYes
Message bodiesDeliveryYes — see below
Public keysSharing key sharesYes — they are public
Wrapped private keysSign-in from a second deviceNo — sealed with your password

Emergency message bodies are not end-to-end encrypted, because they must reach people with no account and no keys, through carriers. Treat alert text accordingly. Secret values never appear in a notification.

Notification logs

We record every message sent: recipient, channel, template, timestamp and delivery status. The stored copy of the body is redacted — claim links and access codes are stripped before it is written, so the log alone cannot open anything.

Retention

Audit events are retained for the period your plan specifies (7 days on Free through 7 years on Enterprise) and then deleted in whole time windows. Other data is retained while your account is active and for 30 days after termination.

An SMS opt-out is retained indefinitely and survives contact deletion. Forgetting that someone said STOP would let a re-import resurrect permission they withdrew, so we keep the withdrawal specifically to honour it.

Sub-processors

Google Cloud (hosting and storage), Resend (email), Twilio (SMS and voice), Stripe (payments). Details, and what reaches each of them, are on our Trust & compliance page. None receive key material or plaintext secrets.

Your rights

Where we are the processor, direct access, correction and erasure requests to the organisation that holds your data — we will support them in responding. Where we are the controller, contact privacy@breakglass.business.

A note for emergency contacts

If you are listed as an emergency contact by an organisation, they uploaded your details, not us. You can opt out of text messages permanently by replying STOP to any message. To have your details removed entirely, contact the organisation that listed you; if that is not possible, write to us and we will help.