ShieldNav ("ShieldNav," "we," "our," or "us") is a crime-aware navigation application for iOS and Android. We take your privacy seriously. This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, and what choices you have. Please read it carefully. By using ShieldNav you agree to the practices described here.
If you have questions, contact us at any time:
1. Scope and Who We Are
This Privacy Policy applies to the ShieldNav mobile application (the "App") available on iOS (Apple App Store) and Android (Google Play Store), as well as any related websites or services that link to this policy (collectively, the "Services").
Our primary contact for privacy matters is support@shieldnav.com.
ShieldNav is currently offered exclusively to users located in the United States.
2. Children's Privacy (COPPA)
We do not knowingly collect personal information from children under 13 years of age. By creating an account or using the App, you represent that you are at least 13 years old. If you are between 13 and 18, you represent that you have your parent's or guardian's permission to use the App.
If we become aware that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will take immediate steps to delete that information from our records. If you believe we have collected information from a child under 13, please contact us immediately at support@shieldnav.com.
This policy is consistent with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq.
3. Information We Collect
We collect the following categories of information:
3.1 Information You Provide Directly
- Account registration data: Your email address and display name when you sign up with email/password, Google Sign-In, or Sign in with Apple.
- Profile photo: An optional profile photo you choose to upload. Profile photos are stored in Firebase Storage.
- Feedback and bug reports: Text descriptions, severity ratings, report type, and any optional screenshots you submit through the in-app feedback tool. These are stored in Firebase Firestore.
3.2 Information Collected Automatically
- Location data: GPS coordinates while the App is actively navigating. See Section 4 for a full description of what is and is not stored.
- Saved places and scheduled drives: Destinations you save (such as Home, Work, or custom places), your recent destinations, and the start/end points of drives you schedule. These include addresses and coordinates and are stored in your account so they sync across your devices. See Section 4.3.
- Device information: iOS/Android version, device model, app version, and unique device identifiers. Collected via Firebase Performance Monitoring.
- Performance telemetry: App start times, screen render durations, and network request latencies. Collected via Firebase Performance Monitoring.
- Push notification tokens: Firebase Cloud Messaging (FCM) registration tokens, used to deliver in-app and system notifications to your device.
- Service usage counts: A running monthly count, stored with your account, of how many routing and place-search requests our servers made on your behalf. These are counts only — they do not record what you searched for, where you drove, or any coordinates — and we use them to manage infrastructure costs, plan capacity, and detect abuse of the paid services behind the App.
3.3 Subscription and Purchase Information
- Subscription status and entitlements: Whether your account is in its free trial, on a monthly plan, or on an annual plan, and whether that subscription is active. Current pricing is shown in the App Store and in the app before you subscribe. This is managed by RevenueCat and linked to your Firebase UID. We do not store or process your payment card information — all payment transactions are handled by Apple (App Store) or Google (Play Store) directly.
3.4 Information from Third-Party Sign-In
If you sign in with Google or Apple, we receive a limited profile (name, email address, and a provider-specific unique identifier) from those services. We do not receive your passwords, payment details, or any other data held by those providers. See their respective privacy policies for more information.
3.5 Drive Logs (Local Only)
The App may create drive logs on your device for diagnostic and personal review purposes. These logs are stored locally on your device and are never uploaded to our servers. You can delete them at any time by uninstalling the App or clearing App data in your device settings.
4. Location Data — What We Collect and What We Don't
4.1 What We Collect
When you actively use navigation in ShieldNav, the App accesses your device's GPS coordinates. This location data is used only in real time, within that active navigation session, for the following purposes:
- Calculating and displaying your route (via the HERE Maps SDK).
- Providing turn-by-turn directions and re-routing.
- Overlaying crime heatmaps and scoring areas along your route.
- Displaying current speed limits and toll information.
4.2 What We Do NOT Store
Your precise GPS coordinates from individual navigation sessions are not stored persistently on our servers. Once a navigation session ends, session-level location data is discarded. We do not build a history of your movements or trips. The only location data stored in your account is the saved-place data described in Section 4.3, which you control.
4.3 Saved Places, Recent Destinations, and Scheduled Drives
Separately from real-time GPS data, we store certain destination data in your account (in Firebase Firestore) so it can sync across your devices:
- Saved places: Destinations you explicitly save, such as Home, Work, or custom places, including their names, addresses, and coordinates.
- Recent destinations: A short list of destinations you have recently navigated to, so you can quickly select them again. This is a list of endpoints you chose — it is not a GPS trace or a record of the routes you traveled.
- Scheduled drives: The origin and destination (addresses and coordinates) of drives you schedule in the App, used to send you your requested drive reminders.
You can edit or delete saved places, recent destinations, and scheduled drives at any time in the App. All of this data is deleted when you delete your account (see Section 13). We do not use it for advertising, and we do not sell it or share it with third parties except the service providers described in Section 6.
4.4 Data Sent to HERE Technologies
To calculate routes and provide mapping services, your location data is transmitted to HERE Technologies' servers. HERE processes this data as a service provider on our behalf subject to HERE's Data Privacy Notice (available at here.com/privacy). HERE may retain anonymized, aggregated telemetry for product improvement purposes in accordance with their own policies.
4.5 Background Location
ShieldNav requests location access only while the App is actively navigating (foreground use). If permitted, the App may continue to update your position while the screen is locked during an active navigation session. We do not access your location when the App is closed or when navigation is not active.
4.6 Revoking Location Permission
You may revoke location permission at any time via your device's Settings. Note that revoking location access will disable navigation and crime-overlay features of the App.
5. How We Use Your Information
| Purpose | Information Used |
|---|---|
| Provide and operate the App (navigation, crime overlays, routing) | Location data, account info, subscription status |
| Authenticate your identity and maintain your account | Email, display name, Firebase UID, OAuth tokens |
| Manage your subscription and verify entitlements | Firebase UID, RevenueCat subscription data |
| Send push notifications (navigation alerts, product updates) | FCM registration token |
| Process and respond to feedback and bug reports | Feedback text, severity, type, optional screenshot, account info |
| Monitor App performance and fix bugs | Device info, performance telemetry |
| Manage infrastructure costs, plan capacity, and detect abuse of paid services | Firebase UID, service usage counts (routing and search request totals) |
| Improve App features and user experience | Aggregated, anonymized usage patterns |
| Enforce our Terms of Service and prevent fraud | Account info, device info |
| Comply with legal obligations | As required by applicable law |
We do not use your personal information to serve you third-party advertising. We do not sell, rent, or trade your personal information to data brokers or marketing companies.
6. Third-Party Services We Use
ShieldNav relies on the following third-party service providers. Each acts as a service provider or processor, meaning they may receive certain data only to perform services on our behalf. They are not authorized to use your data for their own independent purposes.
6.1 Firebase (Google LLC)
We use multiple Firebase products: Authentication, Cloud Firestore (database), Cloud
Storage, Cloud Messaging (push notifications), Performance Monitoring, and App Check.
Google may collect device identifiers and usage data in connection with these services.
Privacy policy: policies.google.com/privacy
6.2 HERE Technologies
HERE provides maps, geocoding, routing, and speed-limit data. Your location and route
queries are sent to HERE's servers to compute navigation results.
Privacy policy: here.com/privacy
6.3 RevenueCat, Inc.
RevenueCat handles subscription management and in-app purchase validation for iOS and
Android. RevenueCat receives your Firebase UID, purchase receipts (from Apple), and
subscription status. RevenueCat does not receive your full name, email address, or payment
card details.
Privacy policy: revenuecat.com/privacy
6.4 Apple (Sign in with Apple / App Store)
When you use Sign in with Apple, Apple shares a stable identifier and, optionally, an
email address with us (Apple may relay the address). All payment processing for iOS
subscriptions is handled solely by Apple.
Privacy policy: apple.com/privacy
6.5 Google (Google Sign-In)
When you use Google Sign-In, Google shares your name, email address, and a Google-specific
identifier with us. No payment data is shared.
Privacy policy: policies.google.com/privacy
6.6 Public City Crime Databases
Crime heatmap data is sourced from publicly available municipal and law-enforcement databases. This data is purely public-record information and does not involve any personal information about you.
8. Data Retention
We retain your personal information only for as long as necessary to provide the Services and fulfill the purposes described in this policy, unless a longer retention period is required by law.
| Data Type | Retention Period |
|---|---|
| Account information (email, display name, Firebase UID) | Retained for the life of your account; deleted within 30 days of account deletion request |
| Profile photo | Retained until you delete it or delete your account |
| Real-time GPS location (active navigation session) | Not stored server-side; discarded at session end |
| Saved places, recent destinations, and scheduled drives (addresses and coordinates) | Retained until you edit or delete them in the App; deleted with your account |
| Drive logs | Stored on-device only; not uploaded; deleted when you uninstall the App or clear App data |
| Feedback submissions | Retained for up to 2 years to allow us to track and resolve reported issues, then deleted |
| FCM push notification tokens | Retained while you have the App installed and notifications enabled; removed on account deletion |
| Performance telemetry | Retained in aggregated form for up to 90 days per Firebase Performance defaults |
| Product-interaction analytics events (Firebase Analytics) | Retained per Google Analytics for Firebase's configured data-retention setting |
| Service usage counts (monthly routing/search request totals for your account) | Retained 13 months, then deleted automatically; deleted sooner if you delete your account |
| Subscription records (RevenueCat) | Retained per RevenueCat's policies; typically up to 2 years for dispute resolution. See RevenueCat's privacy policy. |
When you delete your account, we initiate deletion within 30 days. Some anonymized or aggregated data may be retained indefinitely as it cannot be linked back to you. Certain data may be retained longer where required by applicable law (for example, for tax or fraud-prevention purposes).
9. Security
We implement reasonable administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, alteration, or disclosure. These measures include:
- Data in transit is encrypted using TLS (Transport Layer Security).
- Firebase Firestore and Firebase Storage access is governed by Security Rules that enforce per-user read/write permissions.
- Firebase App Check is used to verify that requests originate from genuine instances of ShieldNav, reducing abuse by unauthorized clients.
- Authentication credentials are managed by Firebase Authentication and are never stored in plain text.
- Third-party OAuth providers (Google, Apple) handle authentication secrets directly; we never see your passwords for those services.
No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights or freedoms, we will notify affected users and relevant authorities as required by applicable law.
If you discover a security vulnerability, please report it responsibly to support@shieldnav.com.
11. Your Rights and Choices
Regardless of where you live, we provide the following rights to all ShieldNav users:
11.1 Right to Access
You may request a copy of the personal information we hold about you. Email us at support@shieldnav.com with the subject line "Data Access Request." We will respond within 45 days.
11.2 Right to Correction
You may update your display name and profile photo directly in the App (Settings › Profile). To correct your email address or other account data, contact us at support@shieldnav.com.
11.3 Right to Deletion
You may request deletion of your personal information at any time. See Section 13 for step-by-step instructions. We will process deletion requests within 30 days, subject to any legal retention requirements.
11.4 Right to Opt Out of Non-Essential Communications
You may opt out of push notifications at any time via your device Settings or within the App's notification preferences. Note that we may still send you transactional messages (e.g., account security alerts) that are necessary for the operation of your account.
11.5 Right to Withdraw Consent
Where processing is based on consent (for example, access to location), you may withdraw consent at any time by adjusting your device permissions. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
11.6 Non-Discrimination
We will not discriminate against you for exercising any of these rights. You will not receive a reduced quality of service, higher prices, or penalties for making a request.
11.7 Submitting a Request
To exercise any of the above rights, email us at support@shieldnav.com. We may ask you to verify your identity before fulfilling the request to protect your account security.
12. California Privacy Rights (CCPA / CPRA)
If you are a resident of California, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you additional privacy rights described below.
12.1 Categories of Personal Information Collected
Over the past 12 months, we have collected the following categories of personal information as defined by the CCPA:
| CCPA Category | Examples | Collected? |
|---|---|---|
| Identifiers | Email address, Firebase UID, device ID | Yes |
| Personal information (Cal. Civ. Code § 1798.80) | Name, profile photo | Yes (optional photo) |
| Geolocation data | GPS coordinates during active navigation; saved places and scheduled-drive endpoints you choose | Yes (navigation coordinates are in-session only; saved places are stored until you delete them — see Section 4.3) |
| Internet / electronic network activity | App performance telemetry; monthly counts of routing and place-search requests made for your account | Yes |
| Inferences drawn from personal information | Subscription tier inference | No |
| Sensitive personal information — precise geolocation | GPS coordinates during navigation; coordinates of places you save | Yes (navigation is in-session only; saved places are stored at your direction — see Section 4) |
| Financial information | Payment card data | No (handled by Apple/Google) |
| Protected classifications | Race, religion, health status, etc. | No |
| Biometric information | Fingerprints, facial recognition data | No |
| Audio/visual information | Voice recordings, photos taken in-app | No (profile photos only if you upload one) |
12.2 Sources of Personal Information
We collect personal information from:
- You directly (account registration, profile settings, feedback forms).
- Your device automatically (location, performance metrics).
- Third-party sign-in providers (Google, Apple).
12.3 Business or Commercial Purposes for Collection
As described in Section 5 above.
12.4 Categories of Third Parties We Share With
As described in Sections 6 and 7 above. We share with:
- Service providers (Firebase/Google, HERE Technologies, RevenueCat).
- Government entities, when required by law.
12.5 Sale or Sharing of Personal Information
12.6 Use of Sensitive Personal Information
We collect precise geolocation data (a "sensitive" category under CPRA) in two ways: (1) during active navigation sessions, used in real time only and not stored persistently on our servers; and (2) as the coordinates of places you explicitly save (Home, Work, custom places, recent destinations, and scheduled drives), which are stored in your account at your direction until you delete them (see Section 4.3). We use this information only to provide the core features of the App. You have the right to direct us to limit the use of your sensitive personal information to the uses necessary to provide the requested services. Our use is already limited as described — no further opt-out is required.
12.7 Your CCPA Rights
California residents have the right to:
- Know: Request disclosure of the specific pieces of personal information we have collected about you, the categories of sources, our business purpose for collecting it, and the categories of third parties we share it with.
- Delete: Request deletion of your personal information, subject to certain exceptions (legal compliance, security, etc.).
- Correct: Request correction of inaccurate personal information.
- Opt Out of Sale/Sharing: Opt out of the sale or sharing of your personal information for cross-context behavioral advertising. (We do not engage in these activities, so no opt-out action is required.)
- Limit Use of Sensitive Personal Information: Request that we limit our use of your sensitive personal information to what is necessary to provide the Services. (Our use is already so limited.)
- Non-Discrimination: Not be discriminated against for exercising your CCPA rights.
12.8 How to Submit a CCPA Request
To exercise your CCPA rights, email us at support@shieldnav.com with the subject line "CCPA Privacy Request." We will respond within 45 calendar days. We may extend the response period by an additional 45 days when reasonably necessary and will notify you of such extension. We will verify your identity before fulfilling the request.
You may designate an authorized agent to submit a request on your behalf. Authorized agents must provide written authorization and we may require you to verify your identity directly with us.
12.9 Shine the Light
California Civil Code § 1798.83 permits California residents to request information about personal information shared with third parties for their direct marketing purposes. As noted above, we do not share personal information with third parties for direct marketing.
13. How to Delete Your Account
You can delete your ShieldNav account and associated data at any time using either of the following methods:
Method 1: In-App Deletion (Recommended)
- Open ShieldNav and go to Settings.
- Tap Account.
- Scroll to the bottom and tap Delete Account.
- Confirm deletion when prompted.
Method 2: Email Request
Email support@shieldnav.com from the email address associated with your account. Use the subject line "Account Deletion Request." We will confirm the deletion within 30 days.
What Happens When You Delete Your Account
- Your Firebase Authentication record, your Firestore profile and the data stored under it — including saved places, recent destinations, scheduled drives, and service usage counts — and your profile photo in Firebase Storage will be deleted within 30 days.
- Your FCM push notification token will be revoked.
- Feedback submissions associated with your account will be anonymized or deleted within 30 days.
- Your RevenueCat subscription record will be retained per RevenueCat's data retention policy for dispute-resolution purposes; cancellation must be done separately through the App Store (iOS) or Play Store (Android).
- Drive logs stored locally on your device are not affected — delete them by uninstalling the App.
- Anonymized and aggregated data that cannot identify you may be retained indefinitely.
14. Third-Party Links and Services
ShieldNav may display links to external websites, map data attributed to public sources, or references to third-party services. This Privacy Policy applies solely to information collected by ShieldNav and does not govern the practices of third-party websites or services that you may access through the App or that are linked from within the App.
We are not responsible for the privacy practices or content of third-party websites or services. We encourage you to review the privacy policies of any third-party site or service before providing your personal information. Third-party services integrated into the App (Firebase, HERE, RevenueCat, etc.) are governed by their own respective privacy policies, as linked in Section 6.
Crime data displayed in the App is sourced from publicly available municipal and law-enforcement databases. We do not control the accuracy or completeness of that data and are not responsible for how third-party data sources handle any information related to their datasets.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other business reasons. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Post a notice in the App, or send you an email notification to the address on file, at least 14 days before the changes take effect.
Your continued use of ShieldNav after the effective date of the revised policy constitutes your acceptance of the changes. If you do not agree with the updated policy, please discontinue use of the App and delete your account.
We encourage you to review this policy periodically. The current version is always available within the App under Settings › Privacy Policy, and at shieldnav.com/privacy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
We aim to respond to all privacy-related inquiries within 5 business days and to fulfill substantive rights requests within 45 calendar days, unless a longer period is permitted by applicable law.