Defcon5 — Privacy Policy

Defcon5 — Privacy Policy

Last updated: September 10, 2026 Operated by: Unicorn United, 6 rue d'Armaillé, 75017 Paris, France Contact: contact@unicorn-united.com

⚠️ This policy has been drafted with real, specific facts filled in where the law is well-established (France is an EU member state, so GDPR applies in full). It is still not a substitute for review by a lawyer before launch — see "Open items for your lawyer" at the end for what genuinely still needs one.

Summary (plain language — see full text below)

1. Who Operates Defcon5

This policy covers the Defcon5 mobile application and its backend service, operated by Unicorn United, 6 rue d'Armaillé, 75017 Paris, France. As a company established in France, Unicorn United is subject to the EU General Data Protection Regulation (GDPR) and French data protection law (Loi Informatique et Libertés) for all processing described in this policy, regardless of where a user is located.

If you are a parent or guardian setting this up for a minor under "Parent Mode," see Section 8.

2. What We Collect

2.1 Account data (kept until you delete your account)

2.2 Status data (kept while your account is armed, or as configured)

2.3 Location data (the most sensitive category — read this carefully)

2.4 What we do NOT collect

3. How We Use Your Data

We do not use your data for advertising, profiling, or any purpose other than operating the safety features described here. This is also our GDPR "purpose limitation" commitment: data collected for the safety service is not repurposed for anything else.

Legal basis under GDPR (Article 6): processing your account and status data is necessary for the performance of a contract with you (providing the service you signed up for). Processing your location data during an alert is based on your explicit consent, given when you enable location sharing — you can withdraw it at any time by disabling location in the app, which stops future collection immediately.

4. Who We Share Your Data With

5. How Long We Keep Data

5.1 Viewing (not exporting) the trail — and why there's no download button

While your location trail is available (during an alert or within the 48-hour window after it ends), guardians can view it — a map and a timestamped list — directly in their own app. There is deliberately NO download or export button. This was a specific design decision:

6. The Decoy / "Under-Pressure" Feature

If you enter your under-pressure code (instead of your normal passcode) — for example, because someone is forcing you to check in — Defcon5 shows a calm, reassuring "all good" screen on YOUR device, for the benefit of whoever may be watching you. Behind that screen, the real system state is Defcon 2 or worse, and your linked guardians see this real state, not the decoy, in their own app. This is intentional safety design, disclosed here so you understand exactly what each code does before you rely on it.

7. Security

8. Minors And Parent Mode

Defcon5 includes a "Parent Mode" allowing a parent or guardian to set up and manage the app for a minor.

Under French law (implementing GDPR Article 8), a minor may consent to information-society services on their own behalf starting at age 15. Below age 15, processing is only lawful with the joint consent of the minor and the holder of parental authority. If you are setting up Defcon5 for a child under 15, you as the parent/guardian must provide this consent, and Parent Mode is built around that requirement — you set the parent PIN during setup, and the child cannot remove a confirmed guardian without it.

[YOUR LAWYER SHOULD STILL REVIEW: whether the current Parent Mode setup flow adequately captures and records this consent in a way that would satisfy a CNIL audit, and whether a Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 given the combination of location data, safety-critical data, and children's data at scale — this is a genuine, fact-specific judgment call, not something a template can safely resolve.]

9. Your Rights (Gdpr)

As a resident of the EU/EEA (and as a matter of policy, for all our users regardless of location), you have the right to:

To exercise any of these rights, contact us at contact@unicorn-united.com.

10. Changes To This Policy

We may update this policy from time to time. Material changes will be notified in-app and via the "Last updated" date above; where required by law, we will seek renewed consent before continuing to process data under materially changed terms.

11. Contact

Unicorn United 6 rue d'Armaillé, 75017 Paris, France contact@unicorn-united.com

Open items for your lawyer before launch

  1. Parent Mode / minors — confirm whether the current consent-capture flow (parent sets a PIN during setup) is legally sufficient under CNIL guidance for verifiable parental consent, or whether additional steps (e.g., a documented consent record, identity verification) are needed.
  2. Confirm whether a Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 — likely given the combination of location data, safety-critical/potentially special-category-adjacent data, and children's data at scale.
  3. Confirm whether Unicorn United needs to appoint a Data Protection Officer (DPO) under GDPR Article 37 (mandatory if core activities involve large-scale, regular and systematic monitoring, or large-scale processing of special categories of data — assess based on actual user volume).
  4. If you expect users outside the EU/EEA (e.g., US, UK, Canada), confirm which additional regimes apply (CCPA/CPRA for California residents, UK GDPR, PIPEDA for Canada) and add corresponding sections.
  5. Confirm the exact CNIL registration/formality requirements applicable to Unicorn United's processing (prior authorization is rarely required post-GDPR, but confirm no sector-specific exception applies).
  6. Consider whether the 48-hour retention window and view-only trail feature need additional disclosure or consent flows beyond what's drafted here, particularly given the domestic-safety use case this app is designed for.
  7. Confirm HTTPS/TLS is actually configured on your production backend before relying on Section 7's statement (it should be, if you've completed the nginx+certbot setup — verify).