Defcon5 — Privacy Policy
Defcon5 — Privacy Policy
Last updated: September 10, 2026 Operated by: Unicorn United, 6 rue d'Armaillé, 75017 Paris, France Contact: contact@unicorn-united.com
⚠️ This policy has been drafted with real, specific facts filled in where the law is well-established (France is an EU member state, so GDPR applies in full). It is still not a substitute for review by a lawyer before launch — see "Open items for your lawyer" at the end for what genuinely still needs one.
Summary (plain language — see full text below)
- We store a username, a hashed (never plaintext) passcode and under-pressure code, and a share code — no name, email, or phone number is required to create an account.
- Nobody can become your guardian by simply having your share code — you must first invite them by username, and they must then confirm using that code as proof. Removing a CONFIRMED guardian isn't instant — see Section 4.
- Your live location is only ever collected while you are in an active alert (Defcon 3, 2, or 1) and only if you turned location on.
- That location trail is visible only to guardians you've confirmed.
- The trail is kept for up to 48 hours after an alert ends, then permanently deleted from our servers.
- Guardians can VIEW that trail (map + timestamps) in their own app, on screen — there is no download or export button, deliberately, so no permanent structured copy leaves our systems.
- We do not sell your data, run ads, or share your data with any third party other than your own chosen guardians.
- You can delete your account and all associated data at any time.
- As an EU-based company, we are subject to GDPR — you have the rights described in Section 9, and can complain to the CNIL (France's data protection authority) at any time.
1. Who Operates Defcon5
This policy covers the Defcon5 mobile application and its backend service, operated by Unicorn United, 6 rue d'Armaillé, 75017 Paris, France. As a company established in France, Unicorn United is subject to the EU General Data Protection Regulation (GDPR) and French data protection law (Loi Informatique et Libertés) for all processing described in this policy, regardless of where a user is located.
If you are a parent or guardian setting this up for a minor under "Parent Mode," see Section 8.
2. What We Collect
2.1 Account data (kept until you delete your account)
- A username you choose (does not need to be your real name)
- A cryptographically salted hash of your passcode and your under-pressure ("duress") code — we cannot see or recover the original codes ourselves; only comparison hashes are stored
- A randomly generated "share code" you give to people you want as guardians
- A device authentication token, used only to prove requests come from your own device
2.2 Status data (kept while your account is armed, or as configured)
- Your current Defcon level (how urgently you need to check in)
- Timestamps of your check-ins and the next check-in deadline
- Whether you are in "duress" mode (see Section 6 — this reflects your REAL state, shown to guardians, even while your own device may be intentionally showing a calm decoy screen to whoever is standing near you)
2.3 Location data (the most sensitive category — read this carefully)
- Collected ONLY while you are at an alert level (Defcon 3, 2, or 1) AND you have enabled location sharing in the app
- NOT collected during normal, safe use of the app
- Retained for up to 48 hours after the alert that generated it ends, then permanently deleted from our servers — see Section 5
- Visible only to guardians you have explicitly confirmed
2.4 What we do NOT collect
- No email address or phone number is required
- No contact list, camera roll, browsing history, or unrelated device data
- No advertising identifiers, no third-party analytics or ad trackers
3. How We Use Your Data
- To run the check-in and escalation logic (deciding whether you've checked in on time)
- To let your linked guardians see your current status and, during an active or recently-ended alert, your location trail
- To automatically stand you down if a session is abandoned (see Section 5)
We do not use your data for advertising, profiling, or any purpose other than operating the safety features described here. This is also our GDPR "purpose limitation" commitment: data collected for the safety service is not repurposed for anything else.
Legal basis under GDPR (Article 6): processing your account and status data is necessary for the performance of a contract with you (providing the service you signed up for). Processing your location data during an alert is based on your explicit consent, given when you enable location sharing — you can withdraw it at any time by disabling location in the app, which stops future collection immediately.
4. Who We Share Your Data With
- Your guardians: only accounts YOU have named and invited by username, who have then confirmed using your share code as proof. Nobody can add themselves as your guardian, even with your share code — an invite naming them, from your own account, must come first. You can see every guardian you've invited (confirmed or still pending) on your own "My Guardians" screen.
- Removing a guardian who has already confirmed is deliberately NOT instant: it starts a 24-hour grace period during which the guardian keeps their access and is shown a notice that removal is pending, and you can cancel the removal at any time before it takes effect. This exists specifically so that a coerced or impulsive removal — cutting off the one person who might notice something is wrong — isn't silent or irreversible. In Parent Mode, removing a confirmed guardian additionally requires the parent PIN.
- Nobody else. We do not sell data, run ads, or use third-party email, SMS, or analytics providers — alerts are delivered entirely by guardians' own devices checking your status directly, and we do not transfer your data outside the European Economic Area.
- We may disclose data if legally compelled to do so by a French or EU judicial or law-enforcement authority acting under a valid legal basis (e.g., a réquisition judiciaire or court order). Where legally permitted, we will attempt to notify the affected user before complying, unless doing so is prohibited by law.
5. How Long We Keep Data
- Account data (username, hashed codes, share code): kept until you delete your account.
- Guardian links: kept until either party removes the link (subject to the grace period in Section 4) or deletes their account.
- Location trail: automatically and permanently deleted 48 hours after the alert that generated it ends. If you never enter an alert state, no location data is ever generated in the first place.
- Abandoned sessions: if an armed session receives no check-in for an extended period (24 hours in normal mode), it is automatically disarmed as a safeguard, and no location trail is retained beyond the window above regardless.
5.1 Viewing (not exporting) the trail — and why there's no download button
While your location trail is available (during an alert or within the 48-hour window after it ends), guardians can view it — a map and a timestamped list — directly in their own app. There is deliberately NO download or export button. This was a specific design decision:
- A one-click export would create a permanent, structured copy on a guardian's own device, completely outside our systems and our control, the moment it's downloaded.
- We can't delete, recall, or track a file that's already left our systems — including in a situation where guardian access itself was obtained through coercion or deception.
- Keeping the trail view-only, with a visible, exact erasure date and time, preserves the value of the feature (a guardian can see and act on it in real time; in a genuine emergency, French authorities can request direct server-side access via legal process during the retention window) without creating an uncontrolled, permanent copy as a side effect.
- A screenshot is still technically possible — we can't prevent that on any screen, on any app — but it requires a deliberate, manual action each time, rather than one click that hands over the entire trail as clean, structured data.
6. The Decoy / "Under-Pressure" Feature
If you enter your under-pressure code (instead of your normal passcode) — for example, because someone is forcing you to check in — Defcon5 shows a calm, reassuring "all good" screen on YOUR device, for the benefit of whoever may be watching you. Behind that screen, the real system state is Defcon 2 or worse, and your linked guardians see this real state, not the decoy, in their own app. This is intentional safety design, disclosed here so you understand exactly what each code does before you rely on it.
7. Security
- Passcodes and duress codes are never stored in plaintext — only salted cryptographic hashes.
- All communication between the app and our servers occurs over HTTPS/TLS.
- Database access is restricted to the application server; no third-party analytics or tracking scripts are embedded in the app.
- No system is perfectly secure; we cannot guarantee absolute security of any data. If we become aware of a data breach affecting your personal data, we will notify the CNIL within 72 hours as required by GDPR Article 33, and notify affected users without undue delay where the breach is likely to result in a high risk to their rights, per Article 34.
8. Minors And Parent Mode
Defcon5 includes a "Parent Mode" allowing a parent or guardian to set up and manage the app for a minor.
Under French law (implementing GDPR Article 8), a minor may consent to information-society services on their own behalf starting at age 15. Below age 15, processing is only lawful with the joint consent of the minor and the holder of parental authority. If you are setting up Defcon5 for a child under 15, you as the parent/guardian must provide this consent, and Parent Mode is built around that requirement — you set the parent PIN during setup, and the child cannot remove a confirmed guardian without it.
[YOUR LAWYER SHOULD STILL REVIEW: whether the current Parent Mode setup flow adequately captures and records this consent in a way that would satisfy a CNIL audit, and whether a Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 given the combination of location data, safety-critical data, and children's data at scale — this is a genuine, fact-specific judgment call, not something a template can safely resolve.]
9. Your Rights (Gdpr)
As a resident of the EU/EEA (and as a matter of policy, for all our users regardless of location), you have the right to:
- Access the personal data we hold about you (Article 15)
- Correct inaccurate data (Article 16)
- Request erasure of your data (Article 17) — in practice, deleting your account achieves this immediately for account and status data, and any location trail is erased per the schedule in Section 5 regardless
- Restrict or object to certain processing (Articles 18, 21)
- Receive your data in a portable format (Article 20)
- Withdraw consent at any time where processing is based on consent (e.g., disabling location sharing), without affecting the lawfulness of processing before withdrawal
- Lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés), France's supervisory authority, at www.cnil.fr, or with the supervisory authority in your own EU/EEA country of residence
To exercise any of these rights, contact us at contact@unicorn-united.com.
10. Changes To This Policy
We may update this policy from time to time. Material changes will be notified in-app and via the "Last updated" date above; where required by law, we will seek renewed consent before continuing to process data under materially changed terms.
11. Contact
Unicorn United 6 rue d'Armaillé, 75017 Paris, France contact@unicorn-united.com
Open items for your lawyer before launch
- Parent Mode / minors — confirm whether the current consent-capture flow (parent sets a PIN during setup) is legally sufficient under CNIL guidance for verifiable parental consent, or whether additional steps (e.g., a documented consent record, identity verification) are needed.
- Confirm whether a Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 — likely given the combination of location data, safety-critical/potentially special-category-adjacent data, and children's data at scale.
- Confirm whether Unicorn United needs to appoint a Data Protection Officer (DPO) under GDPR Article 37 (mandatory if core activities involve large-scale, regular and systematic monitoring, or large-scale processing of special categories of data — assess based on actual user volume).
- If you expect users outside the EU/EEA (e.g., US, UK, Canada), confirm which additional regimes apply (CCPA/CPRA for California residents, UK GDPR, PIPEDA for Canada) and add corresponding sections.
- Confirm the exact CNIL registration/formality requirements applicable to Unicorn United's processing (prior authorization is rarely required post-GDPR, but confirm no sector-specific exception applies).
- Consider whether the 48-hour retention window and view-only trail feature need additional disclosure or consent flows beyond what's drafted here, particularly given the domestic-safety use case this app is designed for.
- Confirm HTTPS/TLS is actually configured on your production backend before relying on Section 7's statement (it should be, if you've completed the nginx+certbot setup — verify).