Privacy Policy

Last Updated: August 23, 2026

Homebound LLC, a Utah limited liability company ("we," "us," or "our"), operates the Homebound mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.

This notice describes our practices. It is not a contract, and using the App is not by itself how you consent to anything. Where we rely on your consent — for example, live location sharing — we ask for it separately and you can withdraw it (see Sections 2 and 9).


1. Information We Collect

1.1 Account Information

When you create an account, we collect:

About the age range from Apple. When you finish setting up your profile, the App asks iOS whether it can share an age range for your Apple Account — for example "13–15" or "18 and over". This uses Apple's Declared Age Range feature, and for accounts set up as a child in Family Sharing the range is the one a parent provided.

1.2 Trip & Safety Plan Data

When you create a trip or safety plan, we collect:

Check-ins: When you check in during a trip, we record the time and, if available, your coordinates at check-in.

Check-in photos: You can optionally attach a photo when you check in (or choose one taken during the trip), with an optional short caption. Like profile photos, every check-in photo is re-encoded on our servers before storage and all embedded metadata — including any GPS location saved in the photo file by your camera — is removed. Check-in photos are visible to you, the trip's participants, and your safety contacts on the trip's tracking page while it is active (and briefly after); if you publish the completed trip to the Activity Feed, they are also visible to your friends. Check-in photos are never shown to people outside your friends, even if the trip itself is published with global visibility. You can delete any photo you added at any time, and the trip owner can remove any photo from their trip.

SOS: If you trigger an SOS during an active trip, we collect the time it was triggered, your location coordinates at that moment, and any optional message you include (up to 500 characters).

Group Trips: When you create or join a group trip, we also collect participant lists, roles, invitation timestamps, group checkout settings, each participant's check-in status, each participant's location-sharing choices, and—if individual finish ("I'm home") is enabled—each participant's arrival status.

Quick Trips: If you use the Quick Trips feature, we store your preset configurations (name, activity type, default location, duration, grace period, and selected contacts) locally on your device only. Quick Trip presets are not uploaded to our servers. If you start a Quick Trip using Siri or Apple Shortcuts, the trip is created the same way as one started in the App; your Siri interactions are handled by Apple on your device under Apple's privacy terms.

1.3 Emergency Contact Information

You may add emergency contacts to your account:

You can also add friends (other Homebound users) as safety contacts for your trips; friends receive push notifications instead of emails.

Note: We only store the information you provide. We do not access your device's contact list, and we do not collect phone numbers for your contacts.

1.4 Location Data

Location is the most sensitive data we handle. We collect it only as described below.

Trip Locations: We collect location data when you set a trip's starting location or destination using the map, use your current location for a trip, or check in during a trip. Your check-in events may include the coordinates where you checked in.

Trip Live Location Sharing (Optional): If you enable Live Location Sharing for a trip, we collect real-time location data—including coordinates, altitude, accuracy, speed, and timestamps—while the trip is active, forming a temporary location trail used for safety. This trail is shared only with the safety contacts on that trip (subject to your friend-sharing settings) and is used to help locate you if you become overdue.

Trip Live Location Sharing is:

Circles & On-Demand Location Sharing (Optional): Separately from trips, you can create named "Circles" of your friends (for example, "Family" or "Climbing crew") and choose to share your current location with a Circle. This feature works like a live map of the people you've chosen:

Background Location & Permissions: Some safety features only work if your device can report your location while the App is closed or in your pocket. To support them the App may request "Always" location access. Here is exactly when background location is used, and what for.

The App uses background location only while one of the following is true:

To do this, the App relies on features your device provides: significant-location-change monitoring, visit monitoring, a boundary around your trip's destination, and the silent background notification described above. Your device may briefly wake the App to deliver one of these events. If no trip or Circle share is active when that happens, the App has nothing to send, sends nothing, and turns the background monitoring off.

Outside those windows we do not request, receive, or store your location in the background. When none of the conditions above apply, background location monitoring is switched off entirely.

About your device's "used your location in the background" notice: iOS periodically shows a summary such as "Homebound has used your location N times in the background." That count comes from your device and includes every wake-up where your device handed the App a location — including wake-ups where the App sent nothing to us. If you see this notice while you have no active trip and no active Circle share, you can choose "Change to Only While Using" at any time, and we would be glad to hear about it at the address in Section 10.

You can also use the App with "While Using the App" (foreground-only) access, in which case live and Circle sharing update only while the App is open. Whenever the App is using your location in the background, iOS displays its own location indicator. You can change or revoke location permissions at any time in your device's Settings.

Place Search (Discover): When you use the Discover feature to find nearby places for your activities, your approximate location coordinates are sent to third-party place-search and weather providers (see Section 3.3) to return relevant results. These queries contain location coordinates only—no name, email, or account identifier—and the results are not stored against your account.

Location Access Logging: When another user (such as a group-trip participant) views your location in the App, we log that access (who viewed, what was viewed, and when) so we can maintain an audit trail and protect against misuse. These logs are kept for 90 days and then deleted (see Section 5).

Precise Location Is Sensitive. We treat precise geolocation as sensitive information, and several privacy laws classify it that way — including the California Consumer Privacy Act (as amended by the CPRA), which treats precise geolocation as "sensitive personal information," and the Washington My Health My Data Act, which can treat location information as consumer health data. We use your precise location only to deliver the safety features you have asked for, and for the sharing you have chosen. We do not use it to infer characteristics about you, and we do not use it for advertising, profiling, or any purpose that would require an opportunity to limit its use. See Sections 6.7 and 6.8.

What We Do NOT Do:

1.5 Device Information

To send push notifications and Live Activities, we collect:

Our servers may also send silent background notifications to your device—for example, to request a single current location while you are sharing with a Circle (see Section 1.4), or to ask the App to sync pending safety actions when your connectivity returns.

If you use the Homebound Apple Watch companion, your active trip data is mirrored between your iPhone and your watch; this does not create a new category of data on our servers.

1.6 Automatically Collected Information

When you use the App, we automatically collect:

First-Party Usage Analytics: To understand where new users get stuck and improve the App, we collect basic usage events (such as app opens, onboarding steps, and feature usage), along with your app version and platform. This is done entirely with our own systems—we do not use any third-party analytics or advertising SDKs. Before you sign in, these events are linked only to a random anonymous identifier stored on your device; once you create an account or sign in, subsequent events are associated with your account. If you delete your account, analytics events are detached from it and retained only in de-identified form.

1.7 Subscription Information

If you subscribe to Homebound+, we collect App Store transaction identifiers, the product purchased, purchase and expiration dates, subscription status, auto-renewal status, free-trial status, any promotional or offer codes used, and family-sharing status. This information is processed through Apple's App Store.

1.8 Social & Friend Data

If you use social features, we collect friend connections, friend requests, invite links, Circles and Circle membership, visibility preferences, and achievements visible to friends.

1.9 Activity Feed Data

When you or your friends complete trips, we collect and may share (based on privacy settings):

Activity Feed Privacy Controls:

If your account tells us you are under 18, the first two of these are capped for you — friends-only, and generalized location. See Section 7.

1.10 Comments and Reactions

When you comment on or react to trips and check-ins in the Activity Feed:

1.11 Referral Program

If you participate in the referral program, we collect referral relationships (which account was referred by which invite), invite acceptance timestamps, qualifying-trip status, and the Homebound+ credit granted to each side, including running totals used to apply the program's earning caps.

1.12 Feedback

If you choose to submit feedback, feature requests, or bug reports through our in-app feedback link, that content—and any contact details you include—is handled by our feedback provider (see Section 3.3). Submitting feedback is entirely optional.

1.13 Reports and Blocks

If you use our moderation tools:


2. How We Use Your Information

We use the information we collect to:

For EU/EEA/UK/Swiss Users: We process your data under the following legal bases:

We do not rely on "vital interests" as a legal basis. Everything safety-related that we do is either performance of the contract you entered into with us or a legitimate interest, both of which are available to us and are the appropriate bases.


3. Information Sharing

3.1 Emergency Contacts

When you add emergency contacts to a trip, they will receive emails about trip creation, trip start, check-in updates, ETA extensions, trip completion, overdue alerts, and SOS alerts.

Some of these emails include your location:

How the tracking link is protected. Because the link works without a login, we limit it in the following ways:

Even so, treat the link as sensitive: while a trip is live, anyone your contact forwards it to can see it. If you think a link has reached the wrong person, revoke it as described above, and tell us at privacy@homeboundapp.com if you would like us to look into it.

If you enable Trip Live Location Sharing, your designated safety contacts who are Homebound users can also view your real-time position in the App. If you share with a Circle, the friends in that Circle can view your current location on a map while your share is active.

3.2 Activity Feed Sharing

When you complete a trip with Activity Feed sharing enabled:

3.3 Third-Party Service Providers

Service Purpose Data Shared
Render.com Application hosting — our servers run here, so all App data passes through and is processed on Render infrastructure All data you send to or receive from the App
Resend Email delivery to you and your contacts Email addresses, names, trip details, and—where applicable—your check-in or SOS location
Apple Push Notification service Push notifications and Live Activities Device tokens, notification content
Apple — Sign in with Apple Authentication (optional) Apple user identifier
Apple — Declared Age Range Confirming which side of ages 13, 16, and 18 you fall on, so the right minimum age and under-18 protections apply (Section 1.1) Nothing about you is sent to Apple; iOS returns a range to the App only if you allow it
Apple — App Store & App Store Server API Process and verify Homebound+ subscriptions Transaction identifiers, product identifiers, subscription status
Apple — Maps (MapKit) Display maps and search for places Map search text and device location
Supabase Database hosting, real-time updates, and profile-photo storage App data you create; profile photos; real-time updates delivered to the App
Cloudflare Network security/delivery for the App's connections, and storage and delivery of check-in photos (Cloudflare R2) Traffic between the App and our servers; check-in photos (metadata-stripped)
Tomorrow.io Weather conditions Location coordinates only (no user identifiers)
OpenStreetMap / Nominatim Convert coordinates to place names (reverse geocoding) Location coordinates only (no user identifiers)
Place-search providers (Discover feature): OpenStreetMap/Overpass, Geoapify, Recreation.gov, U.S. National Park Service, U.S. Geological Survey, U.S. Forest Service, U.S. Bureau of Land Management, and OpenBeta Find nearby places for your activities Approximate search coordinates only (no user identifiers)
Ticketmaster Find nearby concerts and events for the Discover "Concert" activity Search coordinates only (no user identifiers)
Canny Feedback and feature requests (only if you choose to submit them) The content and any contact details you submit

If an emergency contact opens a map link contained in a location or SOS email, that link will open in their device's map service (such as Apple Maps or Google Maps). We do not control those services or what they do with the link.

3.4 What We Do NOT Do

3.5 Legal Requirements

We may disclose your information if required by law, such as in response to a subpoena or court order, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

3.6 Business Transfers

If Homebound LLC is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its assets, your information may be transferred as part of that transaction, or disclosed under confidentiality obligations during diligence for one.

This is not a sale of your personal information, and it does not change the commitments in this policy:

3.7 Aggregated and De-Identified Information

We may create and use aggregated or de-identified information (for example, "how many trips were completed last month") that cannot reasonably be used to identify you. We will not attempt to re-identify it, and we will require anyone we share it with to do the same.


4. Data Security

We implement appropriate security measures to protect your information:

While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

If There Is a Security Incident

If we discover a breach of security affecting your personal information, we will:

Because location data is among the most sensitive information we hold, we will treat any incident involving location data as high-risk by default.


5. Data Retention

Data Type Retention Period
Account Data (including your age and the age range from Apple) Until you delete your account
Profile Photo Until you remove it or delete your account
Check-In Photos Until you delete the photo, the trip, or your account (the trip owner can also remove a photo from their trip)
Trip Data Until you delete the trip or your account
Location Data (trip) Until trip completion or account deletion
Trip Live Location Trail Deleted approximately 24 hours after the trip is completed, and in all cases within 7 days of collection
Circle / Current Location Most recent location only; automatically deleted approximately 24 hours after your last update or when you stop sharing
Location Shares Until they expire (a duration you choose, up to 1 week) or you end them; the record of an ended or expired share is purged about 24 hours later
Location Wake Markers Approximately 1 hour (short-lived technical markers used to avoid waking your device repeatedly)
SOS Data Until trip or account deletion
Login Tokens Automatically expire shortly after issuance
Device Tokens Until unregistered, or after 30 days of inactivity, or on account deletion
Live Activity Tokens Deleted after 30 days without an update, or on account deletion
Notification Logs 30 days
Location-Access Logs (who viewed your location) 90 days
Trip Tracking Pages (/t/{token}) Reachable while the trip is planned, active, or overdue, and for 48 hours after completion; immediately unreachable if the trip is cancelled
Data Export Files The download expires 7 days after the export is prepared
Activity Feed Comments Until deleted by author or account deletion
Activity Feed Reactions Until removed or account deletion
Content Reports Retained (with a snapshot of the reported content) after the content is removed; deleted when the reporting or reported account is deleted
Blocked Users Until you unblock the user or account deletion
Weather Data Stored with trip until trip or account deletion
Place-Search Results (Discover) Cached briefly by geographic area; not linked to your account
Quick Trip Presets Stored locally on your device only
Referral Records Until account deletion
Usage Analytics Events Detached from your account on deletion; retained in de-identified form

Account Deletion

You can delete your account at any time through Settings > Account > Delete Account. When you request deletion:

Deletions that do not wait for the grace period. The 30-day grace period exists to protect you from losing your own account by mistake. It does not apply where a delay would be inappropriate. We delete without the grace period, as soon as we have verified the request, when:

Note: You must cancel any active Homebound+ subscription separately through the App Store.

Local Data

To work reliably and support offline use, the App keeps a cache on your device. This may include your trips, emergency contacts, friends and group participants (including the last location a participant has chosen to share), saved locations, Quick Trip presets, weather, and actions or location updates waiting to sync, as well as records of pending in-app purchases. Saved locations and Quick Trip presets are stored on your device only and are not uploaded to our servers.

You can clear cached data via Settings > Resources > Clear Cache, and signing out clears locally stored data. Saved locations and Quick Trip presets can be managed in their respective settings screens.


6. Your Privacy Rights

6.1 All Users

Regardless of your location, you can:

Exporting your data. Settings > Privacy > Export Data produces a machine-readable JSON file containing everything we store about you. It is available to everyone, wherever you live, at no charge, and it includes:

The file opens with a summary listing how many records of each kind it contains, so you can see at a glance what is in it.

Two things are deliberately left out. Security tokens — the links in your contacts' emails, your device's push token, and sign-in tokens — are excluded, because they are credentials rather than information about you, and a copy of them in a file you might forward would be a risk to you. Other people's personal information is excluded too: you will see a friend's name, because a friendship record makes no sense without it, but not the identity of someone you reported or a copy of the content they wrote. Achievements and trip statistics are calculated from the trips already in the file rather than stored separately.

If anything looks missing or wrong, email privacy@homeboundapp.com and we will deal with it on the timelines in Section 6.9.

6.2 European Union, EEA, UK, and Swiss Residents

If you are in the EU, EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:

To exercise any of these rights, contact us at privacy@homeboundapp.com. See Section 6.9 for how we verify and handle requests and how long we take.

6.3 California Residents

If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the CPRA:

Categories of personal information collected in the last 12 months (using CCPA categories): identifiers (name, email, Apple ID identifier, device and install identifiers); commercial information (subscription and referral records); internet or network activity (first-party usage events, app version); precise geolocation; audio/visual information (profile photos and check-in photos); and inferences drawn only for your own trip statistics. We collect these from you, from your device, and from Apple (subscription status). We disclose them for business purposes to the service providers in Section 3.3 and to the recipients you choose. We do not sell or share any category.

Shine the Light (Cal. Civ. Code § 1798.83): We do not disclose personal information to third parties for their own direct marketing purposes.

6.3.1 Do Not Track and Global Privacy Control

Homebound is a mobile app with no advertising, no third-party analytics, and no cross-site tracking, so there is nothing for a browser-based tracking signal to turn off.

If we ever begin selling or sharing personal information, we will update this section, honor GPC as a valid opt-out request, and provide the required opt-out link before doing so.

To exercise your rights, contact us at privacy@homeboundapp.com. See Section 6.9 for how we handle requests.

6.4 Canadian Residents

If you are in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):

To exercise your rights, contact us at privacy@homeboundapp.com.

If you are in Quebec, Law 25 (the Act to modernize legislative provisions as regards the protection of personal information) gives you more:

6.4.1 Our Privacy Officer

The person responsible for the protection of personal information at Homebound LLC is the Founder, who can be reached at privacy@homeboundapp.com or at the postal address in Section 10. Quebec's Law 25 requires us to publish this; we do it here for everyone, not only Quebec residents.

6.5 Australian Residents

If you are in Australia, you have rights under the Privacy Act 1988:

To exercise your rights, contact us at privacy@homeboundapp.com.

6.6 New Zealand Residents

If you are in New Zealand, you have rights under the Privacy Act 2020:

To exercise your rights, contact us at privacy@homeboundapp.com.

6.7 Other U.S. State Privacy Rights

If you are a resident of a U.S. state with a comprehensive consumer privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island, and others as they take effect — you have the following rights, regardless of which of those states you live in. Where your state's law grants you less than this, we still apply the list below.

Your Right to Appeal. If we deny your privacy request, in whole or in part, we will tell you why. You may appeal that decision by replying to our response, or by emailing privacy@homeboundapp.com with "Privacy Appeal" in the subject line, within a reasonable time after you receive our decision.

We will review the appeal and give you a written answer, including the reasons, within 45 days of receiving it (or within 60 days where your state's law allows an extension, in which case we will tell you). If we deny your appeal, we will give you a way to contact your state Attorney General to submit a complaint. This right applies to every U.S. resident who asks for it, whether or not their state law requires it.

6.8 Washington and Nevada — Consumer Health Data

Washington's My Health My Data Act and Nevada's SB 370 define "consumer health data" broadly, and both can treat precise location information as consumer health data in some circumstances.

We publish a separate Consumer Health Data Privacy Policy covering the disclosures those laws require — the categories we collect and why, our sources, what is shared and with whom, the complete list of third parties and affiliates, our geofencing commitment, and how to exercise your rights. The summary below is the short version; that notice governs.

Homebound is a safety app, not a health app. We do not collect health conditions, diagnoses, treatments, medications, biometric data, reproductive-health information, or gender-affirming-care information, and we do not attempt to infer any of those from your trips.

Even so, because your trip destinations and precise coordinates could in principle reveal something about health, we want to be explicit:

6.9 How We Handle Privacy Requests

Where to send them. privacy@homeboundapp.com, or the postal address in Section 10. Requests made from the email address on your Homebound account are the fastest to verify.

Verification. To protect you, we verify that a request actually comes from you before we act on it. Normally that means confirming that the request comes from — or can be confirmed at — the email address on the account, which is also the credential you use to sign in. For requests seeking specific pieces of sensitive information, or for deletion, we may ask you to confirm details we already hold. We use information you give us for verification only for that purpose, and we do not create new accounts or collect new data in order to verify you. If we cannot verify a request, we will tell you, and we will treat an unverifiable access request as an opt-out request where the law directs us to.

Timing.

Cost. Free. We may charge a reasonable fee, or decline, only for requests that are manifestly unfounded or excessive, particularly repetitive ones — and we will explain why before doing so.

Appeals. See Section 6.7. EU, UK, and Swiss users may also complain to their supervisory authority (Section 6.2); Canadian, Australian, and New Zealand users to the regulators named above.


7. Age Requirements

Homebound has different minimum age requirements based on your region:

Region Minimum Age
European Union, EEA, and Switzerland 16 years old (per GDPR Article 8)
United Kingdom 13 years old (per UK GDPR/Age Appropriate Design Code)
Canada (except Quebec), Australia, New Zealand 13 years old
Quebec 14 years old, or 13 with the consent of a parent or guardian (Quebec's Law 25 requires parental consent below 14)
United States and other regions 13 years old

Homebound is no longer offered in the European Union, the EEA, Switzerland, or the United Kingdom. As of 27 July 2026 the App was removed from those App Store storefronts, and new accounts cannot be created from those regions. The thresholds above are retained because a small number of accounts created before that date remain active, and everything in this document — including the rights in Section 6.2 — continues to apply to them for as long as they use Homebound.

How we determine your region — and its limits. We use your App Store storefront country as a starting point, because it is the signal available to the App. A storefront is not the same thing as where you live, and the law that protects you depends on where you are, not where your Apple account is registered. So:

How we know your age. Two ways, and the more protective one wins. You enter an age when you set up your profile, and — if you allow it — iOS also tells us the age range Apple holds for your Apple Account, which for a child account is the one a parent set (Section 1.1). If those two disagree in a way that matters, we apply whichever indicates you are younger.

Users below the minimum age. We do not knowingly collect personal information from users who do not meet the minimum age requirement for their region. If we learn that an account belongs to someone below that age, we delete it and the associated data without waiting for the 30-day grace period (Section 5).

Parents and guardians. If you are a parent or guardian and believe your child has provided us with personal information, email privacy@homeboundapp.com. We will:

We will not require you to create a Homebound account, or to provide more information than we need to verify the request, in order to do this.

Extra protections for users under 18. Homebound is a location-sharing app, so accounts that tell us they are under 18 are limited in what they can publish. These limits are enforced on our servers, not just in the App, and they cannot be turned off:

This applies to the per-trip setting, the account-wide default, and trips published automatically at checkout.

What is not restricted, and why. Live location sharing during a trip, and Circle sharing, still work — those go only to the specific safety contacts and friends the user chose, and they are the safety features the App exists to provide. Turning them off for minors would remove the protection a parent most likely wants.

A note for parents. Two things already limit contact from strangers: becoming someone's friend requires both people to exchange an invite link (there is no way to search for a user or send an unsolicited friend request), and only friends can comment on or react to a trip. If your child uses Homebound, we still encourage you to review Settings > Privacy together, and to talk about who belongs in their Circles. You can ask us to delete their account at any time using the process above.


8. International Data Transfers

Our servers are located in the United States. If you access the App from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.

For EU/EEA/Swiss Users: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection for transfers to the United States.

For UK Users: We rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs for transfers to the United States.

For Canadian Users: We ensure transfers comply with PIPEDA requirements for cross-border data transfers.

For Australian Users: We take reasonable steps to ensure overseas recipients handle your information consistently with Australian Privacy Principles.

For New Zealand Users: We ensure transfers comply with the Privacy Act 2020 requirements.

Sub-Processors

Sub-Processor Purpose Location
Render.com Application hosting United States
Supabase Database hosting, real-time sync, and image storage United States
Cloudflare Network security/delivery and check-in photo storage (R2) United States (global edge network)
Resend Email delivery United States
Apple Inc. Push notifications, Sign in with Apple, subscription processing, and maps United States
Tomorrow.io Weather data United States
OpenStreetMap Foundation Geocoding (location name lookup) and place data United Kingdom / European Union
Geoapify Place search (Discover) European Union
U.S. recreation & mapping data providers (Recreation.gov, U.S. National Park Service, U.S. Geological Survey, U.S. Forest Service, U.S. Bureau of Land Management) Place data (Discover) United States
OpenBeta Climbing-area data (Discover) United States
Ticketmaster Concert/event search (Discover) United States
Canny Feedback portal United States

The providers that process personal information on our behalf — Render, Supabase, Cloudflare, Resend, Apple, and Canny — each handle it under their data processing terms, which require them to protect it in accordance with applicable data protection laws, to act only on our instructions and for the purposes we have specified, and not to use it for their own purposes. Where the law requires a data processing agreement, we have one in place.

The remaining providers in the table above are sent nothing that identifies you: the geocoding, weather, and place-search services receive location coordinates only, with no name, email, or account identifier, and several of them are public or government services that we query without any commercial relationship.


9. Your Consent & Changes to This Privacy Policy

9.1 How We Record Your Consent

This Privacy Policy and our Terms of Service are versioned separately. Each is identified by the "Last Updated" date at the top of that document.

You are asked to accept both documents when you create your account and complete your profile. When you accept, our servers record, against your account, which version of each document you accepted and the date and time you accepted it. The version recorded is the one published on our servers at that moment — it is not supplied by your device.

You can review your consent record — whether consent is on file, and the version accepted, for each document — at any time in Settings > Privacy. It is also included in the data export described in Section 6.

9.2 When We Ask You to Consent Again

We may update this Privacy Policy from time to time. When we do, we update the "Last Updated" date at the top.

If the "Last Updated" date of either this Privacy Policy or our Terms of Service is newer than the version you last accepted, the App shows you a full-screen notice the next time it loads your profile. That notice tells you which document changed, links to both documents, and asks you to agree before you continue using the App. Because the two documents are versioned independently, a change to one is not described as a change to the other: if only the Terms of Service change, the notice says so.

Agreeing records the current version of both documents. If one of them has not changed since you last accepted it, its original acceptance date is kept, so your record continues to reflect when you actually agreed to each version.

This prompt depends only on the versions of these documents. It is independent of your App version, and updating the App does not by itself change your consent record.

9.3 If You Do Not Agree

If you do not wish to accept an updated Privacy Policy or Terms of Service, stop using the App and delete your account through Settings > Account > Delete Account.

You may also withdraw consent for non-essential processing at any time (Section 6) without deleting your account. If you do, your account remains active for the core safety functionality — such as notifying your emergency contacts if you become overdue — because that processing is performance of the contract between us, not something you consented to separately. Withdrawing consent turns off the optional features that rely on it (Trip Live Location Sharing and Circle sharing) and does not affect processing that already happened.

We ask for your agreement through the in-app notice described in Section 9.2. Simply continuing to use the App is not how you accept an updated policy, and we do not treat it as acceptance.


10. Contact Us

Homebound LLC is the controller of the personal information described in this policy.

If you have questions about this Privacy Policy or our privacy practices:

Email: privacy@homeboundapp.com Postal: Homebound LLC, 1518 Lake Front Ct, Park City, UT 84098, United States

The same address handles California privacy rights, other U.S. state privacy rights and appeals (Section 6.7), consumer health data requests (Section 6.8), EU/UK/Swiss GDPR requests (Section 6.2), and requests from non-users (Section 11). You do not need to use a particular form of words — just tell us what you want.


11. Emergency Contacts and Other People Who Are Not Homebound Users

Homebound users can add other people as emergency contacts by entering a name and email address. If someone has added you, we hold your name and email address even though you never signed up. This section is for you.

Where your information came from. A Homebound user entered it. We did not obtain it from you, and we did not buy it from anyone. The email you received tells you who added you.

What we hold. Your name, your email address, the trips you have been designated a contact for, and the delivery records for messages we sent you. Nothing else. We do not have your phone number, we do not read your device contacts, and we do not build a profile of you.

What we do with it. We use it for one purpose: sending you the safety messages the user asked us to send — trip created, trip started, check-in, ETA extended, trip completed, overdue alert, and SOS alert. Some of those messages include the user's location and a link to a page showing their trip. We do not send you marketing, we do not sell your information, and we do not use it for anything else.

Our legal basis (if you are in the EU, EEA, UK, or Switzerland) is our legitimate interest, and the user's, in your being able to act if they do not come back safely. We are the controller for this processing, and this section is our notice to you under Article 14 of the GDPR.

How long we keep it. Until the user deletes you as a contact or deletes their account, or until you ask us to remove you — whichever comes first.

Your rights. You do not have to accept being someone's emergency contact, and you do not need their permission to opt out. You can:

Email privacy@homeboundapp.com and say what you want. We handle these on the timelines in Section 6.9 and we will not ask you to create an account to do it.

If you think someone is misusing this. If a Homebound user is adding you as a contact to harass you, or you believe the App is being used to track or intimidate someone, email privacy@homeboundapp.com and tell us. We will block further messages to you and act on the account under our Terms of Service.


This Privacy Policy is effective as of July 27, 2026.