Privacy Policy
Last Updated: August 23, 2026
Homebound LLC, a Utah limited liability company ("we," "us," or "our"), operates the Homebound mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
This notice describes our practices. It is not a contract, and using the App is not by itself how you consent to anything. Where we rely on your consent — for example, live location sharing — we ask for it separately and you can withdraw it (see Sections 2 and 9).
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address (required for authentication)
- First and last name (for personalization and to share with emergency contacts)
- Age (to verify you meet the minimum age requirement for your region)
- Age range from Apple (see below)
- Profile photo (optional, only if you choose to add one). Photos you upload are re-encoded on our servers before storage, and all embedded metadata—including any GPS location saved in the photo file by your camera—is removed. Your photo is visible to your friends, group-trip participants, and safety contacts in the App, and on invite pages you share.
- Apple ID identifier (if you sign in with Apple)
- Notification preferences (trip reminders, check-in alerts, friend activity notifications)
- Friend visibility settings (controls what friends can see about you, such as your check-in locations, live location, trip notes, achievements, and trip statistics). Your age is never shown to friends — it is used only for the minimum-age and under-18 rules described in Section 7.
- Activity Feed preferences (trip publishing mode, visibility scope, location privacy defaults)
- Privacy and consent records (which version of this Privacy Policy and which version of our Terms of Service you accepted, and the date and time you accepted each, plus your locale and App Store region, used for compliance and to apply the correct minimum-age and regional rules — see Section 9)
- App version (for compatibility and troubleshooting)
About the age range from Apple. When you finish setting up your profile, the App asks iOS whether it can share an age range for your Apple Account — for example "13–15" or "18 and over". This uses Apple's Declared Age Range feature, and for accounts set up as a child in Family Sharing the range is the one a parent provided.
- You choose. iOS shows you the request and you can decline. Declining costs you nothing: the App works exactly the same, and we simply keep the age you typed.
- We receive a range, not a birthday. We never learn your date of birth from this, and we do not ask Apple for it.
- What we store: the range, whether Apple described it as declared by you or by a guardian, and the date we received it.
- What we use it for: one thing only — applying the correct minimum age for your region, and the under-18 protections in Section 7. It plays no part in what you are shown, what you are charged, or anything we send you.
- It can only add protections, never remove them. If Apple's range says you are under 18 but the age you typed says otherwise, we treat you as under 18. It never works the other way round, so nobody can lift the under-18 limits by interfering with this.
- Apple does not learn anything about you from this. The request tells Apple only that an app asked whether you fall above or below the ages 13, 16, and 18.
1.2 Trip & Safety Plan Data
When you create a trip or safety plan, we collect:
- Trip title and activity type
- Start time and estimated time of arrival (ETA)
- Grace period preferences
- Location information (starting location and optional destination)
- Optional notes about your trip
- Optional trip difficulty grade
- Timezone information
- Check-in interval preferences
- Quiet hours settings
- Live location sharing preference
- Custom notification messages (for trip start and overdue alerts)
- Weather conditions at trip start and completion (temperature, feels like, conditions, precipitation probability, wind speed, UV index, humidity)
- Activity feed publishing preferences for the trip (visibility scope, location privacy, participant visibility)
Check-ins: When you check in during a trip, we record the time and, if available, your coordinates at check-in.
Check-in photos: You can optionally attach a photo when you check in (or choose one taken during the trip), with an optional short caption. Like profile photos, every check-in photo is re-encoded on our servers before storage and all embedded metadata — including any GPS location saved in the photo file by your camera — is removed. Check-in photos are visible to you, the trip's participants, and your safety contacts on the trip's tracking page while it is active (and briefly after); if you publish the completed trip to the Activity Feed, they are also visible to your friends. Check-in photos are never shown to people outside your friends, even if the trip itself is published with global visibility. You can delete any photo you added at any time, and the trip owner can remove any photo from their trip.
SOS: If you trigger an SOS during an active trip, we collect the time it was triggered, your location coordinates at that moment, and any optional message you include (up to 500 characters).
Group Trips: When you create or join a group trip, we also collect participant lists, roles, invitation timestamps, group checkout settings, each participant's check-in status, each participant's location-sharing choices, and—if individual finish ("I'm home") is enabled—each participant's arrival status.
Quick Trips: If you use the Quick Trips feature, we store your preset configurations (name, activity type, default location, duration, grace period, and selected contacts) locally on your device only. Quick Trip presets are not uploaded to our servers. If you start a Quick Trip using Siri or Apple Shortcuts, the trip is created the same way as one started in the App; your Siri interactions are handled by Apple on your device under Apple's privacy terms.
1.3 Emergency Contact Information
You may add emergency contacts to your account:
- Contact names
- Contact email addresses
- Optional contact groups for organization
You can also add friends (other Homebound users) as safety contacts for your trips; friends receive push notifications instead of emails.
Note: We only store the information you provide. We do not access your device's contact list, and we do not collect phone numbers for your contacts.
1.4 Location Data
Location is the most sensitive data we handle. We collect it only as described below.
Trip Locations: We collect location data when you set a trip's starting location or destination using the map, use your current location for a trip, or check in during a trip. Your check-in events may include the coordinates where you checked in.
Trip Live Location Sharing (Optional): If you enable Live Location Sharing for a trip, we collect real-time location data—including coordinates, altitude, accuracy, speed, and timestamps—while the trip is active, forming a temporary location trail used for safety. This trail is shared only with the safety contacts on that trip (subject to your friend-sharing settings) and is used to help locate you if you become overdue.
Trip Live Location Sharing is:
- Optional — you must explicitly enable it for a trip
- User-controlled — you can disable it at any time
- Limited sharing — only shared with the safety contacts you choose for that trip
Circles & On-Demand Location Sharing (Optional): Separately from trips, you can create named "Circles" of your friends (for example, "Family" or "Climbing crew") and choose to share your current location with a Circle. This feature works like a live map of the people you've chosen:
- You choose exactly who can see you. Sharing is one-directional—adding a friend to your Circle, or being added to theirs, does not automatically share your location back.
- Time-boxed. Each share lasts for a duration you choose (from 1 hour up to a maximum of 1 week) and then automatically expires. There is no indefinite sharing.
- Current location only, no trail. For Circle sharing we store only your most recent location fix (coordinates, altitude, accuracy, speed, and the time of the update)—not a continuous history.
- On-demand. To save battery, your device generally provides a fresh location only when it moves or when someone in your Circle is actively looking at the map. To support this, our servers may send a silent background notification to your device asking it to upload a single current location.
- Revocable. You can stop sharing, remove a friend from a Circle, or delete a Circle at any time, which immediately ends access. While you are sharing, the App displays a persistent banner so you always know.
Background Location & Permissions: Some safety features only work if your device can report your location while the App is closed or in your pocket. To support them the App may request "Always" location access. Here is exactly when background location is used, and what for.
The App uses background location only while one of the following is true:
- You are on an active trip with Trip Live Location Sharing enabled — so your safety contacts can still see you when your phone is locked or the App is closed. This ends when you check out, when the trip is completed or cancelled, or when you turn sharing off.
- You have an active Circle share — so your current location does not go stale for the people you chose. This ends when the share expires or when you stop it.
- You are on an active trip with a destination set — your device watches for your arrival near that destination so the App can remind you to check out. This is a local reminder on your device; the arrival itself is not reported to us. It ends when the trip ends.
To do this, the App relies on features your device provides: significant-location-change monitoring, visit monitoring, a boundary around your trip's destination, and the silent background notification described above. Your device may briefly wake the App to deliver one of these events. If no trip or Circle share is active when that happens, the App has nothing to send, sends nothing, and turns the background monitoring off.
Outside those windows we do not request, receive, or store your location in the background. When none of the conditions above apply, background location monitoring is switched off entirely.
About your device's "used your location in the background" notice: iOS periodically shows a summary such as "Homebound has used your location N times in the background." That count comes from your device and includes every wake-up where your device handed the App a location — including wake-ups where the App sent nothing to us. If you see this notice while you have no active trip and no active Circle share, you can choose "Change to Only While Using" at any time, and we would be glad to hear about it at the address in Section 10.
You can also use the App with "While Using the App" (foreground-only) access, in which case live and Circle sharing update only while the App is open. Whenever the App is using your location in the background, iOS displays its own location indicator. You can change or revoke location permissions at any time in your device's Settings.
Place Search (Discover): When you use the Discover feature to find nearby places for your activities, your approximate location coordinates are sent to third-party place-search and weather providers (see Section 3.3) to return relevant results. These queries contain location coordinates only—no name, email, or account identifier—and the results are not stored against your account.
Location Access Logging: When another user (such as a group-trip participant) views your location in the App, we log that access (who viewed, what was viewed, and when) so we can maintain an audit trail and protect against misuse. These logs are kept for 90 days and then deleted (see Section 5).
Precise Location Is Sensitive. We treat precise geolocation as sensitive information, and several privacy laws classify it that way — including the California Consumer Privacy Act (as amended by the CPRA), which treats precise geolocation as "sensitive personal information," and the Washington My Health My Data Act, which can treat location information as consumer health data. We use your precise location only to deliver the safety features you have asked for, and for the sharing you have chosen. We do not use it to infer characteristics about you, and we do not use it for advertising, profiling, or any purpose that would require an opportunity to limit its use. See Sections 6.7 and 6.8.
What We Do NOT Do:
- Sell your location data
- Share your location with advertisers or data brokers
- Track, collect, or store your location when you are not on an active trip with live location enabled or actively sharing with a Circle
- Keep background location monitoring running after your trip ends or your Circle share expires
- Access your location without your permission
1.5 Device Information
To send push notifications and Live Activities, we collect:
- Device push notification token
- Device platform (iOS)
- App environment (development or production)
- Live Activity tokens (for lock screen widgets, including when you watch a friend's trip)
- Last activity timestamp
- An app-install identifier (a random identifier for your app installation, used to keep push tokens accurate across reinstalls and token changes)
Our servers may also send silent background notifications to your device—for example, to request a single current location while you are sharing with a Circle (see Section 1.4), or to ask the App to sync pending safety actions when your connectivity returns.
If you use the Homebound Apple Watch companion, your active trip data is mirrored between your iPhone and your watch; this does not create a new category of data on our servers.
1.6 Automatically Collected Information
When you use the App, we automatically collect:
- Timestamps of account creation and last login
- Trip creation and completion timestamps
- Check-in, check-out, and ETA extension events
- SOS events
- Location-access logs (when your location is viewed by others)
- Notification delivery logs (for troubleshooting and to confirm safety alerts were sent)
First-Party Usage Analytics: To understand where new users get stuck and improve the App, we collect basic usage events (such as app opens, onboarding steps, and feature usage), along with your app version and platform. This is done entirely with our own systems—we do not use any third-party analytics or advertising SDKs. Before you sign in, these events are linked only to a random anonymous identifier stored on your device; once you create an account or sign in, subsequent events are associated with your account. If you delete your account, analytics events are detached from it and retained only in de-identified form.
1.7 Subscription Information
If you subscribe to Homebound+, we collect App Store transaction identifiers, the product purchased, purchase and expiration dates, subscription status, auto-renewal status, free-trial status, any promotional or offer codes used, and family-sharing status. This information is processed through Apple's App Store.
1.8 Social & Friend Data
If you use social features, we collect friend connections, friend requests, invite links, Circles and Circle membership, visibility preferences, and achievements visible to friends.
1.9 Activity Feed Data
When you or your friends complete trips, we collect and may share (based on privacy settings):
- Completed trip details: Trip title, activity type, duration, completion timestamp
- Location information: Subject to your location privacy setting (exact location, generalized city/region, or hidden)
- Weather data: Conditions at trip start and end
- Engagement data: Reactions and comments on trips, including the identity of the person reacting or commenting and comment content (max 500 characters); comments may include @mentions of friends, who are notified
- Group trip participant information: Participant names and photos (or count only, based on your visibility setting)
Activity Feed Privacy Controls:
- Publishing Mode: Choose 'auto' (always share completed trips), 'ask' (choose per trip — the default), or 'never' (never share)
- Visibility Scope: Share with 'friends' only or 'global' (all Homebound users)
- Location Privacy: Show exact location, generalize to city/region (default), or hide entirely
- Participant Visibility: For group trips, show all participants or display only "with X others"
If your account tells us you are under 18, the first two of these are capped for you — friends-only, and generalized location. See Section 7.
1.10 Comments and Reactions
When you comment on or react to trips and check-ins in the Activity Feed:
- Comments: We store comment content, your user ID, timestamps, and any @mentions. Comments are visible to the trip owner and others who can view the trip.
- Reactions: We store your reactions (such as emoji) to trips, check-ins, and comments. Reaction counts are visible to others; individual reactions may be visible to the trip owner.
1.11 Referral Program
If you participate in the referral program, we collect referral relationships (which account was referred by which invite), invite acceptance timestamps, qualifying-trip status, and the Homebound+ credit granted to each side, including running totals used to apply the program's earning caps.
1.12 Feedback
If you choose to submit feedback, feature requests, or bug reports through our in-app feedback link, that content—and any contact details you include—is handled by our feedback provider (see Section 3.3). Submitting feedback is entirely optional.
1.13 Reports and Blocks
If you use our moderation tools:
- Reports: When you report a post, comment, or user, we store the report—including the reason you select, any details you add, the account you reported, and a snapshot of the reported content captured at the time—so our moderation team can review and act on it.
- Blocks: When you block a user, we store the block so we can hide that user's content from you and yours from them. You can view and remove blocks in Settings > Privacy > Blocked Users.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service: Create and manage your safety plans, group trips, Circles, and the Discover and Activity Feed features
- Send Safety Notifications: Alert you about trip status, remind you to check in, deliver SOS alerts, and notify your emergency contacts if you're overdue
- Enable Location Sharing: Share your live trip location with your safety contacts and your current location with the Circles you choose
- Authenticate Your Account: Verify your identity via magic link codes or Apple Sign In
- Show You Your Own Trip History: Compute the statistics and safety insights we show you from your own completed trips (for example, totals, streaks, and favorite activities). These are computed for you and shown to you; what your friends can see is controlled by your friend visibility settings.
- Improve the App: Understand how the service is used and make improvements (using first-party analytics only)
- Operate the Referral Program: Attribute referrals and apply Homebound+ credit
- Communicate with You: Send service-related emails (magic link codes, trip notifications)
- Moderate and Protect the Service: Review reports, enforce our Terms, investigate abuse of the location-sharing and SOS features, and keep the service secure
- Comply with Law: Meet our legal obligations and respond to lawful requests (see Section 3.5)
For EU/EEA/UK/Swiss Users: We process your data under the following legal bases:
- Contract Performance (Art. 6(1)(b)): Providing the Homebound safety service you signed up for — including creating trips, running the overdue check, and notifying the emergency contacts you designated. This is the basis for the core safety function, because notifying your contacts if you do not check out is the service you asked us to perform.
- Legitimate Interest (Art. 6(1)(f)): Service security, abuse prevention, content moderation, first-party product analytics, and the location-access audit trail
- Legal Obligation (Art. 6(1)(c)): Retaining consent records and responding to lawful requests
- Consent (Art. 6(1)(a)): Optional features that go beyond the core service — Trip Live Location Sharing and Circle location sharing. You can withdraw consent at any time, and doing so stops that feature going forward.
We do not rely on "vital interests" as a legal basis. Everything safety-related that we do is either performance of the contract you entered into with us or a legitimate interest, both of which are available to us and are the appropriate bases.
3. Information Sharing
3.1 Emergency Contacts
When you add emergency contacts to a trip, they will receive emails about trip creation, trip start, check-in updates, ETA extensions, trip completion, overdue alerts, and SOS alerts.
Some of these emails include your location:
- Check-in emails include the name of your check-in location and your exact coordinates at check-in.
- SOS emails include your exact coordinates and a link to view them on a map.
- Each email also includes a secure tracking link to a web page that shows the trip's status, ETA countdown, your first name, and the trip's timeline and last known location. Anyone who has this link can view that page without logging in, so treat it as sensitive.
How the tracking link is protected. Because the link works without a login, we limit it in the following ways:
- It is unguessable. Each link contains a 256-bit random token. It cannot be found by guessing, enumerating, or crawling.
- It is scoped to one trip. A link reveals only the trip it was issued for. It gives no access to your account, your other trips, your contacts, or your profile beyond your first name.
- It stops working. The page is available while the trip is planned, active, or overdue, and for 48 hours after the trip is completed. After that the link returns "not found." A cancelled trip's link stops working immediately.
- You can revoke it. Open the trip and choose Revoke Shared Links in the Safety Contacts section. Every link in every email already sent for that trip — the tracking page and the one-tap check-in and check-out links — stops working immediately, and new ones are issued. Your contacts are not cut off: their next message about the trip carries the new links, and the trip itself continues normally.
Even so, treat the link as sensitive: while a trip is live, anyone your contact forwards it to can see it. If you think a link has reached the wrong person, revoke it as described above, and tell us at privacy@homeboundapp.com if you would like us to look into it.
If you enable Trip Live Location Sharing, your designated safety contacts who are Homebound users can also view your real-time position in the App. If you share with a Circle, the friends in that Circle can view your current location on a map while your share is active.
3.2 Activity Feed Sharing
When you complete a trip with Activity Feed sharing enabled:
- Friends: Your friends on Homebound can see your completed trip details, subject to your privacy settings
- Global Users: If you choose 'global' visibility, all Homebound users can see your trip
- Engagement: Friends (or all users for global trips) can react to and comment on your trips
- Weather & Duration: Trip weather conditions and duration are visible in the feed
- Location: Your location is shared based on your location privacy setting (exact, generalized, or hidden)
3.3 Third-Party Service Providers
| Service | Purpose | Data Shared |
|---|---|---|
| Render.com | Application hosting — our servers run here, so all App data passes through and is processed on Render infrastructure | All data you send to or receive from the App |
| Resend | Email delivery to you and your contacts | Email addresses, names, trip details, and—where applicable—your check-in or SOS location |
| Apple Push Notification service | Push notifications and Live Activities | Device tokens, notification content |
| Apple — Sign in with Apple | Authentication (optional) | Apple user identifier |
| Apple — Declared Age Range | Confirming which side of ages 13, 16, and 18 you fall on, so the right minimum age and under-18 protections apply (Section 1.1) | Nothing about you is sent to Apple; iOS returns a range to the App only if you allow it |
| Apple — App Store & App Store Server API | Process and verify Homebound+ subscriptions | Transaction identifiers, product identifiers, subscription status |
| Apple — Maps (MapKit) | Display maps and search for places | Map search text and device location |
| Supabase | Database hosting, real-time updates, and profile-photo storage | App data you create; profile photos; real-time updates delivered to the App |
| Cloudflare | Network security/delivery for the App's connections, and storage and delivery of check-in photos (Cloudflare R2) | Traffic between the App and our servers; check-in photos (metadata-stripped) |
| Tomorrow.io | Weather conditions | Location coordinates only (no user identifiers) |
| OpenStreetMap / Nominatim | Convert coordinates to place names (reverse geocoding) | Location coordinates only (no user identifiers) |
| Place-search providers (Discover feature): OpenStreetMap/Overpass, Geoapify, Recreation.gov, U.S. National Park Service, U.S. Geological Survey, U.S. Forest Service, U.S. Bureau of Land Management, and OpenBeta | Find nearby places for your activities | Approximate search coordinates only (no user identifiers) |
| Ticketmaster | Find nearby concerts and events for the Discover "Concert" activity | Search coordinates only (no user identifiers) |
| Canny | Feedback and feature requests (only if you choose to submit them) | The content and any contact details you submit |
If an emergency contact opens a map link contained in a location or SOS email, that link will open in their device's map service (such as Apple Maps or Google Maps). We do not control those services or what they do with the link.
3.4 What We Do NOT Do
- Sell your personal information
- Share your data with advertisers
- Use third-party analytics, advertising SDKs, or tracking services (our usage analytics are first-party only — see Section 1.6)
- Share your information with data brokers
3.5 Legal Requirements
We may disclose your information if required by law, such as in response to a subpoena or court order, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
3.6 Business Transfers
If Homebound LLC is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its assets, your information may be transferred as part of that transaction, or disclosed under confidentiality obligations during diligence for one.
This is not a sale of your personal information, and it does not change the commitments in this policy:
- Any successor will be bound by this Privacy Policy for information transferred to it, unless and until you are given notice of a different policy and, where the law requires it, an opportunity to consent or to object.
- We will notify you in the App or by email before your information becomes subject to a materially different privacy policy.
- Your rights in Section 6 — including deletion — continue to apply, and you can exercise them before or after a transfer.
3.7 Aggregated and De-Identified Information
We may create and use aggregated or de-identified information (for example, "how many trips were completed last month") that cannot reasonably be used to identify you. We will not attempt to re-identify it, and we will require anyone we share it with to do the same.
4. Data Security
We implement appropriate security measures to protect your information:
- Encryption in Transit: All data transmitted between the App and our servers uses HTTPS/TLS encryption
- Secure Authentication: JWT tokens with cryptographic signatures
- Secure Storage: Sensitive data is stored in the iOS Keychain with
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnlyprotection (kept on your device, not synced to iCloud) - Access Controls: Authentication required for all personal data access
- Location Access Logging: We log when your location is viewed by others to maintain an audit trail
- No Passwords Stored: We use magic link authentication, so no passwords are stored
While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
If There Is a Security Incident
If we discover a breach of security affecting your personal information, we will:
- Investigate and contain it promptly, and take reasonable steps to mitigate harm.
- Notify the relevant regulator where the law requires it. For users in the EU/EEA and the UK, that means notifying the competent supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to your rights and freedoms (GDPR/UK GDPR Article 33). For users in Quebec, it means reporting a confidentiality incident presenting a risk of serious injury to the Commission d'accès à l'information and keeping a register of incidents, as Law 25 requires. For users elsewhere in Canada, it means reporting to the Office of the Privacy Commissioner where PIPEDA's real-risk-of-significant-harm threshold is met.
- Notify you directly — by email and, where appropriate, in the App — without undue delay when the breach is likely to result in a high risk to your rights and freedoms (GDPR/UK GDPR Article 34), and in any case as and when required by the breach-notification law of your state or country.
- Tell you what happened, in plain terms: what information was involved, what we have done, and what you can do.
Because location data is among the most sensitive information we hold, we will treat any incident involving location data as high-risk by default.
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Account Data (including your age and the age range from Apple) | Until you delete your account |
| Profile Photo | Until you remove it or delete your account |
| Check-In Photos | Until you delete the photo, the trip, or your account (the trip owner can also remove a photo from their trip) |
| Trip Data | Until you delete the trip or your account |
| Location Data (trip) | Until trip completion or account deletion |
| Trip Live Location Trail | Deleted approximately 24 hours after the trip is completed, and in all cases within 7 days of collection |
| Circle / Current Location | Most recent location only; automatically deleted approximately 24 hours after your last update or when you stop sharing |
| Location Shares | Until they expire (a duration you choose, up to 1 week) or you end them; the record of an ended or expired share is purged about 24 hours later |
| Location Wake Markers | Approximately 1 hour (short-lived technical markers used to avoid waking your device repeatedly) |
| SOS Data | Until trip or account deletion |
| Login Tokens | Automatically expire shortly after issuance |
| Device Tokens | Until unregistered, or after 30 days of inactivity, or on account deletion |
| Live Activity Tokens | Deleted after 30 days without an update, or on account deletion |
| Notification Logs | 30 days |
| Location-Access Logs (who viewed your location) | 90 days |
Trip Tracking Pages (/t/{token}) |
Reachable while the trip is planned, active, or overdue, and for 48 hours after completion; immediately unreachable if the trip is cancelled |
| Data Export Files | The download expires 7 days after the export is prepared |
| Activity Feed Comments | Until deleted by author or account deletion |
| Activity Feed Reactions | Until removed or account deletion |
| Content Reports | Retained (with a snapshot of the reported content) after the content is removed; deleted when the reporting or reported account is deleted |
| Blocked Users | Until you unblock the user or account deletion |
| Weather Data | Stored with trip until trip or account deletion |
| Place-Search Results (Discover) | Cached briefly by geographic area; not linked to your account |
| Quick Trip Presets | Stored locally on your device only |
| Referral Records | Until account deletion |
| Usage Analytics Events | Detached from your account on deletion; retained in de-identified form |
Account Deletion
You can delete your account at any time through Settings > Account > Delete Account. When you request deletion:
- Your account enters a 30-day grace period during which you can cancel the deletion request
- After 30 days, we permanently delete all your data, including your profile, profile photo, check-in photos (yours everywhere, and everyone’s on trips you owned), trips, contacts, devices, friendships, Circles, location history, achievements, referral records, Activity Feed comments and reactions, reports you filed, your blocked-user list, and Quick Trip presets; usage analytics events are detached from your account and retained only in de-identified form
- This deletion is irreversible after the grace period
Deletions that do not wait for the grace period. The 30-day grace period exists to protect you from losing your own account by mistake. It does not apply where a delay would be inappropriate. We delete without the grace period, as soon as we have verified the request, when:
- A parent or guardian asks us to delete the account or data of a child below the minimum age for their region (Section 7);
- We determine that an account belongs to someone below the minimum age for their region; or
- The law requires deletion on a shorter timeline.
Note: You must cancel any active Homebound+ subscription separately through the App Store.
Local Data
To work reliably and support offline use, the App keeps a cache on your device. This may include your trips, emergency contacts, friends and group participants (including the last location a participant has chosen to share), saved locations, Quick Trip presets, weather, and actions or location updates waiting to sync, as well as records of pending in-app purchases. Saved locations and Quick Trip presets are stored on your device only and are not uploaded to our servers.
You can clear cached data via Settings > Resources > Clear Cache, and signing out clears locally stored data. Saved locations and Quick Trip presets can be managed in their respective settings screens.
6. Your Privacy Rights
6.1 All Users
Regardless of your location, you can:
- Access your data through the App
- Update your profile information at any time
- Delete your account and all associated data
- Export your data (see "Exporting your data" below)
- Review your consent record — which version of this Privacy Policy and of our Terms of Service you accepted, and when — in Settings > Privacy
- Opt out of non-essential communications
Exporting your data. Settings > Privacy > Export Data produces a machine-readable JSON file containing everything we store about you. It is available to everyone, wherever you live, at no charge, and it includes:
- your profile, account settings, notification and friend-visibility preferences, and your consent record;
- your trips, with location, weather, feed settings, and per-trip notification settings;
- your check-ins, ETA extensions, and other trip events, and any SOS alerts;
- your emergency contacts, contact groups, and the safety contacts assigned to each trip;
- your friends, Circles and Circle memberships, and location shares;
- your recent live-location trail and your current shared location;
- the log of who viewed your location, and when;
- your devices, subscriptions, referral credits, and pinned activities;
- your Activity Feed comments and reactions, comment reactions, mentions of you, check-in reactions, and group check-out votes;
- reports you have filed, your blocked-user list, your notification history, and your usage-analytics events.
The file opens with a summary listing how many records of each kind it contains, so you can see at a glance what is in it.
Two things are deliberately left out. Security tokens — the links in your contacts' emails, your device's push token, and sign-in tokens — are excluded, because they are credentials rather than information about you, and a copy of them in a file you might forward would be a risk to you. Other people's personal information is excluded too: you will see a friend's name, because a friendship record makes no sense without it, but not the identity of someone you reported or a copy of the content they wrote. Achievements and trip statistics are calculated from the trips already in the file rather than stored separately.
If anything looks missing or wrong, email privacy@homeboundapp.com and we will deal with it on the timelines in Section 6.9.
6.2 European Union, EEA, UK, and Swiss Residents
If you are in the EU, EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:
- Right to Access: Request a copy of your personal data. Use our Export Data feature or contact us.
- Right to Rectification: Request correction of inaccurate data. You can update your profile directly in the App.
- Right to Erasure: Request deletion of your data. Use Delete Account in the App or contact us.
- Right to Restrict Processing: Request that we pause non-essential processing while we address your concerns. Safety-critical notifications (overdue and SOS alerts) continue, because they are performance of the contract you entered into with us — they are the service itself.
- Right to Data Portability: Receive your data in a machine-readable format via our Export feature (Section 6.1), which returns your complete record.
- Right to Object: Object to processing based on legitimate interests by contacting us.
- Right to Withdraw Consent: Withdraw consent at any time through your account settings. This does not affect prior processing.
- Right to Lodge a Complaint: File a complaint with your local data protection authority. Find yours at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
- Rights of People You Add as Contacts: If someone has added you to Homebound as an emergency contact and you are not a Homebound user, you have your own rights — including the right to be told we hold your details, to object, and to have them erased. See Section 11.
To exercise any of these rights, contact us at privacy@homeboundapp.com. See Section 6.9 for how we verify and handle requests and how long we take.
6.3 California Residents
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the CPRA:
- Right to Know / Access: What personal information we collect, the categories of sources, the business purposes, the categories of third parties we disclose it to, and the specific pieces of personal information we hold about you.
- Right to Delete: Request deletion of your personal information, subject to the exceptions the CCPA allows.
- Right to Correct: Request correction of inaccurate personal information. You can correct your name and age directly in the App; for anything else, contact us.
- Right to Opt Out of Sale or Sharing: We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months, including for consumers we know to be under 16. Because we do not sell or share, there is nothing to opt out of and we do not offer a "Do Not Sell or Share My Personal Information" link.
- Right to Limit Use of Sensitive Personal Information: We collect precise geolocation, which the CCPA classifies as sensitive personal information. We use it only to provide the safety features you request and the sharing you choose, and to prevent abuse of those features. We do not use or disclose it to infer characteristics about you or for any other purpose. Because our use falls entirely within the exempt purposes in Cal. Civ. Code § 1798.121(a), the right to limit does not give you anything additional here — but you can still stop the collection at any time by turning off live location sharing, ending Circle shares, or revoking location permission in your device Settings.
- Right to Non-Discrimination: We will not deny you service, charge you a different price, or give you a lower quality of service for exercising any of these rights. Homebound+ pricing has nothing to do with privacy choices.
- Authorized Agents: You may use an authorized agent to submit a request. We will ask for proof of the agent's authority and, for access and deletion requests, for verification directly from you.
Categories of personal information collected in the last 12 months (using CCPA categories): identifiers (name, email, Apple ID identifier, device and install identifiers); commercial information (subscription and referral records); internet or network activity (first-party usage events, app version); precise geolocation; audio/visual information (profile photos and check-in photos); and inferences drawn only for your own trip statistics. We collect these from you, from your device, and from Apple (subscription status). We disclose them for business purposes to the service providers in Section 3.3 and to the recipients you choose. We do not sell or share any category.
Shine the Light (Cal. Civ. Code § 1798.83): We do not disclose personal information to third parties for their own direct marketing purposes.
6.3.1 Do Not Track and Global Privacy Control
Homebound is a mobile app with no advertising, no third-party analytics, and no cross-site tracking, so there is nothing for a browser-based tracking signal to turn off.
- Do Not Track (DNT): Our web pages (our marketing site, the tracking pages, and the dashboard) do not track you across other websites or over time, so we do not respond differently to a DNT header. There is no industry-standard meaning for DNT that would apply to what we do.
- Global Privacy Control (GPC): We do not sell or share personal information, so there is no sale or sharing for a GPC signal to opt you out of. We honor GPC in the sense that we already behave as if every user had sent one.
If we ever begin selling or sharing personal information, we will update this section, honor GPC as a valid opt-out request, and provide the required opt-out link before doing so.
To exercise your rights, contact us at privacy@homeboundapp.com. See Section 6.9 for how we handle requests.
6.4 Canadian Residents
If you are in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):
- Access: Request access to your personal information
- Correction: Request correction of inaccurate information
- Withdrawal of Consent: Withdraw consent to the collection, use, or disclosure of your information (subject to legal restrictions)
To exercise your rights, contact us at privacy@homeboundapp.com.
If you are in Quebec, Law 25 (the Act to modernize legislative provisions as regards the protection of personal information) gives you more:
- Consent for minors. We do not knowingly collect personal information from anyone under 14 in Quebec without the consent of the person having parental authority. See Section 7.
- Privacy by default. Any setting that would make your information public is off unless you turn it on. Trips are not published to the Activity Feed unless you choose to publish them, the default audience is your friends rather than everyone, and location on a published trip is generalized by default.
- De-indexation and portability. You may ask us to stop disseminating your information, to de-index it, and to receive a computerized copy of the information you gave us — the export in Section 6.1 provides the last of these.
- Automated decisions. We do not make decisions about you based solely on automated processing. If that ever changes, we will tell you and you will be able to ask for a human review.
- Complaints. You may complain to the Commission d'accès à l'information du Québec. We also report confidentiality incidents to the Commission where the law requires it (see Section 4).
6.4.1 Our Privacy Officer
The person responsible for the protection of personal information at Homebound LLC is the Founder, who can be reached at privacy@homeboundapp.com or at the postal address in Section 10. Quebec's Law 25 requires us to publish this; we do it here for everyone, not only Quebec residents.
6.5 Australian Residents
If you are in Australia, you have rights under the Privacy Act 1988:
- Access: Request access to your personal information
- Correction: Request correction of inaccurate information
- Complaint: Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
To exercise your rights, contact us at privacy@homeboundapp.com.
6.6 New Zealand Residents
If you are in New Zealand, you have rights under the Privacy Act 2020:
- Access: Request access to your personal information
- Correction: Request correction of inaccurate information
- Complaint: Lodge a complaint with the Office of the Privacy Commissioner
To exercise your rights, contact us at privacy@homeboundapp.com.
6.7 Other U.S. State Privacy Rights
If you are a resident of a U.S. state with a comprehensive consumer privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island, and others as they take effect — you have the following rights, regardless of which of those states you live in. Where your state's law grants you less than this, we still apply the list below.
- Confirm and Access: Confirm whether we process your personal data and obtain a copy of it.
- Correct: Correct inaccuracies in your personal data.
- Delete: Delete personal data we hold about you.
- Portability: Obtain your data in a portable, machine-readable format.
- Opt Out of Targeted Advertising, Sale, and Profiling: We do not engage in targeted advertising, do not sell personal data, and do not use automated profiling to make decisions that produce legal or similarly significant effects. There is nothing here to opt out of.
- Consent for Sensitive Data: Precise geolocation is sensitive data under these laws. We process it only to provide the safety features you ask for. In states that require opt-in consent for sensitive data, we ask for that consent before turning on live location sharing or a Circle share, and you can withdraw it at any time.
Your Right to Appeal. If we deny your privacy request, in whole or in part, we will tell you why. You may appeal that decision by replying to our response, or by emailing privacy@homeboundapp.com with "Privacy Appeal" in the subject line, within a reasonable time after you receive our decision.
We will review the appeal and give you a written answer, including the reasons, within 45 days of receiving it (or within 60 days where your state's law allows an extension, in which case we will tell you). If we deny your appeal, we will give you a way to contact your state Attorney General to submit a complaint. This right applies to every U.S. resident who asks for it, whether or not their state law requires it.
6.8 Washington and Nevada — Consumer Health Data
Washington's My Health My Data Act and Nevada's SB 370 define "consumer health data" broadly, and both can treat precise location information as consumer health data in some circumstances.
We publish a separate Consumer Health Data Privacy Policy covering the disclosures those laws require — the categories we collect and why, our sources, what is shared and with whom, the complete list of third parties and affiliates, our geofencing commitment, and how to exercise your rights. The summary below is the short version; that notice governs.
Homebound is a safety app, not a health app. We do not collect health conditions, diagnoses, treatments, medications, biometric data, reproductive-health information, or gender-affirming-care information, and we do not attempt to infer any of those from your trips.
Even so, because your trip destinations and precise coordinates could in principle reveal something about health, we want to be explicit:
- What we collect and why: The location data described in Section 1.4, collected solely to deliver the trip-safety, live-location, and Circle features you turn on.
- Who receives it: Only the people you designate — your safety contacts for a trip, and the friends in a Circle you share with — plus the service providers in Section 3.3 who process it on our behalf.
- We do not sell it. We have never sold consumer health data and we will not. Washington and Nevada both require your separate written authorization before any such sale; we do not seek one because we do not sell.
- Your rights: You may confirm whether we collect, share, or sell your consumer health data; access it; obtain a list of the third parties it has been shared with; withdraw consent to its collection and sharing; and have it deleted. To exercise these rights, email privacy@homeboundapp.com. We respond within 45 days, with one 45-day extension where permitted, and you may appeal a denial as described in Section 6.7.
- Deletion: On a verified deletion request we delete the data from our live systems and direct our processors to do the same.
6.9 How We Handle Privacy Requests
Where to send them. privacy@homeboundapp.com, or the postal address in Section 10. Requests made from the email address on your Homebound account are the fastest to verify.
Verification. To protect you, we verify that a request actually comes from you before we act on it. Normally that means confirming that the request comes from — or can be confirmed at — the email address on the account, which is also the credential you use to sign in. For requests seeking specific pieces of sensitive information, or for deletion, we may ask you to confirm details we already hold. We use information you give us for verification only for that purpose, and we do not create new accounts or collect new data in order to verify you. If we cannot verify a request, we will tell you, and we will treat an unverifiable access request as an opt-out request where the law directs us to.
Timing.
- We acknowledge requests within 10 business days of receipt.
- We respond substantively within 45 calendar days. Where the law permits and the request is complex, we may extend once by a further 45 days (or, for EU/UK requests, by up to two further months) and we will tell you why within the original window.
- For EU/UK requests under Section 6.2 we respond within one month, extendable as GDPR Article 12(3) allows.
Cost. Free. We may charge a reasonable fee, or decline, only for requests that are manifestly unfounded or excessive, particularly repetitive ones — and we will explain why before doing so.
Appeals. See Section 6.7. EU, UK, and Swiss users may also complain to their supervisory authority (Section 6.2); Canadian, Australian, and New Zealand users to the regulators named above.
7. Age Requirements
Homebound has different minimum age requirements based on your region:
| Region | Minimum Age |
|---|---|
| European Union, EEA, and Switzerland | 16 years old (per GDPR Article 8) |
| United Kingdom | 13 years old (per UK GDPR/Age Appropriate Design Code) |
| Canada (except Quebec), Australia, New Zealand | 13 years old |
| Quebec | 14 years old, or 13 with the consent of a parent or guardian (Quebec's Law 25 requires parental consent below 14) |
| United States and other regions | 13 years old |
Homebound is no longer offered in the European Union, the EEA, Switzerland, or the United Kingdom. As of 27 July 2026 the App was removed from those App Store storefronts, and new accounts cannot be created from those regions. The thresholds above are retained because a small number of accounts created before that date remain active, and everything in this document — including the rights in Section 6.2 — continues to apply to them for as long as they use Homebound.
How we determine your region — and its limits. We use your App Store storefront country as a starting point, because it is the signal available to the App. A storefront is not the same thing as where you live, and the law that protects you depends on where you are, not where your Apple account is registered. So:
- The storefront only ever sets a default. It never reduces the protection you are entitled to.
- If you live in the EU, EEA, Switzerland, or the UK but use a different storefront, the rights in Sections 6.2 and 8 still apply to you in full, and we will apply the age threshold for your actual country of residence.
- If your storefront and your residence differ, tell us at privacy@homeboundapp.com and we will correct the region on your account. You can also see the region we have on file in Settings > Privacy.
How we know your age. Two ways, and the more protective one wins. You enter an age when you set up your profile, and — if you allow it — iOS also tells us the age range Apple holds for your Apple Account, which for a child account is the one a parent set (Section 1.1). If those two disagree in a way that matters, we apply whichever indicates you are younger.
Users below the minimum age. We do not knowingly collect personal information from users who do not meet the minimum age requirement for their region. If we learn that an account belongs to someone below that age, we delete it and the associated data without waiting for the 30-day grace period (Section 5).
Parents and guardians. If you are a parent or guardian and believe your child has provided us with personal information, email privacy@homeboundapp.com. We will:
- Confirm receipt within 10 business days;
- Delete the account and its data, without the 30-day grace period, once we have verified the request;
- Confirm to you in writing when it is done.
We will not require you to create a Homebound account, or to provide more information than we need to verify the request, in order to do this.
Extra protections for users under 18. Homebound is a location-sharing app, so accounts that tell us they are under 18 are limited in what they can publish. These limits are enforced on our servers, not just in the App, and they cannot be turned off:
- No global publishing. A completed trip shared to the Activity Feed goes to friends only. If a global audience is requested, we save it as friends-only instead.
- No exact location in the feed. Location shown on a published trip is generalized to a city or region. If exact location is requested, we save the generalized setting instead.
This applies to the per-trip setting, the account-wide default, and trips published automatically at checkout.
What is not restricted, and why. Live location sharing during a trip, and Circle sharing, still work — those go only to the specific safety contacts and friends the user chose, and they are the safety features the App exists to provide. Turning them off for minors would remove the protection a parent most likely wants.
A note for parents. Two things already limit contact from strangers: becoming someone's friend requires both people to exchange an invite link (there is no way to search for a user or send an unsolicited friend request), and only friends can comment on or react to a trip. If your child uses Homebound, we still encourage you to review Settings > Privacy together, and to talk about who belongs in their Circles. You can ask us to delete their account at any time using the process above.
8. International Data Transfers
Our servers are located in the United States. If you access the App from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
For EU/EEA/Swiss Users: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection for transfers to the United States.
For UK Users: We rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs for transfers to the United States.
For Canadian Users: We ensure transfers comply with PIPEDA requirements for cross-border data transfers.
For Australian Users: We take reasonable steps to ensure overseas recipients handle your information consistently with Australian Privacy Principles.
For New Zealand Users: We ensure transfers comply with the Privacy Act 2020 requirements.
Sub-Processors
| Sub-Processor | Purpose | Location |
|---|---|---|
| Render.com | Application hosting | United States |
| Supabase | Database hosting, real-time sync, and image storage | United States |
| Cloudflare | Network security/delivery and check-in photo storage (R2) | United States (global edge network) |
| Resend | Email delivery | United States |
| Apple Inc. | Push notifications, Sign in with Apple, subscription processing, and maps | United States |
| Tomorrow.io | Weather data | United States |
| OpenStreetMap Foundation | Geocoding (location name lookup) and place data | United Kingdom / European Union |
| Geoapify | Place search (Discover) | European Union |
| U.S. recreation & mapping data providers (Recreation.gov, U.S. National Park Service, U.S. Geological Survey, U.S. Forest Service, U.S. Bureau of Land Management) | Place data (Discover) | United States |
| OpenBeta | Climbing-area data (Discover) | United States |
| Ticketmaster | Concert/event search (Discover) | United States |
| Canny | Feedback portal | United States |
The providers that process personal information on our behalf — Render, Supabase, Cloudflare, Resend, Apple, and Canny — each handle it under their data processing terms, which require them to protect it in accordance with applicable data protection laws, to act only on our instructions and for the purposes we have specified, and not to use it for their own purposes. Where the law requires a data processing agreement, we have one in place.
The remaining providers in the table above are sent nothing that identifies you: the geocoding, weather, and place-search services receive location coordinates only, with no name, email, or account identifier, and several of them are public or government services that we query without any commercial relationship.
9. Your Consent & Changes to This Privacy Policy
9.1 How We Record Your Consent
This Privacy Policy and our Terms of Service are versioned separately. Each is identified by the "Last Updated" date at the top of that document.
You are asked to accept both documents when you create your account and complete your profile. When you accept, our servers record, against your account, which version of each document you accepted and the date and time you accepted it. The version recorded is the one published on our servers at that moment — it is not supplied by your device.
You can review your consent record — whether consent is on file, and the version accepted, for each document — at any time in Settings > Privacy. It is also included in the data export described in Section 6.
9.2 When We Ask You to Consent Again
We may update this Privacy Policy from time to time. When we do, we update the "Last Updated" date at the top.
If the "Last Updated" date of either this Privacy Policy or our Terms of Service is newer than the version you last accepted, the App shows you a full-screen notice the next time it loads your profile. That notice tells you which document changed, links to both documents, and asks you to agree before you continue using the App. Because the two documents are versioned independently, a change to one is not described as a change to the other: if only the Terms of Service change, the notice says so.
Agreeing records the current version of both documents. If one of them has not changed since you last accepted it, its original acceptance date is kept, so your record continues to reflect when you actually agreed to each version.
This prompt depends only on the versions of these documents. It is independent of your App version, and updating the App does not by itself change your consent record.
9.3 If You Do Not Agree
If you do not wish to accept an updated Privacy Policy or Terms of Service, stop using the App and delete your account through Settings > Account > Delete Account.
You may also withdraw consent for non-essential processing at any time (Section 6) without deleting your account. If you do, your account remains active for the core safety functionality — such as notifying your emergency contacts if you become overdue — because that processing is performance of the contract between us, not something you consented to separately. Withdrawing consent turns off the optional features that rely on it (Trip Live Location Sharing and Circle sharing) and does not affect processing that already happened.
We ask for your agreement through the in-app notice described in Section 9.2. Simply continuing to use the App is not how you accept an updated policy, and we do not treat it as acceptance.
10. Contact Us
Homebound LLC is the controller of the personal information described in this policy.
If you have questions about this Privacy Policy or our privacy practices:
Email: privacy@homeboundapp.com Postal: Homebound LLC, 1518 Lake Front Ct, Park City, UT 84098, United States
The same address handles California privacy rights, other U.S. state privacy rights and appeals (Section 6.7), consumer health data requests (Section 6.8), EU/UK/Swiss GDPR requests (Section 6.2), and requests from non-users (Section 11). You do not need to use a particular form of words — just tell us what you want.
11. Emergency Contacts and Other People Who Are Not Homebound Users
Homebound users can add other people as emergency contacts by entering a name and email address. If someone has added you, we hold your name and email address even though you never signed up. This section is for you.
Where your information came from. A Homebound user entered it. We did not obtain it from you, and we did not buy it from anyone. The email you received tells you who added you.
What we hold. Your name, your email address, the trips you have been designated a contact for, and the delivery records for messages we sent you. Nothing else. We do not have your phone number, we do not read your device contacts, and we do not build a profile of you.
What we do with it. We use it for one purpose: sending you the safety messages the user asked us to send — trip created, trip started, check-in, ETA extended, trip completed, overdue alert, and SOS alert. Some of those messages include the user's location and a link to a page showing their trip. We do not send you marketing, we do not sell your information, and we do not use it for anything else.
Our legal basis (if you are in the EU, EEA, UK, or Switzerland) is our legitimate interest, and the user's, in your being able to act if they do not come back safely. We are the controller for this processing, and this section is our notice to you under Article 14 of the GDPR.
How long we keep it. Until the user deletes you as a contact or deletes their account, or until you ask us to remove you — whichever comes first.
Your rights. You do not have to accept being someone's emergency contact, and you do not need their permission to opt out. You can:
- Stop receiving messages. Email privacy@homeboundapp.com from the address that received them and say you want to be removed. (Our automated messages are sent from a no-reply address, so please write to privacy@ rather than replying.) We will remove you from the trips you have been added to and stop sending to that address. You do not need to give a reason.
- Ask what we hold about you, and get a copy.
- Correct your name or email address.
- Object to the processing, or ask us to restrict it.
- Have your details erased. We will delete them and tell the user that a contact was removed, without telling them anything about you beyond that.
- Complain to your data protection authority (see Section 6.2) or your state Attorney General.
Email privacy@homeboundapp.com and say what you want. We handle these on the timelines in Section 6.9 and we will not ask you to create an account to do it.
If you think someone is misusing this. If a Homebound user is adding you as a contact to harass you, or you believe the App is being used to track or intimidate someone, email privacy@homeboundapp.com and tell us. We will block further messages to you and act on the account under our Terms of Service.
This Privacy Policy is effective as of July 27, 2026.