Privacy & safety

Your note. Your choice of who can read it.

BackBy is designed to give you control over who can read your note and when. Your Backer list stays off the server, while check-in times and events provide the record needed to run a Plan.

The server stores

Only what it needs to run your daily check-in

  • Plan events under random identifiers, including deadlines and status changes
  • An optional encrypted note
  • Integrity records for checking Plan history

The server does not store

Who you are or who looks out for you

  • No readable legal name, phone number, or address book
  • No list of your Backers
  • No cookies, analytics, or login sessions. The hosting design calls for no retained IP records.

Your private note

You decide when the people you chose can read it.

Emergency Only is the default

BackBy is designed to keep the note locked until the Plan needs attention, you ask for help, or a completion carries the private safety signal. A normal completion keeps it locked.

Right Away is optional

Right Away is designed to let Backers read the note as soon as the Plan starts. It also shares any legal name, phone number, or map pin you add. Choose it only if you want those details shared immediately. You cannot take back a copy someone has read.

Important limits

Where privacy has limits.

Check-in times can reveal a routine

The server sees Plan deadlines and may infer routines from their timing. Repeat labels are encrypted for paired Backers. Minimizing connection records throughout the hosting stack is part of the privacy design.

Optional maps share data with a map provider

Maps are off by default. Loading a map can share your IP address and the area you view with the map provider. Read the privacy notice before turning maps on.

Someone with access to your phone may see details

Lock-screen notifications show details by default, with a generic-text option in Settings. Device passcodes and encrypted storage help protect local records; they cannot stop malware already on a phone.

BackBy is not emergency services

The server does not call police, doctors, family, or a monitoring center. It notices a missed check-in. It cannot notice a fall. Your Backers decide what to do, using the plan you prepared with them.

Legal process

What a records request could reveal.

The design limits stored records to Plan events, encrypted notes, and integrity records. Readable notes and Backer lists stay off the server. The privacy policy and data inventory describe the intended records and their handling.

How long records stay

Encrypted notes expire under rules that keep them available through the Plan’s attention window. Plan events under random identifiers are kept permanently. The data inventory explains the retention rules.

For reviewers

Explore the design.

How note encryption works

The design encrypts notes on the phone with AES-GCM and uses state-controlled key capsules to govern access. Pairing gives Backers the secrets needed to read authorized notes. The protocol explains the full design.

How state reads are protected

The design requires a secret credential for each Plan read. Missing, wrong, or expired credentials receive the same response as missing data.

How history is meant to be checked

The design adds each change to Plan history and publishes signed proofs so independent reviewers can check for tampering.

How private completion is designed to work

The private completion path is designed to show ordinary success to the Planner and “Confirm they’re OK” to an authorized Backer. The Backer cannot tell why it happened. The protocol and threat model explain the design.