The server stores
Only what it needs to run your daily check-in
- Plan events under random identifiers, including deadlines and status changes
- An optional encrypted note
- Integrity records for checking Plan history
Privacy & safety
BackBy is designed to give you control over who can read your note and when. Your Backer list stays off the server, while check-in times and events provide the record needed to run a Plan.
The server stores
The server does not store
Your private note
BackBy is designed to keep the note locked until the Plan needs attention, you ask for help, or a completion carries the private safety signal. A normal completion keeps it locked.
Right Away is designed to let Backers read the note as soon as the Plan starts. It also shares any legal name, phone number, or map pin you add. Choose it only if you want those details shared immediately. You cannot take back a copy someone has read.
Important limits
The server sees Plan deadlines and may infer routines from their timing. Repeat labels are encrypted for paired Backers. Minimizing connection records throughout the hosting stack is part of the privacy design.
Maps are off by default. Loading a map can share your IP address and the area you view with the map provider. Read the privacy notice before turning maps on.
Lock-screen notifications show details by default, with a generic-text option in Settings. Device passcodes and encrypted storage help protect local records; they cannot stop malware already on a phone.
The server does not call police, doctors, family, or a monitoring center. It notices a missed check-in. It cannot notice a fall. Your Backers decide what to do, using the plan you prepared with them.
Legal process
The design limits stored records to Plan events, encrypted notes, and integrity records. Readable notes and Backer lists stay off the server. The privacy policy and data inventory describe the intended records and their handling.
Encrypted notes expire under rules that keep them available through the Plan’s attention window. Plan events under random identifiers are kept permanently. The data inventory explains the retention rules.
For reviewers
The design encrypts notes on the phone with AES-GCM and uses state-controlled key capsules to govern access. Pairing gives Backers the secrets needed to read authorized notes. The protocol explains the full design.
The design requires a secret credential for each Plan read. Missing, wrong, or expired credentials receive the same response as missing data.
The design adds each change to Plan history and publishes signed proofs so independent reviewers can check for tampering.
The private completion path is designed to show ordinary success to the Planner and “Confirm they’re OK” to an authorized Backer. The Backer cannot tell why it happened. The protocol and threat model explain the design.