Privacy & Trust

Privacy by architecture

Raw audio stays on your device. It is never transmitted to SplitSec.

What happens on your device

Raw microphone audio used for detection is processed locally and is not transmitted to SplitSec cloud services for detection.

Input

Microphone sound

Temporary sound input used by the device.

On-device

Temporary processing

Local conversion into model-ready data.

On-device

Detection model

Evaluates patterns associated with possible gunfire.

What information can be transmitted

Connected features require some data, but raw microphone audio for detection or false-positive feedback is not the payload.

InformationSent to SplitSec?Notes
Raw microphone audio used for detectionNoDetection runs on-device.
Raw audio used for false-positive feedbackNoThe raw recording used to create feedback is not transmitted.
Derived numerical sound signatureOnly when selectedCreated on-device when the user chooses an applicable labeled feedback action.
Detection/event informationYes, where neededUsed for connected SplitSec features and service operation.
Precise device locationWhen applicableRequires applicable permission and a location-dependent feature.
Nearby nonparticipant phone informationNoSplitSec does not collect device or location information from nearby phones that are not participating.
Carrier or cell-tower location recordsNoSplitSec does not obtain these records.

Sound signatures

A sound signature is a derived numerical representation created from the relevant sound on the user's device. It is not the raw audio recording.

If you choose a feedback action that submits a sound signature, your device creates a derived numerical representation on-device. SplitSec receives the sound signature, not the raw audio.

Sharing controls

Declining automatic sharing does not affect otherwise eligible rewards. Turning it off stops future and pending uploads; previously submitted signatures follow the Privacy Policy’s retention rules.

SplitSec does not use sound signatures for speaker identification, voice authentication, or other biometric identification.
1
Created on-device

The transformation occurs before transmission.

2
User controlled

Signatures may be submitted through clearly labeled feedback or optional automatic sharing, which is off by default and requires a separate opt-in. Raw audio is never transmitted to SplitSec.

3
Normally retained up to 45 days

See the Privacy Policy for exceptions and backup retention.

Location

Location can support nearby awareness and coordinated detection when permission is granted. It is not used to build profiles of individual users' movements or travel patterns.

No carrier location

SplitSec does not obtain carrier or cell-tower location records.

No nearby-phone harvesting

We do not collect location or device information from nearby nonparticipating phones.

No travel profiles

Location is not used to build profiles of individual users' movements or travel patterns.

Retention

We publish specific retention expectations rather than saying data is kept only "as long as needed."

45 days
Sound signatures — normally retained up to this period
45 days
Precise device location tied to detection/alert events — normal active-system limit

Limited exceptions, including legal holds and certain security or legal requirements, and temporary backup retention are described in the Privacy Policy.

Pilot partners

Pilot partners generally receive aggregated or de-identified pilot information. SplitSec does not provide ongoing or bulk access to individual users' precise location histories, sound signatures, or identifiable account information.

Law enforcement

SplitSec does not automatically report detections to 911 and does not provide law enforcement with an ongoing feed of users' locations, sound signatures, or account activity. The Privacy Policy describes circumstances where disclosure may be permitted or required.

Account deletion

App permissions can be managed through your device. You can delete your SplitSec account through the in-app deletion flow or by contacting support.

Software and model updates

Executable app updates use authorized distribution channels. This is different from separately updating a detection-model file.

APP

Executable application code

SplitSec does not use an in-app over-the-air mechanism to remotely replace or modify executable application code outside authorized app-store or operating-system distribution channels.

ML

Detection-model files

The app may separately check for and download updated detection-model files. A model download does not cause raw microphone audio to be uploaded to SplitSec.

Book 30 minutes