Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains what information Guardian collects, how we use it, and the choices you have. Guardian is a product of OWOS Global Ventures, Inc., a Delaware corporation, which is the data controller for Guardian. It forms one legal set with our Terms of Service and our Emergency Disclaimer; this Policy controls on questions of data handling.
1. What we store
- Account: your email address and a hashed password.
- Identity link: your OWOS Identity Number (PPID), your OVIN-issued Support ID, and the federation status of your account.
- Emergency profile (only the fields you choose to enter): display name, date of birth, home address, blood type, allergies, medical conditions, medications, care notes and communication needs, insurance provider and policy details, emergency contacts (name, relationship, phone number, and email address), and any insurance or wallet documents you upload.
- QR tokens and card settings: the active and revoked Emergency QR tokens issued to you, your chosen QR privacy mode, the time you acknowledged the offline-card warning, and the time an offline card was last generated.
- SOS sessions: the time you triggered an SOS, the situation category you selected (if any), the message you included, any later situation updates you add — which are stored as timestamped, append-only entries rather than replacing earlier text — the location coordinates you chose to share (if any), which contacts were notified on which channel, the delivery result reported by our SMS and email providers, any acknowledgement a recipient submits through the link in their alert, and the time you marked yourself safe or cancelled the alert.
- Geolock: when you start or stop a live-location session, the location updates your device sends during that session, and which people you granted or revoked access to. Geolock is off by default and every grant is revocable by you.
- Check-ins: the private check-in schedules you create and the times you confirm you are okay.
- Sponsorships: if you fund memberships for other people, we store the seat codes issued, which codes were redeemed, and when. Paying for someone's membership never gives a sponsor access to that person's profile, medical data, contacts, location, or SOS history.
- Wallet and documents: emergency wallet passes you generate and any insurance or wallet documents you upload, stored in private application storage.
- Email preferences: unsubscribe requests and suppression entries for addresses that have opted out or bounced.
- Billing: your subscription status, plan, renewal date, and payment-processor customer and subscription identifiers. We never receive or store your card number.
- Audit log: a tamper-evident record of identity-sensitive events (sign-in ownership checks, QR rotations, scan resolutions, SOS triggers and deliveries, federation events) including timestamps, outcomes, and request metadata such as IP address and user agent. You can review your own record in the in-app transparency log.
2. What we never store
- We do not sell your data. Ever.
- We do not store payment card numbers. Billing is handled by our payment processor.
- We do not run third-party advertising trackers in Guardian.
3. What gets shared on a scan
When someone scans your active Emergency QR and it resolves online, our server returns only the fields you have explicitly marked visible in your profile. Hidden fields are never returned. If you have not marked your display name visible, scanners do not see your name. If your QR has been rotated, the old QR returns a "revoked" response and shares nothing.
Every online scan is recorded in your audit log with the time, IP address, user agent, and the list of fields disclosed. We rate-limit scan resolution by token and IP address to prevent bulk harvesting.
4. Offline QR cards: information embedded in the code itself
Guardian offers three QR privacy modes. In Maximum Privacy your QR contains only a link, and nothing is disclosed without our server. In Balanced and Maximum Emergency Access, selected lifesaving fields are encoded directly inside the QR image so a responder can read them with no internet connection.
- Balanced may embed: display name, blood type, allergies, medical conditions, medications, and up to two primary emergency contacts.
- Maximum Emergency Access may additionally embed: care notes, communication needs, and up to four emergency contacts.
- Never embedded in any mode: your OWOS Identity Number, Support ID, insurance provider or policy details, home address, date of birth, email address, uploaded documents, and your audit log.
Information embedded in a QR is permanent and cannot be revoked. Anyone who scans, photographs, screenshots, or prints that code can read the embedded fields forever, offline, with no request to our servers — which also means offline scans do not appear in your audit log. Rotating your QR, editing your profile, switching to Maximum Privacy, or deleting your account only affects codes generated afterward. See section 7 of the Terms of Service.
Because of this, we require an in-app acknowledgement before generating your first offline card and we store the time of that acknowledgement. Without a recorded acknowledgement, Guardian falls back to link-only mode.
5. What gets shared in an SOS alert
When you trigger an SOS, we send the contacts you have saved an SMS and/or email containing your display name, the message you wrote, a map link to the location you chose to share, and a link they can use to confirm they are responding. To do this we share the recipient's phone number or email address, and the alert content, with our SMS and email delivery providers. Recipients may retain those messages indefinitely, and we cannot recall a message once sent. Recipients can unsubscribe from Guardian emails, which may prevent future alerts reaching them by email. Limitations on SOS are described in the Emergency Disclaimer.
Text messages go only to numbers whose owner personally opted in and confirmed the number with a one-time code. For those contacts we keep consent evidence: the normalized phone number, consent and verification timestamps, the version and hash of the consent text shown, the invitation reference, the IP address and browser user agent recorded at consent, and any later opt-out with its source. We keep this record for as long as the contact exists plus the period we are required to be able to prove consent, and we keep opt-out (STOP) records indefinitely so a number that opted out is never texted again. Mobile numbers and SMS consent are never sold or shared with third parties or affiliates for marketing or promotional purposes, and are shared with our messaging provider only to deliver the messages you or your contacts asked for. The complete opt-in flow is published at /sms-consent-review.
Situation context and updates. If you choose to add a situation category or a short description of what happened, that text is shown on the secure page each notified recipient opens, labelled as reported by the person who activated the SOS. It is treated as context for that one incident and is not added to your medical profile. Text is stored and displayed as plain text only. Updates you add afterwards are appended with their own timestamps; earlier text is never overwritten. Only the authorized activator can add context — holding a recipient acknowledgement link does not permit editing an incident.
Resolution notices. When you mark yourself safe or cancel an SOS, we send a follow-up notice only to the recipients who already received the original alert, on the channels they already consented to, and the secure page updates to show the incident is closed.
Recipients see only their own alert. Each recipient link is scoped to one SOS and one recipient, expires, and can be revoked. Nothing hidden in your profile, no other person's data, and no sponsor is ever given access.
6. Identity federation with OWOS Core (OVIN)
Guardian is a federation module of the OWOS identity system. When you sign up or sign in, we verify with OWOS Core that the email and OWOS Identity Number you supplied belong to the same Core account, and we retrieve the permanent Support ID that OVIN issues for your Passport. If verification fails we refuse the sign-in and record the attempt. We do not generate or modify OWOS Identity Numbers or Support IDs in Guardian.
7. How we use your information
- To operate your emergency profile, Emergency QR, and offline card.
- To deliver SOS alerts to the contacts you have saved.
- To verify your identity through OWOS Core at sign-up and sign-in.
- To bill your subscription and provide customer support.
- To detect and prevent abuse, fraud, and security incidents.
- To meet legal obligations.
7a. Legal bases for processing (EEA and UK users)
- Contract. Operating your account, profile, QR, wallet, check-ins, SOS delivery, and billing is necessary to provide the service you signed up for.
- Explicit consent. Health information — blood type, allergies, medical conditions, medications, care notes and communication needs — is special-category data. You choose whether to enter it, whether to mark it visible, and whether to embed it in an offline card. We process and disclose it on the basis of your explicit consent, and you can withdraw that consent at any time by hiding or deleting the field, switching to Maximum Privacy, rotating your QR, or deleting your account. Withdrawal cannot retract information already embedded in an offline card that exists in the world.
- Vital interests. Where an SOS or a scan happens in a genuine emergency and you are unable to give consent at that moment, disclosure of the fields you already chose to make available may also rest on the protection of vital interests.
- Legitimate interests. Security, abuse and fraud prevention, audit logging, and proving SMS consent.
- Legal obligation. Accounting records and responses to lawful requests.
8. Service providers
We use trusted providers to host the application and database, verify identity through OWOS Core, send transactional and SOS email, send SOS text messages, render map links, and process payments. They are bound by contractual confidentiality obligations and process data only on our instructions.
8a. Where your data is processed
Guardian is operated from the United States and our providers may process data in the United States and other countries. If you use Guardian from the EEA, the UK, or another region with data-transfer rules, your information will be transferred to and processed in the United States. Where required, those transfers rely on the European Commission's Standard Contractual Clauses (and the UK addendum) or another lawful transfer mechanism in our agreements with those providers.
8b. Cookies and device storage
Guardian uses no advertising, marketing, or third-party tracking cookies, and no cross-site profiling. We use only what the app needs to function: a sign-in session token, and browser local storage for your inactivity timer and, if you choose it, the "Remember me" setting and the email address to prefill on that device. Clearing your browser storage signs you out and removes those preferences.
9. Data retention
We retain your profile data for as long as your account is active, including during any past-due or suspended period. When you delete your account we delete or anonymize your profile data within 30 days. Geolock location points are kept only for the session they belong to and are removed when the session ends or is revoked. SOS records, including situation text and updates, are retained with your safety history so you and the people involved can review what happened. Audit log entries, suppression entries, SMS consent evidence, and billing records may be retained longer where required for security, fraud prevention, accounting, or legal reasons. We cannot retract information already embedded in an offline QR card (see section 4).
10. Your rights
You can access, correct, export, or delete your profile from your account settings at any time. Export produces a human-readable copy of the information we hold about you. If you are in a jurisdiction that grants additional rights (such as the EEA, UK, or California), you may also have the right to object to certain processing, to restrict it, to withdraw consent, or to lodge a complaint with a supervisory authority. You may also contact us at guardian-privacy@owosgv.com and we will respond within the time your law allows. We will never charge you or degrade your service for exercising a privacy right.
10a. California privacy rights
We do not sell your personal information and we do not share it for cross-context behavioral advertising. California residents may request to know what we collect, request deletion or correction, and limit the use of sensitive personal information; Guardian only uses sensitive information (including health information) to provide the emergency features you asked for, never to infer characteristics or to advertise. You may exercise these rights through your account settings or by emailing guardian-privacy@owosgv.com, and you may use an authorized agent. Exercising them will not affect your price or service level.
11. Security
We use encryption in transit, row-level security on the database so each account can only access its own data, an append-only audit trail for sensitive actions, fail-closed QR resolution, rate limiting on public scan endpoints, and strict separation between Guardian and other OWOS modules. No system is perfectly secure; please use a strong, unique password.
12. Children and teens
You must be at least 13 years old to create a Guardian account for yourself. Guardian is available to users age 13 and older, and we confirm that at signup.
We do not knowingly collect information from children under 13. Children under 13 may not register or use Guardian independently, and there is currently no parent- or guardian-managed child profile in Guardian. If you believe a child under 13 has created an account, email guardian-privacy@owosgv.com and we will delete the account and its data.
Users age 13–17 have the same privacy controls as everyone else: nothing in your Guardian profile is shared publicly unless you mark that field visible, and you can rotate or revoke your Emergency QR at any time. We encourage teens to review these controls with a parent or legal guardian.
13. HIPAA and other health-privacy laws
Guardian is a personal safety tool you control, not a clinical system. OWOS Global Ventures, Inc. is not a healthcare provider, health plan, or healthcare clearinghouse, we do not act as a business associate for one, and Guardian is not a medical device or an electronic health record. Because of that, HIPAA's rules for covered entities and business associates do not govern the copy of your information that you choose to store in Guardian. If your clinician, hospital, or health plan holds the same details, their copy remains subject to HIPAA.
We do not claim that health information can never be protected under any law simply because it sits in Guardian. If we ever provide a service on behalf of a covered entity, HIPAA obligations could attach to that arrangement, and other laws — state health-privacy, genetic- and biometric-privacy, consumer health data, and breach notification statutes — can apply to health information held by a consumer service like ours. Where they apply, we intend to follow them. This section describes how Guardian operates today and is under ongoing professional legal review; it is not legal advice, and it is not a guarantee about how any particular law will be applied to your information.
14. Changes
We will post any material changes to this Privacy Policy at this URL and, where appropriate, notify you by email.
15. Contact and data controller
The controller responsible for your information is:
OWOS Global Ventures, Inc.
910 Noddymill Lane East
Worthington, OH 43085
United States
Privacy questions: guardian-privacy@owosgv.com. General support: guardian-support@owosgv.com.
Related documents
- Terms of Service — membership, billing, acceptable use, and offline QR permanence.
- Emergency Disclaimer — what Guardian and SOS can and cannot do in an emergency.