PingTrix Logo
  • Features
  • Privacy
  • Terms

Privacy Policy

Last Updated: July 19, 2026

PingTrix ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App") and our website.

1. Information We Collect

We collect information that you provide directly to us when you register for an account, such as:

  • User Profile: Name, email address, phone number, and password.
  • Trusted Contacts Circle: Trusted contact names, email addresses, phone numbers, and physical postal addresses.
  • The Last Note: The emergency note text you draft. This is encrypted instantly on upload and is never visible to backend staff in plain text.

2. How We Use Your Information

We use the information we collect to operate and maintain our automated safety alerts:

  • To track your check-ins and identify missed check-in schedules.
  • To alert your trusted circle in case of missed check-ins using Emails (with SMS and WhatsApp capabilities preserved for future releases).
  • To release your decrypted Last Note to your trusted circle only when the 7-day recovery period has fully expired.

3. Advanced Cryptographic Data Protection

We implement a strict cryptographic security system to ensure your highly sensitive data remains confidential, even in the event of database access:

  • Envelope Encryption: Last Notes are encrypted using AES-256-GCM with a unique Data Encryption Key (DEK). The DEK is then encrypted using a Master Key Encryption Key (KEK) and stored securely in wrapped format.
  • Tamper Prevention: A server-side HMAC-SHA256 signature is calculated over the note's ciphertext. During decryption, this signature is verified. If the database row is tampered with by any unauthorized party, the signature fails validation and key release is blocked.
  • Field-Level Address Encryption: To protect the privacy of your trusted circle, postal addresses are encrypted at rest with a dedicated address key using AES-256-GCM.
  • Key Custody Coordinator (KCC): Stored keys cannot be accessed arbitrarily. The KCC enforces an automated lockout protocol. It rejects key release and decryption requests unless there is an active check-in lapse that has exceeded the recovery threshold.
  • OTP Verification Checks: To prevent unauthorized disabling or tampering of the Last Note toggle, any modifications to this status require confirmation via a secure 6-digit email OTP.
HomePrivacy PolicyTerms of ServiceSupport

© 2026 PingTrix. All rights reserved.