top of page

Privacy Policy

Operated by: SENA App, Inc, a Delaware Public Benefit Corporation ("SENA," "we," "our," "us")

Applies to: the SENA beta mobile application (the "App") and the SENA website (the "Website") together, the "Platform." 

Effective Date / Last Updated: June 1, 2026 

Contact: privacy@senaapp.org

At a Glance

 

The full details are below, but the whole policy comes down to six commitments:

 

  • Core resources — hotlines, non-profits, safety and mental-health apps — work without an account, a name, or your story. Only the Awareness section asks you to sign in, with just an email address.

  • All content is built into the App and works offline. What you read, save, and color stays on your phone — SENA operates no servers that hold your activity.

  • If you use location to find nearby resources, the matching happens on your device. Your location never leaves your phone and is never stored.

  • To improve the App, we count which features get used — as anonymous totals never connected to your identity, account, or location.

  • If the App crashes, a technical crash report goes to Google's Firebase Crashlytics so we can fix bugs. It never contains what you read, searched, or typed.

  • No ads. No data sales. No behavioral profiles. Ever. The beta is free.
     

1. Who We Are, and Why This Policy Reads Differently

 

SENA is a private safety resource infrastructure addressing gender-based violence. The App organizes existing resources — hotlines, non-profit organizations, government agencies, and legal, medical, mental-health, and safety information — and educates users about their rights and options.

 

Most privacy policies describe how a company limits its use of the data it collects. This one mostly describes data we deliberately never collect. That is not a marketing posture; it is the product's architecture. Many of our users may live with someone who monitors their phone, and some may one day face a legal proceeding in which an abuser's attorney seeks records about them. We resolve both threats the same way: information that is never collected cannot be seen, leaked, subpoenaed, or misused. Where we do handle data, this policy names each item, why it exists, where it lives, and how to remove it.

 

What SENA is not. SENA has no advocates, counselors, or crisis staff. No person at SENA sees or responds to anything you do in the App, and SENA has no personnel who are mandatory reporters — using SENA never triggers a report to any authority. SENA does not dispatch police or emergency services; nothing you do in the App sends anyone to your location. SENA does not create case files, evidence records, or histories about you. Platforms that dispatch help or build case records must collect identity and location; because SENA educates rather than dispatches, it does not need to know who you are — so it doesn't ask.

2. The Two Tiers of the App

 

Free core resources — no account. The hotline directory, non-profit directory, safety-app and mental-health-app directories, and the App's safety features require no account, no name, no email, and no personal information of any kind. You can install SENA and use everything in this tier without ever telling us you exist.

 

The Awareness section — account required. SENA's educational Awareness content requires creating an account. An account needs exactly two things: an email address and a password. We ask for nothing else — no name, no phone number, no date of birth — and your email address does not need to contain your real name. Section 4 describes exactly how account data is handled.

 

During the beta, everything in the App — both tiers — is free.

3. The Complete Data Inventory

 

This section lists every category of data that exists anywhere in SENA's systems or those of its service providers. If a category is not listed here, SENA does not collect it.

3.1 Account information (only if you create an account)

  • Email address -> Firebase Authentication (Google) -> Sign-in and account recovery

  • Password (stored as a secure hash, never readable) -> Firebase Authentication (Google) -> Authenticating you

  • Account identifier (random UID) -> Firebase Authentication (Google) -> Distinguishing your account technically
     

Authentication is provided by Firebase Authentication, a Google service. Your credentials are stored on Google's infrastructure, not on SENA servers — SENA operates no server of its own holding account data. Critically, your account is not connected to your activity: SENA's systems contain no record linking your account to what you read, save, search, color, or do in the App. The account exists to unlock the Awareness section, and that is all it does.

3.2 Crash reports (all users)

 

If the App crashes or encounters an error, Firebase Crashlytics (a Google service) automatically receives a report containing the technical error details, standard device metadata (such as device model and operating-system version), and short internal feature labels written by our developers. Crash reports never contain the content you viewed, saved, searched, or typed, and are never linked to your account. Crash reporting exists so we can find and fix bugs; it is disabled in our internal development builds and governed by Google's Crashlytics retention policy.

3.3 Website technical data

 

The Website is hosted by Wix.com Ltd. As with any hosted website, Wix processes standard technical data — visitor IP addresses, browser type, and similar server information — as part of providing hosting. The Website requires no account and offers its informational resources to everyone.

3.4 Email you send us

 

If you email privacy@senaapp.org or otherwise contact us, we receive what you choose to send. We use it only to respond, and we discourage including sensitive personal details in any message to us.

 

That is the entire inventory. No names (unless your email contains one), no phone numbers, no contacts, no photos, no messages, no reading history, no search logs, no location records, no advertising identifiers, no behavioral profiles.

 

4. What We Deliberately Do Not Collect

 

The following categories are not collected by design — the App contains no code paths that could collect them:

 

  • Descriptions of abuse or personal narratives. The App never asks what happened to you, and has no free-text field that transmits to us.

  • Reading, browsing, or search history. Content is on your device; browsing it creates no record with us.

  • Location records. See Section 5 — location is processed on your device and never transmitted or stored.

  • Contacts, photos, microphone, or files. The App does not request these permissions.

  • Legal case records, medical records, identity documents.

  • Advertising or cross-app tracking identifiers. The App contains no advertising SDK and performs no cross-app or cross-site tracking.
     

5. Location: On Your Device, Only in the Moment

 

The App can show resources near you. Here is exactly how that works, because the design is unusual and deliberately so:

 

The full resource directory ships inside the App. When you grant location access, your device's own operating system provides your position to the App, the App matches it against the directory on the device itself, and shows you what's nearby. Your coordinates are never transmitted to SENA or anyone else, never included in usage events or crash reports, never written to any log, and never stored — the moment the search is done, the location is gone. No location history exists anywhere: not on your device, not on any server, not with any third party.

 

Location permission is requested only "while using the App," never in the background. And it is entirely optional: you can decline it and select your borough or area manually, with full functionality.

 

If a court ever ordered SENA to produce a user's location history, our answer would be that none exists — by architecture, not by policy choice that could quietly change.

6. What Stays on Your Device

 

Everything you do in the App lives only on your phone: your settings, saved resources, coloring pages, security preferences, and the record that you accepted these terms. All resource content ships inside the App, so browsing works offline and generates no server traffic. SENA operates no backend server holding user data — there is no server that could observe your activity even in principle.

 

One honest caveat about your own device. Your phone's operating system (Apple's or Google's) may include app data in the device backups it makes under your settings — that process belongs to your phone, not to SENA. If someone else has access to your device, its cloud account, or its backups, review your device's backup settings. More broadly: no app can protect you from a device that someone else controls or monitors. If you are concerned your phone is monitored, consider using a safer device, such as a public library computer, and consult technology-safety guidance from organizations such as the Safety Net project of the National Network to End Domestic Violence.

7. Safety-by-Design

 

SENA is built for people who may use it in unsafe circumstances, including on shared or monitored devices. The App includes discreet-access features — including optional access protection chosen by you, and screens that hide sensitive content when switching between apps. For safety reasons, we do not publicly document the full mechanics of these features: a public manual would defeat their purpose. You can learn exactly how they work inside the App itself.

8. Adults Only (18+)

 

The Platform is intended solely for users 18 years of age or older. SENA does not knowingly permit use by, or collect personal information from, anyone under 18. If we learn that a person under 18 has created an account, we will delete it. Some content on the Platform addresses situations involving minors (for example, resources for an adult supporting a minor survivor); that content is written for adult readers.

9. Service Providers

 

SENA uses a small number of service providers, each processing only what its function requires:

  • Firebase Authentication (Google) -> Account sign-in -> Email, hashed credential, account UID

  • Firebase Crashlytics (Google) -> Crash reporting -> Crash reports (Section 3.2)

  • Wix.com Ltd. -> Website hosting -> Standard website technical data
     

These providers act as processors on SENA's behalf under their terms of service. SENA does not sell personal data to anyone, does not share personal data with anyone for advertising, and has no data-sharing relationships beyond this table. A current version of this list is always available on request at privacy@senaapp.org.

10. Legal Requests and Government Demands

 

Because of the architecture described above, SENA holds very little that anyone could demand. If SENA received a subpoena, court order, or other legally binding demand concerning a user, the complete universe of potentially responsive data is: the account email and identifier held at Firebase (if that user created an account); anonymous aggregate usage totals that cannot be tied to any individual; and crash reports containing neither identity nor content. There is no reading history, no search log, no location record, no message archive, and no link between any account and any activity in the App.

 

If SENA is ever legally compelled to disclose information, we will: disclose only what we are compelled to disclose; challenge overbroad or improper demands where reasonably possible; and — where legally permitted and where any means of contacting the affected user exists — notify that user before disclosure. SENA does not voluntarily provide user information to law enforcement or immigration authorities.

11. Data Security

 

Safeguards in place include: encryption of data in transit for all network traffic the App generates; credential storage as secure hashes via Firebase Authentication (SENA cannot read your password); the on-device data model itself, which is the strongest safeguard — data that never leaves your phone cannot be breached from a server; and access controls limiting SENA's internal systems to essential personnel. No digital platform can guarantee absolute security, and we won't pretend otherwise — but we have arranged things so that the consequences of any breach are as small as the data we hold.

12. Data Breach Notification

 

If a security breach affecting personal information occurs, SENA will notify affected users and applicable regulators as required by law (including state breach-notification statutes) without unreasonable delay, describing what happened, what information was involved, and what steps you can take.

13. Retention and Deletion

 

  • Account (email, credential, UID) - Until you delete your account

  • Anonymous usage totals - Retained as aggregates that identify no one 

  • Crash reports - Per Google's Crashlytics retention policy

  • Email to SENA - Deleted once no longer needed to respond

  • Everything on your device - Yours — deleted when you delete the App or its data
     

Deleting your account: available at any time, directly inside the App, or via senaapp.org/delete-account. Deletion removes your account record — email, credentials, and identifier. Because your account was never linked to your activity, there is no activity record to chase; deleting the account removes everything SENA's providers hold about you as an identifiable person.

14. Your Privacy Rights

 

You may request access to, correction of, deletion of, or a copy of your personal data, and you may withdraw consent for optional processing, by emailing privacy@senaapp.org. You will not be treated differently for exercising any right.

 

Given our data model, here is what exercising these rights actually looks like: for users without accounts, our truthful answer is that we hold no data about you, and we will confirm that in writing. For account holders, the data we can produce is your account email and identifier — and the fastest deletion path is the in-app control, no email required.

 

California residents (CCPA/CPRA): you have the right to know the categories of personal information collected and the purposes (Sections 3 and 9 are that disclosure); the right to opt out of "sale" or "sharing" of personal information — SENA does not sell or share personal information as those terms are defined in the CPRA; and the right to limit use of sensitive personal information — SENA does not use sensitive personal information beyond permitted service purposes.

 

Residents of other U.S. states with comprehensive privacy laws (including New York, Colorado, Connecticut, Virginia, and Texas) may have similar rights under those laws.

 

We verify rights requests using minimal reasonable means — we will never demand identity documents from a user base we deliberately do not identify — and respond within the timeframe applicable law requires (generally 30–45 days). If we deny a request in whole or part, we will explain why, and you may lodge a complaint with your state attorney general or applicable supervisory authority.

15. International Users

 

SENA is operated from the United States, and the beta is oriented to New York City resources. If you access the Platform from outside the U.S., the limited data described in this policy may be processed in the United States and other countries where our service providers operate. Where required, SENA relies on appropriate safeguards for such transfers.

16. Do Not Track and Global Privacy Control

 

The Platform honors Global Privacy Control signals where applicable law requires. Because SENA does not sell personal data or serve advertising, such signals do not change the Platform's core behavior — there is nothing to opt out of.

17. Changes to This Policy and to SENA

 

SENA will grow — future versions may add features that involve data (for example, planned on-device AI features are being designed so conversations never leave your device and SENA cannot read them). Any such change will update this policy before the feature launches, with material changes highlighted in the App and prior versions available on request. What will not change are the commitments this policy is built on: collect the minimum, keep it the shortest possible time, design so there is as little as possible to disclose, and never introduce advertising, data sales, or behavioral profiling.

18. Contact

 

SENA App, Inc. (a Delaware Public Benefit Corporation)
Email: privacy@senaapp.org
Registered agent: Corporation Service Company, 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808

bottom of page