Surv · Privacy Policy
Privacy Policy
Effective 2 September 2026 · Surv (iOS) · Last updated 5 September 2026
What stays on your device, always
The following never leaves your iPhone. We have no copy of it and no way to read it:
- Your medical card — name, blood group, allergies, conditions, treatments, emergency contacts.
- Your family plan, meeting points and code word.
- Your inventory, expiry dates and kit checklists.
- Your saved waypoints, your trail and your field-log notes.
- Your autonomy diagnostic and its history.
All of it lives in a single file inside the app's private storage. Deleting the app erases it permanently. The honest consequence: if you lose the phone and have no encrypted device backup, that data is gone with it.
Location
Surv asks for your location only when you open the compass, your coordinates, the waypoints or the field log. It is used on the device to display a bearing, a distance and your coordinates — it is never transmitted, and the app contains no code that could transmit it. You can refuse the permission and every other feature keeps working.
Optional usage measurement — off by default
Surv can send usage events with pseudonymous identifiers that tell us where people stop in the app. This is switched off when you install it, and you turn it on yourself in Settings, or during setup. If you turn it on, what is sent is:
- Step names and counters — for example "onboarding step 3", "paywall shown" — plus the selected plan, trial duration, purchase outcome, price and currency when applicable.
- The app version, the device language and country, and the number of days since installation.
- A random identifier created on first launch and hashed with SHA-256 before being sent. It is reset if you reset the app.
What is never sent: your notes, your position, your medical card, your inventory, your name, your email, an advertising identifier, or any health data. There is no tracking across apps or websites, and no advertising.
These counters go to TelemetryDeck, hosted in the European Union. Turning them off removes no feature.
Purchases
Purchases are handled by Apple. Surv never sees your payment details. Your subscription status is read locally from the receipt Apple stores on the device, which is why the app keeps working offline after you buy.
We also use RevenueCat to observe purchases and measure sales. It receives a pseudonymous identifier generated by its SDK and App Store transaction data. These identifiers are not your name, but are not described here as irreversibly anonymous. RevenueCat receives none of your notes, location, medical card or inventory. StoreKit determines access to Surv Pro.
Nearby link
The nearby link sends short messages directly from phone to phone over Bluetooth and peer-to-peer Wi-Fi, within a few dozen metres. There is no server and nothing leaves the area. Messages are sent in clear text to anyone in range running Surv with that screen open — so treat it as something said out loud, not as a private channel. It only runs while that screen is open.
Notifications
If you ask Surv to track an expiry date, it schedules a local notification 30 days before. Local notifications never leave the device.
Children
Surv is not directed at children under 13. Optional usage measurement and purchase services process the technical and transaction data described above; this policy does not claim that all such data is anonymous.
Your rights
We do not receive the personal content you save in the app. Technical identifiers and transaction data may nevertheless be processed by the services described above. For requests about access to or deletion of those data, contact us using the address below. You can erase the content stored locally from Settings → Erase all my data, or by deleting the app. For any question, write to Gambinoromeo9@gmail.com.
Changes
If this policy changes, the date at the top changes with it.
Official links
Contact : Gambinoromeo9@gmail.com
Originally published at dualnbackapp.github.io/surv/privacy.html, reproduced here on 6 September 2026.