HollerGet early access

Legal

Privacy Policy

How Holler collects and uses your data in the app and on this website. Last updated 13 July 2026.

1. About this policy

This Privacy Policy explains how Stolen Orbit LLC ("Holler", "we", "us", "our") collects and uses personal data through the Holler: Walk Home Safety Alarm mobile application (the "App") and the website getholler.app, including the live-location tracking pages it hosts (the "Site") — together, the "Service".

We are committed to handling your personal data lawfully, fairly and transparently, in line with the EU General Data Protection Regulation (GDPR), the UK GDPR and the Data Protection Act 2018, and applicable United States state privacy laws.

This policy was last updated on 13 July 2026.

2. Who is responsible for your data

The data controller for personal data collected through the Service is Stolen Orbit LLC, 8 The Green, Suite B, Dover, DE 19901, United States. You can contact us about privacy at privacy@getholler.app.

If you are in the EEA or the UK, we will appoint a representative under Article 27 of the EU GDPR (established in an EU Member State) and a separate representative under Article 27 of the UK GDPR (established in the UK) where required, and we will publish each representative's name and contact details here before the relevant processing begins.

Apple is an independent controller of your Apple ID, App Store account and payment data under its own privacy policy. We never receive or store your payment card details.

We have not appointed a Data Protection Officer. You may raise any data protection matter using the contact details in this policy.

3. The personal data we collect

Holler is built around data minimisation: the App works without a name, email address or password. We collect:

  • Anonymous account identifier: a random account ID created when you first open the App (Firebase anonymous authentication). We do not ask for your name, email address or password to use the App.
  • Precise location: collected and shared only during alerts and “Walk with me” sessions that you start, so that the trusted contacts you chose can see where you are via the live-location link. The App may use background location services on your device to keep protection features such as shake detection running, but your location is not shared or uploaded outside an alert or session you started.
  • Evidence recordings: video from the front and back cameras during alerts, and audio only where lawful in your region and only if you have opted in — always disclosed on screen while recording. See section 5.
  • Trusted-contact details: the phone numbers (and names, if you add them) of the contacts you choose, used solely to send them your alert messages.
  • Onboarding survey answers: your responses to a short survey during setup (such as your main safety concern, persona, age range and how you heard about Holler), used for analytics only.
  • Purchase and subscription status: whether you have an active Holler Plus subscription or trial, processed through RevenueCat so the App knows what to unlock. Payment itself is processed by Apple.
  • Usage analytics: events describing how the App and Site are used (screens viewed, features used, device model, app version), processed with PostHog.
  • Advertising attribution: if — and only if — you allow tracking in Apple's App Tracking Transparency prompt, limited app events (such as app activation and subscription start) are shared with Meta Platforms to measure our advertising.
  • Push notification tokens: a device token from Firebase Cloud Messaging so we can send you notifications, such as alert delivery receipts.
  • Crash and diagnostics data: crash reports and performance data via Firebase Crashlytics, used to keep the App reliable.
  • Site data: the email address (and, optionally, city) you submit to a waitlist form, your cookie and analytics consent choice (stored locally in your browser), privacy-respecting analytics if you accept them, and standard technical logs (including IP address) processed by our hosting provider to serve pages securely and prevent abuse.

4. Location data and live-location links

When you trigger an alert or start a “Walk with me” session, the App sends your chosen contacts a text message containing a unique link on getholler.app created for that session. Anyone who has the link can open the page and see your live position while the session is active, together with the display name you chose. Location updates through the link stop when the session ends.

You are always the one who starts location sharing. Holler never shares your location with anyone other than the contacts you chose (and whoever they pass the link to), and we do not use your location for advertising or profiling.

5. Evidence recordings

During alerts the App records video from the front and back cameras as evidence. Audio recording is off by default, offered only where we understand it to be lawful in your region, requires your explicit opt-in, and is always disclosed on screen while active.

Recordings are uploaded to Google Firebase cloud storage, encrypted in transit and at rest, and are visible to you in the App's private logbook. They are deleted automatically 60 days after capture by a scheduled purge.

Deletion of recordings is deliberately server-controlled and append-only: recordings cannot be erased directly from a device, so someone who takes your phone cannot destroy evidence. When you delete your account, your data is deleted, and any remaining recordings are removed no later than the end of their 60-day retention window.

6. How we use your data, and our legal bases

We use your data for the purposes below. Where the GDPR or UK GDPR applies, our legal basis is shown in brackets.

  • To provide the safety features you use — sounding the alarm, sharing your live location with your chosen contacts, sending alert messages via SMS, recording evidence video, and maintaining your logbook (performance of a contract, Article 6(1)(b)).
  • To record audio during alerts, where available in your region (consent, Article 6(1)(a)); you can decline or switch this off at any time in the App.
  • To send you push notifications about your safety sessions and account, such as alert delivery receipts (performance of a contract and our legitimate interests, Article 6(1)(b) and (f)).
  • To manage your subscription, trial and purchases (performance of a contract, Article 6(1)(b)).
  • To understand how the Service is used and improve it (our legitimate interests, Article 6(1)(f), balanced against your rights, and consent where your jurisdiction requires it for analytics).
  • To measure the performance of our advertising via Meta (consent, Article 6(1)(a), given through Apple's App Tracking Transparency prompt; withdraw it at any time in iOS Settings → Privacy & Security → Tracking).
  • To keep the Service secure, prevent abuse, and diagnose crashes (our legitimate interests, Article 6(1)(f)).
  • To contact you about Holler if you join a waitlist on the Site (consent, Article 6(1)(a)). You can withdraw consent at any time.
  • To respond to your requests and comply with our legal obligations, including data protection requests (legitimate interests and, where applicable, legal obligation, Article 6(1)(c)).

7. Cookies and local storage on the Site

The Site uses a small amount of browser local storage to remember your consent choice. This is strictly necessary and does not require consent.

We load privacy-respecting analytics on the Site only after you accept analytics in our consent banner. We do not use advertising or cross-site tracking cookies on the Site. You can change or withdraw your choice at any time by clearing your browser storage or contacting us, and analytics will stop loading.

8. Who we share your data with

We do not sell your personal data, and we do not share it with data brokers. Your data is shared only:

  • With the trusted contacts you chose: they receive your alert message, the display name you chose, and the live-location link for the session.
  • With service providers (processors) who help us run the Service, acting on our instructions under contract: Google (Firebase — authentication, database, cloud storage, push notifications, crash reporting), RevenueCat (subscription management), PostHog (analytics, hosted in the United States), Twilio (SMS delivery), Vercel (Site and live-location page hosting), and Resend (email delivery).
  • With Meta Platforms, for advertising attribution and measurement, only if you allow tracking in Apple's App Tracking Transparency prompt.
  • With Apple, which processes your subscription purchase as an independent controller.
  • With authorities or other parties where the law requires it, or where reasonably necessary to protect the rights, property or safety of you, us or others.

9. International transfers

Stolen Orbit LLC is established in the United States, and our service providers process data in the United States and other countries. Where personal data of EEA or UK users is transferred outside the EEA or the UK, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another recognised transfer mechanism then in force, such as the EU-US Data Privacy Framework and its UK extension where the recipient is certified. You can ask us for more detail using the contacts in this policy.

10. How long we keep your data

We keep personal data only as long as we need it:

  • Evidence recordings: deleted automatically 60 days after capture (see section 5).
  • Alert and session data: kept in your private logbook until you delete your account.
  • Trusted-contact numbers: until you remove the contact in the App or delete your account.
  • Account, survey and subscription data: until you delete your account, plus any short period required to comply with legal obligations.
  • Analytics, attribution and crash data: retained for limited periods configured with each provider, and in aggregate thereafter.
  • Site waitlist details: until Holler launches in your market and for a reasonable period afterwards, or until you ask us to delete them. Security and server logs are kept for a short period.

11. How we protect your data

We use encryption in transit and at rest, access controls, the append-only evidence design described in section 5, and the principle of data minimisation — starting with not requiring your name or email to use the App. No method of transmission or storage is completely secure, but we take reasonable and appropriate measures to protect your personal data.

12. Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Have inaccurate data corrected, and incomplete data completed.
  • Have your data erased (the right to be forgotten).
  • Restrict or object to our processing.
  • Receive your data in a portable format, or have it transmitted to another controller, where technically feasible.
  • Withdraw consent at any time, without affecting processing carried out before withdrawal.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not carry out such processing).

13. How to exercise your rights, and complaints

The fastest way to delete your data is in the App itself: Settings → delete my data. This deletes your account and associated data server-side, without needing to contact us.

For any other request, email us at privacy@getholler.app. Because accounts are anonymous, we may ask you to make the request from the App or verify control of the device so we can locate your data. We will respond within one month, which we can extend by two further months for complex requests, and we will tell you if we do. There is normally no fee.

If you are in the EEA or the UK and you believe we have not handled your data properly, you have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EEA it is the data protection authority in your country of residence, place of work, or where the alleged infringement took place. We would appreciate the chance to address your concerns first.

14. US state privacy rights

If you are a resident of California or another US state with an applicable privacy law, you have the right to know what personal information we collect and how we use it, to request access to and deletion or correction of your personal information, to receive it in a portable format, to opt out of the sale or sharing of personal information and of targeted advertising, and not to be discriminated against for exercising these rights.

Sensitive personal information. Your precise geolocation and your camera and microphone recordings are “sensitive personal information” under some state laws. We collect them only with your permission and use them only to provide the safety services you request — never to infer characteristics about you, and never for advertising. We therefore do not use or disclose sensitive personal information for purposes that would require a “limit the use of my sensitive personal information” right, and we do not sell it.

Sale and sharing. We do not sell personal information. If you allow tracking in Apple's App Tracking Transparency prompt, our disclosure of limited app events to Meta Platforms for ad measurement may be considered “sharing” for cross-context behavioural advertising under California law; you can opt out at any time by disabling tracking for Holler in iOS Settings → Privacy & Security → Tracking. On the Site, we honour browser opt-out preference signals such as Global Privacy Control. We do not sell or share the personal information of consumers we know to be under 16.

To exercise these rights, use the in-app deletion described in section 13 or contact us at privacy@getholler.app. You may use an authorised agent where your state's law provides for one. If we deny a request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state's attorney general.

15. Children's privacy

Holler is intended for users aged 16 and over. We set this floor to reflect the highest digital-consent age across the markets we serve. The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

16. Third-party links and services

The Service may link to third-party sites and services (for example the App Store or social media). We are not responsible for their privacy practices, and we encourage you to read their policies.

17. Changes to this policy

We may update this policy as Holler develops or as the law changes. We will update the date at the top of this policy when we do, and we will make material changes clear — including in the App where appropriate. Your continued use of the Service after a change means you accept the updated policy.

18. Contact us

For any question about this policy or your personal data, contact Stolen Orbit LLC at privacy@getholler.app, or by post at 8 The Green, Suite B, Dover, DE 19901, United States.

Holler is not a substitute for emergency services

If you are in immediate danger, call your local emergency number directly: 112 across Europe, 999 in the UK, 911 in the US. Holler alerts a contact you choose and helps you raise the alarm, but it does not call the emergency services for you, and it may not work in all circumstances.