Privacy Policy
The English-language version of this document is the official, legally binding version. Any translation is provided for convenience only; in the event of a discrepancy between the English version and a translation, the English version prevails.
1. Introduction
Tryggo ("we", "our", "us") is a web application designed and operated from Norway. We are committed to protecting your privacy and handling your data transparently. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
2. Information We Collect
We collect the following types of information when you use Tryggo:
- Account information: Email address, first name (optional), and authentication credentials.
- Profile information: Country of residence, who lives at each home — the adults by first name, children by first name and age group (child 3–15 or baby 0–2; no exact age or birth date), pets by name and kind — with optional photos of children and pets, special needs, living environment, and emergency preparedness preferences. Names and photos of children are entered by the adults of that home and are visible only to the home's members; they are never shared with third parties.
- Inventory data: Items you add to your essentials inventory, including names, quantities, expiration dates, categories, and images you upload.
- Device information: Push notification subscription data if you opt in to notifications.
- When you last opened the app: We record the time you last opened Tryggo while signed in — at most once every 15 minutes, and not while you are offline. It is a timestamp and nothing else: not your location, not what you did, not whether the app is open right now. Where it is shown is deliberately narrow: only during an active alert or an active check-in at one of your homes, and only to the other people who live at that home. It is not shown on a calm day, and it is not shown to someone who watches over a home without living in it. The reason for the limit is that “last opened the app two hours ago” cannot tell anyone whether you are alright — during an emergency it is a weak signal worth having while nobody has confirmed, and outside one it is only a record of your habits. There is no separate switch for it; it is removed when you delete your account (Section 7).
- Feedback you send us: The messages you write in the Feedback panel, and any screenshot you choose to attach. A screenshot is uploaded only when you pick one — nothing is captured automatically — and it may show whatever was on your screen at the time, which can include a home's name, its area, or the people in it, so please check before attaching. Your feedback messages and their screenshots are readable by our support team so we can act on them, and are not shared with any third party. You can ask us to delete your feedback conversation at any time.
- Country detection: We work out which country you are in from your device's time zone, which your operating system sets for you. This asks for no permission, sends nothing to us or to anyone else, needs no network, and updates by itself within hours of you arriving somewhere new. If the time zone cannot be matched to a country, we fall back to the country configured for your household. We use the country only to show the right emergency numbers and country guidance.
- Showing where you are on the map (optional): The Map page has a "Show where I am" button. When you tap it — and only then — your browser asks your permission to share your device's location, and we place a marker on the map so you can see where you are. Those coordinates stay on your device. They are drawn on the map and discarded; they are never stored, never sent to our servers, and never shared with anyone else. Nothing requests your location on your behalf: it is read only when you tap this button, or when you mark yourself safe after agreeing to share your location (next item). Your device location is not used to fetch weather or other hazard alerts — those are matched to your household's coarse grid cell on our servers (see Section 4).
- Your location when you mark yourself safe (optional): If you agree — we ask once, the first time you tap "I'm safe", and you can change your answer at any time in Settings → Preferences — then each time you mark yourself safe, your device's location at that moment (its coordinates and how accurate they are) is added to that safe mark. It is shown on the map to the people at your homes: the same people who can already see that you marked yourself safe, including anyone who watches over one of those homes from elsewhere. It is stored on our servers (Supabase, EU) for 24 hours and then deleted; it is removed straight away if you undo your safe mark, replaced by your next safe mark, and deleted with your account. We keep no history of where you have been, and we never look up an address or place name for it. If you say no, or your device does not share its location, your safe mark is saved without one. Someone at your home who taps "Check road conditions" on your location opens Google Maps with those coordinates (see Section 4).
- Emergency messages: When you send an emergency message, we store that you sent one, when, and your device's location at that moment (its coordinates and how accurate they are) — your device asks for permission first, and if you refuse, the message is sent without it. An emergency message always asks for your location, even if you chose not to share it with your safe marks, because it is how the people at your homes find you. It goes to everyone who shares a home with you, including anyone who watches over one of those homes from elsewhere, as a push notification, an email and a notice in the app, and they see your location on the map. You can send your location again or end the message ("I'm OK now") at any time; ending it tells the same people, marks you safe, and records where you are at that moment — ending an emergency message may come hours later from somewhere else, so the people who were told can see you are fine and where. That one location is recorded whatever your "share my location when I mark myself safe" setting says, because it closes the emergency you opened; it is deleted after 24 hours like any other. The location is deleted 24 hours after the message, and the message itself after 30 days; both are deleted with your account. We never look up an address or place name for it. Tryggo does not contact emergency services — an emergency message reaches only the people at your homes.
- Household location (optional): If you save a postcode or coordinates against your household, we store an approximate grid cell (~111×111 km) used to match incoming earthquake, tsunami, severe-weather, and wildfire events. The full coordinates are stored encrypted-at-rest and used for distance estimates shown in the app (e.g. "87 km away") and to decide whether an earthquake or wildfire is close enough to alert you. They are never sent to upstream alert providers per request — see Section 4 for details on how earthquake / tsunami alerts work without per-user location calls. The one exception is the optional weather map: if you tap "Check on Windy" on a severe-weather alert, coordinates rounded to ~1 km (not your exact location) are placed in the link that opens Windy.com, so the map centres on your area — see Section 4. The in-app Map page draws your homes locally in your browser; the map imagery it loads reveals only the area being viewed, never your saved coordinates as data — see Section 4. You can also place your home on a map by hand instead of, or to refine, a postcode. If you tap "Use my current position" there, your device's location only moves the map under the pin — nothing is saved until you confirm the point, and we never look up an address or place name for a point you have pinned.
3. How We Use Your Information
We use your information to:
- Provide and personalize the Tryggo service, including tailored preparedness recommendations based on your household profile.
- Send you expiration reminders and preparedness notifications (if you opt in).
- Improve our service and fix technical issues.
- Communicate with you about your account and service updates.
4. Third-Party Services
We use the following third-party services to operate Tryggo:
- Supabase: Our backend platform — the PostgreSQL database that stores your account, profile, household, inventory, emergency-plan, and in-app feedback data, plus authentication and the server-side functions that run the app. Hosted in the EU (Ireland). Your feedback messages are read only by our support team and are not shared with any third-party chat provider. See Supabase's privacy policy for details.
- Cloudflare: Application hosting, content delivery, and image storage, all kept in the EU. Cloudflare serves the app and routes its traffic (hosted in Ireland), and stores and optimizes the images you upload (profile pictures, item photos, photos of the pets and children at your home, and any screenshot you attach to feedback) on Cloudflare R2 under EU data jurisdiction. On devices without browser speech recognition, Cloudflare Workers AI (Whisper) also transcribes your short voice-dictation clips to text (see the voice entry below). It therefore processes technical connection data such as IP addresses and request metadata. Cloudflare also provides our page analytics (Cloudflare Web Analytics): a small script measures page views, referrers and page-load speed in aggregate, without cookies, without fingerprinting and without tracking you across other sites, so we can see where visitors come from and how fast pages load. See Cloudflare's privacy policy for details.
- Open Food Facts / Open Beauty Facts: Barcode product lookup. When you scan a product barcode, the barcode is sent to these open public databases to retrieve the product's name, brand, and quantity, which pre-fill the new item. No account data is sent. See their respective privacy policies for details.
- Anthropic (Claude): Automatic catalogue matching and Smart Update. When you add or scan an item, its name, brand, and quantity are sent to Anthropic's Claude API to suggest the closest catalogue entry, a category, and a unit. When you use Smart Update to record a stock change, the note you type or dictate is sent — together with the names, units, and quantities of your household's kit items — so Claude can interpret which items changed and by how much; you confirm every change before it is applied. No account identifiers are sent, and under Anthropic's commercial API terms these inputs are not used to train their models. See Anthropic's privacy policy for details.
- Voice dictation: Optional. When you tap the microphone to dictate a Smart Update note, your speech is converted to text in one of two ways, depending on your device. Where your browser provides speech recognition (e.g. desktop Chrome, Android), it is used directly — some browsers transcribe on-device, others (e.g. Chrome) send the audio to their vendor's speech service (e.g. Google), governed by your browser vendor's privacy policy; in this case we receive only the resulting text. Where that isn't available (e.g. the installed iOS app), we record a short clip (up to 10 seconds) and send it to Cloudflare Workers AI (Whisper, hosted in the EU) to transcribe; the audio is used only to produce the text and is not stored. Either way, the resulting text is then handled as the Smart Update note described above. You can always type instead.
- Resend: Transactional email — hazard alerts, check-in alerts, kit reminders, invitations to a home or plan, the welcome email, and account-related emails (e.g. sign-in and account deletion). We send your email address and the message content. See Resend's privacy policy for details.
- Brevo: Marketing emails. If you opt in to product-update emails, we share your email address with Brevo to manage that mailing list. See Brevo's privacy policy for details.
- Grafana (Faro): Performance monitoring and error reporting. Collects technical diagnostics — page views, performance metrics, error reports, and browser/device information. The only identifiers attached are system-generated, opaque account and household IDs we assign internally so we can group errors for debugging — never your name, email, or any of your content, and meaningless to anyone without access to our database. See Grafana's privacy policy for details.
- Google OAuth: Optional sign-in provider. When you sign in with Google, we receive your email address and basic profile information as authorized by Google.
- OpenStreetMap (Nominatim): Postcode geocoding. When you save a household location by postcode, the postcode and country are sent to the OpenStreetMap Nominatim service to resolve approximate coordinates, from which we derive your coarse grid cell. See the OpenStreetMap Foundation's privacy policy for details.
- National Weather Service (NWS): Severe-weather alerts for US grid cells. On a server-side schedule we query NWS using the coarse grid-cell centre (~111 km) of cells that have households — never your exact coordinates — and match the results to your cell locally. NWS is a US government service; data is public domain.
- OpenWeather: Severe-weather alerts for grid cells not covered by a national-authority feed (i.e. outside the US, Europe, Canada, and Japan). On a server-side schedule we query OpenWeather using the coarse grid-cell centre (~111 km) of cells that have households — never your exact coordinates. See OpenWeather's privacy policy for details.
- MeteoAlarm: Severe-weather warnings for European countries. We ingest MeteoAlarm's public per-country feeds on a server-side schedule and match warnings to your household's grid cell locally — no per-user coordinates are sent. See MeteoAlarm's privacy policy for details.
- Environment and Climate Change Canada (ECCC): Severe-weather alerts for Canada. We crawl ECCC's public CAP alert directory on a server-side schedule and match alerts to your grid cell locally — no per-user coordinates are sent. Government of Canada service; data is public.
- Japan Meteorological Agency (JMA): Severe-weather warnings for Japan. We ingest JMA's public XML feed on a server-side schedule and match warnings to your grid cell locally — no per-user coordinates are sent. Japanese government service; data is public.
- MetService (Meteorological Service of New Zealand): Severe-weather watches and warnings for New Zealand. We read MetService's public CAP feed on a server-side schedule and match warnings to your grid cell locally — no per-user coordinates are sent. MetService is New Zealand's official alerting authority for severe weather; the feed is public.
- Windy.com: Optional weather map. When you tap "Check on Windy" on a severe-weather alert, the app opens Windy.com in a new browser tab with your household coordinates rounded to ~1 km included in the link, so the map opens centred on your area. This happens entirely in your browser and only when you choose to open the map — nothing is sent to Windy unless you tap it, and we never include your exact location. See Windy's privacy policy for details.
- Google Maps: Optional road conditions and hospital search. When you tap "Check road conditions" (or "Road conditions") on a card on the Map page, the app opens Google Maps with the coordinates of that point in the link — a wildfire, your own position, a spot you marked, a home, or where someone at your home marked themselves safe or sent an emergency message — so the map opens there with traffic and road closures. When you tap "Nearest hospital" — on your own position, on where someone sent an emergency message, or on your own emergency message — the app opens a Google Maps search for hospitals around those coordinates. This happens entirely in your browser and only when you tap a button; nothing is sent to Google otherwise. See Google's privacy policy for details.
- USGS (U.S. Geological Survey): Earthquake feed (M2.5+ globally, last 24 hours). We poll the public global feed on a server-side schedule and match events against your household's coarse grid cell — your coordinates are never sent to USGS. Public domain US government service.
- EMSC (European-Mediterranean Seismological Centre): Earthquake feed (M2.5+ globally, ~200 most recent events). Polled the same way as USGS — global server-side fetch, cell-match locally, no per-user coordinates leaving our servers. See EMSC's terms for details.
- NOAA NTWC (National Tsunami Warning Center): Tsunami bulletins (Warnings, Advisories, Watches, Threats) for the Pacific, Caribbean, and US/Canada coasts. Polled the same way — global server-side fetch, cell-match locally, no per-user coordinates leaving our servers. NOAA is a US government service; data is public domain.
- NOAA PTWC (Pacific Tsunami Warning Center): Tsunami bulletins for the Pacific and other international ocean basins. Polled the same way — global server-side fetch, cell-match locally, no per-user coordinates leaving our servers. NOAA is a US government service; data is public domain.
- GDACS (Global Disaster Alert and Coordination System): Modelled global tsunami estimates, used to fill the coastal gaps the NOAA feeds don't reach (a joint United Nations / European Commission service). Polled the same way — global server-side fetch, cell-match locally, no per-user coordinates leaving our servers. See GDACS's terms for details.
- NASA FIRMS: Active-wildfire detections. On a server-side schedule we query the FIRMS area endpoint with a coarse bounding box around each grid cell that has households — never your exact coordinates — and match detections to your cell locally. NASA service; data is public.
- OpenFreeMap: Basemap tiles for the in-app hazard map. When you open the Map page, your browser loads map imagery for the area you are viewing directly from OpenFreeMap (a non-profit tile service) — so, like any web map, the requests reveal the map area on screen. No account data, household data, or saved coordinates are included in these requests. See OpenFreeMap's site for details.
- NASA GIBS: Live satellite wildfire-detection imagery shown on the in-app map. Loaded the same way as the basemap — your browser requests imagery only for the map area you are viewing; no personal or household data is sent. NASA is a US government service; data is public domain.
- MET Norway: Daily weather forecasts shown for your households. Our servers fetch forecasts on a schedule for coarse forecast points (rounded to about 1 km) derived from household postcodes — never your precise coordinates, and never from your device — so MET receives no per-user or per-household data. Forecast data is provided under MET's open licences (CC-BY 4.0 / NLOD).
These services process data in accordance with their own privacy policies. We share only the minimum data necessary for each service to function. No alert lookup ever uses your exact device location. Earthquake, tsunami, and feed-based weather alerts work without sending any per-user data to the upstream providers — we ingest public feeds on a schedule and match them to your household's grid cell entirely on our servers. The few point-based lookups (NWS, OpenWeather, and NASA FIRMS) send only the coarse grid-cell centre or bounding box (~111 km), shared by every household in that cell — never your precise coordinates.
5. Data Storage & Security
Your account and household data are stored securely on cloud infrastructure located in the European Union (Ireland). We use encryption in transit (HTTPS) and implement row-level security to ensure that your data is only accessible by you. Uploaded images are stored on Cloudflare R2 (EU jurisdiction).
6. Cookies & Local Storage
Tryggo uses browser local storage and session storage for authentication tokens and application state. We do not use third-party tracking cookies or advertising cookies. Your country is read from your device's time zone each time (see Section 2); it is not cached and no location is ever requested for it.
7. Your Rights
Under the GDPR and applicable Norwegian data protection law, you have the right to:
- Access: View all personal data we hold about you within the application.
- Rectification: Update your personal information at any time through Settings.
- Deletion: Permanently delete your account and your personal data — including your profile photo — from Settings; we do not retain it afterwards. Content you added to a shared household (such as item photos) belongs to the household and is removed when the household itself is deleted. This action is irreversible.
- Data portability: Your data is accessible through the application interface.
- Withdraw consent: You can disable notifications and email communications at any time.
8. Children's Privacy
Tryggo is not directed at children under 16, and a child cannot hold an account. We do not knowingly collect personal information from children themselves. Information about the children who live at a home — a first name, an age group (child 3–15 or baby 0–2) and an optional photo — is entered by the adults of that home, and only for two purposes: sizing the home's preparedness needs, and letting the people who live there mark a child safe during an alert or check-in. It is visible only to that home's members, is never shared with third parties, and is removed when the adults remove the child or the home.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of significant changes via email or in-app notification. Your continued use of the service after changes constitutes acceptance of the updated policy.
10. Contact
If you have questions about this Privacy Policy or your data, please contact us through the app.