Raw audio never leaves the phone.
An on-device analyzer discards raw audio unless its shape matches the impulse signature of a firearm discharge. Only a small acoustic fingerprint — a few hundred bytes — ever leaves the phone.
One canonical statement of what leaves the phone, what doesn't, and what the network records. This page is the source of truth for every privacy claim on this site — when wording on another page appears to disagree, defer to the language here.
An on-device analyzer discards raw audio unless its shape matches the impulse signature of a firearm discharge. Only a small acoustic fingerprint — a few hundred bytes — ever leaves the phone.
Audio is not retained after a candidate event has been scored. Whether a transient, scoring-only buffer ever exists on-device is not asserted here — see the wording note below for how other pages currently describe it.
An on-device detector watches for the impulse signature of a firearm discharge — not loud noises in general. Detection runs locally; it is not a continuous stream of speech or ambient sound leaving the phone.
There is no continuous location trail. Only the coarse GPS fix tied to a corroborated event is captured — and only enough to triangulate a source area, not a moving dot.
The payload that leaves the phone is a fingerprint: a few dozen scoring features, a timestamp, a confidence score, and a coarse GPS fix. There is no raw audio in the payload. There is no PII.
Each sealed record is bounded: timestamp, coarse GPS, fingerprint, confidence. Records are opt-in by geography and time window, and exportable to you. Partner sharing requires opt-in and is narrow.
No contact list is read. No persistent device identifier is broadcast or sold. No per-user behavior profile is built. Each phone is a witness; the record is the artifact.
There is no continuous location logging and no per-user behavior profile. The network records events, not people. What you hold is the record, not a trail.
While consolidating, we noticed small wording differences across pages of this site. The home page suggests there is no audio buffer; the Security page says on-device buffers are discarded within hours. Both phrasings can be honest at the same time — but they do not match at a glance, and we do not want you to have to reconcile them. This page is the source of truth, and the rest of the site is being aligned to the language above. Where wording on another page appears to disagree, defer to the language above. We have not added any new technical claim about whether a transient audio buffer exists; we flag the inconsistency rather than invent a resolution.
The Privacy FAQ and the Security page go deeper on individual topics.