Counts, never content.

Watching over you. Never watching you. Here is exactly what that means — what leaves your phone, what never does, and why you can check for yourself.

Audio is listened to and discarded on the device — no transcripts, and no passive streaming (the one exception, Live Watch, is below — and only you can start it). If you explicitly opt in to evidence recording, a threat clip is captured — and it stays in the app's private storage on the phone that recorded it, is deleted automatically if you mark the incident a false alarm, and expires on a schedule you can see. Your account only ever learns that a recording exists. Camera frames are analysed on the device and thrown away unless a confirmed threat makes you choose to keep evidence. Face data, if you opt in to face recognition, is stored in your phone's secure enclave and never syncs anywhere — the account only ever holds a count of enrolled faces. Voice-prints, if you opt in to voice recognition, work the same way: an embedding of how a voice sounds, on this phone only — Halo recognises who is speaking, never what they say, and no speech is ever transcribed. Your home location stays on the phone too: the geofence is judged on-device, so your coordinates never reach your account. Raw sensor streams — accelerometer, barometer, light, magnetometer — and every learned baseline are processed live and never uploaded. Your safe word and duress word are stored only as salted hashes; the words themselves exist nowhere.

There is exactly one way live audio or video leaves a phone, and only you can start it: Live Watch. If you open Live Watch on one of your phones from your dashboard, that phone turns its camera and microphone on and streams — to you, and only you — for as long as you keep the session open. It is never automatic and never passive: the phone shows a persistent "Live to owner" banner the entire time, starting a stream requires you to re-confirm it's you (Face ID on a phone, your password on the web), and every session and every action you take from it — sounding the alarm, alerting a contact — is written to the incident's audit trail. Close it and the camera and microphone go off; nothing is kept unless you separately chose to save evidence.

Some things we hold in a form that we ourselves cannot read. Your safe and duress words are salted, one-way hashed — there is no key, so nothing can decrypt them: not us, not a court order, not a thief with a copy of the database. And the most sensitive things of all — recordings, face templates, voice-prints, your location — we solved even more simply: we never take them in the first place. What we cannot read, no one can take.

If it isn't on this list, it doesn't leave the phone.

  • Sign-in email, display names, household name, member roles, invite emails.
  • Device names, platform, LiDAR yes/no, last check-in, charging state — so a phone that stops guarding is noticed.
  • Every setting: sensitivities, response ladder, engine tuning, schedules, quiet hours, radio mode, opt-in flags, welfare interval.
  • Safe/duress words as salted one-way hashes only — unreadable even to us.
  • Familiar-sound labels with their hours and per-signal reliability tallies — labels, never audio.
  • Incident records: timestamp, tier, peak confidence, signal-label timeline, sensor snapshot readings, your real/false answer, the written report if you generate one.
  • Recording metadata: that a clip exists, voice or video, its length, which phone holds it, retention status. Never the clip.
  • Trusted contact names, contact routes and alert delivery status.
  • SOS live-location pings, if you opt in — as ciphertext only. Your position is encrypted on your phone; the key travels inside the link your contacts receive and never touches our servers, so we relay bytes we cannot read. Deleted the moment you stand down, and within 24 hours regardless.
  • Live-session signalling, if you opt in to live SOS audio, remote live view or verified alarm — the connection handshake only (WebRTC offers, answers and network candidates), plus who asked, approved and when. The audio and video themselves travel directly between the two devices, encrypted end to end, and never touch our servers. Sessions expire after 10 minutes and the handshake records are deleted within 24 hours.
  • Your home Wi-Fi device list, if you opt in — hardware address, device name and maker, plus the labels and trust marks you set. Never your traffic, browsing or location.
  • Scam-check verdicts, if you use the scam checker — the verdict band, a category and the time. The message or screenshot you checked is discarded the moment it is judged; there is no column for it.
  • Everyday-routine bands, if you opt in — one coarse word a day (steady, shifted, or changed a lot), up to three plain reasons (less movement, irregular sleep, less contact), and the date. That is the whole of it. The routine itself — how much someone moved, when the lights went out, when the phone was used, whether it was home or away — is measured on the phone, kept on the phone, and compared against a baseline that never leaves the phone. No measurements, no times of day, no location. Switching it off deletes the bands too.
  • Anonymous sound contributions, if you opt in to help improve Halo — a feature vector (numbers describing a sound: how confident the classifier was, how it was classed, how often it recurred) plus your own “real” or “false alarm” answer. Never audio, never a recording, and audio cannot be reconstructed from it. These rows are unlinkable by construction: the table has no household, account or device column at all — not blanked, absent — and only a day-grain date. Off by default, and identical on free and paid; we will never charge you to keep your data private.

The microphone indicator stays on while Halo listens — it never listens invisibly. That includes the optional sleep-listening check: if you opt in, a brief pre-arm classification runs with the indicator showing, and the audio is discarded like all the rest. Trusted contacts get a courtesy note the moment you name them, and the "summon" feature — sounding an alert on their own phone — only works if they explicitly agree, and either side can withdraw. Face recognition requires a signed acknowledgement and each person's consent. The highest response tier — "call for help" — rings your trusted contacts and household owner, who decide whether to call the police; Halo never claims to dispatch police itself, and the tier is off until you opt in. Nothing in Halo watches anyone who hasn't been told.

If you turn on Online Footprint (it is off until you do), Halo checks whether details you choose to enrol — your name, usernames, email addresses — appear in data breaches or on the public web. That necessarily means sending those exact identifiers to two outside services: Have I Been Pwned for breach checks, and a web search provider for public mentions. A consent screen lists precisely what will be sent, to whom, and how often, before anything leaves — and you can withdraw any identifier at any time. What we keep is minimal: the address of a page, its title, a category, and a fingerprint of the snippet — never the page content itself. And we are honest about the limit: we find things and help you send removal requests (like GDPR erasure requests); no service, including ours, can delete someone else's website. Findings never touch the alarm engine — this is information for you, not a trigger.

When Halo is disarmed, nothing listens — the microphone is simply not running. While armed, the phone's microphone indicator is on and sound is classified into labels on the device, never recorded (recording is a separate, explicit opt-in). Hosting overnight guests? Tell them Halo is on watch — and use Guest night in the on-watch panel to pause listening and the camera until you stand down, leaving doors, windows and motion sensing active. Consent is a feature, not a footnote.

The app's Activity screen shows "sensing right now" — live confidence, each signal's contribution, and the last events seen — all computed on the phone in front of you. Your weekly report states the same promise and is built only from the account data described above. Every table in the backend is protected by row-level security: your household's data is readable by your household, and no one else.

Questions, or want your data deleted? Contact us and the household — devices, incidents, settings, everything — is purged. Halo.

Back to Halo