legal
Privacy Policy
Last updated: 5 June 2026
This Privacy Policy explains how alamak labs ("we", "us", "our") collects, uses, stores, discloses, and protects personal data in connection with the imokie mobile and web application (the "Service"). We are the data controller for the personal data described below. By using the Service you acknowledge that you have read and understood this Policy.
Who we are and how to contact us
The Service is operated by alamak labs. For any privacy enquiry, data subject request, or to exercise the rights described in this Policy, contact us at privacy@getimokie.com. If your local law requires us to appoint a representative or data protection officer, those details will be made available on request.
Data we collect
Account data. When you create an account we collect identifiers such as your name (or chosen handle), email address, phone number (if provided), authentication credentials, language and time-zone, and device identifiers.
Check-in activity. We record the timestamp of each daily check-in, missed check-ins, reminder events, and the state of any nudges sent to you or your circle. This is the minimum activity needed for the Service to function.
Circle and emergency contacts. You may add contacts to your "circle" and to your emergency-contact list. We store the name and contact details (email, phone, or both) that you provide for those people, together with the notification preferences you set. You are responsible for ensuring you have a lawful basis to share their information with us (see "Information about other people" below).
SOS data. When, and only when, you actively trigger SOS we collect and transmit to your circle and/or emergency contacts: (a) your live device location for the duration of the SOS session, and (b) automated ambient voice recordings of short duration captured by your device microphone. SOS data is not collected during ordinary use of the Service.
Vault contents. Anything you place in your encrypted vault — passwords, account-recovery instructions, letters, documents, media — is encrypted on your device with a key that we cannot read. We store only the resulting ciphertext. We never see vault contents in the clear and cannot recover them if you lose your key.
Technical and diagnostic data. We collect basic technical data such as IP address, device type, operating system version, app version, crash logs, and aggregated usage analytics. Where the law treats IP address as personal data, we treat it accordingly.
Payment data. If the Service offers paid features, payments are processed by third-party payment processors. We receive transaction confirmations and limited billing metadata but do not store full card numbers on our servers.
How we use your data and our legal bases
We process personal data only where we have a lawful basis to do so, including:
Performance of a contract — to create and operate your account, deliver check-ins and reminders, run the SOS flow when you trigger it, store and release the vault according to your instructions, and provide customer support.
Legitimate interests — to secure the Service against fraud and abuse, debug and improve product quality, conduct aggregated analytics, and communicate service-related updates. We balance these interests against your rights and have determined that the processing is proportionate.
Consent — for optional marketing communications, optional analytics cookies, and any other processing for which consent is required by local law. You may withdraw consent at any time without affecting prior lawful processing.
Vital interests — to share your location and voice data with the people you have nominated when you trigger SOS, where doing so may be necessary to protect your life or physical safety, or that of another natural person.
Legal obligation — to comply with applicable law, lawful requests from public authorities, court orders, or to defend our legal rights.
The legacy release (digital estate)
The vault is designed to be released to the beneficiaries you have named only after a sustained period of missed check-ins and after we have sent you multiple reminders. The exact thresholds are configurable within the Service. We rely on your instructions and cannot independently verify your status; you are responsible for keeping your circle, beneficiaries, and release settings up to date.
The legacy-release feature is a contractual convenience offered by the Service and is not a substitute for a validly executed will, power of attorney, or other testamentary instrument under your local law. We make no representation that release of vault contents constitutes a legally effective bequest, and we recommend you consult a qualified estate-planning professional.
Information about other people
When you add a person to your circle, emergency-contact list, or beneficiary list, you are sharing their personal data with us. You confirm that you have the right to do so and that you have informed them, where required by law, that their data will be processed by us for the purposes described in this Policy. A person whose data has been provided to us may contact us at any time to request access, correction, or deletion of their information.
Sharing and disclosure
We share personal data only as described below.
Your circle, emergency contacts, and beneficiaries — receive the specific information you have configured (check-in status, SOS location and audio, or vault contents on legacy release).
Service providers — we use vetted third parties for cloud hosting, push notifications, SMS/email delivery, payment processing, crash reporting, and analytics. They process data on our behalf under written agreements and are not permitted to use it for their own purposes.
Legal and safety — we may disclose data if required by law, by a valid legal process, or if we reasonably believe disclosure is necessary to protect the rights, property, or safety of any person.
Corporate transactions — in the event of a merger, acquisition, or asset sale, personal data may be transferred, subject to the acquirer continuing to honour this Policy or providing equivalent protections.
We do not sell your personal data and do not share it for cross-context behavioural advertising.
International transfers
Personal data may be processed in countries other than the one in which you reside. Where data is transferred out of the United Kingdom, the European Economic Area, or another jurisdiction with data-export restrictions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement, or an equivalent mechanism recognised by your local law.
Security
We use industry-standard administrative, technical, and organisational measures to protect your data, including encryption in transit (TLS) and at rest, strict access controls, audit logging, and regular security reviews. Vault contents are encrypted end-to-end with a key held only by you; consequently, we cannot recover vault contents if your key is lost. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
Retention
We retain personal data only for as long as necessary for the purposes set out in this Policy. Account data is retained for the lifetime of your account and for a limited period thereafter to satisfy legal, accounting, or reporting obligations. Check-in metadata is retained on a rolling basis and is automatically deleted after the period stated in your in-app settings. SOS recordings are retained for the minimum period necessary to deliver them to your circle and to handle any related dispute, after which they are deleted. Encrypted vault ciphertext is retained until the vault is released, you delete it, or your account is closed.
Your rights
Depending on your jurisdiction (including under the UK GDPR, EU GDPR, California Consumer Privacy Act, and similar laws), you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to certain processing; obtain a portable copy of your data; withdraw consent; and lodge a complaint with your supervisory authority. To exercise these rights, contact us at the address above. We will respond within the period required by your local law.
From within the Service you can also export your data, delete individual entries, or wipe your account entirely from a single screen.
Children
The Service is not directed to children under 16 (or the equivalent minimum digital age in your jurisdiction) and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
Cookies and similar technologies
The website uses a minimal set of cookies and similar technologies that are strictly necessary to operate the site, plus, where you consent, optional analytics. You can manage cookie preferences through your browser settings.
Changes to this Policy
We may update this Policy from time to time. Material changes will be notified in-app or by email before they take effect. The "Last updated" date at the top of this Policy indicates when it was last revised. Continued use of the Service after an update constitutes acceptance of the revised Policy where permitted by law.
Not an emergency service
imokie is a personal-safety companion app. It is not an emergency response service, medical device, or replacement for contacting your local emergency number. In any life-threatening situation, call your local emergency services first.