Yalerta

Privacy policy

Version 1 · 20 September 2026

This is a courtesy translation. The Spanish text is the one that binds; if the two differ, the Spanish version prevails. Read it in Spanish.

Yalerta keeps little and explains everything. It never publishes data about people, does not track you, and deletes what is no longer needed within the periods you see below. The original file of a photo, a clip or a voice note is deleted the moment its processed version is published. This page complies with the General Data Protection Regulation (GDPR) and Ley Orgánica 3/2018 (LOPDGDD, the Spanish data protection act).

Who the controller is

The controller is Iñigo Escribano Calvo, sole trader (autónomo). Tax ID (NIF) and postal address: in the Legal notice.

For anything about your data: privacidad@yalerta.com. Given the size and the kind of processing, the law does not require us to appoint a data protection officer; that mailbox is handled directly by the owner.

The anonymous session and the account

Looking at the map needs nothing. The first time you do something that does need it (joining a waiting list, flagging a report, voting, saving a zone) an anonymous session is created on your device: a random identifier, with no e-mail address or name. In the app it is created the first time you open it.

To publish, vote, receive alerts or ask for help you need an account. You can create it with your e-mail address and a one-time code, or by signing in with your Google or Apple account. In all three cases the anonymous session becomes that account, with the same identifier, so whatever you had saved before is kept. There is no password, and your e-mail address is shown to nobody.

If you sign in with Google or Apple we receive only your e-mail address (or the relay address Apple creates if you choose “Hide My Email”) and an identifier of that account: the name and picture those services send are discarded the moment they are stored, by a rule in the database itself, and are never shown or kept.

What data, what for and for how long

DataWhat forLegal basisHow long
E-mail addressCreating the account, signing in with a code, sending you the decision on a notice if you ask for itPerformance of the contract (terms of use)Until you delete the account
Sign-in with Google or Apple: e-mail address (or Apple’s relay address), the identifier of your account with that service and, if you signed in with Apple, a token whose only use is telling Apple that you deleted the accountSigning in without a code and, when you delete the account, revoking the access at ApplePerformance of the contract (terms of use)Until you delete the account
Account identifier, trust level, counters of reports and confirmations, date you accepted the termsSo that your reports have someone behind them and the community knows how far to trust them; preventing abuseContract and legitimate interest (quality and anti-abuse)Until you delete the account
Notification token (Expo or Web Push), platform, language, app versionDelivering the alerts you asked forContractUntil you turn alerts off or delete the account
Zones: the point you choose (home, work…), radii, quiet hours, muted categoriesAlerting you to what happens near those placesContractUntil you delete them or delete the account
“Follow me”: a map cell of ~1 km² and its centre, not your exact positionAlerting you to emergencies near wherever you areConsent (the switch in Zones)2 hours; we keep no history of your movements
Position at the moment you report, confirm or ask for helpChecking that you are within 200 m of what you describe; in “Ask for help”, telling those who can come where you areLegitimate interest (truthfulness) · consent when you press “Ask for help”Only the distance to the report is kept; the report’s point, rounded to ~11 m, lives with the report
Reports you publish: category, rounded point, filtered note of up to 140 characters, timeSo that people nearby know about it and confirm itContract and consent when you publishPublic while active; the note is deleted 90 days after the report closes; the fact remains with nothing that leads to you
Voice notes: original audio, automatic transcription, the text you validateDescribing what you see without typing; only what you approve is publishedConsent when you record and when you publishThe original is deleted as soon as the published copy exists; the public audio, 90 days after the report closes; the transcription, 90 days
Photos and short clips (camera only): original, version with faces and number plates blurred, transcription of the sound to check that it identifies nobody, and a log of what that process did (detections, frames followed by motion tracking, decision on the sound, renditions)Showing what is happening without identifying anyone; only the blurred version is published; being able to evidence the diligence appliedConsent when you capture and when you publish; legitimate interest for the automatic blurring and its logThe original is deleted as soon as the blurred version exists; the blurred version, 90 days after the report closes; the transcription, 90 days; the log, with the report
Your declaration when you send a report (the version of the text and the moment you accepted it)Evidencing that whoever publishes answers for their content, in the face of claims or requestsContract; legitimate interest (defence against claims)With the report; if you delete the account, the report remains with nothing that leads to you
Confirmations (“Still there”, “It’s over”, “It’s false”) and their distanceWorking out each report’s confidenceLegitimate interestThe vote is kept; who cast it is forgotten after 90 days
Circles: the circle’s name, members, “I’m fine” with its timeSo that your people know you are fineContractUntil you leave the circle or delete the account; they never store your position
Notices: reason, details, optional e-mail addressReviewing the content and replying to you (Digital Services Act)Legal obligationThe e-mail address, 30 days after the decision; the file, 12 months
Waiting list: e-mail address, city, the layer you are interested inLetting you know when it arrivesConsentUntil you unsubscribe, or 3 years
Log of notifications sent and usage limits (per account, or per an irreversible fingerprint of the IP address: we do not store the address)Not repeating alerts, respecting the daily maximum, curbing abuseLegitimate interestNotifications, 90 days; limits, 1 day
Technical server logsSecurity and failuresLegitimate interestUp to 30 days, at our hosting provider
App usage data: random install identifier, platform, version, language, chosen city, screens opened and actions (creating a zone, sending a report, opening a notification). No position or free text; not linked to your accountKnowing how Yalerta is used and improving it: how many people open it, what works and what does notLegitimate interestEvents, 180 days; identifier, 13 months from last use; afterwards only aggregate figures with no identifiers
Ranking: your alias (a made-up name, for example “Faro Atento 412”), your mascot, your points and the city where you earned them. Never your e-mail address, nor which reports you have publishedRecognising those who confirm and get it right, and giving a reason to come backLegitimate interestWhile you have an account; the points history, 13 months

The ranking is only visible inside the app and only shows the alias, the mascot and the points: nobody can get from there to what you have published, or find out who you are. You can leave it whenever you like from “Me” and keep earning points and levels for yourself. If you delete the account, your alias is freed and your points disappear.

Usage data is tied to the install, not to you: the server cannot link that identifier to your account, which is why it does not appear in “Download my data” and does not change when you delete the account. The website is measured without cookies, in aggregate figures (details on the cookies page).

We try not to process third parties’ data: the categories have no fields about people; every note, typed or dictated, goes through an automatic filter that blocks names, descriptions, nationalities, number plates, phone numbers and social-media handles before it is published; in photos and clips, faces and number plates are blurred and the sound is removed when it names or describes someone. Whoever uploads the content declares that it contains nobody’s data and answers for it; if an image still identifies someone, we take it down as soon as we know (flag it from the report itself or write to privacidad@yalerta.com).

Who processes it on our behalf

  • Supabase (database, accounts and files), in Frankfurt.
  • Vercel (website, API and agent), functions in Frankfurt and a global delivery network; it also counts visits to the website without cookies (Vercel Web Analytics, aggregate figures only). On the home page we use the approximate city Vercel derives from your IP address to show you the nearest map first; we do not store it.
  • Expo (sending notifications to the apps), United States; Apple and Google deliver the notification to your phone.
  • OpenFreeMap (map tiles): it receives your IP address when the map loads, like any web server.
  • Anthropic and OpenAI, through Vercel AI Gateway: classifying text from public sources, filtering notes and transcribing voice notes. No training on your data.

There is a data processing agreement with each of them. We do not sell data or pass it on to anyone else. The only exception is requests from authorities, which we explain in the next section.

Google and Apple do not process data on our behalf when you sign in with them: they check that it is you, in your own account, under their own privacy policies and as independent controllers, and we only receive the result (e-mail address and identifier). For notifications they do act on our behalf, as the list says.

Outside the European Union

The data lives in the European Union. Notifications to phones go through Expo, Apple and Google, sign-in with Google or Apple through those two companies, and the text models through Anthropic and OpenAI, all based in the United States: in those cases the European Commission’s standard contractual clauses or the EU–US Data Privacy Framework apply.

Requests from authorities

The judicial police or the public prosecutor (Ministerio Fiscal) can ask us directly for the data that identifies who is behind an account — the e-mail address, the identifier, the sign-up and last-access dates — and we are obliged to hand it over (article 588 ter m of the Ley de Enjuiciamiento Criminal, the Spanish criminal procedure act). For everything else — a photo, a clip, a voice note, the text of a note, a transcription or a moderation file — judicial authorisation is needed (article 588 ter j). Without that authorisation we do not hand it over. We may also receive European production or preservation orders from another Member State (Regulation (EU) 2023/1543), with the same split: identification data may be requested by a prosecutor; content has to be requested by a judge.

What we do not have, we cannot hand over. The original of every photo, clip or voice note is deleted the moment its processed version is published, so from that instant there is no copy to give. We are not a telecommunications operator: Ley 25/2007 (the Spanish data retention law) does not bind us and we keep no data “just in case”. Nor do we keep your exact position, a history of your movements, your IP address in our database or private conversations: they do not exist in Yalerta.

An authority can order us to preserve, for a time, data already in our possession (article 588 octies of the Ley de Enjuiciamiento Criminal: 90 days, extendable once up to 180). When that happens, we block the automatic deletion of what the order names, and of that alone; it stays frozen, is not shown or used for anything, and is deleted as soon as the order lapses. If you ask to delete your account while such an order covers something of yours, the deletion is deferred and we explain it to you (article 17(3) of the General Data Protection Regulation); you can complain to the Agencia Española de Protección de Datos, the Spanish data protection authority.

If an authority asks us for information about you, we tell you: what they asked for, who asked, on what legal basis, what we handed over and whom you can turn to if you disagree (article 10(2) of Regulation (EU) 2022/2065, the Digital Services Act). We write to your account’s e-mail address, at the latest when we hand the information over. The only exception is when the order itself forbids us from telling you — for example, proceedings declared secret —; then we tell you as soon as we can. The point of contact for authorities is legal@yalerta.com, published under Contact.

Your rights

Access and portability: “Download my data” in your account or in the app’s “Me” tab gives you a complete copy on the spot. Erasure: “Delete my account” in the same places; everything personal is deleted and your published reports remain as anonymous facts. If an authority has ordered us to preserve something of yours, that part cannot be deleted while the order lasts: the deletion is deferred, we explain it to you and we complete it as soon as the order lapses (see “Requests from authorities”). Rectification, objection, restriction and any question: privacidad@yalerta.com, with a reply within a month at most. If you think we are not doing it right, you can complain to the Agencia Española de Protección de Datos (aepd.es).

Under-14s

Yalerta is for people aged 14 and over, the age from which Spanish law lets you consent for yourself. If we learn that an account belongs to someone younger, we delete it.

Automated decisions

An automatic filter decides whether a note is published or not, and a model transcribes voice notes. None of those decisions has legal effects on you or affects you significantly: at most, a note is not published. If you think it got it wrong, every notice or appeal is reviewed by a person.

How we protect it

Encryption in transit always, and at rest in the database; access to the data only from our server, never directly from the browser or the app; rounded coordinates and presence in coarse cells; deletion of the original at publication and scheduled deletion of the rest within the periods above; and a crisis protocol to take content down fast if it were ever needed. If there were ever a breach that affects you, we will tell you and notify the Agency within the 72 hours the law sets.

Changes to this policy

The version and the date are at the top. If a change matters, we will let you know in the app and on the website before it takes effect.

If something here looks wrong, write to us and we will fix it.