Halovia
Back to landing page

Halovia

Halovia MVP privacy

What the Halovia MVP collects, why it is used, how it is shared, and where production legal review is still required.

Information stored

The backend stores account identity, chosen display name, contacts, journey details, destination, genuine device coordinates during active sharing, route metrics, safety events, viewer sessions, and retention preferences. Exact locations are not written to application logs by design.

Where it is stored

Structured records use a Cloudflare D1 database. Vehicle images use a private R2 bucket and are served only after owner authentication or a valid viewer token. Theme, language, locale, reduced-motion choice, and a bounded temporary location queue may remain in browser storage.

Processors and sharing

The hosting environment supplies authenticated identity. OpenFreeMap, Photon, and community OSRM services receive the map, destination-search, and route requests needed for the journey experience under their respective terms. A holder of an active shared-journey link receives only the journey fields shown on the read-only view. No advertising or analytics integration is included.

Deleting data

Users can revoke viewer sessions, end sharing, remove vehicle images, clear local cache, or delete their backend account data. Completed journeys are configured for 7- or 30-day retention and the backend exposes a scheduled cleanup job to enforce deletion without a user request.

Security and legal limitations

Transport encryption and platform storage controls reduce risk but do not make a safety service infallible. A public production launch still requires an independent security audit, legal and regulatory review, data-processing agreements, incident response, and jurisdiction-specific retention analysis.

Halovia supports journey sharing and safety check-ins. It does not replace emergency services; use your phone’s normal emergency options when immediate help is needed.