Jetra EWS — Android app & Web platform · Effective 25 July 2026
Jetra Early Warning System (“Jetra EWS”, “we”, “us”) operates a nationwide public-safety reporting and rapid-response platform for Nigeria. This Privacy Policy explains what personal data our Android application and web platform collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It is written to comply with the Nigeria Data Protection Act 2023 (NDPA), the Google Play User Data policy, and applicable international standards.
1. Who is the data controller
Jetra EWS is the data controller for personal data processed through the app and platform. For any privacy question, request or complaint, contact us at privacy@jetraews.com.
2. Information we collect
2.1 Information you provide
Account details: full name, email address, phone number, sex, date of birth, state and Local Government Area (LGA) of residence, and password.
Reports and tips: incident category, description, plain-language details, photos, videos, and voice notes you attach.
SOS sessions: live audio captured while an SOS is active, and any transcript generated from it.
Missing person / stolen vehicle listings: the details and images you choose to publish.
Call intake records (call-centre agents only): notes captured during citizen calls.
Staff verification data (field agents, analysts, super administrators only): agency, role, badge or ID reference, and any documents you upload during verification.
Support & correspondence: any message you send us by email or in-app chat.
2.2 Information collected automatically
Precise location (GPS): captured when you install the app, submit a report, trigger an SOS, or open the map. Location access is required for the core early-warning functionality of the app; you can revoke it at any time in your Android settings, but core features will stop working.
Microphone audio: only while an SOS session is active, so the audio can be streamed for responder awareness and AI transcription. The microphone is not accessed at any other time.
Camera & photo library: only when you choose to attach media to a report or profile.
Device & push token data: device model, OS version, app version, language, time zone, and the Firebase Cloud Messaging / WebPush token used to deliver alerts.
Diagnostics & security logs: crash traces, error events, and audit records of sensitive actions (for example, when staff reveal a reporter’s identity).
Approximate area names: we reverse-geocode your coordinates using Google Maps so the UI can show a human-readable place name.
2.3 Sensitive data
Reports, SOS recordings and missing-person listings can contain sensitive information (health, criminal allegations, images of minors). We treat this data with elevated safeguards: staff access is role-based, every reveal of identifying data is audited, and retention windows are shorter than for ordinary account data.
3. Why we use your data (legal bases)
Provide the service — routing alerts, dispatching responders, showing maps and status updates, and delivering the features you request. (Contract.)
Protect life and public safety — sharing your live location and SOS audio with security agencies and emergency responders during an active incident. (Vital interests & public interest.)
Verify incidents and prevent abuse — deduplication, AI triage, media analysis (for weapons / violence signals), and fraud prevention. (Legitimate interests.)
Communicate with you — sending push alerts for geo-fenced warnings, transactional emails, and support responses. (Contract / consent.)
Aggregate analytics & hotspot forecasting — statistical dashboards for analysts and ministries. Data used here is anonymised or aggregated. (Legitimate interests / public interest.)
Security, audit and legal compliance — detecting misuse, keeping audit logs, and responding to lawful requests. (Legal obligation / legitimate interests.)
4. AI processing
We use third-party AI models (currently Anthropic Claude and OpenAI Whisper / GPT-4o audio transcription) strictly to: triage incident severity, translate reports between English, Hausa, Yoruba, Igbo and Nigerian Pidgin, transcribe SOS audio, analyse media for safety signals, summarise analyst dashboards, and forecast hotspots. These providers process data on our behalf under contractual data-processing terms and are not permitted to train their public models on your data. AI outputs are advisory only — human staff make final verification, dispatch and enforcement decisions.
5. Who we share data with
Security agencies, ministries and emergency responders — where necessary to act on an incident or SOS. Access is scoped by agency and by role.
Authorised Jetra EWS staff — call-centre agents, field agents, analysts and super administrators — subject to role-based access controls and audit logging.
Service providers (processors) that host or power the platform: Supabase (database, auth, storage), Cloudflare (edge hosting), Google (Maps, Firebase Cloud Messaging, Play services), Anthropic and OpenAI (AI models). Each is bound by data-processing terms.
Public listings — details you publish on a missing-person or stolen-vehicle listing are visible to the public by design. Reporter contact details on these public views are hidden from anonymous visitors.
Legal & regulatory disclosures — where we are compelled by law, court order, or a lawful request from a competent Nigerian authority.
We do not sell your personal data and we do not use it for third-party advertising.
6. International transfers
Some of our processors store or process data outside Nigeria (for example, in the EU or the United States). Where this happens, we rely on the transfer safeguards permitted under the NDPA — including standard contractual clauses and adequacy-equivalent controls — to keep your data protected to the same standard.
7. How long we keep your data
Active account data — kept while your account is active.
Resolved incidents — anonymised after the configured retention window (default ≈ 6 months) so they can no longer be linked back to you, then permanently deleted after the deletion window (default ≈ 2 years). Super administrators can adjust these windows in the Command Center.
SOS audio — retained only for the shorter of the incident retention window or until the associated case is closed.
Audit logs — retained for a longer period for security, oversight and legal-compliance reasons.
Backups — encrypted backups are kept on a rolling basis and cycle out automatically.
8. How we protect your data
Encryption in transit (TLS) and at rest for the database and stored media.
Row-level security policies so users only see data their role permits.
Optional two-factor authentication (TOTP) for staff and citizens.
Auditing of every sensitive action (identity reveals, role changes, retention purges).
Least-privilege access for staff and for third-party processors.
9. Your rights
Under the NDPA and comparable frameworks, you have the right to:
Access the personal data we hold about you.
Correct data that is inaccurate or incomplete.
Request deletion of your account and personal data — see our Delete your account page for the fastest route.
Object to, or restrict, certain processing (for example, non-essential analytics).
Withdraw consent for optional processing at any time.
Port your data in a common machine-readable format.
Lodge a complaint with the Nigeria Data Protection Commission (NDPC).
To exercise any of these rights, email privacy@jetraews.com. We respond within 30 days.
10. Android permissions we request
Location (fine / background) — to attach precise location to reports and SOS sessions, and to deliver geo-fenced alerts near you.
Microphone — only while SOS is active, to stream audio for responders and generate a transcript.
Camera & media — only when you choose to attach a photo or video to a report.
Notifications — to deliver early-warning alerts and case updates.
Foreground service — to keep an SOS session running when the screen is locked.
You can revoke any of these permissions in Android Settings; features that depend on them will stop working.
11. Children
Jetra EWS is not directed to children under 13. Minors between 13 and 18 may use the app only with the consent and supervision of a parent or guardian. If you believe a child has provided personal data without appropriate consent, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy to reflect new features, legal requirements or operational changes. Material changes will be highlighted in-app and by updating the effective date at the top of this page.