Privacy Policy

Last updated: September 2026

About DUPHIX

This Privacy Policy explains how DUPHIX handles information used by its passive safety application. DUPHIX is planned for Android and iOS, and some technical behavior may differ by platform. This policy describes the current product design and may be updated as the service develops.

DUPHIX performs scheduled checks during the routines a user chooses. It can warn the user when permitted activity information has not changed and can send an automatic SOS alert to selected recipients when the warning flow finishes without a response. DUPHIX is not an emergency service or a guarantee of rescue.

Information DUPHIX may handle

Depending on the feature and platform, DUPHIX may handle the following categories:

  • An installation App ID and the installation credential used to authorize requests. The credential is stored securely on the device; the App ID is also recorded by DUPHIX systems so an installation can be recognized.
  • Safety settings such as protection state, timezone, daily activity windows, and the selected automatic check interval.
  • Checkpoint identifiers, scheduled times, checkpoint outcomes, and activity-change results needed to operate and recover a safety check.
  • Push notification registration information, including an FCM token and its platform, associated with the installation App ID.
  • App-ID recipient identifiers required to route an automatic SOS request. The recipient set is selected and frozen on the device for that request.
  • Operational request, delivery, retry, and security information needed to protect the service and deliver safety notifications.
  • Advertising, consent, and related technical information handled by the advertising SDK described below, where advertising is enabled and applicable.

DUPHIX does not use an account, login, email address, or phone number as a user identity. It does not claim to continuously collect location, audio, video, or medical information.

Information stored on your device

The application stores its installation identity and credential in secure device storage. Safety settings, activity snapshots used for comparison, warning state, notification state, local SOS presentation state, and the in-app Contacts list are stored in the application’s local storage where needed for the feature.

DUPHIX Contacts are App-ID entries and optional private nicknames entered by the user. They are not the device’s entire address book. The nickname and local contact row remain on the device; the backend does not receive the local Contacts list.

Information sent to DUPHIX systems

The Android implementation sends the information needed to allocate and authenticate an installation, register its push token, save safety settings, claim and report checkpoints, and submit an automatic SOS request. An SOS request contains the checkpoint identity, a request identifier, and the selected recipient App IDs needed for push routing.

DUPHIX systems retain operational safety and push-delivery records needed for active checks, recovery, deduplication, retry and reconciliation, SOS routing, abuse or security protection, and operational integrity. The request-scoped recipient identifiers are validated and used for delivery; they are not a permanent backend Contacts table. Issued App IDs are kept in the installation registry and are not recycled.

The current design does not provide a fixed deletion period for every operational record. Information is retained only for as long as reasonably necessary for the operational purpose for which it is used, subject to applicable requirements and the needs of reliable recovery and delivery.

Safety checks and SOS alerts

The application compares permitted activity information between scheduled checks on the device. It is not designed as continuous monitoring. The comparison, warning sequence, and automatic SOS decision occur on the device. When an SOS is created, the backend validates the request and queues push delivery to the selected App-ID recipients.

The service may process checkpoint and delivery state so it can reject duplicate effects, retry interrupted work, and present an incoming SOS alert. It does not upload the user’s entire address book.

Notifications and Firebase Cloud Messaging

DUPHIX uses Firebase Cloud Messaging (FCM) or the platform’s equivalent push infrastructure for safety-related and other application notifications. FCM and related providers may process technical information, such as a push token and delivery metadata, that is required to route a notification. Firebase is a delivery service; it is not the authority for DUPHIX safety state or the decision to create an SOS.

Advertising and third-party services

DUPHIX is designed to be supported by advertising on ordinary application surfaces. The current application integrates AppLovin MAX for advertising. Where enabled and applicable, advertising SDKs or their mediation partners may handle device, advertising, interaction, consent, or similar technical information according to their own policies, platform settings, and configuration. Vendors and availability may vary by platform, region, and configuration.

Advertising does not control safety state. Safety-critical transitions, warnings, SOS handling, and incoming recipient alerts take priority over advertising. DUPHIX does not add analytics, cookies, or tracking code to this website.

Device permissions

The Android implementation may request permissions or system capabilities needed for the following purposes:

  • Notifications, so the application can show warnings and safety-related alerts.
  • Activity recognition, so permitted activity information can be collected for the scheduled comparison.
  • Internet access, so the application can communicate with DUPHIX systems and push infrastructure.

The verified Android manifest does not request camera, microphone, precise location, SMS, phone-call, Bluetooth, or address-book permissions. The in-app Contacts feature uses App IDs entered by the user and is separate from the device phonebook.

Data retention and minimization

DUPHIX is designed to minimize information. Data stays local when the feature does not require server processing. Backend records are limited to the operational information needed for safety checks, push delivery, recovery, retry, reconciliation, security, and service integrity. No arbitrary fixed retention period is stated because different operational records have different lifecycles.

When a user stops using the application or uninstalls it, local application data is generally removed by the platform according to its normal uninstall behavior. Backend operational records may remain for as long as reasonably necessary for their operational purpose. There is no user-account deletion workflow because the current product has no user-account system.

Security

DUPHIX uses reasonable technical and organizational measures intended to protect information, including authenticated installation requests, secure local storage for installation credentials, access controls, and operational safeguards around push delivery. No method of storage or transmission can be guaranteed to be perfectly secure.

Children's privacy

DUPHIX is not designed specifically as a service for children. Age-related requirements and available protections may depend on applicable law and platform rules. We do not use this policy to set an age threshold that has not been approved for the product.

International processing

DUPHIX and its service providers may process information in countries other than the country where a user lives. The locations and providers used can depend on the platform, region, configuration, and operational services. This policy does not claim a specific data-center location or a particular legal transfer mechanism.

Your choices

  • You can control notification permission through the operating system.
  • You can control activity-related permission through the operating system; refusing it can prevent the related safety check from working.
  • You can add, change, or remove App-ID Contacts and their local nicknames in the application.
  • Advertising consent or preference controls may be provided by the platform, the advertising SDK, or the applicable consent flow.
  • You can stop using or uninstall the application through the operating system.

The current product has no account dashboard or in-app account-deletion control. Uninstalling does not necessarily immediately remove operational records already needed by DUPHIX systems.

Changes to this Privacy Policy

DUPHIX may update this policy when the product, platforms, service providers, or data practices change. The “Last updated” date will identify the latest published version. Material changes should be communicated in a manner appropriate to the service and the affected users.

Contact

DUPHIX is operated by VDAST CO., LTD.

Privacy questions may be sent to vuduyanh1294@gmail.com. This is the current public contact channel and may later be replaced by a dedicated DUPHIX or VDAST address.