Privacy Policy — Concuss

Last updated: 23 July 2026

 

This policy explains what personal data the Concuss app and Concuss impact sensor collect, why we collect it, and what rights you have over it. For any privacy question or request, contact us at concuss.sensor@gmail.com.

1. What Concuss does

Concuss is a cycling safety product. A helmet-mounted sensor monitors acceleration and motion while you ride. When it detects a suspicious impact, the Concuss app can alert the emergency contacts you have nominated.

Concuss is not a medical device and does not diagnose concussion or any other injury. It is an alerting tool. It may fail to detect an impact, or may report an impact where no crash occurred. Never rely on it as your only means of getting help.

2. Data we collect

Sensor and impact data. Acceleration, rotation, and impact-event data recorded by the helmet sensor. This includes continuous motion recording during a ride, and the full sensor window around any detected impact together with its magnitude and time. It is transmitted to your phone over Bluetooth and uploaded to our server. If you label an event in the app — crash, drop, pothole, knock, or false alarm — that label is stored alongside the event and used to improve detection.

Location data. If you grant permission, the app records your device’s location so that an alert can tell your emergency contacts where you are. Your location is captured at the moment an impact is detected, and for up to two minutes afterwards so that we can tell whether you have moved away from the site. It is not recorded at any other time. Because an impact can happen while the app is in the background, iOS will ask you for “Always” location permission.

Emergency contact details. The names, phone numbers, and/or email addresses of the people you nominate to be alerted after an impact. These are held on your phone, and are sent to our server with each alert so that it can pass them to our SMS provider for delivery.

Guardian pairing. If you use in-app guardian alerts instead of SMS, our server holds the paired device’s public key, display name, and push notification token so that it can relay an alert. The content of a guardian alert is end-to-end encrypted between your phone and your guardian’s phone; our server holds only ciphertext it cannot read.

Device and diagnostic data. The helmet’s sensor identifier, an identifier generated by the app for your installation, and a push notification token. With each impact alert we also record your phone’s battery level and whether it is in Low Power Mode, so that a contact knows whether your phone is about to go offline. Our server and the network provider in front of it log the IP address you connect from. We do not run any analytics or crash-reporting code inside the app, and we do not collect your device model, operating system version, app version, or helmet firmware version.

We do not collect payment details, contacts from your address book beyond the ones you enter yourself, or any health record data. The app asks for access to your address book only so that you can pick a contact from it; nothing is read unless you select it.

3. Why we collect it, and our legal basis

Data

Purpose

Legal basis (GDPR)

Sensor and impact data

Detecting impacts; improving detection accuracy

Contract performance; legitimate interest

Location

Telling emergency contacts where you are

Consent

Emergency contacts

Sending impact alerts

Contract performance

Device identifiers

Linking your data to your helmet and to your app installation

Contract performance

Device and diagnostic data

Fixing faults and improving reliability

Legitimate interest

You can withdraw consent for location at any time in iOS Settings. Doing so means alerts will not include your position.

4. Where your data is stored

Sensor data, impact events, and the location captured at the time of an impact are transmitted to and stored on our server, which we operate ourselves in Switzerland. Data in transit is encrypted with TLS. The server’s own disk is not encrypted. Access to it is restricted to the operator, and backups are encrypted before they leave the machine. Concuss is a prototype, not yet a hardened commercial service; please take that into account when deciding what to entrust to it.

The helmet sensor stores ride and impact data in its own onboard memory until it syncs with the app. A file is erased from the helmet only after our server confirms it has been received.

If your phone cannot reach our server at the moment of an impact, the alert — including your location — is held on your phone and retried for up to two hours, then discarded.

5. Who we share it with

Your emergency contacts. By design, when an impact is detected, the people you have nominated receive an alert containing the fact that an impact was detected, an impact score and estimated severity, your location as a map link, and a warning if your phone’s battery is low or in Low Power Mode. The message does not contain your name — your contacts identify you by the fact that you nominated them. You are responsible for telling those people that you have listed them, and for having their permission to do so.

Service providers. Apple (push notification delivery, and TestFlight if you are a beta tester); Twilio (SMS delivery — a United States provider, so an alert and the contact number it is sent to leave Switzerland); Cloudflare (secure routing of traffic to our server; it terminates the encrypted connection and sees the IP address you connect from). The server that stores your data is operated by us, not by a third-party host. We do not use any advertising or analytics service.

Legal. We may disclose data where required by law.

We do not sell your personal data, and we do not use it for advertising.

6. How long we keep it

Impact and sensor data: kept for as long as you take part in the beta, and deleted within 30 days of your asking us to remove it. Emergency contact details: held on your phone until you remove them; on our server only as part of alerts already sent. Diagnostic records: 12 months.

When you delete the app or ask us to end your participation, all associated server-side data is deleted within 30 days. An alert already delivered to an emergency contact — an SMS they have received — cannot be recalled.

7. Your rights

Under Swiss data protection law (FADP) and, where it applies, the EU GDPR, you have the right to:

     Access the personal data we hold about you

     Correct inaccurate data

     Have your data deleted

     Restrict or object to processing

     Receive your data in a portable format

     Withdraw consent at any time

     Lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), or with your national supervisory authority in the EU

To exercise any of these, email: concuss.sensor@gmail.com. We will respond within 30 days.

8. Beta testing

If you are using Concuss through Apple TestFlight, Apple collects usage and crash data as described in Apple’s own privacy policy. Concuss itself contains no crash-reporting or analytics code — that data is collected by Apple, and only if you have opted in to sharing it with developers. Beta builds may be less reliable than released versions. Do not rely on a beta build of Concuss as a safety system.

9. Security

Traffic between the app and our server is encrypted with TLS. Guardian alerts sent through the app are end-to-end encrypted between your phone and your guardian’s phone. Access to the server is restricted to the operator, and backups are encrypted. If you believe you have found a security problem, please contact us at the address below.

10. Changes to this policy

We will post any changes on this page and update the date above. Material changes will be notified in the app.

11. Contact

concuss.sensor@gmail.com