ECAPS.DEV ("we," "our," or "us") operates the KitaKita mobile application ("the App"). This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations, as administered by the National Privacy Commission (NPC) of the Philippines.
By creating an account and using KitaKita, you consent to the data practices described in this policy.
1. Information We Collect
1.1 Information You Provide
- Account information: name, email address, phone number, date of birth (for age verification), and profile photo.
- Family circle data: circle names, member relationships, and invite codes you generate or accept.
- Messages: text messages sent within your family circles through the App's chat feature.
- Event data: events you create including titles, descriptions, locations, and participant lists.
- Emergency contacts: SOS contact numbers and emergency message content you configure.
1.2 Information Collected Automatically
- Location data: precise GPS coordinates collected in the foreground and background to enable real-time family location sharing and SOS alerts. Background location is collected only while you are an active member of a family circle and have granted permission.
- Device information: device model, operating system version, unique device identifiers, and Firebase Cloud Messaging (FCM) tokens for push notifications.
- Usage data: app interaction logs, feature usage patterns, and crash reports (via Firebase Crashlytics).
1.3 Information from Third-Party Services
- Firebase Authentication tokens (Google Sign-In, email/password)
- Firebase Cloud Firestore (data storage)
- Firebase Cloud Messaging (push notifications)
2. How We Use Your Information
- Core functionality: enabling real-time location sharing among family circle members, in-app messaging, and event coordination.
- Safety features: sending SOS alerts with your location to designated emergency contacts via in-app notifications and SMS.
- Age verification: confirming users meet the minimum age requirement of 13 years.
- Account management: creating, maintaining, and authenticating your account.
- Push notifications: delivering alerts for circle invitations, SOS events, messages, and app updates.
- Service improvement: analyzing anonymized usage patterns and crash reports to improve app stability and features.
3. Legal Basis for Processing
Under the Data Privacy Act of 2012 (RA 10173), we process your data based on:
- Consent: you provide explicit consent when creating your account and enabling location services.
- Contractual necessity: processing required to provide the services you requested.
- Legitimate interest: improving service quality, preventing fraud, and ensuring platform safety.
- Legal obligation: compliance with Philippine law, including responding to lawful government requests.
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We share data only as follows:
- Within your family circle: your location, messages, and profile information are visible to members of circles you have joined.
- SOS recipients: when you trigger an SOS alert, your real-time location and emergency message are sent to your configured emergency contacts.
- Service providers: we use Google Firebase services (Firestore, Authentication, Cloud Messaging, Crashlytics) to operate the App. Google's privacy practices are governed by the Google Privacy Policy.
- Legal requirements: we may disclose information when required by Philippine law, regulation, court order, or government request, or to protect the safety of our users.
5. Data Storage and Retention
- Storage: your data is stored in Google Firebase (Cloud Firestore) servers. Firebase infrastructure operates under Google's security certifications (SOC 2, ISO 27001).
- Retention: we retain your personal data for as long as your account is active. Location history is retained for up to 24 hours for the location trail feature, then automatically purged.
- Deletion: upon account deletion, we cascade-delete all associated data across all collections within 30 days, including: profile data, circle memberships, messages, events, location records, and FCM tokens.
6. Data Security
We implement reasonable security measures to protect your personal information, including:
- Firebase Authentication with secure token management
- Firestore Security Rules restricting data access to authorized circle members
- HTTPS/TLS encryption for all data in transit
- Server-side validation of user permissions for all data operations
No method of electronic storage or transmission is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Your Rights Under RA 10173
As a data subject under the Data Privacy Act, you have the following rights:
- Right to be informed: you have the right to know how your data is being collected and processed.
- Right to access: you may request a copy of your personal data held by us.
- Right to object: you may object to the processing of your data in certain circumstances.
- Right to erasure (deletion): you may request deletion of your data by deleting your account through the App's settings, or by contacting us directly.
- Right to rectification: you may update or correct your personal data through your profile settings.
- Right to data portability: you may request your data in a structured, machine-readable format.
- Right to file a complaint: you may file a complaint with the National Privacy Commission (NPC) at https://www.privacy.gov.ph if you believe your data privacy rights have been violated.
To exercise any of these rights, contact us at the address provided in Section 12.
8. Children's Privacy
KitaKita is intended for users aged 13 years and older. We do not knowingly collect personal information from children under 13. If a parent or guardian becomes aware that their child under 13 has provided us with personal data, please contact us and we will promptly delete such information.
For users between 13 and 17 years old, we recommend that a parent or guardian create the account and manage the child's participation in family circles.
9. Background Location Disclosure
KitaKita collects your precise location data in the background (when the app is closed or not in use) for the following purposes:
- Continuous family safety: so family circle members can see your real-time location at any time.
- SOS alerts: so your emergency contacts receive your current location immediately when you trigger an SOS, even if the app is not open.
You can disable background location at any time through your device's Settings > Apps > KitaKita > Permissions > Location. Disabling background location will prevent real-time tracking and may delay SOS alerts.
10. SMS Permission Disclosure
KitaKita requests SMS permission solely to send SOS alert messages to your designated emergency contacts when you activate the SOS feature. The App does not read, store, or access your SMS inbox or message history.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the App and updating the "Effective Date" above. Your continued use of the App after changes constitutes acceptance of the revised policy.
12. Contact Us
If you have questions, concerns, or wish to exercise your data privacy rights, you may contact us at:
You may also file a complaint directly with the National Privacy Commission (NPC) of the Philippines at https://www.privacy.gov.ph.