NattevaktNorsk
Back to Nattevakt

Privacy Policy

How Nattevakt handles local app data, location, push notifications, advertising, Premium, and technical website data.

Effective
21 August 2026
Last updated
24 August 2026

On this page

  1. Scope and operator
  2. Mobile app data
  3. Third-party services
  4. Website data
  5. Purposes and bases
  6. Storage and deletion
  7. Rights and choices
  8. Transfers and security
  9. Children and contact

1. Scope and operator

This Privacy Policy explains how the Nattevakt mobile application for iOS and Android and the Nattevakt website handle information. It also explains which information stays on your device and which information is processed by Nattevakt or third-party services.

Nattevakt is an independent project developed and operated under the Nattevakt brand. For the purposes of this policy, Nattevakt is the controller responsible for the processing described here. For privacy questions and requests, email support@nattevakt.app.

Nattevakt has no user accounts, registration, authentication, or user profiles. The app does not ask for your name, email address, or phone number.

2. Information handled by the mobile app

Information stored locally

The following information is stored locally on your device through the app's local settings storage (SharedPreferences):

  • selected zones and their coordinates;
  • place names and zone radius;
  • language and notification settings;
  • incident history; and
  • onboarding state.

These local settings are not a Nattevakt user profile. They remain on the device until you change them, clear the app's data, or uninstall the app.

Location

The app may request access to your location to determine your position and help you create zones. Current location is processed by the app on your device for map and proximity features you choose to use. Nattevakt does not store raw current location in its Supabase backend. Coordinates for zones you create are stored locally as described above; a zone-derived topic may be sent to FCM for push subscriptions. Loading a map may disclose the requested map area and ordinary request data to OpenStreetMap. You can deny or revoke location permission in system settings, but some features will then be limited. Nattevakt does not create a long-term movement profile.

Push notifications and Supabase

Firebase Cloud Messaging (FCM) is used to deliver push notifications. The device's FCM token, platform, and token update time are transmitted to and stored in Supabase. Push subscriptions may use a topic formed from a zone selected by the user. A token is a pseudonymous device identifier; Nattevakt does not attach it to a Nattevakt account or named user profile because no such accounts exist.

Incident information and maps

Incident information is supplied by Politiloggen, Statens vegvesen, and Nattevakt's own Supabase backend. Maps are loaded using OpenStreetMap. These sources provide content and infrastructure; they are not presented as Nattevakt user profiles.

3. Advertising, subscriptions, and third-party services

Advertising and consent

Google AdMob supplies advertising and Google User Messaging Platform (UMP) manages advertising consent where required. On iOS, Nattevakt uses Apple's App Tracking Transparency (ATT) permission. An advertising identifier may be available to advertising services only in accordance with your choice and the applicable system permission.

If you do not consent to personalized advertising or do not allow tracking, Google may still provide limited or non-personalized advertising where permitted. Such delivery can still involve technical information such as IP address, device information, and ad interaction data under Google's policies.

Firebase Analytics and Firebase Crashlytics are not currently used in the app.

Premium and payments

RevenueCat and Apple App Store or Google Play Billing process purchases, subscription status, and Premium entitlements. Nattevakt can receive purchase or entitlement status needed to unlock and restore Premium, but does not receive your full payment-card details. Subscription management is described on the subscriptions page.

Providers and sources

  • Firebase / Google — push notification delivery.
  • Google AdMob and UMP — advertising and consent choices.
  • RevenueCat — subscriptions and Premium entitlement status.
  • Apple — App Store purchases, ATT, and platform services.
  • Google Play — Android purchases and platform services.
  • Supabase — backend, incident data, and FCM token records.
  • OpenStreetMap — map data and, depending on tile configuration, map requests.
  • Politiloggen / Politiet and Statens vegvesen — incident content sources.

4. The Nattevakt website

The website and the mobile app handle data differently. The website does not read the zones, coordinates, notification settings, event history, onboarding state, FCM token, or Premium status stored or used by the mobile app.

The website currently has no visitor analytics, advertising, contact form, or non-essential cookies, and does not use cookie-based behavioral tracking. A fictitious consent banner is therefore not shown. If analytics, advertising, or another non-essential technology is added later, Nattevakt will obtain any required consent before it loads and will update this policy.

Standard technical request data, such as IP address, request time, requested URL, browser information, and security events, may be processed by the future hosting or content-delivery provider to deliver and protect the website. The production hosting provider has not yet been selected and will be named here before deployment. The domain is managed through Cloudflare, which may process DNS or network-security metadata when its relevant services are enabled.

The current website loads fonts from Google Fonts. This means Google can receive normal request information such as an IP address and browser information when the font files are requested. Clicking an external link also takes you to a third party governed by its own privacy terms. If you email support, your email provider and Google's email services process the message; the website itself does not receive it through a form.

5. Purposes and legal bases

Where the GDPR applies, information is processed for the following purposes and bases:

  • Requested app functions: map, location, zones, incident display, notifications, and Premium access — to provide the service or take steps requested by you (GDPR Article 6(1)(b)).
  • Advertising choices: personalized advertising or access to an advertising identifier — consent where required (Article 6(1)(a)); consent can be withdrawn through the available privacy choices and system settings.
  • Purchases: processing and confirming subscriptions — performance of a contract (Article 6(1)(b)) and compliance with legal obligations where applicable (Article 6(1)(c)).
  • Security and operation: preventing abuse, protecting services, and maintaining reliable delivery — Nattevakt's legitimate interests (Article 6(1)(f)).
  • Support and privacy requests: responding to messages and documenting requests — performance of the service, legitimate interests, or a legal obligation, depending on the request.

6. Storage and deletion

  • Local app data: remains until you change it, clear the app's data, or uninstall the app.
  • FCM token records in Supabase: there is currently no fixed, implemented automatic retention period for stale tokens. Tokens, platform, and update time are retained for push delivery and operational management. A definite period will not be claimed until it is implemented. You can request deletion of server-side data by email; because there is no account, Nattevakt may need enough technical information to locate the relevant record.
  • Subscription, store, and advertising data: retained by RevenueCat, Apple, Google, and their services according to their policies, contractual needs, consent choices, and legal requirements.
  • Support messages: kept only as long as reasonably necessary to answer the request, protect legitimate interests, and meet applicable legal requirements.
  • Website security logs: retained according to the operational and security criteria of the selected hosting provider; the provider and any defined period will be added before production deployment.

7. Your rights and choices

Subject to the conditions in the GDPR, you may have the right to access, rectify, erase, restrict, or object to processing; receive portable data where applicable; and withdraw consent without affecting processing that was lawful before withdrawal. You may also complain to the Norwegian Data Protection Authority (Datatilsynet).

  • Delete local data by clearing app data or uninstalling the app.
  • Control location and notifications in device settings.
  • Use in-app advertising privacy choices and iOS ATT settings where available.
  • Manage purchases through Apple App Store or Google Play.
  • Email support@nattevakt.app for access or deletion requests concerning server-side data.

8. International transfers and security

Some providers may process information outside Norway or the European Economic Area. Where required, transfers must rely on a recognized safeguard, such as an adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism. The provider links above explain their arrangements in more detail.

Nattevakt uses reasonable technical and organizational measures appropriate to the limited information it handles, including limiting the data collected, using provider access controls, and using protected network connections where supported. No internet or storage system can be guaranteed to be completely secure.

9. Children, changes, and contact

Nattevakt is not directed to children under 13, and Nattevakt does not knowingly collect personal data from children under 13. If you believe a child has provided data through a third-party service or support request, contact us so the matter can be reviewed.

This policy may be updated when the app, website, providers, or legal requirements change. Material changes will be reflected on this page with a new “Last updated” date.

Operator: Nattevakt
Email: support@nattevakt.app
Website: nattevakt.app

Nattevakt

A calmer overview of police, fire, and traffic incidents near you.

Product

HomeHow it worksAvailability

Help and legal

SupportSubscriptionsPrivacyTerms

© 2026 Nattevakt

Made for Norway