Watcho App
Privacy Policy
Effective Date: May 14, 2026
Last Updated: August 21, 2026
Operated by: Taque Studios (Adrian Hernandez)
Contact: adrian@taquestudios.com
Overview
Watcho is a read-only public-safety awareness map for Los Angeles County. This Privacy Policy explains what information Watcho handles, how it is used, and the choices available to you.
The short version: No accounts. No ads. No developer analytics. No cross-app tracking. Watcho does not transmit or store your map latitude or longitude in its backend. If you enable optional daily alerts, Watcho stores only an opaque push token and your English/Spanish language choice. Apple, Google, Expo, and Supabase process the technical requests needed to provide maps, notifications, and incident data under their own privacy terms.
1. Information We Collect
From Public Users
Aside from the optional push notification token and language described below, Watcho does not ask you for or create a personal profile. Specifically:
- We do not require an account or registration
- We do not collect your name, email, phone number, account, or other direct identity information
- We do not collect or store your advertising identifier
- We do not use cookies or tracking technologies
- We do not run analytics, and we do not track usage or behavior
Location Data
Watcho may request access to your device's location solely to center the map on your current position. This is an optional, device-side feature:
- Your latitude and longitude are not transmitted to or stored in Watcho's backend
- Your map location is not added to notification registration
- Watcho does not store location history
- You can use Watcho without granting location permission — the map will default to Los Angeles County
Push Notifications
Watcho can send one daily summary when new reports have been added. It does not send an alert for every report. Notifications are optional — you can decline permission or turn alerts off later and still use the full map.
If you enable notifications:
- Your device generates an opaque Expo push token, a pseudonymous app-installation routing identifier, using the Expo notifications framework.
- We store that token on our Supabase backend and send it to Expo (exp.host) so notifications can be routed to your device. Expo relays each alert through Apple's Push Notification service (APNs) on iOS and Google's Firebase Cloud Messaging (FCM) on Android. See the Expo entry in Section 3.
- We also store your selected notification language (
enores). - The notification registry does not include your name, contact information, account, advertising ID, map location, searched addresses, or location history.
- We use the token only to deliver notifications. We do not use it for advertising, analytics, profiling, or cross-app tracking, and disclose it only to the service providers needed for delivery.
- Turning alerts off in Watcho requests deletion of the remembered server token. You can also change permission in device Settings and then open Watcho once so the app can reconcile the change. You may email adrian@taquestudios.com with privacy questions, although without an account we may be unable to associate an email with a particular opaque token.
Watcho also deletes an old token during successful token rotation and deletes tokens that Expo immediately reports as no longer registered. Uninstalling an app does not provide a reliable deletion callback, so an unused token may remain until it is replaced, rejected, or the notification registry is cleared.
Crash Diagnostics
The current Watcho build does not transmit app crash reports to Watcho's backend. Earlier versions distributed before version 1.1.3 included a developer-operated path that could send an error message, stack trace, platform, OS version, and app version to Watcho's backend and Telegram. Version 1.1.3 removes that transmission, but this legacy disclosure remains while older versions may still be installed or distributed.
Address Search
When you use the search bar to look up a neighborhood or address, that text is sent to a geocoding service (provided by Apple on iOS and Google on Android) to convert it to map coordinates. This is a standard platform service. The search text is not transmitted to Taque Studios servers and is not stored by us.
Automatically Collected Technical Data
When you use the app, your device communicates with our backend service (Supabase) in two ways:
- Incident data requests — your device fetches the list of incident pins over HTTPS. This is a standard read request and does not include personal data.
- Real-time connection — the app maintains a persistent encrypted WebSocket connection (WSS) to Supabase Realtime so new incidents appear on the map without requiring a manual refresh. This connection carries no personal data.
Watcho's application database does not attach these requests to an account or store a history of which pins you viewed. Service providers may process standard network information, such as an IP address and request metadata, to operate and secure their services.
2. Information We Do Not Collect
To be explicit, Watcho does not collect:
- Name, email, or contact information
- Map location or location history in Watcho's backend
- Search history or queries
- Advertising identifiers or cross-app tracking IDs
- Developer analytics or cross-app activity stored by Watcho
- Financial information
- Health information
- App crash reports or device diagnostics from the current Watcho build
The optional push token is the only persistent app-installation identifier stored in Watcho's application database, together with the selected language. This statement does not describe technical data independently processed by platform mapping and push providers.
3. Third-Party Services
Watcho uses the following third-party services to deliver core functionality:
Supabase
We use Supabase to store and serve public incident data and the minimal notification registry. The public app registers and unregisters notification tokens through a validated, rate-limited server function; the notification table is not directly public. Supabase's privacy policy is available at https://supabase.com/privacy.
Expo (Expo Application Services, Inc.)
Watcho uses Expo's push service to deliver alerts. When you enable notifications, the opaque token stored in Watcho's backend is sent to Expo so it can route each notification through Apple's Push Notification service on iOS or Firebase Cloud Messaging on Android. On Android, the required Firebase Installations component creates a per-installation identifier and FCM processes app-version and device/app technical metadata needed to operate the service. Watcho does not receive the Firebase installation identifier in its application database, use Firebase Analytics, enable notification-delivery export to BigQuery, or send map locations or searched addresses to Firebase. See https://expo.dev/privacy.
Legacy crash diagnostics
Earlier Watcho versions could send crash diagnostics to Watcho's backend and relay them to a private Telegram channel for debugging. Version 1.1.3 removes that transmission. No other Watcho data was sent through this legacy path.
Telegram (Telegram FZ-LLC)
Telegram was used only by the legacy crash-diagnostic path described above. Version 1.1.3 no longer sends crash diagnostics to Watcho's backend or Telegram. See https://telegram.org/privacy.
Apple Maps / Google Maps
The app uses Apple Maps on iOS and Google Maps on Android to render map tiles and support platform geocoding. These providers receive the requests needed to return map or search results and apply their own privacy terms.
On Android, the Google Maps SDK automatically processes request and device metadata, SDK stack traces and crash metrics, an IP address, and a pseudonymous Maps SDK identifier. It may also process map interaction events such as panning and zooming when the app uses map camera APIs. Watcho does not store those identifiers, interaction events, or mapping SDK diagnostics in its application database.
4. Children's Privacy
Watcho is not directed to children under the age of 13, and we do not knowingly collect personal information from children. Watcho has no accounts and does not ask any user for personal information, so there is little for a child to provide — but if you believe a child's personal information has somehow reached us, please contact us at adrian@taquestudios.com and we will remove it promptly.
5. Data Security
Data is transmitted using encrypted HTTPS/WSS connections. The notification table blocks direct public access; the public app can register or unregister only through a validated, rate-limited server function. Service-role credentials are never included in the app.
6. Links to External Sources
Incident pins may include a link to an external source (such as a news article). Taque Studios is not responsible for the privacy practices of those external websites. We recommend reviewing the privacy policy of any external site you visit.
Family Donation Links (GoFundMe)
Some incident pins include a link to a GoFundMe campaign run by the affected family. When you tap the "Support this family" or "Donate" button, your device opens the GoFundMe campaign URL in your default web browser. No donation, payment, or financial information ever passes through the Watcho app or Taque Studios servers. All payment processing, account creation, and personal-data handling for donations is performed entirely by GoFundMe under their own privacy policy (https://www.gofundme.com/c/terms/privacy-notice). Taque Studios does not receive any funds, does not retain a percentage, and does not have visibility into who donates or how much.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. Continued use of the app after any changes constitutes your acceptance of the updated policy. We encourage you to review this page periodically.
8. Your Rights
You may use the map without location or notification permission. You can turn Watcho alerts off from the in-app daily-alert settings, which requests deletion of the remembered server token. You can also change permission in iOS or Android Settings; after doing so, open Watcho once so it can reconcile the change. Because Watcho has no user accounts, we may be unable to associate an email request with a particular opaque token without information from the device. For questions, contact adrian@taquestudios.com.
9. Governing Law
This Privacy Policy is governed by the laws of the State of California, United States, without regard to its conflict of law provisions.
10. Contact Us
If you have any questions about this Privacy Policy, please contact: