Skip to content
Salvus
  • Home
  • About
  • Guide
EN/BG
Download

Privacy Policy

Last updated: September 10, 2026

On this page

  • 1. Data Controller
  • 2. Information We Collect
  • 3. How We Use Your Data
  • 4. Analytics & Consent
  • 5. Accident Risk-Zone Warnings
  • 6. Crowd-Sourced Slow-Down Zones
  • 7. Data Sharing
  • 8. Data Retention
  • 9. Legal Basis (GDPR)
  • 10. Your Rights
  • 11. International Transfers
  • 12. Children’s Privacy
  • 13. Changes
  • 14. Contact
  • Data Sources & Attribution

Salvus (“we,” “our,” “us”) is a mobile application designed to improve road safety by alerting drivers about speeding events and historically dangerous locations nearby. We respect your privacy and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable laws.

1. Data Controller

Salvus is operated by an individual: Toncho Lozev, Bulgaria. The operator is the data controller responsible for your personal data.

For any privacy question or to exercise your rights, contact us at: support@salvusmobile.com.

2. Information We Collect

  • Location data: GPS coordinates, speed, and heading. Collected while a session is active, including in the background, to detect nearby speeding and deliver alerts. Detecting a speeding event processes location about both the vehicle detected as speeding and the nearby drivers who are warned; in every case you are identified only by a pseudonymous identifier, and alerts never reveal who the speeding driver is. Live location is short-lived; a record of each alert you trigger or receive is kept for up to 30 days so it can be shown to you in the app (see §8).
  • Alert history: for each alert you trigger or receive — the time, the location, the speed involved, and the applicable speed limit. Shown only to you, in the app, and only while you have an active subscription. A record of an alert you received contains nothing identifying the other driver.
  • Device & account information: device model, operating system, app version, your Firebase user ID (anonymous by default, or linked to Apple/Google if you sign in), your email address if you sign in with Apple or Google (or Apple’s private-relay address, if you choose to hide your email), and a push notification token (Firebase Cloud Messaging) used to deliver alerts to your device.
  • Hazard reports you file: if you report a slow-down zone, the coordinates you are at when you file it, plus a one-way token derived from your user ID and two short-lived reporting counters. See §6.
  • App usage data: session timestamps, notification events, and crash logs.
  • Analytics & diagnostic identifiers (only if you consent — off by default): an app-generated instance/installation identifier (Firebase installation ID), your IP address (transient — used to establish the connection and derive approximate, coarse location at the network level), and in-app behavioral events and screen-view events. See §4.
  • Subscription data: product identifier, purchase/entitlement status, renewal/cancellation/refund status, transaction identifiers, platform, and app user ID (your Firebase user ID), processed via RevenueCat and the app stores. We do not receive or store your full payment card details.

You are not required to provide your name, email, or phone number to use Salvus. If you choose to sign in with Apple or Google, your email address (or Apple’s private-relay address, if you opt to hide it) and a unique account identifier are stored on your Firebase authentication record to secure your account and preserve your data across devices. We do not collect your name or phone number, and we never receive your password.

3. How We Use Your Data

  • Provide the core service: speeding detection and alerts.
  • Show you a history of the alerts you have triggered and received, including on a map (a subscription feature).
  • Publish crowd-sourced slow-down zones from hazard reports, and rate-limit reporting to deter abuse.
  • Determine active user limits by country (free vs subscription access).
  • Detect and diagnose crashes and keep the app reliable.
  • Understand feature usage and improve the app (product analytics — only with your consent).
  • Verify and manage subscription status.
  • Comply with legal obligations (GDPR requests).

4. Analytics & Consent

We use Firebase Analytics to understand how features are used (for example, in-app events and screen views) so we can improve the app. Analytics collection is off by default and only takes place if you opt in. You can grant or withdraw analytics consent at any time in the app’s settings; withdrawing consent stops further analytics collection and has no effect on any safety feature.

Independently of analytics consent, we operate essential crash reporting (Firebase Crashlytics) and minimal diagnostic logging to keep the app stable and secure. This runs under our legitimate interest (see §9) and does not include behavioral analytics.

Separately, our website (salvusmobile.com) uses privacy-friendly, cookieless analytics (Umami) to understand aggregate visitor activity — such as page views, which download links are clicked, and the site language. This does not set cookies, does not store any identifier on your device, and does not track you across sites; it collects only anonymous, aggregated statistics and no personal data. Because it involves no cookies and no personal data, it requires no consent and is unrelated to the in-app analytics described above.

5. Accident Risk-Zone Warnings

The app can warn you as you approach historically dangerous crash locations. This feature is powered by public, anonymized accident data published by the Bulgarian Ministry of Interior (MVR), which is bundled into the app. Detection runs entirely on your device — no location data is sent to us or to any third party for this feature, and it works fully offline. You can turn these warnings off at any time in the app’s notification settings.

6. Crowd-Sourced Slow-Down Zones

The app lets you report a temporary hazard on the road ahead — an accident, an obstacle, standing water — so that other drivers approaching the same spot can be warned to slow down. Reporting is entirely voluntary; you can use every other feature of the app without ever filing a report.

When you file a report, your device sends us the coordinates you are at, at that moment. From that report we store:

  • The hazard itself: its position, when it was first reported, and how many distinct people have reported it. This is the only part other drivers’ devices ever receive. It describes a place, not a person: it carries no identifier of yours, and a single report is one point, never a track of your journey.
  • A reporter token: a one-way, salted cryptographic value derived from your user ID (HMAC-SHA256), kept in that zone’s reporter list for one purpose — to answer “has this person already marked this spot?”, which is what stops one person confirming their own report. It is never sent to any other user’s device and never written to our logs. Because it is derived from your user ID, we treat it as personal data relating to you even though it cannot be read back into your ID without our secret key.
  • Two reporting counters keyed to your user ID: one enforcing a cooldown between reports, one counting your reports for the current day. They exist only to rate-limit reporting (one report per minute, up to 30 per day) and to deter abuse.

How long each of these lives is set out in §8. Note in particular that a zone — and the reporter tokens attached to it — lives for one hour from the most recent report on that zone, not from your report: while people keep reporting the same spot, the zone stays live and its reporter tokens stay with it.

Detection of a slow-down zone happens on your device: your phone downloads nearby zones and decides on its own whether to warn you. We are not told which zones you have been warned about, and no location is sent to us for that purpose. You can turn these warnings off at any time in the app’s notification settings.

7. Data Sharing

We do not sell your data. We share personal data only with the providers below, in the roles and under the safeguards shown:

Provider Role Data shared Location Transfer safeguard
Firebase / Google LLC Processor Authentication, Firestore, cloud functions, push notifications (FCM), Analytics (opt-in), Crashlytics EU + USA Standard Contractual Clauses
RevenueCat, Inc. Processor Subscription/entitlement state (see §2) USA Standard Contractual Clauses
Apple (App Store) / Google (Google Play) Independent controllers Purchase, billing, renewals, refunds for your platform EU + USA Their own terms & safeguards
Sentry Processor Backend error and performance monitoring EU + USA Standard Contractual Clauses
Render Processor / host Hosting of our location-processing backend EU (Frankfurt) hosting; US processing reserved under Render’s DPA EU Data Privacy Framework / Standard Contractual Clauses
OpenStreetMap & mapping providers Processor Coordinates only, for road speed-limit lookups — never your identity EU / global Coordinates only; no personal identifiers sent

8. Data Retention

  • Live location presence: cleared automatically within about 10 minutes of your last activity. The presence record expires at 10 minutes, and a background sweeper removes any residual geo-index entry within roughly a minute of that.
  • Speed-limit cache: up to 30 days.
  • Alert throttle/cooldown records: up to 15 minutes.
  • Alert logs: up to 14 days.
  • Legal acceptance records (the terms/privacy versions you accepted): until you delete your account.
  • Aggregate alert counters (number of alerts you have sent and received): until you delete your account.
  • Your alert history (for each alert you triggered or received: the time, the location, the speed involved, and the applicable speed limit): up to 30 days, or until you delete your account, whichever comes first. This history is shown only to you, in the app. It is never shown to other users: the record of an alert you received contains no information identifying the other driver.
  • Subscription/billing records (held by RevenueCat and the app stores): retained as required for subscription, tax, and accounting obligations. These records are keyed to your app user ID; after you delete your account they remain only as pseudonymous billing entries and are not linked back to a live account.
  • Slow-down zone reports (hazard coordinates, first-report time, confirmation count — no reporter identity): 1 hour from the most recent report on that zone. Each further report on the same spot extends it by another hour, so a spot that is reported repeatedly stays live until an hour after the last report.
  • Slow-down zone reporter tokens (the salted, one-way token derived from your user ID): held with their zone and expiring with it — again 1 hour from the most recent report on that zone, not from yours.
  • Slow-down zone reporting counters (keyed to your user ID): the per-report cooldown expires 60 seconds after a report; the daily counter expires 24 hours after your last report of that day.
  • Crash/analytics logs: up to 90 days.

Slow-down zone records are not erased on account deletion, because they self-delete within the windows above and there is nothing in a published zone that links it to you. If a report of yours is still within its window when you delete your account, it expires on its own shortly afterwards.

When you delete your account, your legal acceptance record, your saved preferences, your aggregate alert counters, and your alert history are removed immediately — your alert history is deleted straight away rather than being left to reach the end of its 30-day window. All other data above expires automatically within the retention windows listed. See §10 (Your Rights) for the full deletion procedure.

9. Legal Basis (GDPR)

We process personal data under the legal bases mapped to each purpose below:

Purpose Data Legal basis
Speeding detection & nearby alerts (core service) Location, speed, heading, FCM token Legitimate interest (road safety); consent for the background-location device permission
Accident risk-zone warnings None leaves your device (on-device only) Legitimate interest (no server processing)
Crowd-sourced slow-down zones Hazard coordinates, reporter token, reporting counters Legitimate interest (road safety)
Country capacity / queue control Coarse country, active-session count Legitimate interest; contract (for Pro access)
Subscriptions & entitlements Subscription/billing data Performance of a contract
Crash reporting & essential diagnostics Crash logs, device info Legitimate interest (app stability & security)
Product analytics Events, screen views, diagnostic IDs Consent (opt-in; withdrawable)
Retaining billing records Subscription/billing data Legal obligation (tax & accounting)
Handling rights requests & compliance Contact + relevant records Legal obligation

10. Your Rights

As an EU user, you have the right to access, correct, delete, restrict, or object to processing of your data, and to receive a copy of your data in a portable format. You may withdraw consent for background location (via device settings) or for analytics (via in-app settings) at any time. To exercise these rights, contact us at support@salvusmobile.com.

Deleting your account. You can delete your account at any time from the app (Profile → Delete account) or by emailing us. On deletion, your legal acceptance record, your saved preferences, your aggregate alert counters, and your alert history are erased immediately. Live location presence and geo-index entries self-expire within about 10 minutes; alert logs, throttle, and queue records expire within their retention windows. Subscription/billing records held by RevenueCat and the app stores are retained as pseudonymous, unlinked entries under our legal, tax, and accounting obligations (see §7–§8).

Consequences of refusing or withdrawing permissions.

  • Location: Salvus cannot detect speeding, send alerts, or provide risk-zone warnings without location access — the app becomes non-functional for its core purpose.
  • Notifications: notification permission is optional. During an active driving session, safety warnings are also delivered over the app’s own connection and played as audible and on-screen warnings, so refusing notifications does not by itself stop them. Without notification permission you will not receive warnings as system notifications, including when the app is not running. You may separately silence the audible warnings in the app’s settings; with both channels off you will not receive safety warnings.
  • Analytics: declining or withdrawing analytics consent has no effect on any feature.
  • Account/sign-in: there is no traditional account to refuse — Salvus is anonymous by default. Declining Apple/Google sign-in simply means your data is not preserved if you reinstall or switch devices.

Complaint to a supervisory authority. If you believe your data is not handled lawfully, you may lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP / КЗЛД):

  • Address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.
  • Email: kzld@cpdp.bg · Phone: +359 2 915 3518 · Web: www.cpdp.bg

11. International Transfers

Some providers (Firebase/Google, RevenueCat, Sentry, Render) may process data on servers outside the EU (e.g. the USA). Such transfers are protected by the European Commission’s Standard Contractual Clauses (SCCs), the EU–US Data Privacy Framework, and, where applicable, additional safeguards.

Our own location-processing backend runs on Render in the EU (Frankfurt) region, so your location data is stored and processed in the EU. Render is a US company and its data-processing agreement reserves the right to carry out processing operations in the United States (for example, for support and platform operations). Any such transfer is covered by the safeguards named above.

12. Children’s Privacy

Salvus is not intended for children under 16 years. We do not knowingly collect data from minors.

13. Changes

We may update this Privacy Policy from time to time. Updates will be posted in-app and on this page, with the “Last updated” date revised.

14. Contact

Toncho Lozev, Bulgaria

Email: support@salvusmobile.com

Data Sources & Attribution

Salvus is built on open data, and we credit our sources here:

  • Speed-limit & map data: © OpenStreetMap contributors, made available under the Open Database License (ODbL) — see openstreetmap.org/copyright.
  • Accident risk-zone data: road-traffic accident data published by the Bulgarian Ministry of Interior (МВР) through the Bulgarian Open Data Portal (data.egov.bg) under CC0 1.0.

Salvus independently processes the accident data to generate its risk-zone warnings. These warnings are produced by Salvus and are not official MVR warnings. We do not use MVR logos, dashboard visuals, or map tiles.

Salvus

A real-time driver safety network. Anonymous by design.

EN/BG

Product

  • About
  • Guide
  • FAQ
  • Download

Legal

  • Privacy
  • Terms
  • Delete account

Support

  • support@salvusmobile.com

Follow

© 2026 Salvus. All rights reserved.

Map & speed data: © OpenStreetMap contributors (ODbL). Accident data © Bulgarian Ministry of Interior (МВР)via data.egov.bg (CC0). Risk warnings are generated by Salvus. They are not official MVR warnings.