Privacy Policy.
Last updated · 20 July 2026OnSiren is a safety network for licensed security professionals. This policy explains, in plain language, what personal data we collect, why we collect it, who we share it with, and the rights you have over it under UK data protection law.
01Who we are
OnSiren is operated by Onsiren Limited, a company registered in England and Wales. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Onsiren Limited is the data controller of the personal data described in this policy.
You can contact us about anything in this policy at privacy@onsiren.com.
02Who the app is for
OnSiren is for working security professionals who hold a valid licence from the Security Industry Authority (SIA). You must be at least 18 to hold an SIA licence, so the app is not directed at, and must not be used by, anyone under 18. We do not knowingly collect data from children.
03The data we collect
Account and identity
When you register we collect your name, email address, phone number, and the call sign you choose. Your call sign, not your name, is what other officers on the network see.
SIA licence verification
To verify that you are a licensed officer, you photograph your SIA licence card in the app. We extract your licence number from the image and check it against the SIA’s public register. We keep your licence number and the verification result. The photograph of your card is stored securely, is not used for any other purpose, and is accessible only to authorised staff carrying out verification. You can ask us to delete it at any time, and it is erased when you delete your account.
Face verification (biometric data)
During registration we run a face-liveness check to confirm you are a real person and that you match your licence. Biometric data used to identify a person is special category data under Article 9 UK GDPR, so we ask for your explicit consent in the app before any capture begins. We store the outcome of the check (pass/fail and confidence scores). We do not create or keep a biometric template for ongoing identification, and we never use your face to identify you elsewhere in the product. The images captured during the check are stored securely, restricted to authorised staff, and erased on request or when you delete your account. You can decline, but we cannot verify your account without the check.
Location
OnSiren is built around where you are. While you are on duty, your live location is shared with nearby licensed officers on the network and is used to place you in a coverage channel, deliver alerts that are relevant to where you stand, and detect when you leave your channel. Other officers’ live positions shown on your map are held in your device’s memory only and are never written to its storage. We also keep a server-side history of location events and channel membership for safety, audit, and incident-review purposes. When you go off duty, live sharing stops.
Communications
- Push-to-talk audio and transcripts.Voice transmissions on the channel are relayed live to the officers in your channel and transcribed into the channel’s written log.
- Chat messages you type into the channel.
- Alerts you send or receive, including any voice note (which we transcribe, and translate into English where needed) and any evidence photo you attach. Photos are safety -scanned before storage; a photo the scan rejects is never stored.
Device and diagnostics
We collect your device’s push notification token so alerts can reach you, and crash and error reports so we can fix faults. Crash reports are tagged with a pseudonymous user ID, your call sign, and the app version, not your name, location, or contact details.
Engagement
We record when you acknowledge your channel briefing, which feeds the engagement standing shown on your own profile.
04Why we use it, and our legal bases
Under UK GDPR, every use of your data needs a legal basis:
- Performing our contract with you: running your account, verifying your licence, delivering alerts and voice communications, and operating the network you signed up to use.
- Your explicit consent: for the biometric face-liveness check (Article 9(2)(a)). You can withdraw consent at any time by deleting your account.
- Legitimate interests: keeping officers and the public safe, preventing misuse and abuse of the network, moderating content, securing the service, and improving it. We balance these interests against your rights before relying on them.
- Legal obligations: where we must retain or disclose data to comply with the law, or respond to lawful requests from authorities.
We do not use your data for advertising, we do not sell it, and we do not track you across other companies’ apps or websites.
05How AI processes your data
Alpha One, the AI in the system, exists to give you situational awareness. To do that it processes network data on our behalf:
- Speech to text: push-to-talk transmissions and alert voice notes are transcribed, and translated into English where needed, so the channel has a written record everyone can read.
- Briefings and summaries: Alpha One reads channel activity (alerts, transcripts, channel events) to brief you when you sign on and to summarise what you missed. A summary you request is private to you and is not shared with other officers or fed back into the AI’s context.
- Content safety: attached evidence photos are checked automatically before anything is stored or broadcast, and messages are screened against an abusive-language filter.
AI output is informational. It does not make decisions with legal or similarly significant effects about you. Account decisions (such as removal from the network) are made by people.
06Who we share it with
Other officers on the network. That is the point of OnSiren: your call sign, on-duty location, alerts, and voice transmissions reach the licensed officers around you.
Service providers (processors). Trusted providers process data on our behalf, under contract, and only on our instructions:
- Amazon Web Services: hosting, storage, and AI processing.
- OpenAI (EU endpoints): speech-to-text for alert voice notes and the Alpha One voice conversation.
- Deepgram: live speech-to-text for push-to-talk.
- Google Firebase: push notification delivery (Android) and crash reporting.
- Apple: push notification and push-to-talk delivery on iOS.
The SIA public register: we check your licence number against the register the SIA publishes; this is a lookup of public data, not a disclosure of your account.
Authorities: we may disclose data where the law requires it or where it is necessary to protect someone’s life or safety.
We never sell personal data.
07International transfers
We keep processing in the United Kingdom and the European Economic Area wherever we can. Where a provider processes data outside the UK, we rely on safeguards recognised by UK GDPR: an adequacy decision, or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, so your data has equivalent protection wherever it is processed.
08How long we keep it
We keep personal data no longer than necessary for the purposes set out in this policy. Operational records, such as alerts, transcripts, and location history, are retained for safety and audit purposes, and account data is kept while your account is active. We review what we hold and remove records we no longer need.
You do not have to wait for that review: you can delete your account at any time from the app. When you do, we erase the personal data we hold about you, except the minimum we must retain to meet a legal obligation or handle a live dispute. You can also ask us to delete specific data at any time. See Your rights.
09Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you;
- Rectify data that is inaccurate or incomplete;
- Eraseyour data (“right to be forgotten”);
- Restrict or object to processing, including processing based on legitimate interests;
- Port the data you gave us to another service in a machine-readable format;
- Withdraw consent at any time where processing is based on consent (such as the biometric check), without affecting processing that happened before you withdrew.
To exercise any of these rights, email privacy@onsiren.com. We respond within one month.
If you are unhappy with how we handle your data, you can complain to the UK regulator, the Information Commissioner’s Office, at ico.org.uk. We would appreciate the chance to resolve it with you first.
10Deleting your account
You can delete your account at any time, in the app: Settings → Delete account. Deletion removes your personal data as described in section 08. You do not need to email us or give a reason. If you prefer, you can also request deletion at privacy@onsiren.com.
11Security
We protect your data with technical and organisational measures appropriate to its sensitivity: encryption in transit, access controls, audit logging across the network, and the data-minimisation choices described above: processing raw images rather than storing them, and keeping other officers’ live positions out of persistent storage on your device. No system is perfectly secure, but if a breach ever puts your rights at risk we will notify you and the Information Commissioner’s Office as the law requires.
12Changes to this policy
When we change this policy we will update the date at the top and, for significant changes, tell you in the app before they take effect. Continued use of OnSiren after a change means the updated policy applies.
13Contact
Questions about this policy or your data: privacy@onsiren.com. For anything else, see www.onsiren.com/contact.