This Privacy Policy explains how the Avalon Sentinel mobile application (“the App”), published by Avalon Artificial Intelligence Limited, handles information. It should be read together with the privacy notice of the organisation that operates the Sentinel deployment you connect to.
1. About the App and who controls your data
Avalon Sentinel is a mobile client. In Remote Mode, it connects to a Sentinel server controlled by your organisation (the “Customer”), hosted on-premises or in the Customer’s own cloud. By default there is no separate Avalon-operated data-collection cloud — the information you view and submit through the App is processed by, and stays with, the Customer’s Sentinel deployment.
For most information handled through the App, the Customer is the data controller and Avalon Artificial Intelligence Limited acts as a technology provider / processor on the Customer’s behalf. Please direct data-subject requests to your organisation’s administrator (see Section 11).
The App also offers Explore Demo, a self-contained demonstration mode that uses local sample data only. Explore Demo data never leaves your device and never represents real device activity.
2. Accounts
Accounts are provisioned by Sentinel administrators. There is no in-app self-registration or account creation. You authenticate with an email and password issued or managed by your organisation.
3. Information the App handles
The categories below apply to Remote Mode. Explore Demo uses only local sample data. All Remote-Mode traffic is encrypted in transit (HTTPS/TLS and WSS).
Authentication / account information: your account email and password, submitted to your Customer’s Sentinel server to sign in. The password is used to authenticate and is not stored by the App. After sign-in, the server issues access and refresh tokens (JWT) which the App stores encrypted on your device (iOS Keychain / Android EncryptedSharedPreferences).
Security events, incidents and evidence: incident, event, and evidence metadata for display. Evidence media (video/images) is viewed via short-lived signed links and is not stored on your device.
Safety findings: camera/robot-derived safety observations, including possible-fall and activity findings, where your Sentinel system provides this capability. These are safety signals, not medical or health records.
AI query text (“Ask Avalon”): natural-language questions you type for AI-assisted investigation, sent to your Customer’s Sentinel server. Where the Customer has configured a third-party AI provider, your query is only transmitted to that provider after you give explicit, revocable consent in the App (Settings → AI Data Processing).
AI feedback reports: if you tap “Report this answer”, minimal metadata (reason, optional comment, provider, app version) is sent to your Sentinel server so the output can be reviewed. Raw evidence is not automatically attached.
Device and premises metadata: status information about devices and premises in your Sentinel system.
Diagnostics: app version and device model/OS version, used for support and troubleshooting when you contact support.
Notifications / push token: collected only if your Customer configures push notifications. In the App’s default configuration the push provider is unavailable, so a push token is not collected.
Optional product analytics: if you turn on Product Analytics in Settings (it is off by default), the App sends anonymous, non-personal usage events — for example which areas of the App you open — to our analytics processor (Mixpanel, EU region) to help us improve the App. This never includes your evidence, images, faces, licence plates, AI questions or answers, incident/premises/access content, or your account details; it uses an anonymous identifier (no name or email) and no IP-based location. You can turn it off at any time in Settings.
4. Information the App does NOT collect
No advertising identifier (IDFA/AAID) and no advertising.
No precise or coarse location tracking (no location permission).
No cross-app or cross-site tracking of any kind.
No access to contacts, photos library, microphone, camera, Bluetooth, or local network.
No health/medical records.
No advertising or cross-app / cross-site tracking SDKs, and no crash-reporting SDK. (Optional product analytics is off by default, anonymous, and described in Section 3.)
No in-app purchases or payment data.
5. How information is used
Information is used to provide the App’s functionality: authenticating you, displaying incidents/events/evidence/access/device information from your Sentinel system, answering your AI queries, securing your session (optional biometric App Lock), and supporting you when you request help. Information is not used for advertising or cross-app tracking.
6. On-premises / customer-controlled processing
By design, your operational data is processed by the Customer’s own Sentinel server. Retention and use of that data on the server are governed by the Customer’s policies and configuration, not by the App.
7. Data sharing
The App does not sell your data and does not share it with third parties for advertising. In Remote Mode, data is transmitted to the Customer’s Sentinel server to provide the service.
Third-party AI (only if configured and consented): If your Customer configures a third-party AI provider for Ask Avalon, your query text is transmitted to that provider only after you grant explicit, revocable consent in the App. The App discloses the provider before the first transfer, and no query leaves for that provider until you consent. You can withdraw consent at any time in Settings → AI Data Processing.
Optional external alerting: If your Customer explicitly configures an external alerting provider (for example push or WhatsApp), minimal alert metadata may be sent off-premises to that provider only for delivering alerts. This is a Customer-configured, server-side behaviour that is off by default and is not initiated by the App.
Product analytics (only if you opt in): If you enable Product Analytics, anonymous, non-personal usage events are sent to Mixpanel (EU region), acting as our processor, solely to improve the App. It is off by default, contains no personal or customer/security data, and you can disable it at any time in Settings.
8. Security
Encrypted connections (HTTPS/TLS, WSS) to the Sentinel server.
Authentication tokens stored in the device secure store (Keychain / EncryptedSharedPreferences).
Optional biometric App Lock (Face ID / fingerprint). Biometric matching is performed by your device’s operating system; the App never receives your biometric templates.
On Android, application backup is disabled and data-extraction rules prevent secrets from being backed up or transferred.
No method of transmission or storage is completely secure; we and the Customer apply reasonable measures appropriate to security-operations software.
9. Retention
On device: tokens are retained until you log out or they expire; other operational data is held only transiently for display during your session. Evidence media is not persisted on the device.
On the server: retention is determined by the Customer’s Sentinel deployment and policies.
10. Children and safety context
The App is not directed to children. Its intended audience is property, security, and business users and household account holders. Any child-safety or elderly-safety monitoring capability is intended for authorised adults and is not a childcare or medical device. Safety findings (including possible-fall detection) are indicative — described as possible or suspected — and require human judgement. The App does not guarantee prevention of crime, intrusion, theft, falls, or injury, and does not provide medical diagnosis or emergency-response services.
11. Your rights and data-deletion / access requests
Because accounts are administrator-provisioned and there is no in-app self-registration, requests to access, correct, delete, or restrict your personal data should be made:
To your organisation’s Sentinel administrator (the data controller), and/or
Certain security-event and audit records may be retained by the Customer’s deployment for legitimate security, safety, and audit purposes even after a deletion request, to the extent permitted by applicable law.
12. International processing
Where the Customer hosts its Sentinel deployment determines where operational data is processed. Optional external providers, if configured by the Customer, may process alert metadata in their own locations.