ADPH

Alabama Department of Public Health

Southeastern District — Infant Safety Program

Terms of Service

Privacy Policy

Last updated: July 8, 2026

This Privacy Policy describes how the Alabama Department of Public Health, Southeastern District (“ADPH”, “we”, “our”) collects, uses, and shares information when you use the W.I.N.S. Infant Safety App mobile application (Android package com.adph.wins) and the associated administrator portal (collectively, the “Service”).

1. Information we collect

We only collect information that is needed to provide the Service. The categories below correspond to the Google Play Data Safety disclosure for this app.

a. Account information

  • Email address, display name, and (optionally) phone number you provide at sign-up.
  • If you sign in with Google or Apple, the unique account identifier and the basic profile fields those providers return (name, email, profile image URL). We do not receive your password.
  • Password hash (when you sign in with email and password). Stored and verified by our authentication provider; we never see your plaintext password.

b. Profile & child information you provide

  • Profile photo, county, and contact preferences.
  • Child name, date of birth, and (optionally) photo, entered by you in order to receive age-appropriate vaccine, milestone, and safety content.
  • Quiz answers and milestone progress you submit in the app.

c. Device & technical information

  • Device model, OS version, app version, language, and time zone.
  • A push notification token (Firebase Cloud Messaging) issued to the app instance on your device.
  • Approximate IP address (logged at the network layer by our hosting providers for fraud prevention and abuse detection).
  • Diagnostic and crash data (Firebase Crashlytics): stack traces, non-personal device characteristics, and a Crashlytics installation identifier. We do not attach your email or child information to crash records.
  • Aggregated, non-identifying usage analytics (Firebase Analytics): screen views, button taps, app open/close events. We do not use this data for advertising.

d. Location & activity (Back Seat Alert feature only)

  • Approximate and precise location, including in the background when the app is closed, used solely to detect when a drive ends and to issue the Back Seat Alert reminder. See section 4 below.
  • Physical-activity recognition signals (e.g. “in vehicle” vs “still”) provided by Android, used only to decide when to start and stop a drive.

Location and activity data are processed on your device. We do not upload your live location or driving traces to our servers.

e. Photos & camera

  • Photos you select from your gallery or capture with the camera for your profile picture or child profile picture. Uploaded only when you tap save.

2. How we use information

  • Provide the Service: authenticate you, deliver vaccine schedules and milestone reminders timed to your child’s age, and display county-specific resources.
  • Send notifications: push reminders for vaccines, milestones, scheduled local notifications, and the Back Seat Alert.
  • Keep the app reliable: diagnose crashes and defects via Firebase Crashlytics; understand which features are used (Firebase Analytics) so we can improve them.
  • Prevent abuse: verify human sign-up requests via hCaptcha to block automated account creation.
  • Communicate with you: respond to support requests sent to the address below.

We do not sell your personal information, use it for behavioural advertising, or share it with data brokers.

3. How we share information

We share information only with the limited categories of recipients below:

  • Service providers that host or process data on our behalf (see section 10). They are contractually restricted to acting on our instructions.
  • ADPH personnel with a legitimate operational need (e.g. content administrators, support staff) accessing data through the administrator portal under role-based access controls.
  • Legal authorities, when we are required to do so by law, valid legal process, or to protect the safety of any person.
  • Successor entities, if ADPH’s Infant Safety Program is transferred to another public-health entity.

4. Location data (foreground & background)

The Back Seat Alert (“BSA”) feature requires access to your device’s location, including in the background, in order to detect the end of a drive and remind you to check the back seat. Specifically:

  • We use coarse location, precise location, and Android activity recognition to determine when a drive starts and ends.
  • Location samples are processed on-device in a foreground service that displays a persistent notification while active. They are not sent to our servers and are not retained after the drive ends.
  • You may revoke background location at any time in your device’s system settings. The Back Seat Alert will then no longer fire automatically; the rest of the app continues to work.
  • You can also disable the Back Seat Alert from inside the app without revoking the OS permission.

5. Notifications, exact alarms & overlay

  • Push notifications are delivered via Firebase Cloud Messaging. You may turn them off in your device settings or from within the app.
  • Exact alarms (Android USE_EXACT_ALARM / SCHEDULE_EXACT_ALARM) are used only to deliver the Back Seat Alert and time-sensitive vaccine reminders at their scheduled time. This is permitted under Google Play’s policy for alarm and safety apps.
  • Display over other apps (SYSTEM_ALERT_WINDOW) is used to bring the Back Seat Alert to the foreground when your phone is locked or another app is in front. No content is overlaid outside that flow.

6. Information about children

The Service is intended for parents, legal guardians, and caregivers. It is not directed to children under 13 and we do not knowingly collect personal information from a child for the child’s own use.

Information about an infant or child entered into the app (name, date of birth, photograph, milestone progress) is provided by the parent or guardian operating the account. The parent or guardian controls this information and may delete it at any time from within the app or by contacting us.

7. Data retention & account deletion

  • We keep your account and child profile records for as long as your account is active.
  • Crash and analytics records are retained on a rolling basis (up to 90 days for Crashlytics, up to 14 months for aggregated Analytics) and are not linked to your account.
  • Records of which app screens are opened — which we use to understand how the app is used and where to improve it — are automatically deleted after 90 days. If you are signed in, these may be linked to your account until then; deleting your account removes that link.
  • Your in-app notification history (the reminders and alerts shown inside the app) is kept for about 6 months and then automatically cleared.
  • You may delete your account at any time from Profile → Settings → Delete Account inside the mobile app, from our account deletion request page, or by emailing adph.support@previseit.com. On deletion we remove your profile, child profiles, and quiz / milestone records within 30 days, except where retention is required by law (for example, audit logs).

8. Security

We use industry-standard safeguards:

  • All network traffic between the app and our servers is encrypted with TLS 1.2 or higher.
  • Data at rest in our database is encrypted by the hosting provider.
  • Access to administrator tools is gated by per-account credentials, role-based access, and row-level security policies.
  • Authentication tokens are stored on your device using the platform’s secure storage (Keychain on iOS, EncryptedSharedPreferences on Android).

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the appropriate regulators as required by law.

9. Your rights & choices

  • Access & correction — view and edit your profile and child information from within the app.
  • Deletion — see section 7.
  • Permission revocation — disable notifications, location, camera, or photo access at any time in your device’s system settings.
  • Marketing opt-out — we do not send marketing email. Operational and safety notifications (e.g. Back Seat Alert) are part of the Service and cannot be disabled while the feature is enabled.

10. Third-party service providers

The Service relies on the following processors. Each is bound by its own privacy policy:

  • Supabase — authentication, application database, and file storage. Hosted on AWS.
  • Google Firebase (Cloud Messaging, Crashlytics, Analytics) — push delivery, crash reporting, aggregated usage analytics.
  • Google Sign-In and Sign in with Apple — optional federated login.
  • hCaptcha — automated-abuse prevention during sign-up, sign-in, and password reset.
  • Google Play / Apple App Store — app distribution and update channel.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced in the app and, where required by law, by email. The “Last updated” date at the top reflects the latest revision.

12. Contact us

Questions, deletion requests, or privacy concerns should be directed to:

adph.support@previseit.com