Watcho App
Privacy Policy
Effective Date: May 14, 2026
Last Updated: July 18, 2026
Operated by: Taque Studios (Adrian Hernandez)
Contact: adrian@taquestudios.com
Overview
Watcho is a public safety awareness map for Southern California, with coverage expanding to other parts of California. This Privacy Policy explains what information we collect (if any), how we use it, and your rights as a user.
The short version: No accounts. No ads. No analytics. No tracking. We never sell or share your data. The app is read-only for the public — you view the map and incident details without creating an account or signing in. The only data Watcho handles is a device token used to deliver notifications you turn on, and crash reports used to fix bugs — nothing about who you are, nowhere you go, nothing behavioral. Both are detailed in Section 1.
1. Information We Collect
From Public Users
Aside from the optional push notification token and crash diagnostics described below, Watcho does not ask you for or collect personal information. Specifically:
- We do not require an account or registration
- We do not collect your name, email, phone number, or any identifying information
- We do not collect or store your advertising identifier
- We do not use cookies or tracking technologies
- We do not run analytics, and we do not track usage or behavior
Location Data
Watcho may request access to your device's location solely to center the map on your current position. This is an optional, device-side feature:
- Your location is never transmitted to our servers
- Your location is never stored or logged
- You can use Watcho without granting location permission — the map will default to a regional view of Southern California
Push Notifications
Watcho can send push notifications about new or updated incidents. Notifications are optional — you can decline the permission, or turn them off later in your device Settings, and still use the full map.
If you enable notifications:
- Your device generates an Expo push token (a random, device-specific identifier of the form
ExponentPushToken[…]) using the Expo notifications framework. - We store that token on our Supabase backend and send it to Expo (exp.host) so notifications can be routed to your device. Expo relays each alert through Apple's Push Notification service (APNs) on iOS and Google's Firebase Cloud Messaging (FCM) on Android. See the Expo entry in Section 3.
- The token identifies a device, not a person. Watcho has no accounts, so it is not linked to your name, email, or any profile.
- We use the token only to deliver notifications. We do not use it for advertising, analytics, profiling, or cross-app tracking, and we do not sell or share it.
- Turning notifications off in your device Settings stops delivery. You may also email adrian@taquestudios.com to request deletion of your token.
Crash Diagnostics
If the app crashes, Watcho sends a diagnostic report to our backend so we can find and fix the problem. A report contains:
- the error message and stack trace,
- the platform and OS version, and
- the app version.
A crash report contains nothing that identifies you — no name, no account, no device identifier, no location. Crash reports are used only for debugging. They are not used for advertising, analytics, profiling, or tracking, are not linked to any account, and are not sold or shared.
Address Search
When you use the search bar to look up a neighborhood or address, that text is sent to a geocoding service (provided by Apple on iOS and Google on Android) to convert it to map coordinates. This is a standard platform service. The search text is not transmitted to Taque Studios servers and is not stored by us.
Automatically Collected Technical Data
When you use the app, your device communicates with our backend service (Supabase) in two ways:
- Incident data requests — your device fetches the list of incident pins over HTTPS. This is a standard read request and does not include personal data.
- Real-time connection — the app maintains a persistent encrypted WebSocket connection (WSS) to Supabase Realtime so new incidents appear on the map without requiring a manual refresh. This connection carries no personal data.
No IP addresses, device fingerprints, or usage patterns are retained on our end.
2. Information We Do Not Collect
To be explicit, Watcho does not collect:
- Name, email, or contact information
- Location history
- Search history or queries
- Advertising identifiers or cross-app tracking IDs
- Browsing or usage behavior
- Financial information
- Health information
- Any other personal data
The only data Watcho does handle is described in Section 1: the optional push notification token (used to deliver notifications you asked for) and crash diagnostics (used to fix bugs). Neither is linked to your identity, and neither is used for advertising, analytics, or tracking.
3. Third-Party Services
Watcho uses the following third-party services to deliver core functionality:
Supabase
We use Supabase (supabase.com) to store and serve incident data. Supabase receives standard HTTPS requests and WebSocket connections from the app to load and stream incident pins. No user personal data is included in these communications. Supabase's privacy policy is available at https://supabase.com/privacy.
Expo (Expo Application Services, Inc.)
Watcho uses Expo's push service to deliver alerts. When you enable notifications your device generates an Expo push token (a random, device-specific identifier), which we store on our Supabase backend and send to Expo (exp.host) so it can route each notification to your device. Expo relays notifications via Apple's Push Notification service (APNs) on iOS and Google's Firebase Cloud Messaging (FCM) on Android. The token is used solely to deliver notifications — never for advertising, analytics, or tracking — is not linked to any account, and is deleted when you disable notifications or on request. See https://expo.dev/privacy.
Crash diagnostics
If the app crashes, a diagnostic report (error message, stack trace, platform, OS version, app version) is sent to our backend to fix the problem. It contains nothing that identifies you. Used only for debugging; never for advertising or tracking.
Telegram (Telegram FZ-LLC)
Crash diagnostics (see Section 1) are relayed from our backend to a private Telegram channel so our team is alerted to bugs in real time. The contents of a crash report — error message, stack trace, platform, and OS version — pass through Telegram's messaging service so the alert can reach us. This data is not personal and is not linked to you; Telegram receives it solely to deliver that alert, never for advertising or tracking, and no other Watcho data is sent to Telegram. See https://telegram.org/privacy.
Apple Maps / Google Maps
The app uses Apple Maps (on iOS) and Google Maps (on Android) to render the map tiles and provide geocoding for the address search feature. These services are provided by Apple and Google respectively and are governed by their own privacy policies. We do not share any user data with these providers beyond what is inherent in loading map tiles and processing address searches.
4. Children's Privacy
Watcho is not directed to children under the age of 13, and we do not knowingly collect personal information from children. Watcho has no accounts and does not ask any user for personal information, so there is little for a child to provide — but if you believe a child's personal information has somehow reached us, please contact us at adrian@taquestudios.com and we will remove it promptly.
5. Data Security
Watcho handles very little user data, and none that identifies you. The push notification token and crash diagnostics described in Section 1 are stored on our backend and transmitted over encrypted connections. Incident content displayed in the app is public information and is transmitted over encrypted HTTPS and WSS connections.
6. Links to External Sources
Incident pins may include a link to an external source (such as a news article). Taque Studios is not responsible for the privacy practices of those external websites. We recommend reviewing the privacy policy of any external site you visit.
Family Donation Links (GoFundMe)
Some incident pins include a link to a GoFundMe campaign run by the affected family. When you tap the "Support this family" or "Donate" button, your device opens the GoFundMe campaign URL in your default web browser. No donation, payment, or financial information ever passes through the Watcho app or Taque Studios servers. All payment processing, account creation, and personal-data handling for donations is performed entirely by GoFundMe under their own privacy policy (https://www.gofundme.com/c/terms/privacy-notice). Taque Studios does not receive any funds, does not retain a percentage, and does not have visibility into who donates or how much.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. Continued use of the app after any changes constitutes your acceptance of the updated policy. We encourage you to review this page periodically.
8. Your Rights
Because Watcho has no accounts and does not collect data that identifies you, most data rights (access, deletion, portability) have little to apply to. The one piece of data tied to your device is the push notification token: turn notifications off in your device Settings, or email us, to delete it at any time. For any question or concern, you are always welcome to contact us at adrian@taquestudios.com.
9. Governing Law
This Privacy Policy is governed by the laws of the State of California, United States, without regard to its conflict of law provisions.
10. Contact Us
If you have any questions about this Privacy Policy, please contact: