Overview

CERT Command is a closed emergency response coordination tool used exclusively by authorized Community Emergency Response Team (CERT) members during official activations. It is not a general-purpose app and does not serve the public.

This policy explains what data the app collects, how it is used, and who can see it.

CERT Command does not use data for advertising, analytics, or any purpose outside of real-time team coordination during a CERT activation. No data is sold or shared with third parties.
Data Collected
Data Purpose Where it goes
Full name Identifies you to your team leader and teammates on the coordination dashboard Your team's server only
Role & equipment Helps the team leader assign tasks appropriate to your skills and resources Your team's server only
Precise location Displays your position on the team map; attached to incident reports you file Your team's server only
Device token (anonymous UUID) Identifies your device across sessions so the server can route remote checkout notifications to the correct device Your team's server only
Status updates Available, Assigned, Injured, etc. — visible to your team leader for coordination Your team's server only
Incident reports Field observations (type, severity, location, description) submitted during activation Your team's server only; high/life-safety reports escalate to County EOC

The app does not collect email addresses, phone numbers, payment information, browsing history, contacts, photos, or any biometric data.

How Data Is Stored

All data transmitted by the app is sent to the server URL you enter at check-in. This is a server operated by your CERT team or county emergency management program — not a server operated by the app developer.

Server-side: Member data (name, role, location, status) is held in memory for the duration of the activation. It is not written to a persistent database. Data is automatically cleared when the server restarts or when you check out.

On-device: Your name, role, status, and reports are cached locally in app storage so the app can function if briefly disconnected. Your authentication PIN is stored in the iOS Keychain. Your server address is stored in app preferences. This data is cleared when you check out.

Who Can See Your Data

Within the app, your name, role, status, location, and reports are visible to:

  • Your Team Leader — via the web dashboard
  • Other checked-in team members — name, role, and status visible on their Team Members list
  • County EOC staff — high-severity incident reports are escalated automatically

The app developer has no access to any data on your team's server at any time.

Location Data

CERT Command requests location access while the app is in use ("When In Use"). It does not request background location access.

Location is used to:

  • Show your position on the team coordination map visible to your team leader
  • Automatically attach GPS coordinates to incident reports you submit

You can switch to Manual location mode at any time from the Status tab. In Manual mode, your location is only shared when you explicitly tap "Share My Location Now."

Location data is not shared outside your team's server and is cleared when you check out.

Data Retention & Deletion

When you check out of an activation, your member record is removed from the server and your locally cached data is deleted from the device.

Incident reports submitted during the activation are retained on the server in an audit log for after-action review by the team leader. This audit log is managed by your team's server operator (your team leader or county emergency management), not the app developer.

To request deletion of any data held on your team's server, contact your team leader or county emergency management program directly.

No Third-Party Sharing

CERT Command does not use any third-party analytics SDKs, advertising networks, crash reporting services, or tracking tools. No data is shared with Apple (beyond standard App Store operation), Google, Meta, or any other company.

The app makes no network requests other than to the server address you enter at check-in.

Children

CERT Command is intended for adult CERT volunteers. It is not directed at children under 13 and does not knowingly collect data from minors.

Changes to This Policy

If this privacy policy changes materially, the updated version will be posted here and the effective date will be updated. Continued use of the app after a policy change constitutes acceptance of the new policy.

Contact

Questions about this privacy policy or your data:

Frank Gadot
frank@w6fgc.com