In force

Privacy Policy

OnSiren is a safety network for licensed security professionals. This policy explains, in plain language, what personal data we collect, why we collect it, who we share it with, and the rights you have over it under UK data protection law.

Last updated
7 October 2026
Applies to
The OnSiren app, network and website

1. Who we are

OnSiren is operated by Onsiren Limited, a company registered in England and Wales (company number 16981806). For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Onsiren Limited is the data controller of the personal data described in this policy.

You can contact us about anything in this policy at privacy@onsiren.com.

2. Who the app is for

OnSiren is for working security professionals who hold a valid licence from the Security Industry Authority (SIA). You must be at least 18 to hold an SIA licence, so the app is not directed at, and must not be used by, anyone under 18. We do not knowingly collect data from children.

3. The data we collect

Your account

When you sign up, we collect your phone number, which you confirm with a code, and your SIA licence number. We take your name, licence type and expiry date from the SIA register (see below). You choose a call sign: it, not your name, is what other officers on the network see. When you finish verifying your account, we also ask for your email address and confirm it with a code.

When you sign up, we note where you are, to show you the channels near you. Each time you sign in, we record your device (its model, operating system and name), the app version and your IP address, to keep your account secure.

SIA licence verification

You type your SIA licence number when you sign up, and we check it against the SIA’s public register. We keep your licence number and what the register says about it: your name, licence type, status and expiry date. If the register can’t be reached at that moment, we let you carry on and mark your number as not yet checked.

Later, when you finish verifying your account, you photograph your licence card. An automated check confirms the photo shows a readable SIA licence card, our team can look at it, and it is the reference picture for your face check. The photo is stored securely and is accessible only to authorised staff. You can ask us to delete it at any time, and it is erased when you delete your account.

Face verification (biometric data)

When you finish verifying your account, we run a face-liveness check to confirm you are a real person and that you match the photo on your licence card. An AI model makes the comparison (see How AI processes your data). Biometric data used to identify a person is special category data under Article 9 UK GDPR, so we ask for your explicit consent in the app before any capture begins. We store the outcome of the check (pass or fail, and confidence scores). We do not create or keep a biometric template for ongoing identification, and we never use your face to identify you elsewhere in the product. The images captured during the check are stored securely, restricted to authorised staff, and erased on request or when you delete your account. You can decline, but we cannot verify your account without the check.

Location

OnSiren is built around where you are. The app uses your location only with your permission, which you give for while you’re using the app. While you have a channel, your live location is shared with the officers on the network around you, and our staff can see it in our control console. On iPhone, sharing can carry on for a while after you leave the app; on Android, it runs only while the app is open. Turning your radio off in the app doesn’t stop it. Sharing stops when you sign out, when you no longer have a channel, or when you turn off location for OnSiren in your phone’s settings.

You choose your channel from a list of channels near you, and it stays your channel until you pick another: the app doesn’t move you as you travel. Other officers’ live positions shown on your map are held in your device’s memory only and are never written to its storage.

We keep a history of your location at key moments: from your live location (at most once a minute), when you sign up, when you look for channels, and when you send or receive an alert. An alert you raise keeps the place you raised it, which the officers who receive it can see.

If you look for a channel somewhere OnSiren doesn’t cover yet, we keep where you were and the name of the place, so we can plan where to open channels, and we may tell you when coverage starts near you. If you use a map tool, such as the nearest police station or transport, the app sends your location to find what’s nearby, and we don’t keep it.

Communications

  • Radio transmissions. Your voice transmissions are relayed live to the officers on your channel, recorded, and turned into text for the channel’s written log. Officers on the channel and our staff can play recordings back. If you speak another language, we detect it, translate the text into English and keep your original words too.
  • Channel chat. Messages you type, and photos you send with any caption. Photos are checked automatically for unsafe content before they are stored, unless the check is switched off for your channel. A photo the check rejects is never stored.
  • Alerts you send or receive, including where you raised them, your answers, any voice note (which we transcribe, and translate into English where needed) and any photo you attach, which is checked in the same way. A voice note is uploaded while the alert counts down, so we keep it even if you cancel the alert.
  • Channel activity. When you join or leave a channel, the officers on it can see that, and we keep a record of the channels you have been on. When you acknowledge a channel briefing, your call sign appears in the channel chat as a radio check. Channels you mark as favourites are visible only to you.
  • Reports and blocks. If you report a message, we keep your report and our team reviews the message. If you block someone, we keep that so their messages stay hidden from you.

Alpha One

Alpha One, the assistant in the app, is optional. If you use it, we keep your conversations with it, by voice or text. To answer you, it can look at information in the app that you could see yourself, such as your alerts, your channel’s messages, your notifications, and which officers are near you (as a distance and direction, not an exact position). If you allow it, Alpha One also remembers useful facts about you. You can see and delete them, or switch Alpha One off, in Settings → AI & your data.

Safety check

Safety check is an optional wellbeing check-in. If you use it, we keep how you said you were feeling, anything you chose to add, and Alpha One’s reply. This is information about your health, so we ask for your explicit consent first. Only you can see it. You can change how often it asks, see or delete your history, or turn it off, in Settings → Safety check.

Notifications

We keep your device’s notification tokens so alerts can reach you, a record of the notifications we send you and whether they reached your phone, whether the app is open or in the background, and your notification settings. If you have been away from your channel, we may send a notification naming the officers who spoke. You can turn this off in Settings → Notifications → Channel chatter.

Device and diagnostics

Crash and error reports help us fix faults. They are tagged with a pseudonymous user ID, your call sign, and the app version, not your name, location, or contact details.

The app also records your screen while you use it, and logs the screens you open and the actions you take, linked to your account, your call sign and your channel. We use these recordings to find faults and improve the app. Sign-in codes, your phone number, your licence details and the camera during your identity check are hidden from recordings, and the Safety check screens are not recorded. Anything else on your screen can appear in a recording, including the map with other officers’ positions, channel messages and photos. The app doesn’t currently let you turn this off. You have the right to object: email privacy@onsiren.com.

Feedback

If you send us feedback, we keep what you write or say, your call sign, your channel, the area you were in (a place name your phone works out, not your exact location), and your phone model and app version.

Rank badges

When rank badges are switched on, acknowledging your channel briefings builds the standing on your profile, and officers near you can see your rank badge unless you turn off Show my rank on the map in Settings → Privacy.

Network launch

If you ask for a reminder before the network launches, we keep that. At launch, we record the first officers to transmit on each channel (call sign, channel and time) for the launch prize, and our staff can play that transmission back.

4. Our website, our field team and contacting us

Reserving a call sign

You can reserve a call sign through the Clocked challenge, and until 7 October 2026 you could also reserve one on our website. When you reserve one, we collect your phone number, which you confirm with a code, the call sign, and your email address if you give it, which you also confirm with a code. We note your IP address and browser details to stop abuse, and whether you reserved on our website or through Clocked, so we can see which works better. When you join the app with that phone number, your reservation carries over.

Meeting our field team

Members of our field team meet security officers in person. If you talk to one of them, they may note your name, phone number, email address, employer, SIA licence number, notes about the conversation and where you met, and send you a Join OnSiren link by text or email. When you check your licence on that link, we keep what the SIA register says about it, with your IP address and browser details. If you then join, we link that record to your account. We use this to send you the link, to check your licence when you use it, and to credit the team member who helped you. Your licence number stays on that record; it is not copied into our contact list.

Messages we send you

We use the email address you give us to send you service messages about what you signed up for or asked us for, and about significant changes to this policy. If you use the app, that means messages about your account and our terms. If you reserved a call sign on onsiren.com or through the Clocked challenge, it means messages about your reservation, such as when it is ready to activate. If you asked our field team for a Join OnSiren link, we text you the link, and email it too if you gave us an email address. After that we send you service messages only after you use the link (you check your licence on it, go to an app store or sign up), to help you get started. These are not marketing, and we add no open or click tracking to them. Your Join OnSiren link is personal to you, so we record when you use it (see “Our contact list”).

If you are in our contact list (see below), we may also send you marketing emails and texts about OnSiren without you signing up for them. Unlike service messages, marketing emails carry open and click tracking. You can stop marketing emails at any time with the unsubscribe link in any of them, and marketing texts by replying STOP to any of them.

Every service or marketing email we send has an unsubscribe link; using it stops both. It does not stop one-off emails you ask for, such as a code to verify your email address, the Join OnSiren link our field team sends at your request, or the confirmation of a reservation you have just made; those carry no unsubscribe link.

If an email we send you bounces for good, or you mark one as spam, our email provider tells us and we stop sending you service and marketing emails at that address. One-off emails you ask for still reach you after a spam report, but not at an address that has bounced for good.

Our contact list

We keep one contact record for each person who uses the app, reserves a call sign, gives their details to our field team, fills in one of our forms or is added from a list we import. It holds your name, email address and phone number where we have them, any call sign you reserved, where you came to us from, your licence sector (never your licence number), how far you have got (for example whether you checked your licence through your Join OnSiren link, went to an app store or finished signing up), which email topics you have switched off, and whether you opened or clicked our marketing emails: those contain a small tracking image and links that pass through our servers, so we can see when they are opened and which links are clicked. When you fill in one of our forms, we also keep the time, your IP address and browser details as a record of your choice. We group these records into lists and score them to decide which messages are relevant to you. The record holds no biometric data and no location.

Contacting us

If you email us or send us a request, we use what you send and your contact details to reply and to deal with it. We keep that correspondence while we need it for that purpose, and to show how we handled it.

6. How AI processes your data

Some OnSiren features use AI. The companies that provide it are listed under Who we share it with.

  • Speech to text: radio transmissions, and voice notes on alerts and broadcasts, are turned into text, and translated into English where needed, so the channel has a written record everyone can read.
  • Checks: photos you attach are checked for unsafe content, and an AI model checks your licence card photo and compares your face with it to confirm your identity. Messages are also screened against a list of abusive words.
  • Briefings and summaries: your channel briefing is put together automatically from alerts, broadcasts, channel activity and public information, and no AI writes it. When you tap Summarise, AI writes a short summary of your briefing or of your channel’s chat. A summary you ask for is private to you.
  • Channel history: AI picks out notable events from your channel’s radio transcripts and keeps them as the channel’s history, which briefings and Alpha One can draw on.
  • Alpha One, if you use it: answers your questions by voice or text and can help draft an incident report. While you talk to it, your voice goes straight from your phone to OpenAI. Where it offers to prepare something for you, such as an alert, nothing is sent or changed until you confirm it.
  • Safety check, if you use it: AI writes Alpha One’s reply to your check-in.

AI output is informational. Two things happen automatically and affect your account: the identity check, which uses AI, and the limits the app applies if you don’t finish verifying in time. If either affects you and you think it’s wrong, email privacy@onsiren.com and a person will review it. Decisions to suspend or remove an account are made by people.

7. Who we share it with

Other officers on the network. That is the point of OnSiren: your call sign, live location, alerts, and voice transmissions reach the licensed officers around you.

Service providers (processors). These providers process data on our behalf, under contract, and only on our instructions:

  • Amazon Web Services: hosts OnSiren in its London region (eu-west-2): our servers, database, cache, logs and file storage, including licence card and face-check images, radio and alert audio, and photos. Through Amazon Bedrock it also runs the AI models we use, including Anthropic’s Claude, for the identity check, photo checks, translation, summaries, Alpha One’s typed chat and Safety check replies. Bedrock may run these models in other AWS regions in the EU. Anthropic does not receive this data. Amazon SES, in the same London region, sends our emails, such as email verification codes, Join OnSiren links, call sign reservation confirmations, service messages and marketing emails.
  • OpenAI (EU endpoints): turns channel radio, and voice notes on alerts and broadcasts, into text; runs Alpha One’s voice conversations, for which your phone connects to OpenAI directly while you talk; and reads some briefing summaries and the welcome tour aloud.
  • Deepgram (EU endpoint): turns channel radio into text when we choose it instead of OpenAI.
  • Apple: notifications and push-to-talk on iPhone.
  • Google Firebase: notifications on Android, and crash reports.
  • PostHog (EU): app analytics and screen recordings, as described under The data we collect.
  • Twilio: text messages: sign-in codes, codes for reserving a call sign, the links our field team sends, marketing texts, and replies such as STOP with our automatic answers to them.
  • Slack: our team’s internal notifications, for example when someone reserves a call sign (with the phone number and email partly hidden), asks for coverage where we have none yet, or sends feedback (the notification doesn’t include the feedback itself).
  • Google reCAPTCHA: security checks when you sign up or sign in to the app, reserve a call sign, ask for access on our law enforcement page or our page for BIDs and local authorities, or use a Join OnSiren link.
  • Cloudflare: a Turnstile security check on Join OnSiren links.
  • Google Maps Platform: maps in our staff console, which can show an officer’s last known position, and place names for coverage requests.
  • Google Sign-In: identity provider for the admin console. Staff only; officers never see it.
  • Google Tag Manager: tag management container for analytics on this site. The container loads only after you accept analytics cookies. Nothing loads if you decline.
  • Google Analytics: aggregated visitor analytics (GA4) on the landing site, consent-gated, with Google Signals off and ads personalisation off. Google states that GA4 does not log or store visitor IP addresses. Analytics data is processed by Google in the United States under an approved UK transfer mechanism (see our Cookie Policy).

Services your phone contacts directly. The app’s map comes from OpenFreeMap, a community map service: your phone asks it for map images, which shares your IP address and the area you are looking at. When the app shows a street or place name for a location, your phone asks Apple (on iPhone) or Google (on Android) to name the spot.

The SIA public register: we check your licence number against the register the SIA publishes. This is a lookup of public data, not a disclosure of your account.

Authorities: we may disclose data where the law requires it or where it is necessary to protect someone’s life or safety.

We never sell personal data.

8. International transfers

We keep processing in the United Kingdom and the European Economic Area wherever we can. Our servers and AI models run on AWS in London and elsewhere in the EU, and OpenAI, Deepgram and PostHog process through their EU services.

Some providers process data outside the UK and the EEA, or may do: Twilio, Slack, Cloudflare, Google (reCAPTCHA, staff sign-in, maps, Tag Manager and Analytics), Apple and Google for notifications and place names, and OpenFreeMap. Where a provider processes data outside the UK, we rely on safeguards recognised by UK GDPR: UK adequacy regulations, or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, so your data has equivalent protection wherever it is processed. You can ask us for a copy of the safeguards we rely on.

9. How long we keep it

We keep personal data no longer than necessary for the purposes set out in this policy. Operational records, such as alerts, transcripts, recordings and location history, are kept for safety and audit purposes, and account data is kept while your account is active.

You can delete your account at any time from the app. When you do, we erase the personal data we hold about you, apart from:

  • alerts you raised, which stay in the incident record with your call sign, where you raised them and what you sent, so the record stays complete;
  • our staff’s audit log of actions taken on your account;
  • records from a conversation with our field team, apart from the link to your account;
  • some copies in our team’s internal notifications, and data held by our analytics and crash-reporting providers.

If any of your records have to be kept for a legal reason, such as an open investigation, you can’t delete your account until they no longer need to be kept, and the app tells you so. You can also ask us to delete specific data at any time. See Your rights.

10. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you;
  • Rectify data that is inaccurate or incomplete;
  • Erase your data (the “right to be forgotten”);
  • Restrict or object to processing, including processing based on legitimate interests;
  • Port the data you gave us to another service in a machine-readable format;
  • Withdraw consent at any time where processing is based on consent (such as the biometric check), without affecting processing that happened before you withdrew.

You have the right to object to direct marketing at any time, including any profiling for it. To stop our marketing emails, use the unsubscribe link in any of them; to stop marketing texts, reply STOP; to object to all of it at once, email privacy@onsiren.com.

Some of this you can do yourself in the app: Settings → AI & your data shows what Alpha One remembers about you and lets you delete it, and Settings → Safety check lets you see and delete your check-ins. For anything else, email privacy@onsiren.com. We respond within one month.

If you are unhappy with how we handle your data, you can complain to the UK regulator, the Information Commissioner’s Office, at ico.org.uk. We would appreciate the chance to resolve it with you first.

11. Deleting your account

You can delete your account at any time, in the app: tap your call sign on the map to open your profile, then go to Settings → Account → Delete my account. The app asks you to confirm twice. Deletion removes your personal data as described in How long we keep it, unless some of your records have to be kept for a legal reason. You do not need to email us or give a reason. If you prefer, you can also request deletion at privacy@onsiren.com.

12. Security

We protect your data with technical and organisational measures appropriate to its sensitivity: encryption in transit, access controls, audit logging across the network, and the data-minimisation choices described above, such as keeping other officers’ live positions out of persistent storage on your device. Authorised staff can access an account when they need to support or test the service, and we keep a log when they do. No system is perfectly secure, but if a breach ever puts your rights at risk we will notify you and the Information Commissioner’s Office as the law requires.

13. Changes to this policy

When we change this policy we will update the date at the top and, for significant changes, tell you before they take effect: in the app or, if you don’t use the app, by email where Messages we send you allows us to send you service messages. Continued use of OnSiren after a change means the updated policy applies.

14. Contact

Questions about this policy or your data: privacy@onsiren.com. For anything else, see www.onsiren.com/contact.

Cookies

We use cookies to understand how our website is used and improve your experience. These analytics cookies are optional: nothing is set unless you accept. For more information, please see our Cookie Policy.

Privacy Policy | OnSiren