Privacy policy

Draft. The marked placeholders in square brackets are filled in before publication; this notice is then removed.

Last updated: [Date]

This policy describes which personal data Encounter processes: on this website, in the web app and in the iPad app. It follows the Swiss Federal Act on Data Protection (revFADP).

1. Controller

[Controller: name, address]
E-mail: support@encounterapp.ch

[Review: the role of the organisations that use Encounter – e.g. whether they are themselves responsible for their team’s data and for the recordings on their iPads, with us processing these data on their behalf.]

2. This website

The website itself sets no cookies, uses no analytics or tracking tools, shows no ads and loads no content from third parties. It is delivered through Firebase Hosting by Google. This processes technically necessary access data such as the IP address, the time and the address requested, to provide the pages and to protect the service.

3. The web app

In the web app, the teams of organisations that use Encounter plan the slots of their zones and see their iPads. For this we process:

Sign-in works without a password, with a link that you receive by e-mail. For this we use Firebase Authentication by Google; this service stores the staff e-mail addresses in the US, with the time of account creation and of the last sign-in. The sign-in e-mails are sent from noreply@encounterapp.ch through Hostpoint (Switzerland). When a person no longer belongs to any site, because they were removed from a team or replaced as site manager, their sign-in account is deleted too; this does not apply to the main admin, who sets up the sites.

The web app and its database run on Google Cloud in Zurich (region europe-west6). In the browser, the web app keeps the language setting, the e-mail address entered for signing in (until the sign-in is completed in this browser), then the sign-in session and, through Firebase, the days of use, in the browser’s storage (localStorage, IndexedDB), not in cookies. Firebase’s heartbeat service records the days of use: for each day of use, it stores the date and the version of the Firebase SDK in IndexedDB and sends them to Google with the requests to Firebase Authentication.

Google Cloud logs every request to the web app and the server: the time, the address requested, the browser or device type and the IP address. E-mail addresses are not part of the addresses requested. The logs are kept for [30 days] in [Region].

4. The iPad app

An iPad is set up with a zone’s code: the app reads the QR code with the camera, or you type the code. The camera image is neither stored nor sent. During setup, the iPad sends a random installation ID, the app version, the iPadOS version and the model. After that it regularly reports its app version, iPadOS version, model and last contact so that the organisation sees its iPads; each iPad gets a short ID such as “iPad 7K2QF” for this. The iPad signs in to Firebase Authentication with its own device identity, without names or e-mail addresses, and loads the plan of its zone.

To stop codes from being guessed, the server counts wrong codes per client IP address (up to 10) and per front-end address (up to 50), each for 15 minutes from the first wrong code. This count is kept only in the server’s memory and then expires.

Recordings, transcripts and AI assessments

Recording is optional and is switched on in the app’s own settings (the gear icon). The iPad then records during a slot with its camera and microphone; you first allow access to them in iPadOS. The transcription is created on the iPad; you choose its language in the app’s settings as well, and automatic transcription is on by default. The experimental AI assessment of the working alliance (bond, goals, tasks) runs on the iPad with Apple Intelligence.

Recordings, transcripts and assessments are never uploaded. Transcription and assessment run on the iPad, none of it goes to a server, and the iPad’s backups do not contain them. The app deletes them itself as soon as the review is closed, at the latest before the next slot’s first cue (or 30 minutes after the slot ends if no other slot follows that day). The app also deletes them at every launch on a set-up iPad and whenever it goes to the background.

5. Service providers and data locations

Data are therefore also disclosed to the US and through the worldwide server network of Firebase Hosting. [Add the safeguard for disclosure abroad, e.g. Swiss-U.S. Data Privacy Framework or standard contractual clauses – to be reviewed]

6. Contact by e-mail

If you write to support@encounterapp.ch, we process your e-mail address and your message in order to reply.

7. Purpose and retention

We process these data only to provide and protect Encounter: for sign-in, planning, the display on the iPads and the overview of the iPads. Encounter itself does no tracking, no analytics and no advertising; for Firebase’s heartbeat service, see section 3.

[Add retention periods: team data and sign-in accounts, plans, iPad records]

8. Your rights

Under the revFADP, you can request information about your personal data, have incorrect data corrected and data deleted, object to the processing and ask for your data to be handed over. To do so, write to support@encounterapp.ch; as a team member, you can also contact your site manager. You can also contact the Federal Data Protection and Information Commissioner (FDPIC).

9. Changes

We update this policy when Encounter changes. The version published on this page applies.