Política de Privacidad
WAKEBEAR APP™ — PRIVACY POLICY (v1.0)
Last updated: July 07, 2026. Effective from: July 07, 2026.
Data Controller
In accordance with Law N° 29733 – Personal Data Protection Law of the Republic of Peru, its Regulation approved by Supreme Decree N° 003-2013-JUS, and the directives of D.S. 016-2024-JUS, the owner and controller of personal data is:
- Owner: Luis Angel CG (Iniciativa Peruana)
- ID (DNI): 71041874
- Address: Mz C. 4 Lt 62 Manzanilla II, Lima Cercado, Peru
- Central Contact: iniciativaperuana@gmail.com
- App Support: support@wakebear.app
1. Information We Collect and Process
A. Location Data (Primarily Local Processing — Intermittent Predictive Wake Architecture)
- In-RAM Privacy Principle and Predictive Kinematic Engine: WakeBear does not track your location continuously and uninterruptedly throughout the entire journey. The application implements a predictive kinematic engine that calculates a Safe Wait Time ("T_espera") based on the remaining distance to the destination and the conservative maximum speed of the transport used. Once this interval is calculated, the application attempts to suspend itself and yield CPU control to the operating system. The hardware clock (Android AlarmManager) attempts to wake the application in an isolated environment without a graphical interface (Headless Isolate) to perform a spot GPS reading. We DO NOT store location history, routes, paths traveled, or historical coordinates. Journey coordinates are processed locally in a volatile manner in the device's RAM; as an independent process, certain external queries (such as map link resolution) are required exclusively to provide the destination search service, without persistently linking to your cloud profile.
- Geolocation Engine Operation Modes:
- Cruise Mode (T_espera > 2 minutes): The application programs the processor's hardware clock and suspends itself completely. The CPU remains asleep until the OS kernel wakes it up at the calculated instant. During this period, the application consumes no GPS, network, or battery resources.
- Sprint Mode (T_espera ≤ 2 minutes): When the user is in imminent proximity to the destination (less than 2 minutes estimated travel), the engine activates a high-speed continuous geolocation channel with medium precision (
LocationAccuracy.medium) to ensure the exact alarm trigger without false negatives. - Asymmetric Stepped Degradation Mode (Defensive Fallback — Phase 5): If the operating system revokes the background hardware clock permission (
SCHEDULE_EXACT_ALARM), the engine implements intelligent geographical tier degradation to preserve device battery on long-distance trips (8 to 12 hours), while ensuring 100% local processing without cloud tracking:- Macro Tier (distance to destination > 50 km): The engine exclusively uses cellular antennas and Wi-Fi (
LocationAccuracy.low) with readings every 5 kilometers and a 30-minute interval between pings, reducing consumption to less than 0.2% battery per hour. - Mid-Approach Tier (distance between 10 km and 50 km): The engine activates hybrid GPS hardware (
LocationAccuracy.medium) with readings every 1 kilometer and a 5-minute interval between pings, consuming approximately 1% battery per hour. - Tactical Proximity Tier (distance < 10 km): The engine instantly mutates to the original Sprint Mode with continuous high-speed GPS (
LocationAccuracy.medium, readings every 15 meters), ensuring the exact acoustic alarm trigger upon crossing the border of the configured dynamic radius. - Airplane Mode Exclusion (PRO PLUS Plan): When the transport is Airplane, the system prohibits tier degradation and forces continuous full-power GPS throughout the flight. This is because jet speeds (up to 900 km/h) and fuselage electromagnetic interference (Faraday Cage) make any battery saving incompatible with passenger safety.
- Inertial Tunnel Engine Preservation (Premium Plan — Subway/Train): When the transport is Subway or Train and the distance to destination is less than 10 kilometers, the system ignores macro and mid tiers to keep mathematical prediction multipliers active underground, preventing telemetry blackouts in tunnels or subways.
- Macro Tier (distance to destination > 50 km): The engine exclusively uses cellular antennas and Wi-Fi (
- Negative Security Buffer (-90 seconds): The engine subtracts 90 seconds from the calculated time to compensate for the Cold Start time of the device's GPS antenna, ensuring the hardware is operational prior to effective arrival.
- Inertial Tunnel Engine (v3.6): The position prediction function in tunnels or subways operates volatilely in your device's RAM. Estimated speed and calculated seconds underground are automatically destroyed upon finishing the trip or closing the application. This module does not store or transmit any data.
B. Google Maps Link Interception (All Plans)
When a user uses the location sharing feature from the external Google Maps application to WakeBear, the application receives the shortened URL (maps.app.goo.gl domain).
- The software makes a lightweight technical HTTP header request (
HEADrequest) to the servers to expand the link and extract geographical coordinates ephemerally into RAM. - This query is strictly necessary to provide the destination identification and configuration service. The process is designed not to store, log, or index the name of the establishment, restaurant, or business in our cloud databases. The resulting coordinate is processed locally on the user's device for radar operation.
C. Account and Authentication Data
- Unique User Identifier (UID) generated immutably by Firebase Authentication to securely associate your account.
- Email address and display name obtained via Google Sign-In for profile management.
D. Usage and Monetization Data
- Number of completed trips and available credit balance (stored atomically in the Firestore web server under the
free_trips_remainingandtotal_trips_usedfields). - State of the non-cumulative monthly active subscription plan (
GUEST Trialor Courtesy Trial Period,PREMIUMorPRO PLUS) and transport mode preferences selected by the user.
E. Device Data and Fraud Prevention
- Device model, operating system version, IP address, and application version for stability control.
- Device Fingerprint: Derived from hardware and network metadata, processed server-side in an encrypted manner in the
trials_usedcollection with the sole legitimate purpose of preventing abuse, account cloning, and mass creation of free trial periods on the same phone.
F. Local Disk Persistence Data (SharedPreferences)
To ensure alarm survival against forced process termination by the operating system (Doze Mode, moto_freezer, HyperOS, Joyose), WakeBear stores the following data temporarily and exclusively locally in your device's encrypted internal storage (Android SharedPreferences):
- Active destination coordinates (
destlat,destlng). - Alarm trigger radius (
active_alarm_radius). - Alarm boolean state (
alarm_active,alarm_triggered). - Selected transport mode (
transport_mode).
As a general rule, these operational data are kept locally and are not synchronized with account database servers; their automatic destruction occurs upon deactivating the alarm or closing the trip session. Their main purpose is to allow the application to attempt to recover the alarm state when the CPU is awakened by the hardware clock, although the success of this recovery may depend on operating system power management policies.
G. Data Collected on the Pre-launch Web Page (Waitlist)
WakeBear may collect, through its pre-launch web platform or Waitlist, the email address voluntarily provided by the user when completing the registration form. Such personal data will be treated confidentially and used exclusively to: (i) confirm and manage your waitlist registration; (ii) notify novelties regarding early access, spot allocation, or relevant changes in project status; and (iii) communicate updates linked to the pre-launch phase.
The legal basis legitimizing this processing is the free, prior, express, unequivocal, and informed consent of the data subject, granted at the exact moment of submitting the web form, pursuant to Law N° 29733. The user may revoke their consent and request unsubscription at any time through the cancellation mechanism provided in the communications or via the official support channel.
Unless required by competent authority mandate or legal obligation to the contrary, the email address captured for the Waitlist will be retained only for the time strictly necessary to administer the pre-launch phase and its derivative communications. If the project undergoes definitive closure or cancellation, WakeBear will proceed with the deletion of such records, observing principles of minimization and proportionality.
The email address will not be commercialized, rented, assigned, or transferred to data brokers or third parties foreign to WakeBear's operation. Any promotional communication unrelated to waitlist management will require additional, separate, and specific consent from the user.
2. Transparency and Permission Justification (Google Play Compliance)
To highly reliably provide its main proximity transit alarm function and help prevent you from missing your stop, WakeBear requires requesting the following official Android APIs. Their concession is necessary to provide the continuous geolocation service:
High-Intensity Background Geolocation
- Permissions:
ACCESS_FINE_LOCATION,ACCESS_BACKGROUND_LOCATION,FOREGROUND_SERVICE_LOCATION. - Justification: WakeBear is a geographical proximity alarm. Its main function and reason for existence require calculating the distance between your current position and your selected destination, even with the screen off and the application minimized. Without this permission, the alarm cannot function, and the user runs the risk of missing their station, stop, or airport.
- Privacy Mitigation: Coordinates are processed locally and volatilely in device RAM. They are not permanently stored on disk, not sent to servers, and not shared with third parties. The Intermittent Predictive Wake engine minimizes GPS reading frequency to the minimum technically viable.
Exact Alarms and Processor Hardware Clock
- Permissions:
SCHEDULE_EXACT_ALARM,USE_EXACT_ALARM. - Justification: WakeBear programs the processor's hardware clock (AlarmManager) with the
setExactAndAllowWhileIdle()flag to wake the CPU from deep sleep mode (Android 14/15 Doze Mode) at the precise instant calculated by the kinematic engine. This mechanism is essential to ensure the alarm sounds on time, as inexact OS timers (setInexact) can defer execution by up to 15 minutes, which is unacceptable for a transit safety application where a delay can mean the user misses their destination. - Resource Mitigation: The hardware alarm is programmed with a strict maximum cap of 10 minutes between wake-ups and cancels automatically upon alarm deactivation or arrival at the destination, immediately freeing the kernel clock.
Power Management and Battery Optimization Exemption
- Permissions:
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS,WAKE_LOCK. - Justification: Android device manufacturers (Motorola, Xiaomi, Vivo, OPPO, Samsung) implement aggressive proprietary power management layers (known as
moto_freezeron Motorola,Joyoseon Xiaomi,iManageron Vivo, andHyperOSon recent devices) that freeze or imperatively terminate background processes, including critical geolocation services. Without battery optimization exemption, these proprietary layers can prevent the alarm from sounding, leaving the user asleep or distracted past their destination. - Partial Wake Lock (PARTIAL_WAKE_LOCK): The native Autonomous Acoustic Receiver acquires a partial Wake Lock with a strict maximum time of 3 minutes, exclusively during alarm audio playback. This Wake Lock is released automatically upon expiration of the time limit or upon being silenced by the user. No Wake Lock is maintained during the trip journey.
Emergency Audio Channels and Continuous Vibration
- Audio Channel:
AudioManager.STREAM_ALARMwithUSAGE_ALARMattributes. - Justification: WakeBear uses the operating system's alarm audio channel (
STREAM_ALARM), the same channel used by native Android alarm clocks. This channel has the technical property of ignoring the device's silent mode and Do Not Disturb (DND) mode. This design decision is intentional and critical for user safety: if the passenger falls asleep on public transport with the phone on silent, the alarm must sound anyway to prevent missing their destination. - Loop Vibration: Vibration activates simultaneously with audio in a pulsing wave pattern as a redundant mechanism, ensuring the user is alerted even if the hardware speaker volume is damaged or the device is inside a backpack.
- User Notification: Upon activating the alarm, the application clearly informs the user that sound will play at maximum volume even in silent mode.
Full Screen over Lockscreen
- Permissions:
USE_FULL_SCREEN_INTENT,SYSTEM_ALERT_WINDOW. - Justification: The alarm interface deploys as a high-priority full screen (FullScreenIntent) directly over the device's lock screen, illuminating the screen without requiring the user to unlock it. This behavior is identical to native Android alarm clocks and is necessary to visually awaken the user.
System Boot Reception (BOOT_COMPLETED)
- Permission:
RECEIVE_BOOT_COMPLETED. - Justification: If the device reboots during an active trip (e.g., due to a system update, low battery, or accidental manual reboot), the native Autonomous Acoustic Receiver detects the boot event and launches the application to automatically re-hydrate the previously active alarm. Without this permission, a device reboot mid-journey would silently void the alarm.
3. Resilience Architecture and Autonomous Acoustic Receiver (Technical Transparency)
WakeBear implements an advanced resilience architecture (Phoenix Pattern) via standalone native Kotlin components (AlarmTriggerReceiver and PhoenixReceiver) that operate independently of the application's graphics engine (FlutterEngine).
- Tracking Persistence (Swipe-to-Kill Immunity): If the user or system forcibly closes the interface from the "Recent Apps" view, the background service triggers a hardware resurrection process (
onTaskRemoved) that will revive the application instantly to ensure the geofence is not interrupted. Tracking and location collection actively continue until the user ends the trip by interacting with the "STOP" button in the interface. - Authority over Sound Profiles: The component does not require the application to be open. Upon activation, it intentionally overrides any "Silent Mode," "Vibrate," or "Do Not Disturb (DND)" user settings, emitting the alert on the system's highest priority channel (
STREAM_ALARM) with a partial Wake Lock. - Data Isolation: It accesses exclusively local device data (SharedPreferences) to verify alarm state and makes no network connections upon triggering.
This resilient design seeks to maximize alarm delivery rate even when the user accidentally closes the app or when manufacturer power management layers attempt to terminate the background process.
4. Data Sharing with Third Parties
WakeBear does not sell or commercialize your personal information or location routes. We share limited data with essential infrastructure providers, map platforms, and advertising monetization services. WakeBear does not use Meta Pixel, Google Analytics for Firebase, or any other behavioral analytics system.
| Provider | Shared Data | Purpose | |---|---|---| | Google LLC / Firebase Cloud (us-central1 region) | UID, email, plan state, trip count | Authentication, transactional storage (Firestore), and subscription state. | | Google Maps Platform (or equivalent services) | Necessary coordinate or link queries | Map services, destination resolution, and routing (without linking the full trip to your UID). | | Google Play Billing | Purchase tokens, product IDs | Secure verification and processing of subscriptions. | | Monetization Providers (e.g., Google AdMob or others) | Device identifiers, technical interaction data, or ad signals | Provide integrated in-app ads (including formats like ad reels or equivalents) for monetization and feature unlocking (FUP), as applicable. |
As a general rule, your trip progress is processed locally; separately, certain technical data or device signals may be processed by advertising network providers strictly to facilitate in-app monetization. WakeBear does not share your exact location, your email, or your direct user account with these advertising providers.
If required by the legislation of the Republic of Peru, a legitimate court order, or a competent authority mandate, registration data may be communicated to corresponding entities.
5. Data Retention and Deletion
| Data Type | Server Retention Period |
|---|---|
| Account Data (UID, Email, Name) | Until account cancellation request + 90 calendar days. |
| Trip Quota, Plan State, Preferences | 1 year or until user record deletion request. |
| Record in trials_used collection | Retained to prevent fraudulent reuse of trial period; deleted immediately upon processing account deletion. |
| Local alarm data (SharedPreferences) | Automatically destroyed upon deactivating the alarm. Not stored on servers. |
| Technical advertising data (if applicable) | Subject to the retention policies of the corresponding monetization provider. |
| Waitlist Data (Web) | Until official launch, user unsubscription, or project cancellation. |
6. User Rights (ARCO Rights)
In accordance with Law N° 29733 of the Peruvian State, you have absolute control over your data and can freely exercise your rights of Access, Rectification, Cancellation, and Opposition (ARCO).
- You can request the deregistration and total incapacitation of your records directly from the application by going to: Profile → Danger Zone → Delete Account.
- Or you can send a formal signed request attaching a copy of your identity document to the central support email: support@wakebear.app.
- The maximum mandatory response and resolution period for cancellations or modifications is fifteen (15) business days, in strict compliance with Article 18 of Law N° 29733.
- Data Portability: You have the right to receive your data in a portable and machine-readable format, in accordance with applicable international standards.
- Advertising Choices: You can manage ad preferences or advertising identifiers directly from your device's operating system settings.
7. Children's Privacy
WakeBear is not directed at children under 13 (COPPA). We do not knowingly collect personal data from minors. If we become aware that a child under 13 has provided personal data, we will delete it immediately and irreversibly. Parents or guardians may contact support@wakebear.app to report such situations.
8. Information Security
WakeBear applies advanced technical and organizational safeguards, including:
- Local Data Protection (AES-256 + Hardware KeyStore): To prevent alterations facilitating refund fraud, your trip origin coordinates (
secure_origin_lat,secure_origin_lng) are encrypted using AES-256 viaFlutterSecureStorage, anchoring its cryptographic keys to your device's native security hardware (Android KeyStore / iOS Secure Enclave). These critical data are immunized against disk tampering. - HTTPS/TLS Encryption for all data in transit between the device and Firebase servers.
- API Key Isolation in Google Cloud Secret Manager, never embedded in the application binary.
- Firebase Security Rules (Firestore Security Rules) restricting data access solely to authenticated UIDs.
- Native Signature Cross-Validation (Signature Check): Native Kotlin code verifies the Official Hash (SHA-256) in real-time against pirated APKs. If the system detects the installed application's signing certificate has been altered from its official Google Play Console version, the system forces immediate stoppage to protect user data.
- Server-side purchase verification: Subscriptions are validated exclusively on the server via Cloud Functions (
verifyGooglePlayPurchase), preventing local manipulation of payment states.
No method of transmission, storage, or processing of data is 100% secure. It is recommended to keep the device operating system and application updated.
Security Breach Notification: If a personal data security breach representing a risk to user rights is detected, WakeBear will proceed with automated notification to the National Personal Data Protection Authority (ANPD) and affected users within the periods established by D.S. 016-2024-JUS.
9. International Data Transfers
WakeBear utilizes Google Cloud infrastructure (region: us-central1) and Firebase services. Your data may be processed on servers located outside Peru. Google LLC complies with international data protection frameworks. For Peruvian users, transfers are made under the guarantees recognized by the ANPD.
10. Changes to this Policy
We will notify users of material changes to this Privacy Policy with at least 30 days advance notice via in-app notification and/or email. Continued use of the application after the effective date constitutes acceptance of the updated policy. The history of previous versions of this policy can be consulted by contacting support@wakebear.app.
11. Contact
Support Email: support@wakebear.app Central Email: iniciativaperuana@gmail.com Controller: Luis Angel CG Address: Mz C. 4 Lt 62 Manzanilla II, Lima Cercado, Peru Phone: +51 914 907 002
This Privacy Policy is governed by the laws of the Republic of Peru, specifically Law N° 29733 – Personal Data Protection Law and its regulations, including D.S. 016-2024-JUS.
In the event of any conflict or inconsistency between the Spanish version and the English version of this document, the Spanish version shall prevail.