🧊 DryICE

Privacy Policy

Last Updated: August 22, 2026

🔍 Overview

DryICE is a community-driven application that helps users share and view reports of Immigration and Customs Enforcement (ICE) activity. We are committed to protecting your privacy and being transparent about how we collect, use, and protect your information.

DryICE is available as a web app and as native Android and iOS apps. This policy applies to all versions.

📊 Information We Collect

👤 Account Information

  • Email Address: Collected when you create an account and used for authentication, account recovery, and account-deletion requests
  • Display Name / Username: A username you choose (or one generated for you) that is attached to your sighting reports. This is the only personal identifier shared with reports
  • Authentication Provider: Whether you signed in with email/password, Google Sign-In (web and Android, via Google Credential Manager on Android), or Apple Sign-In (iOS). If you use Google or Apple, we receive the basic profile information they share (name, email, and optional profile photo)
  • Profile Details: Optional profile photo, bio, and location text you choose to add, plus your profile visibility setting (public or private)
  • Role: An internal role (user, volunteer, moderator, admin) used for moderation and administration

📍 Location Data

  • GPS Coordinates: We collect your precise location when you report a sighting or enable location features so we can show nearby reports
  • Last Known Location: If you enable proximity notifications, your most recent approximate location is stored in your private user record so our servers can decide whether a new report is close enough to notify you. It is not shared with other users
  • Favorite Locations: Names, addresses, and coordinates of places you save (for example home, work, or school) so you can receive alerts about sightings near them
  • Report Locations: The coordinates and address of each sighting you report are shared with the community

📝 User-Generated Content

  • ICE Sighting Reports: Location, status, optional notes, the time of the report, and your username
  • Photos: Optional photos attached to reports, stored in Firebase Cloud Storage. Photos are re-encoded on your device before they are uploaded, which removes the metadata cameras embed in image files — including the GPS coordinates of where the photo was taken and your device's identifiers. Only the image itself is sent
  • Votes: Your thumbs up/down votes on reports, used to maintain accuracy
  • Spam Reports: When you flag a report as spam, we store the report ID, your reason, and your user ID (one flag per user per report)
  • Bug Reports: Title, description, category, optional screenshot, and basic device information you submit through the in-app bug reporter

📱 Device, Notification, and Usage Information

  • Push Notification Tokens: Firebase Cloud Messaging (FCM) tokens for each device on which you enable notifications, together with the platform (web, Android, iOS) and basic device info (model, manufacturer, OS version)
  • Notification Settings: Your notification preferences and alert radius
  • Language and Onboarding State: Your chosen language and which onboarding and tutorial steps you have completed, synced to your account so they follow you across devices
  • Device Information: Browser type, operating system, and app version
  • Usage and Performance Data: Feature usage, app crashes, and error reports collected through Firebase Analytics to improve the app

💳 Payment Information (Premium Users Only)

  • Subscription Data: If you subscribe to Premium, we store your subscription status, tier, renewal or trial-end date, and the payment-processor identifiers needed to manage your subscription (for example a Stripe customer ID or RevenueCat customer ID)
  • No Card Storage: We never see or store card numbers, CVV codes, or bank details. Payments are handled entirely by Stripe (web) or by Google Play and the Apple App Store (mobile, via RevenueCat)
  • Admin Grants: Administrators may grant Premium access manually; in that case we record who granted it and when

🏢 ICE Facility Locations (Public Data)

The map includes a permanent layer showing ICE detention facilities and field offices. This layer:

  • Is built from public listings on ice.gov (U.S. Government works in the public domain), not from user reports
  • Is geocoded at build time, on our side, using the U.S. Census Bureau geocoder with OpenStreetMap Nominatim as a fallback. Your device does not contact these services to display the layer
  • Is refreshed periodically but may be approximate (some entries resolve only to city level) or out of date
  • Does not involve any personal data about you

🎯 How We Use Your Information

Primary Uses

  • Community Service: Display ICE sighting information to help community members stay informed and aware
  • Location Services: Show nearby sightings and enable distance-based filtering
  • Notifications: Send proximity alerts, favorite-location alerts, and occasional service announcements to the devices you enable
  • Quality Control: Use voting and spam-report data to maintain the accuracy of reports
  • Account Management: Authenticate you, sync your settings across devices, and manage Premium subscriptions
  • Service Improvement: Analyze aggregate usage to improve functionality and fix bugs
  • Safety and Security: Detect abuse, enforce our Terms of Service, and protect users

Data Processing

  • Local Storage: Preferences and cached data are stored on your device; account data is stored in Firebase (Google Cloud), hosted in the United States
  • Community Sharing: Sighting reports are shared with other users to create a community resource
  • Analytics: Usage patterns are analyzed in aggregate

🔗 Data Sharing and Disclosure

Community Features

  • Public Information: Sighting reports (location, status, notes, time, and username) and vote counts are visible to all users, including users who are not signed in
  • Photo Access: Photos attached to reports are visible to Premium subscribers, administrators, and the report owner. Free users can only view photos they uploaded themselves
  • Protected Data: Email addresses, last known location, favorite locations, device tokens, and subscription details are never shared with other users

Third-Party Services

We use the following third-party services to provide and improve DryICE:

Firebase (Google)

  • Firebase Authentication: Manages user accounts and sign-in (email/password, Google Sign-In, Apple Sign-In)
  • Cloud Firestore: Stores sighting reports, profiles, settings, and other app data
  • Firebase Cloud Storage: Stores report photos and profile photos
  • Firebase Cloud Functions: Runs server-side logic such as notifications, cleanup, spam handling, and payment webhooks
  • Firebase Cloud Messaging: Delivers push notifications
  • Firebase Analytics: Collects usage and crash statistics
  • Firebase Hosting / App Hosting: Serves the web app
  • Privacy Policy: https://firebase.google.com/support/privacy

Google Analytics (marketing website only)

  • What it is: Our public website at dryiceapp.com uses Google Analytics to count visits and see which links people use. This is separate from the analytics inside the app, and it is a separate collection of data
  • What it collects: Pages viewed, links and buttons clicked, roughly where in the world the visit came from (worked out from the IP address, which Google Analytics does not store), the browser and device type, and whether the visit came from a search engine or another site
  • What it does not collect: It is not connected to your DryICE account, because the website has no sign-in. It does not know who you are and does not receive anything you do inside the app
  • Cookies: It sets cookies in your browser to tell repeat visits from new ones. You can block or delete them in your browser settings; the website works normally without them
  • Not on the app: The app at app.dryiceapp.com does not load Google Analytics. Analytics inside the app is Firebase Analytics, and the “Share usage analytics” switch in Settings turns it off
  • Privacy Policy: https://policies.google.com/privacy

Google Maps Platform

OpenStreetMap Nominatim

  • Address Search and Geocoding: When you type an address or use address autocomplete, the text you enter (and, for reverse lookup, coordinates) is sent to the OpenStreetMap Nominatim service to find matching locations
  • Privacy Policy: https://osmfoundation.org/wiki/Privacy_Policy

Payment Processing

  • Stripe (web payments): Processes Premium subscription payments on the web. Stripe handles all payment information directly and we do not store card details.
  • RevenueCat (mobile in-app purchases): Manages in-app subscriptions purchased through Google Play Billing (Android) and the Apple App Store (iOS)
  • Google Play / Apple App Store: Process the actual mobile payments under their own terms and privacy policies

Authentication Providers

Hosting

  • The web app is served from Firebase Hosting and may also be deployed to other static hosting providers (such as Netlify or Vercel). These providers receive standard web-server logs (IP address, user agent, requested pages)

Data Sharing with Third Parties

  • No Data Sales: We do not sell your personal information, and we do not share it with advertisers or data brokers
  • Service Providers: We share limited data with the services listed above only as necessary to provide DryICE functionality
  • Proprietary Software: DryICE is proprietary, closed-source software. User data is stored only in the services described above, never in the application code

Legal Requirements

  • We may disclose information if required by law, subpoena, or court order, or where we believe in good faith that disclosure is necessary to protect the safety of users or the public
  • We will resist overly broad requests where we reasonably can, and we will notify affected users when legally permitted

🔒 Data Security

Protection Measures

  • Encryption: Data is encrypted in transit (HTTPS/TLS) and at rest in Google Cloud
  • Access Controls: Firestore security rules restrict who can read and write each record; private user data is readable only by you and administrators
  • Server-Only Fields: Subscription and role fields can only be changed by our servers or administrators, never by clients
  • Regular Updates: Security measures are regularly reviewed and updated

User Controls

  • Location Permissions: You control location access through your device or browser settings
  • Notifications: You can disable notifications per device and adjust your alert radius in Settings
  • Local Data: You can clear locally stored data in Settings
  • Profile Visibility: You can make your profile private

✅ Your Rights

Depending on where you live (including under the GDPR in the EU/UK and the CCPA/CPRA in California), you may have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Update your profile, username, favorite locations, and settings directly in the app, or ask us to correct other data
  • Deletion: Delete your account and personal data (see Data Retention below)
  • Portability: Receive your data in a commonly used, machine-readable format. Premium users can export sighting data in JSON, CSV, or PDF from the Analytics screen; for a full export of your account data, contact us
  • Opt Out / Object: Withdraw consent for location access or notifications at any time, and object to processing where applicable
  • Non-Discrimination: We will not treat you differently for exercising your privacy rights
  • No Sale Opt-Out Needed: We do not sell or share personal information for cross-context behavioral advertising

To exercise any of these rights, email us at the address in the Contact section. We will respond within 30 days (or sooner where required by law). We may ask you to verify your identity first.

👶 Children's Privacy

DryICE is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13, we will delete it. If you believe a child has provided us with personal information, please contact us.

⏰ Data Retention

Automatic Cleanup

  • Sighting Reports and Photos: Reports are automatically deleted, along with their attached photos, 4 hours after they are reported. A scheduled job runs every hour to remove expired reports
  • Anonymous Records of Expired Reports: When a report expires we keep an anonymous, approximate record of it so we can show long-term trends. That record holds the location rounded to roughly a kilometre, the time rounded to the hour, the report's status, the vote totals, whether a moderator had verified it, and whether a photo or notes were attached. It does not hold who reported it, the address, the text of the notes, or the photo itself, and it is not linked to any account. We keep these individual records for 30 days
  • Long-Term Trend Totals: After 30 days those individual records are combined into daily totals — how many reports there were in a given day and roughly which area they were in, and nothing more — and the individual records are deleted. The totals are counts, not records of anything that happened to a particular person, and we keep them indefinitely
  • Database Backups: Deleted data remains recoverable from our database backups for up to 7 days, after which it is gone for good
  • Security and Bookkeeping Data: Expired server-side verification records and payment-webhook markers are deleted automatically (webhook markers are kept for 7 days)
  • Spam Reports: When you flag a report as spam we record which report you flagged, the reason you gave, and that the flag came from your account. We keep these for 30 days and then delete them automatically
  • Push Tokens: Device tokens are removed when you sign out or disable notifications on a device, and tokens that stop working are marked inactive
  • Analytics: Aggregate usage data is retained according to Firebase Analytics defaults

Account Deletion

You can delete your account yourself, from the Account page in the app. There is no form to fill in and no email to send. You confirm it is you — by re-entering your password, or by signing in again with Google or Apple — and the deletion happens immediately. It cannot be undone, by you or by us.

We delete:

  • Your authentication account (email, password, provider links, profile photo)
  • Your profile, settings, favorite locations, notification settings, device tokens, onboarding state, and last known location
  • Every sighting report you submitted that has not yet expired, including any photos attached to them
  • Your votes, removed from other people's reports along with the record that you cast them
  • Any spam flags you filed, and any bug reports you sent us
  • Your subscription records in our systems

If you signed in with Apple, we also tell Apple to revoke the tokens that connected DryICE to your Apple ID.

Two things we cannot delete, stated plainly rather than buried:

  • Your subscription is not cancelled by deleting your account. Only you can cancel it, in your App Store or Google Play subscription settings, or with Stripe on the web. Cancel there first or you may continue to be charged.
  • A minimal billing record stays with our payment providers, because tax and consumer-protection law requires it. It contains no location data and none of your reports.

The anonymous records of expired reports described above contain no account information, so there is nothing in them to attribute to you or to remove. Deletion is immediate in our live systems; encrypted database backups age out separately within 7 days.

Manual Deletion

  • You can delete your own sighting reports at any time
  • You can clear all locally stored data through the app settings or by clearing browser data

🌍 International Users

DryICE is designed primarily for users in the United States, and our data is stored and processed in the United States on Google Cloud infrastructure. If you use DryICE from another country, your data will be transferred to and processed in the United States, which may have different privacy laws than your jurisdiction. We strive to comply with applicable privacy laws including GDPR, CCPA/CPRA, and other regional regulations.

📝 Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, the app, or legal requirements. When we do, we will update the "Last Updated" date at the top and, for significant changes, notify you through the app (for example in release notes or an in-app notice). Your continued use of DryICE after changes take effect constitutes acceptance of the updated policy. Prior versions are available on request — see the Contact section below.

📞 Contact Information

For questions about this Privacy Policy or to exercise your privacy rights, contact us at support@dryiceapp.com or through the app's feedback system.

✅ Consent

By using DryICE, you consent to the collection and use of your information as described in this Privacy Policy. You may withdraw consent at any time by deleting your account and discontinuing use of the app.

For information about deleting your account and data, please visit our Account Deletion page.