Legal
Privacy policy
How Alarm Station LLC handles information collected through this website, the Alarm Station app, and the monitoring service behind them.
Effective September 11, 2026.
Who we are
This website, the Alarm Station Android app (app.alarmstation.station) and the monitoring service behind them are operated by Alarm Station LLC, a Tennessee limited liability company, referred to here as “we” and “us”. Write to privacy@alarmstation.app with any question about this notice.
Our role
On this website, we decide what is collected and why. If you fill in the contact form, you are dealing with us directly.
In the product, we mostly are not. An alarm company sells Alarm Station to a community, and that community decides which units are monitored, what their rooms are called, who stands in front of a station, and how long records are kept. They control the information. We process it on their instructions, and so does the alarm company that serves them. Where the community is a HIPAA covered entity we act as their Business Associate under a Business Associate Agreement, and their dealer needs one with them as well.
Most of the people whose information is in the system never installed anything and never agreed to anything with us: residents whose sensors report, and staff who answer alarms. If you are one of them, the community you live in or work for is the first place to ask, and we will help them answer you.
This website
If you write to us through the contact form or by email, we receive the name, email address, phone number, organization and message you choose to send. We use it to reply and to keep a record of the conversation, and we do not sell it or use it for advertising.
What you send through the form reaches us by email, handled on the way by the service that delivers it and the one that stores our mailbox. Hosting this site means our provider processes IP addresses and ordinary request logs in order to serve the pages. We do not run advertising pixels or a marketing analytics suite on this website, and we do not set tracking cookies. Essential cookies may be used by the host to deliver the site.
The Alarm Station app
The app runs on a dedicated Android touchscreen mounted in a staff area. It is not a personal device and it has no user accounts. Nobody signs in. The station itself holds a credential, is paired once from the web admin, and is released from there.
The app sends us the following.
- Device information. Device model, operating system version and app version when the station is paired, and then, with the heartbeat it sends every twenty seconds, whether a camera is present and how it is labeled.
- What staff do with an alarm: that it was displayed, that somebody pressed I’m on it, and that it was resolved, each with a time.
- Initials, where the community has turned on attribution. Two or three letters, typed when an alarm is resolved. Nothing verifies them; they are a label, not a login.
- A photograph, where the community has turned on attribution. When an alarm is acknowledged or resolved, the station takes a still image of whoever pressed the button and sends it to us, so that a typed set of initials has evidence behind it.
About the photographs. They are off unless the community turns attribution on. The camera is aimed at the position a person stands in to use the station, and installation requires it to be pointed away from residents. The image is stored on its own and is never matched against anything: we run no face recognition, compute no face template, and do no face detection of any kind. It is a picture for a person to look at, kept for 90 days by default, and the dealer sets that period. Where staff are photographed, the community is the employer doing it and is responsible for telling its own staff.
Photographs wait on the station if it cannot reach us. A station that has lost its connection saves the images to its own storage and sends them when the link returns, because an alarm resolved during an outage is when attribution matters most. They are encrypted on the station with a key that cannot leave it, and each one is deleted from the station as soon as we have it. The queue is small and deliberately so: if a station is offline long enough to fill it, the oldest images are dropped rather than kept.
The app contains no advertising and no analytics or tracking software, and it does not use push messaging. It does include Telnyx’s software for carrying two-way voice calls, which receives the signalling needed to place a call and measurements of how well it is running, such as packet counts, jitter and audio levels, rather than what is said on it.
Two-way voice
On certain alarms the alarm system in a unit places a telephone call to a number we operate. The station answers it, so staff can hear the room and speak into it.
Nothing is recorded. No audio is stored, by us or by the provider that carries the call. What we keep is the fact of the call: which alarm it belonged to, which line it arrived on, when it started and ended, which station joined it, and which controls staff used.
A call runs for five minutes and then ends on its own. Staff can extend it, and it ends when the alarm is resolved.
On duress, panic and holdup alarms the call is listen only. Staff can hear the room, and the alarm system’s speaker stays muted, so anybody there cannot hear the station and the system gives no sign that somebody is listening. A silent alarm exists for the case where a person is being made to act normally by somebody standing next to them, and a voice from the alarm system would tell that person the alarm had been raised. So it enforced rather than left to whoever is at the screen, and every duress and panic alarm is treated this way, including any that were audible.
On other alarms staff choose the direction: two way, speak only, or listen only. In listen only the station’s own microphone is closed.
The station’s side of a call is encrypted. The other side is an ordinary telephone call across the phone network, which we neither control nor encrypt, and the two meet at a bridge. A call is not end-to-end encrypted and we do not describe it as one.
Video verification
On some alarms Alarm.com sends a link, and the app opens Alarm.com’s own page showing live and recorded video from the customer’s cameras.
We do not receive, store or process that video, or the audio with it. It passes between the customer’s system and Alarm.com. What we do is display a page they sent us.
That page is given the use of the station’s microphone so its own two-way audio works. The station’s camera is never given to it. That camera exists for attribution photographs and points at the staff position.
What the service processes
Alarm systems in a community’s units send their signals to us, in some cases through a platform such as Alarm.com. From those signals we keep the account they came from, the sensor and whatever the community named it, which commonly identifies a room or a unit, the kind of event, and when it happened. We group them into incidents, show them on the community’s stations, and record what staff did.
Some of this is health information. In a care or wellness setting the events include fall detection, medical alerts raised from a pendant or an app, and missed welfare check-ins, attached to an identifiable room or unit. We treat that as the sensitive information it is. We do not analyze it, score it, or draw any clinical conclusion from it. We display it and record what happened next.
We also keep an audit trail: when a signal arrived, when it reached a station, when it was acknowledged and resolved, and who or what did each of those. It records reads as well as writes, so opening the detail of an incident is itself recorded. It is append-only, so entries are added and never altered.
Accounts for the dealer and community staff who use the web admin hold a name, an email address, a role, and a hashed password.
How long we keep it
- Signals and incidents are kept for one year by default. The dealer sets the period, and it can be set shorter for a particular community.
- Attribution photographs are kept for 90 days by default. Each one is given an expiry when it is stored, and a sweep removes the expired ones. The dealer sets that period.
- The audit trail is kept longer than signal data, so that a routine deletion does not erase the record of an incident somebody is still asking about.
- Call records are kept for the same period as signals and incidents. There is no audio to keep.
- A legal hold exempts specific records from deletion, for as long as it applies.
- Website inquiries are kept as long as they are useful to the conversation and our ordinary record keeping, then deleted.
Who we share it with
We do not sell personal information, and we do not share it for advertising. We share it only in these ways.
- With the community, whose information it is and who decides what happens to it.
- With the alarm company that serves them. A dealer can see the alarms at their customers’ sites, including the room or unit label and the kind of event, because setting the system up and supporting it requires it. Where that is protected health information, the dealer is handling it too, and needs its own agreement with the customer as well as with us.
- With a central station, if the community has asked us to forward alarms there, either after a delay or immediately. That forwarding is optional and is the community’s choice.
- With the vendors that run the service. The product runs on Google Cloud, under a Business Associate Agreement covering the components we use. Telnyx carries two-way voice calls for us. We also use ordinary vendors to host this website and to deliver and store email, and they handle only what that requires. We can give a current list on request.
- Where the law requires it, or to establish or defend a legal claim.
Information is stored and processed in the United States.
How we protect it
- Encrypted in transit on every connection we control, and encrypted at rest, including on the station itself.
- Each company’s data is isolated in the database, enforced by the database itself rather than by application code, and tested.
- Attribution photographs are held separately from the rest of the data.
- Access is limited to the people who need it to run and support the service.
- We will notify affected customers of a breach of their information without unreasonable delay, and within the time our agreements and applicable law require.
A station identifies itself as a device rather than as a person. We can say which station displayed an alarm and which station resolved it. Where a community has not turned on attribution, we cannot say which individual was standing in front of it, and the community’s control over who can reach the station is what stands in for that.
What we do not do
- We do not dispatch police, fire or medical services, and we place no calls. See how we monitor.
- We do not record two-way voice calls, and we store no audio from them.
- We do not sell or rent personal information.
- We do not use this information for advertising, and we run no ad or analytics SDKs.
- We make no clinical determination and no automated decision about any person.
- We do not use face recognition or any other biometric identification.
Your choices and rights
Depending on where you live, you may have the right to ask what information is held about you, to have it corrected or deleted, and to complain to a regulator. Making a privacy request explains how to do that and what we need in order to find your information.
For information in the product, the community or dealer is the one who decides, so we will normally refer your request to them and help them answer it. Where they instruct us to delete or export information, we do. Under HIPAA, a resident’s rights of access and amendment run against the covered entity, and we support them in meeting those requests.
Children
Neither this website nor the app is directed at children, and the app is a fixed installation in the staff area of a business rather than something anyone uses personally. We do not knowingly collect information from a child through either.
Some of the communities we serve, including schools and dormitories, may house people under 18. Where that is so, an alarm may relate to a room occupied by a minor. The school or operator decides what is monitored and how rooms are labeled, and is responsible for the notices and permissions its own setting requires. We process what they send us on their instructions, and hold it under the same terms as everything else described here.
Changes
If this notice changes in a way that matters, we will update the date at the top of this page. Using the website or the product after that date means the updated notice applies.
Contact
Alarm Station LLC, privacy@alarmstation.app. Related: Terms and how we monitor.