V|A Protection — Mobile App Privacy Policy

How the V|A Protection app (Android and iOS) collects, uses, and shares data during executive-protection operations.

Who publishes this app

Effective: July 31, 2026

V|A Protection (package ID com.executiveprotectionapp) is a private mobile operations application published by Aspis Omnia LLC, doing business as Vanguard Attaché. In this policy, “Aspis Omnia LLC,” “Vanguard Attaché,” “we,” “us,” and “our” refer to the operator of V|A Protection.

V|A Protection is provided to authorized executive-protection agents, drivers, operations personnel, managers, clients, and other approved mission participants. It is not intended for general public use, and it is available on both Android and iOS.

Privacy inquiries: privacy@vanguardattache.com. Deletion requests: datadeletion@vanguardattache.com.

This policy governs the V|A Protection mobile application only. Our marketing website is covered by the main Vanguard Attaché Privacy Policy.

1. Who this policy applies to

This policy applies to everyone who uses V|A Protection on Android or iOS — Vanguard Attaché agents, drivers, operations personnel (concierge, trip-operations, GSOC), managers, authorized clients, and other approved mission participants who have been issued an account by Vanguard.

2. Data we collect

CategoryWhat V|A Protection handlesPurpose
Account informationName, email, phone number, internal user ID, role, employer or organization, profile photoAuthentication, role-based access, and identification
Authentication dataSession tokens, one-time onboarding tokens, authentication sourceSign-in, account security, and session restoration
Mission informationAssignments, principals, itineraries, addresses, accommodations, operational notes, personnel, destinations, and schedule changesMission planning and coordination
Location and movement statePrecise and coarse GPS coordinates, accuracy, speed, heading, timestamps, location history, and a limited still / walking / in-vehicle classification derived from Android Activity Recognition after consent or from GPS speed as a fallbackLive team map, dispatch, safety, ETAs, clock-in/out, efficient GPS cadence, battery/data reduction, and mission audit
Shift recordsClock-in/out, check-ins, time logs, shift status, overtime, and related audit recordsStaffing, payroll support, and operational records
CommunicationsMission-chat text, sender, timestamps, and delivery/read informationCommunication between authorized mission participants
Voice notesUser-initiated microphone recordings, duration, audio files, and generated transcriptsMission communication and transcription
Photos and documentsUser-selected profile photos, booking or mission photos and documents, filenames, types, and upload timestampsProfiles and mission documentation
Push dataFirebase Cloud Messaging token (Android), Apple Push Notification token (iOS), installation identifier, and notification interactionMission alerts, assignments, and chat notifications
Device and diagnosticsDevice model, OS and app version, language, crash stack traces, non-fatal errors, internal user ID, role, email domain, and session diagnosticsApp security, reliability, and troubleshooting
Map and search informationAddresses, destination queries, map interactions, and route requestsLocation selection, routing, and navigation
Operational costsStaff, driver, and vehicle cost entries entered by authorized managersInternal operational reconciliation
Operational cost entries are internal reconciliation figures recorded by authorized managers. They are not consumer payment-card, bank-account, or other consumer financial information, and the app does not process payments.

3. What we do NOT collect

  • We do not collect consumer financial information. The app does not process payment cards, bank accounts, or purchases. (Operational cost figures entered by managers are internal reconciliation data, not consumer payment information.)
  • We do not provide health, wellness, workout, diagnosis, or medical features, and we do not collect medical or workout records. The only physical-activity information is the limited operational movement state described above, collected only during active shift tracking.
  • We do not collect your contacts or calendar. We access the microphone only when you explicitly record a voice note, and media files only when you explicitly attach them to a booking or chat.
  • We do not run third-party advertising or marketing-analytics SDKs. Firebase Cloud Messaging is used for Android push delivery and Firebase Crashlytics for crash diagnostics; the app does not use Firebase Analytics for advertising or marketing.

4. Background location — explicit notice

V|A Protection collects and transmits precise location while an authorized field user is clocked in on an active mission. Location tracking may continue when the app is minimized, the device is locked, or the app is not actively in use.

Location is used for live mission coordination, field safety, dispatch, route progress, ETA calculation, check-in and shift verification, and auditable mission records. A persistent Android foreground-service notification (and the equivalent iOS indicator) is displayed while background tracking is active. Tracking stops when the user clocks out or logs out.

Location is available only to authorized users according to their role and mission assignment. It is not sold, used for advertising, or provided to data brokers.

Granting the background-location permission is a deliberate user action and can be revoked at any time in the device’s system settings. Revoking it will limit your ability to perform field assignments.

5. Physical activity recognition — explicit notice

On supported Android devices, V|A Protection may ask for the Physical activity permission when an authorized staff user starts a shift. Before the Android permission dialog, the app explains that it will access a limited classification such as still, walking, or in a vehicle. Recognition runs only while the user is clocked in and stops at clock-out or logout.

The movement state is used to adjust GPS update frequency and reduce battery and cellular-data use. It is sent with protected shift location pings to Vanguard Attaché’s private CRM and may be retained with the operational shift record. It is not used to count steps, score fitness, infer a medical condition, advertise, or profile the user.

Physical activity access is optional. If the user chooses “Not now” or denies the Android permission, the shift continues and the app estimates movement from GPS speed instead.

6. Voice notes and transcription

Voice recording begins only after the user taps the record control. The user can preview or discard a recording before sending it. The app does not record audio in the background and does not access music libraries or arbitrary audio files.

When a voice note is sent, it is uploaded to Vanguard Attaché’s backend, where the audio is transmitted to OpenAI’s transcription service (hosted Whisper speech-to-text) to generate a text transcript. The audio and the resulting transcript become part of the mission communication record and are visible to authorized mission participants.

OpenAI, L.L.C. acts as our service provider (data processor) for transcription, processing submitted voice notes on OpenAI infrastructure in the United States over encrypted connections to generate transcripts. OpenAI states that API data is not used to train its models by default unless the customer explicitly opts in. Depending on our account configuration, API inputs and outputs may be retained for a limited period for abuse monitoring, security, or legal-compliance purposes.

7. How we use the data

  1. Authenticate users and authorize access based on role and mission assignment.
  2. Plan and coordinate missions, including assignments, itineraries, and schedule changes.
  3. Coordinate live operations between agents, drivers, dispatchers (GSOC), managers, and clients.
  4. Provide the live team map, dispatch, ETAs, and route progress during a mission.
  5. Classify limited movement state during an active shift to tune GPS cadence and reduce battery and cellular-data use.
  6. Verify check-ins and maintain auditable shift, time, and overtime records.
  7. Deliver operational notifications (assignments, alerts, chat) via push.
  8. Transcribe user-initiated voice notes for the mission record.
  9. Support internal operational reconciliation from manager-entered cost entries.
  10. Diagnose crashes and operational issues using backend logs and crash diagnostics.

We do not use the data for advertising, marketing profiling, or any purpose unrelated to executive-protection operations.

8. Who we share data with

Access to data inside V|A Protection is limited by role and mission assignment. Data is available to:

  • Aspis Omnia LLC / Vanguard Attaché operations personnel, for coordination, supervision, and support.
  • Authorized agents, drivers, managers, clients, and other assigned participants of a given mission — limited to the data relevant to that mission and their role.

We also rely on the following service providers, which process data on our behalf under contract:

Service providerPurposeWhere it runs
Fly.ioBackend application hosting (vanguard-attache-backend.fly.dev)Fly.io infrastructure
SupabaseCloud database, including real-time location dataSupabase infrastructure (managed PostgreSQL)
Google Firebase Cloud Messaging (Google LLC)Push notification delivery on AndroidGoogle infrastructure
Apple Push Notification service (Apple Inc.)Push notification delivery on iOSApple infrastructure
Google Firebase Crashlytics (Google LLC)Crash and non-fatal error diagnosticsGoogle infrastructure
Google Maps Platform (Google LLC)Map tiles, place search, and routingGoogle infrastructure
OpenAI, L.L.C.Voice-note transcription (hosted Whisper speech-to-text)OpenAI infrastructure, United States

We may also disclose data to government, law-enforcement, or other authorities when required by a lawful request, subpoena, court order, or applicable law.

We do not sell personal data. We do not share it with advertisers or data brokers, and we do not use it for advertising or marketing profiling.

9. Data retention and deletion

We keep each category of data only as long as necessary for the operational, safety, legal, contractual, insurance, and security purposes described in this policy. When data is no longer needed for those purposes, we delete or anonymize it. In general:

  • Location history is retained for a limited operational window for live coordination and mission audit, and is deleted or anonymized when no longer required under the applicable retention schedule.
  • Movement-state classifications sent with location pings may be retained with the operational shift record under the same mission and audit schedule.
  • Mission, assignment, and shift records are retained for the duration of the engagement and for any period required by our operational, audit, legal, insurance, or contractual obligations.
  • Chat messages, voice recordings, and transcripts are retained as part of the mission communication record.
  • Photos and documents are retained as part of the mission record.
  • Crash and diagnostic data is retained for a limited period for reliability and security analysis.
  • Push tokens and installation identifiers are retained until the app is uninstalled, the token is refreshed, or the account is deactivated.
  • When a user account is deactivated, we revoke access and delete or anonymize personal data after a reasonable period, subject to the legal-retention obligations below.

To request deletion of your account or data, email datadeletion@vanguardattache.com. We may verify your identity before acting on a request. We normally delete your account profile and the personal data associated with it, except where we must retain specific records to meet legitimate legal, contractual, insurance, security, or incident-investigation obligations — in which case we retain only what is necessary, for only as long as necessary.

10. Security

  • All traffic between the app, our backend, and our service providers is encrypted in transit using HTTPS/TLS.
  • Authentication uses signed session tokens with expiration.
  • Access to operational data is controlled by role (agent, driver, manager, staff, client) and mission assignment.
  • Database access is restricted and access-controlled.
  • Keep your account credentials confidential and report any suspected compromise to ops@vanguardattache.com.

11. Your rights

Depending on where you live, you may have rights under Brazil’s LGPD, the California CCPA/CPRA, the EU/UK GDPR, or other applicable laws. These include the rights to:

  • Access the personal data we hold about you and receive a copy.
  • Correct inaccurate or incomplete data.
  • Request deletion of your data, subject to legal-retention obligations.
  • Request restriction of, or object to, certain processing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent where processing is based on consent (for example, background location or Android Physical activity access — by ending your shift or revoking the permission).
  • Not be discriminated against for exercising your rights (CCPA/CPRA).
  • Lodge a complaint with your data-protection authority (Brazil’s ANPD, the California Attorney General, or your EU/UK supervisory authority).

To exercise any of these rights, email privacy@vanguardattache.com, or datadeletion@vanguardattache.com for deletion specifically.

12. International data processing

Vanguard Attaché operates primarily in Brazil. Your data may be processed in Brazil, the United States, and other regions where our service providers (including Fly.io, Supabase, Google, Apple, and OpenAI) operate. By using the app you consent to these transfers, which are protected by the security measures described above and, where required, by appropriate safeguards such as standard contractual clauses.

13. Children

V|A Protection is restricted to Vanguard Attaché personnel, clients, and other authorized adults. It is intended only for users aged 18 and over. It is not directed at, and we do not knowingly collect data from, anyone under 18.

14. Changes to this policy

We may update this policy from time to time. We will communicate material changes through the app or by email to active users. The “Effective” date at the top of this page reflects the current version.

Contact

For privacy questions, or to access or delete your data, contact us:

Privacy inquiries

privacy@vanguardattache.com

Deletion requests

datadeletion@vanguardattache.com

Aspis Omnia LLC, d/b/a Vanguard Attaché

This policy describes the data practices of V|A Protection (com.executiveprotectionapp) version 1.0.0 and later, distributed via Google Play and, where available, the Apple App Store.

WhatsApp