Lybb Tech Innovation
Lybb Tech Innovation
  • Home
  • Products
  • About Us
  • Contact Us
  • More
    • Home
    • Products
    • About Us
    • Contact Us
  • Home
  • Products
  • About Us
  • Contact Us

Witness audio

A dash cam for your life

Have you ever been in a circumstance where something happened that you wish you would have recorded? Maybe you've experienced harassment, bullying or violence and didn't have enough evidence to prove your side of the story. 


Witness Audio allows you to securely and discretely capture audio of interactions you have with other people, so that when something happens, you have the truth on your side. 

Blue shield with a white heart symbol in the center.

Witness audio Privacy Policy

Effective date: April 20, 2026  |  Last updated: April 20, 2026


Witness Audio (“we,” “our,” or “the app”) is a mobile application that records audio in a rolling buffer on your device and lets you save portions of that buffer as audio files. This Privacy Policy explains what information we collect, how we use it, and the choices you have.


Contact: For privacy questions or requests, email info@lybbtech.com.


In-app navigation used in this policy: wherever this policy says “the Privacy screen,” it means the screen you reach by opening the hamburger menu in the app and tapping “Privacy Policy.” That screen shows the privacy notice and contains the analytics opt-out toggle.


1. Who is responsible for your data?

The Witness Audio app is made available by Lybb Tech Inc. For the purposes of this policy, “we” refers to Lybb Tech Inc. as the provider of the Witness Audio application. We are the data controller for the data described below that we process.


2. Information we collect and how we use it


2.1 Audio recordings

• What we collect: When you use the recording feature, the app records audio from your device’s microphone and stores it in a rolling buffer on your device (up to 12 hours). When you save, the app writes the selected portion as a WAV file on your device.

• How we use it: Audio is stored only on your device. We do not upload, transmit, or have access to your audio recordings. Recording, buffering, and saving all happen locally.

• Retention: Buffered audio is overwritten as new audio is recorded. Saved files remain on your device until you delete them.


2.2 Location data

Location is used in three situations. Two are fully local; the third (the map screen) sends information to Mapbox, as described below.

• Safe Zones (on-device only). If you enable Safe Zones, the app uses your device’s location to detect when you enter or leave zones you define, so it can automatically pause or resume recording. This uses Android geofencing on your device. The zones you define are stored on your device only; we do not receive your zones or your position on our servers. Because geofencing must work when the app is not in the foreground, enabling Safe Zones requires Android’s “Allow all the time” (background) location permission. You can revoke this permission in Android system settings at any time, which will disable Safe Zones.

• Maps (Mapbox) for Safe Zone setup. When you open the Safe Zone map screen to create or edit a zone, the app uses the Mapbox SDK to load map tiles. Delivering the map requires sending your device’s IP address (which reveals your approximate location) and the map coordinates you are viewing to Mapbox, along with standard HTTP metadata (e.g., SDK version and user-agent). Mapbox is a third-party processor and handles that data under its own privacy policy (https://www.mapbox.com/legal/privacy). Mapbox is contacted only while the map screen is open — not during recording, not while Safe Zones are active, and nowhere else in the app.

• Evidence Packages (on-device only). When you save a recording, the app automatically creates an Evidence Package (see 2.3). If you have granted location permission, the app records a location sample approximately every 20 minutes while recording, plus one at the moment you save. If you have not granted location permission, no location is included. These samples are written only to the Evidence Package folder on your device; they are never sent to our servers.

We do not use your location for advertising or analytics, and we do not send your location to our servers.


2.3 Evidence Packages

When you save a recording, the app automatically creates an Evidence Package — a folder stored alongside the saved audio on your device. It is designed to help you demonstrate that a recording has not been altered.

• What it contains:

o A SHA-256 cryptographic hash of the saved audio file.

o A digital signature generated by a key held in the Android Keystore on your device.

o Device and app information: manufacturer, model, Android version and SDK, app name, app version and version code, device time zone, and the Android ID (Settings.Secure.ANDROID_ID, a per-app, per-user identifier generated by Android).

o Recording start/end timestamps.

o Location samples, as described in 2.2, if location permission was granted.

o A trusted timestamp response (see 2.4) if one could be obtained.

• Where it’s stored: Evidence Packages are written to the Documents/WitnessAudio folder on your device, or to the app’s private storage if Documents access is unavailable. They are not transmitted to us.

• Retention: Evidence Packages remain on your device until you delete them.


2.4 Trusted Timestamps (third-party request)

To prove when a recording was saved, the app sends the SHA-256 hash of the saved audio (not the audio itself) over HTTPS to an RFC 3161 Time-Stamping Authority (TSA). Only one TSA is contacted per save — whichever one successfully responds. The app tries these in order:

1. FreeTSA — freetsa.org (tried first)

2. Sectigo — timestamp.sectigo.com (fallback if FreeTSA is unreachable)

3. Apple — timestamp.apple.com/ts01 (fallback if both of the above fail)

In normal operation, every save goes to FreeTSA; the other two are contacted only if a previous attempt fails. The TSA receives the audio hash, your device’s IP address, and the time of the request. It does not receive the audio itself or any location or personal data. The signed timestamp response is stored inside the Evidence Package on your device. These third parties operate under their own privacy policies; we have no affiliation with them and do not direct their processing. If no internet connection is available, saving still works — the Evidence Package simply will not include a trusted timestamp.


2.5 App usage analytics (optional)

• What we collect: Unless you opt out, we use Firebase Analytics (Google) to collect anonymous, aggregated data about how the app is used — for example, screen views, that recording was started or stopped, that a save completed, that Exports or Settings were opened, and that certain features (such as Safe Zones) were used. This does not include your name, email, audio, or precise location.

• Advertising identifiers: The app configures Firebase Analytics to not collect the Android Advertising ID (AAID) or the Android ID (SSAID), so your analytics events are not associated with Google’s advertising identifiers.

• How we use it: To understand feature usage, improve the app, and fix issues. Data is aggregated and not tied to your identity.

• Your choice: You can turn analytics off at any time on the Privacy screen by toggling “Share app usage analytics” off. This only affects analytics; crash reporting is separate (see 2.6).

• Third party: Analytics are processed by Google. See https://policies.google.com/privacy.


2.6 Crash reports and diagnostics

• What we collect: We use Firebase Crashlytics to collect crash reports and related technical information (e.g., device model, Android version, stack traces) when the app crashes or when we log non-fatal errors.

• What we do not collect in crash reports: Crash reports do not include your audio recordings or your location.

• How we use it: To diagnose bugs and improve stability.

• Your choice: Crash reporting is not separately toggleable in the app; it is part of our service to maintain stability. If you do not want any crash data sent, please discontinue use of the app.

• Third party: Crashlytics is provided by Google. See https://policies.google.com/privacy.


2.7 Purchases (Google Play Billing)

Witness Audio offers a 7-day free trial. After the trial, continued use of the app requires a one-time in-app purchase, processed by Google Play Billing. When you purchase, Google processes the transaction under its own privacy policy and returns a purchase token to the app so we can recognize your entitlement on your device. We do not receive your payment method, name, or billing address. See https://policies.google.com/privacy.


2.8 Information you give us directly

• Support / bug reports. If you contact us — for example, by using the in-app “Report a bug” option — we use the information you provide (such as your email address and message) only to respond to your request. We do not use it for marketing unless you agree.

• Consent and preferences. When you accept the in-app Use Policy and Privacy Notice, we store that acceptance locally in app preferences. We may also record that consent was given as an anonymous analytics event (without identifying you) for compliance and product purposes.


3. What we don’t do

We do not:

• Collect your name, email, or contact information (except when you voluntarily email us for support).

• Sell or rent your personal data.

• Serve ads, or share data with advertising networks or ad-tech SDKs.

• Transmit the contents of your audio recordings — they never leave your device.

• Send your precise GPS location to our servers — it is used only on your device for Safe Zones and Evidence Packages, and shared with Mapbox only as described in 2.2.


4. Legal basis for processing (EEA/UK)

If you are in the European Economic Area or the United Kingdom:

• Consent — for in-app analytics (while the analytics toggle is on) and for the in-app consent and privacy notice flow.

• Legitimate interests — for crash reports and diagnostics, which we use to maintain and improve the app’s stability and security. We do not use this data for marketing.

• Contract — for processing necessary to provide the app (e.g., storing your preferences, enabling recording and saves, delivering map tiles while the Safe Zone map is open).

You may withdraw consent for analytics at any time on the Privacy screen. Withdrawal does not affect the lawfulness of processing before withdrawal.


5. Data retention

• On your device. Audio in the rolling buffer is overwritten over time. Saved files and Evidence Packages stay on your device until you delete them. We do not control your device storage.

• Analytics. Firebase Analytics data is subject to Google’s retention and aggregation policies. We do not maintain our own copy of analytics data on our own systems.

• Crash reports. Retained as long as needed to diagnose and fix issues, in line with Firebase Crashlytics practices.

• Mapbox map requests. Retained by Mapbox under its privacy policy; we do not retain map tile requests.

• Trusted Timestamp requests. The TSA that handled your save retains records of the request under its own policy; we do not retain them.

• Support emails. Retained as long as needed to resolve your request and for a reasonable period for record-keeping.


6. Sharing and third parties

We do not sell your personal data. We share data only as follows:

• Google — Firebase Analytics & Crashlytics. Analytics and crash-reporting data are processed by Google under its privacy policy and the Firebase terms. Google may process data globally.

• Mapbox. When you open the Safe Zone map screen, map tile requests (your IP and the map area viewed) are sent to Mapbox under its privacy policy.

• Time-Stamping Authority (FreeTSA, with Sectigo and Apple as fallback). When you save a recording, the SHA-256 hash of the saved audio plus your IP address are sent to one TSA per save, as described in 2.4.

• Google Play Billing. Purchase transactions for the one-time unlock are processed by Google under its privacy policy.

• Legal requirements. We may disclose information if required by law, court order, or government request, or to protect our or others’ rights, safety, or property.

• Business transfers. If we transfer our business or assets, we may transfer data as part of that transaction, subject to the same privacy commitments.

Your audio and precise location are not sent to us or to third parties; they remain on your device (including in any saved files and Evidence Packages you create).


7. Data security

• Audio and precise location used by the app are processed and stored only on your device, except as described in 2.2 for Mapbox.

• The Evidence Package signing key is generated and held inside the Android Keystore. On most modern devices it is protected by hardware-backed security (TEE / Secure Element), and the private key does not leave that secure environment.

• Where network processing is involved (Firebase, Mapbox, RFC 3161 Time-Stamping Authorities), we rely on industry-standard services with security measures described in their respective policies.

• No method of transmission or storage is 100% secure; we take reasonable steps to protect the data we process.


8. Your rights

Depending on where you live, you may have the right to:

• Access — request a copy of the personal data we hold about you.

• Correction — request correction of inaccurate data.

• Deletion — request deletion of your personal data, subject to legal exceptions.

• Opt out of analytics — toggle “Share app usage analytics” off on the Privacy screen.

• Portability — in some jurisdictions, request a portable copy of your data. Note that most of your data (audio, saved files, Evidence Packages) already lives on your device and can be copied directly using Android’s file manager; portability primarily applies to analytics and crash data held by Google.

• Object or restrict processing — in some jurisdictions, object to or ask for restriction of certain processing.

• Withdraw consent — where we rely on consent, you may withdraw it at any time (for example, by disabling analytics in the app).

• Complain — lodge a complaint with a supervisory authority in your country.

To exercise these rights, email info@lybbtech.com. Because we do not have access to your recordings, your location, or your Evidence Packages — those stay on your device and you can delete them directly from the Saved Files screen — some requests may need to be handled by the relevant third party (Google, Mapbox, or a TSA) through their own tools.

California residents. We do not sell personal information as defined under the CCPA. We may “share” or “disclose” information for analytics, crash reporting, map rendering, and trusted timestamping as described above; you can opt out of analytics on the Privacy screen.


9. Children

The app is not directed at children under 13 (or a higher minimum age where required by local law). We do not knowingly collect personal data from children. If you believe a child has provided us data, please contact us and we will delete it as required by law.


10. International transfers

If you are outside the United States, your data (e.g., analytics and crash data sent to Firebase, map requests to Mapbox, and timestamp requests to FreeTSA, Sectigo, or Apple) may be transferred to and processed in the United States or other countries where those providers operate. We rely on appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms) where required by law.


11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy at the same URL and update the “Last updated” date. For material changes, we may notify you in the app. Continued use of the app after the effective date of changes constitutes acceptance of the updated policy.


12. Contact

For privacy questions, requests, or complaints:

• Email: info@lybbtech.com

• In-app: open the hamburger menu and tap “Privacy Policy” to view the privacy notice and manage analytics.



Data Deletion

Data Deletion Policy

 Witness Audio is designed with privacy first - almost all of your data
stays on your device and is never sent to our servers. This page explains
how to delete your data.

Key fact: Your audio recordings, saved files, Evidence Packages, and
precise location data are stored only on your device. We never have access
to them. You can delete them at any time without contacting us.

Step 1: Delete Data On-Device

The majority of data that Witness Audio handles lives entirely on your
device:

- Audio recordings & saved files - delete them from the Saved Files screen
  in the app, or from Documents/WitnessAudio using your device's file
  manager.
- Evidence Packages - stored alongside your saved files; delete them the
  same way.
- Safe Zone definitions & app preferences - go to Android Settings > Apps >
  Witness Audio > Storage > Clear Data, or simply uninstall the app.

Uninstalling the app removes all app-private data, preferences, and cached
content from your device.

Step 2: Request Deletion of Off-Device Data

A small amount of anonymous data may exist on third-party servers:

- Firebase Analytics - anonymous, aggregated usage data (if you had not
  opted out).
- Firebase Crashlytics - crash reports and device diagnostics.
- Mapbox - map tile request logs (your IP address, generated when you used
  the Safe Zone map).
- Time-Stamping Authorities - a SHA-256 hash of your saved audio plus your
  IP address (one request per save).

To request that we delete all analytics and crash data associated with your
app instance, email us at info@lybbtech.com with the subject line "Data
Deletion Request." We will process your request within 30 days and confirm
by reply.

What happens after your request: We will delete any analytics
and crash data we can identify as associated with your app instance in
Firebase. For data held directly by third parties (Mapbox, Time-Stamping
Authorities), you may also contact them through their own privacy
processes. We will provide guidance if needed.

After Deletion

- On-device data is deleted immediately when you clear it or uninstall the
  app.
- Off-device analytics and crash data will be deleted within 30 days of
  your request.

Questions?

For any questions about data deletion or your privacy, contact us at
info@lybbtech.com.

See our full Privacy Policy for more details about how we handle your data. 

Copyright © 2026 Lybb Tech Inc. - All Rights Reserved.


Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept