N

Noah — Privacy Policy

Version 0.1 · 19 September 2026 · applies to the Noah mobile app and web application

Closed-testing notice. Noah is in closed testing. The data in the test environment is fictional and was created for demonstration; it does not describe real people. This document states how the software actually behaves today. It has not yet been reviewed by a lawyer, and it must be before the app is used with real participants.

1. Who is responsible

Noah is software licensed to an organization — a school, a tour operator or a similar group organizer. That organization decides which people are entered into Noah and why, and is the data controller for the information about them.

Noah is operated by AKD Systems, which acts as a processor on that organization's instructions. Each organization's data is held in its own tenant and is not visible to any other organization.

2. There is no public sign-up

You cannot create a Noah account yourself. Accounts are issued by your organizer: staff accounts for administrators and guides, and separate accounts for adult travellers and for verified guardians. A child usually has no account at all — guides can run a trip entirely without child logins.

3. What Noah holds

InformationWhyWho entered it
Name, username, chosen languageSigning in and addressing you correctlyYour organizer
Email, phone, date of birth, nationality, staff notes on a client profileOrganizing the tripOrganizer staff
Emergency contactsReaching someone if there is a problem on a tripOrganizer staff
Identity documents (passports, ID cards, visas, consent forms)Travel and border requirements, where the organizer needs themOrganizer staff, on the web app only
Seat, group and itineraryRunning the tripOrganizer staff
Attendance (“unknown”, self-reported, guide-verified, absent, excused) with its time and sourceHeadcountsGuides, travellers, guardians
Answers to polls and formsWhat the organizer askedYou, or a guardian for a linked child
Updates sent to you and your acknowledgementsCommunication during a tripGuides and staff
Game nicknames and scoresThe on-board gamesPlayers
Sign-in records and an audit log of sensitive staff actionsSecurity and accountabilityCreated automatically
Your phone's model, Android or iOS version, the app version, its time zone, and an identifier the app generates for that installationKnowing which phone runs which version when something goes wrong, and — during testing — how much the app is actually used. It is not an advertising identifier and is not shared with anyone.Created automatically by the app
A notification token from Google (Firebase Cloud Messaging)Delivering a notification when the app is closed. The notification itself says only which kind of update arrived — never the message, a name or a place.Created automatically by the app

What Noah does not do

4. Children, parents and guardians

A child and a guardian are two separate identities in Noah; they never share a login. A guardian sees a child's information only after the organizer has verified the link between them, and only for that child — never another family's. Verification can be withdrawn by the organizer, which ends the access at the guardian's next request.

A guardian acknowledging an update means only that the guardian saw it. Noah never treats it as proof that a child was present anywhere.

5. Who can see what

Access is decided by the organizer through roles and permissions, and enforced by the server on every request. In particular: a traveller sees their own seat, plan and updates, never the roster or other people's details; a guide sees the trips they are assigned to; identity documents sit behind a separate permission that guides do not normally have, and every time one is opened it is written to an access log.

6. Keeping it safe

No system is perfectly secure, and Noah does not promise that a message will always arrive on a phone. Device settings, silent mode and network coverage are outside its control.

7. How long it is kept

Trip information is kept while the organization needs it. Identity documents carry an expiry and are deleted automatically by a scheduled job — currently 180 days after they are filed, unless the organizer sets a shorter period. Records of published events used to synchronize the apps are pruned after 24 hours.

8. Your requests

Because your organizer decides what is held about you, ask them first — they can correct or remove information directly in Noah, including deleting an account. If you cannot reach them, write to us at the address below and we will pass the request to the organization responsible and support them in answering it.

9. Changes

If this policy changes materially, the new version is published here with a new date, and organizers are told.

10. Contact

AKD Systems — akdsystemslb@gmail.com