Privacy isn’t a feature here.
It’s the load-bearing wall.

Take it out and nothing above it stands: not the honesty, not the early conversation, not the handoff.

Every product decision on this page follows from one problem we couldn’t argue our way around — a workforce that assumes anything the company hands them reports back. You don’t solve that with a policy. You solve it by building something that has nothing to report.

The problem

They assume
it reports back.

And they’re usually right. Every barrier below is real, rational, and unaffected by a privacy policy nobody reads — which is why the answer had to be architectural.

Camp is a small town

Everyone sees who walked into the medic’s office, who took a call outside the crib room, who got pulled aside by the supervisor. There is no private corridor on a mine site. Reaching for help is a visible act, and being seen doing it carries a cost that has nothing to do with the help itself.

It might end up on a file

The fear isn’t abstract. It’s the next fitness-for-work assessment, the next roster, the next contract renewal. Whether or not that’s how your company works, a worker weighing it up has to assume it might be — and the downside of being wrong is their livelihood.

Company software is assumed to be watched

Because most of it is. Site wifi, the fleet phone, the LMS, the incident system — all of it reports somewhere. An app handed out by the same employer starts from that assumption, and no onboarding screen talks anyone out of it.

Anything that CAN identify you, will be assumed to

This is the one that decided the architecture. Promising not to look is a policy, and policies change with management. The only version a sceptical workforce believes is the one where there is nothing to look at.

So we built one with nothing to look at.

No login, because
there’s nothing to log in to.

Not a privacy setting. Not a mode. There is no account in the product at all — the concept doesn’t exist.

We never ask who they are

No email, no password, no username, no name, no phone number, no employee number. There is no screen anywhere in the app that asks, and no field that would store it. They type the site code you issued and start talking.

What actually reaches our server

Two things: the site code, and a random identifier the app generates on the handset. That identifier isn’t derived from the hardware, a phone number, or anything you issue — so there is nothing on our side to join it back to a person.

Conversations stay on the phone

Encrypted with SQLCipher under a key held in the device keystore. An automated test writes a message, closes the database, reads the raw file off the disk and asserts the text isn’t in it — alongside a control test that fails if the encryption is removed. We’ll run it in front of you.

Being straight about transit

To answer them, a message passes through our gateway to the model. It isn’t stored at either end — but “it never touches our servers” would be the wrong sentence, so we don’t use it.

The ledger has no words in it

Your safety record holds tier, category, companion, what appeared on screen and whether they tapped through. There is no free-text column — not redacted, not permissioned, absent. Nothing to leak, nothing to subpoena, and nothing for a manager to ask you for.

What it costs.

Anonymity cuts both ways, and we’d rather you heard it from us than found it in a clause.

We cannot call 000 on someone’s behalf. There is no name and no number to give an operator. We say so in the app, at the moment it matters, rather than burying it.

That is the trade, and it is deliberate. A system that could raise the alarm for someone is a system that knows who they are — and a workforce that knows it knows simply doesn’t open it. What anonymity buys is that they actually talk, and take the handoff themselves.

The ledger proves the pathway was offered, every time. That is the part you can audit; the conversation is the part nobody can.

What you see as an employer →