Skip to Content

A Safety App That Can't Track You

Every other safety app keeps you safe by watching you. Gart keeps you safe by knowing nothing about you.
June 12, 2026 by
A Safety App That Can't Track You
Gart

The safety and location apps most people rely on track you around the clock, and many sell or leak what they collect. A data broker can hold your location within twenty minutes of you moving. A forged "emergency request" can pull your home address straight out of Apple, Google, or Meta. A hidden tracker can find a fleeing partner faster than any built-in safeguard catches it. And almost nobody has a plan for the moment all of that fails. The full case is in The Price of Being Findable.

Which is why we built Gart

Put all the safety failures of safety apps side by side and the design brief writes itself. The people whose safety depends on getting this right - executives, family offices and their clients, journalists, frequent travelers, crypto holders and families with a real threat model need:

  • an alert that leaves no location trail for a broker to sell,
  • a safety app with no phone number or personal ID attached,
  • no Apple, Google, or Meta account that a forged "emergency request" can pull from,
  • alerts that reliably arrive even when a vendor's server is DDoSed mid-operation,
  • a provider with nothing to hand over to hackers or a subpoena.

Gart was built to be all five and to get the alert through anyway. There is no Gart server your alerts flow through, no database of where you are or who your people are, no phone number or email tied to your identity. The app sits silent and location-blind until the moment you trigger it, then sends one encrypted alert to the handful of people you trust. Your chat and alert history stays encrypted on your own device, not on our servers. We never hold a copy, and couldn't read it if we did. 

We ran the major alert and find-my services through this same test what each one collects, how long it keeps it, and who it sells or hands it to. We'll publish the full comparison soon.

A security practice, not a data company


We harvest no data and run no location tracker; that has never been our business. Gart's business is personal safety training and advisory for private individuals, their families and businesses.

So when it came time to build an app, we didn't inherit the surveillance model the whole alert app category sits on. We started from one question - what has to happen the instant every defense layer fails? - and worked backward from the answer. What came out is a stealth trigger for your response protocol: silent until you fire it, then it sets the right people moving, with nothing collected along the way.

When every other layer fails


This is the layer the app was built for: the last one, when everything in front of it has failed. The lock didn't hold. The negotiation didn't work. The phone got taken. The attacker is in the room.

At that point you have one job: stay calm and send a coherent, trusted alert to the people who can do something about it - your family, security officer, lawyer, or trustee. Without leaking your location to anyone else. Without depending on a corporate server staying up. And without the alert vanishing because someone DDoS'd a vendor at the worst possible moment.

That's what the Gart app does. We did not build a social app, a tracker, or a marketplace. It is an alert-delivery mechanism, privacy-first by architecture, designed to survive the exact conditions where most other "safety" apps fail.

To be clear about what it is and isn't: Gart does not stop an attack. It won't prevent a forced transfer at gunpoint, and we won't pretend otherwise. What it does is make sure that when everything else has failed, the right people find out fast, privately, and reliably.

safety


What the Gart app actually is


The Gart app lets you do four things (for now):

  • Build your trusted circle
  • Invite Watchers - the people who should know first when something is wrong. You decide who they are, and what instructions they receive when you hit the alert button.
  • Send a test and live alert.
  • One tap and your Watchers receive a full-screen alert with your location and your predefined message.
  • Customize your alert message 
  • Next to the Gart button, this is the most important feature. It allows you to prepare the response you want your Watchers, your first responders, to execute.
  • Chat privately.
  • End-to-end encrypted group chat between you and your Watchers.


The core of the product is one idea: eliminate any sensitive data about our users while providing the alerting service.


No phone number, no email connected to your Gart identity, no KYC.

Your account is a Nostr keypair you control. We don't collect what we can't protect.


End-to-end encrypted.

Alert content and chat are encrypted (NIP-44). We can't read them, and the relays that route the alert can't read them. Even if a relay is seized, the contents are just encrypted noise.

  • No single server to take down. 

    Alerts fan out across multiple Nostr relays in parallel. There is no Gart "alert server" sitting in front of your safety.

  • No persistent tracking

    The alert button is silent until you trigger it. It doesn't ride your location in the background, and it doesn't claim it needs to know where you are at 3am to "keep you safe."

  • Nothing to hand over. 

    Because we don't hold your identity, your contacts, or your location history, there's no record for a breach to spill, a subpoena to compel, or a forged "emergency request" to extract. You can't leak what was never collected.

  • Coercion-resistant by design

    We assume an attacker may already have your unlocked phone in front of you. More duress features are coming.

  • Publicly verifiable

    You don't have to take our word that alerts are encrypted. The live event stream is public at gart.io/live. Watch real Gart alerts go by as nothing but encrypted noise. We'd rather you check than trust us.


This is the opposite of how mainstream safety and location apps are built. Where they require an ID, phone number, or email, Gart requires none. Where they keep a live map of your location and a graph of everyone you're connected to, Gart keeps neither. Where they route through a single company's servers. One subpoena, one breach, or one forged emergency request away from exposing you. Gart fans out across a relay network with no central server to compel. Every data point those apps collect to be convenient is a data point Gart refuses to hold, so there is nothing to sell, nothing to leak, and nothing to hand over.


How it's built

The architecture is intentional, and boring in all the right places.

Identity, in two tiers. 
Your main Gart identity is a cryptographic keypair (nsec / npub) the same key you can use in any Nostr client, or hold behind a remote signer if you already use one. Inside the app, a second operational signing identity handles every per-action signature in the background. That's what lets you log in with a remote signer without being asked to approve every chat message, every read receipt, every status ping, signature fatigue at exactly the wrong moment is how people get trained to tap "Approve" without reading. Your main key is for control. The operational key is for traffic.

Transport

The Nostr relay network, the same protocol many of you already use for messaging and zaps. We publish encrypted events; relays fan them out; Watchers' apps subscribe.

Custom event kinds.

Two open Nostr event-kind specs we authored: NIP-GART for the alert and protocol layer, and NIP-TPLD for protocol-template delivery. Both are published as open proposals so other Nostr clients can interoperate.

Recovery. 

Your group memberships and history are bound to your identity, not your device. Lose the phone, install Gart on a new one, log in with your user ID or remote signer, and you're back where you were. The Settings page gives you an encrypted account backup you control. We don't hold it, and couldn't decrypt it if we did.

There is no central Gart server your alert flows through. We run no database of who your Watchers are, where you've been, or what your alerts said. Not because we promise we won't, but because we built the system so we can't.

How it works

The initial flow is deliberately short.
gart-appgart-app

  1. Install and log in. 
    Generate a Nostr keypair if you don't have one. One tap, no signup form, no email verification. Your group is created automatically.
  2. Grant the six permissions Gart actually needs.

    1. Precise location (so Watchers see exactly where you are when you trigger an alert). 
    2. Background location (so the coordinates are reachable even when the app is closed). 
    3. Battery optimization removed (so Android can't quietly suspend the app at the worst possible moment, the single most common reason "safety" apps fail silently). 
    4. Full-screen notification (so the alert breaks through a locked phone and overrides Do Not Disturb). 
    5. Ring at max volume (so the alarm rings even on a silenced phone). And 
    6. Disable manage app if unused (so Android doesn't quietly revoke the permissions you just granted).
      One screen, one Allow all tap.
  3. Invite your Watchers.
    Find existing Gart users by username or npub, or scan their profile QR. For contacts who don't have the app yet, copy your invitation link from your User Profile and share it via Signal, email, or whatever channel you already use; they install Gart, you add them with + Add Watcher. They tap Accept or Decline from the notification. You can invite up to ten, we recommend three to five for a tight first-responder circle.
  4. Configure your protocol. 
    The alert message is the most important thing your Watchers will read. Write it now, in calm conditions, not when your hands are shaking. Include what they actually need: who to call first, what your duress wording sounds like if you have one, how to verify you're alright. The message can be edited up until the moment an alert is sent. Once it's out, it's locked.
  5. Run a Test Alert. 
    Every Watcher should see one before you ever need a real one. The Test Alert fires the entire notification chain, sound, lock-screen breakthrough, response UI, but the coordinates are pinned to Mount Everest and the message says Don't panic, so nobody mistakes a drill for the real thing. Run a Test Alert against every Watcher in the group before you rely on the real button.
  6. When it matters, hit the button. 
    The alert button lives on the home screen. Gart captures your current GPS, encrypts it together with your pre-written message, and fans both out across multiple Nostr relays in parallel, no central server in the path, no single vendor whose outage takes you down with it.
On the Watcher side, the alert breaks through the locked screen with a full-screen notification at maximum volume regardless of phone settings (even overriding Do Not Disturb). Inside the group the Watchers see the alert message, your GPS coordinates as text, and an Open in Maps button that launches the location in their default maps app. They also see an I'm handling this button; tapping it posts a visible acknowledgment inside the group so the Group Owner and the other Watchers know who is on it, without anyone having to type "I got this" by hand. The point is a calm, organized response, not a flood of overlapping replies.

Roles are exactly as named. Group Owners create and manage their group and are the only person who can trigger an alert in it. Watchers monitor and respond. One person can be a Group Owner of one group and trigger alerts to it, while at the same time being a Watcher in many other people's groups. Your spouse runs their group, you run yours, and you each appear in the other's group as a Watcher.

How to download and use

The beta is Android-first, and during beta the only distribution channel is ZapStore, the non-KYC Android app store. Install ZapStore from zapstore.dev (your phone will ask permission to install apps from outside the Play Store; allow it), open ZapStore, search for Gart, and tap Install.

Requirements: Android 8.0 (Oreo) or later and an active internet connection.

iOS is not yet available. We'd rather tell you that than fake a release date. While you wait, this is an excellent reason to do the thing you may have been putting off: pick up a used Google Pixel, flash GrapheneOS, and have a clean second phone with no identity attached, no spyware pre-installed, and no walled-garden system between you and the tools you actually want to run. Our advisors will walk you through it if you want.

Quickstart: go to gart.io/app, install via ZapStore, log in, invite your Watchers to your automatically created Group, customize your alert message, and run a test alert with every Watcher. Then you're ready to be found easily when you most need it.

Beta testers welcome, early-bird status for life.

We're opening the beta to a wider group starting today.

If you join the beta and help us test, you keep early-bird status for life, with perks including early product and feature access, and educational content. The exact pricing structure will be published before general availability, and your early-bird status carries forward regardless of what the final pricing looks like.

What we need from beta testers:

  • Install on a real device you actually use, not a sandbox.
  • Run at least one real drill with a real Watcher, a Test Alert end-to-end, including the I'm handling this acknowledgment from the Watcher side.
  • When something is broken, weird, or unclear, shake your phone. From anywhere inside the app, a shake captures a screenshot and opens a Report Issue form. Add a sentence of context, optionally drop your email if you want a response, and send. The report and the technical logs go straight to us. We read every one.
Where to talk to us.

During beta, the primary support channel is a private Signal group for testers. To get in, enroll as a beta-tester and we'll send the Signal invite.

Release cadence.

During beta we ship at least once a week, sometimes more when fixes are ready. ZapStore notifies you when a new build is available. Please install updates promptly so we're all debugging the same code. The current version number lives in Settings → About; check it before reporting an issue.

What we collect during beta.

Crash reports, technical only, no message content, no location. A separate analytics service records anonymous usage patterns so we can see which screens people get stuck on. No personally identifiable information. Nothing traces back to you.


Download Gart: gart.io/app


If you haven't read it yet, the threat picture this app answers is laid out in full, with sources, in The Price of Being Findable.