ShotDetect is a research prototype that listens for the sound of gunfire. It is not an emergency service and it cannot bring help. It warns the people standing near it whose phones are running it too, and it can forward a corroborated alert to a guardian you have paired with, wherever they are. This paragraph used to end "nobody further away than Bluetooth reaches is told anything". That was true until August 2026. Clause 9 sets out what that forwarding does and does not promise. It is deliberately quieter than the alert shown at the school, and hearing nothing from it tells you nothing.
Since August 2026 it also shares your live position with the people you paired with, while the app is open at either end, in both directions. Since 2026-08-30 a student's phone does that only inside the school zone. That is a separate thing from an alert and it is set out in clause 1a. Version 1.2 of these terms described a position that travelled only inside a warning. That was true then.
By using the app you agree to what follows. If you do not agree, do not use it.
What this app does
ShotDetect listens for loud, sudden sounds through the microphone of the phone it is installed on, and scores each one with a trained classifier to judge whether it sounded like gunfire. When it decides that it did, it broadcasts that judgement — with the moment of the sound and where the phone was — to any phone within Bluetooth range, and it listens for the same from them. A single phone never raises an alarm. It takes at least two phones that heard the same sound at the same moment, from points at least fifteen metres apart; below that the screen says which condition was not met rather than warning you. This clause said "three" until August 2026. Two is the shipped rule, and it was chosen because a family with two handsets cannot reach three — under a three-phone rule their detection rate would be exactly zero while the app told them it was protecting them. The other conditions did not move: separation, timing against the speed of sound, and the requirement that this phone's own microphone contributed are all unchanged.
One thing in the design is not built and two are only partly proven. There is no path by which an alert reaches a school or an emergency service; that describes where the app is going, not where it is today.
Reaching a guardian who is not nearby was in that list until August 2026 and is now built. A corroborated alert is encrypted on your child's phone and forwarded through a relay we operate to the guardian you paired with, wherever they are. It is partly proven in the same sense the Bluetooth link is. An alert has been measured crossing between two real handsets — arriving in well under a second on a phone that was asleep with the app closed — but both phones were on the same desk, reaching a relay on a cable. How often it arrives, and how quickly, across the real internet to a parent in another country has not been measured. Nor has whether a phone keeps watching across a whole school day.
It is also deliberately quieter. A detection must clear a substantially higher confidence bar before it is forwarded to someone who is not at the school than before it is shown to someone who is. That makes false alarms substantially rarer on the forwarded path, and it is paid for in real events: a substantial share of the detections that would raise an alert at the school are never forwarded at all. The measured figures are published on how it performs and are not repeated here, so that a figure frozen into terms somebody agreed to cannot go stale as the detector changes. Silence is not evidence that nothing happened.
The second partly-proven thing is the Bluetooth link: a message has been shown to cross between two handsets on a desk, in under a second and in both directions, but how reliably it crosses a real building — through walls, along a corridor, with many phones at once — has not been measured. Do not install this expecting to be warned about anything.
Paired people see where each other are, and a phone says when it reaches school
This is new in August 2026 and it is the largest change to what this app knows about a child since it began reading a location at all. These terms, and clause 9 below, described a position that travelled only inside a warning and never between warnings. That was true when it was written.
What happens now: while the app is open on a phone, that phone shares where it is with the people it paired with — about once a minute while the phone is still, about every fifteen seconds while it is moving, and about every two seconds during an alert. Each update carries the position, how accurate it is, the time, and whether the phone is moving. On the other phone it draws a dot on a map. It is not a notification, it makes no sound, and no history of it is kept.
Who can see it. Only people you paired with, in person, by showing each other a code. A student's position goes to that student's guardians; a guardian's position goes to their students, and to any co-guardian they paired with. Two guardians of the same child may pair with each other, which shares position and online status between them and nothing else — it does not pass on the child's alerts, which reach only the guardians paired with the child's phone directly. There is no directory, no search, no proximity list, and no way for one family's phone to find another's. Pairing with several people on each side is normal — a child may be paired with two parents and a grandparent, and each of them sees the same thing.
It goes both ways. Alerts travel one way, from a student's phone to a guardian's. Positions do not. A guardian with the app open is showing their children where they are, on the same terms.
When it stops. Closing the app stops your position being published, but it is no longer the whole answer. There are four exceptions. The first is an alert, which sends a position whether the app is open or not. The second is a note saying the phone has reached school or has left it: it carries a time and no position, and it is sent whether the app is open or not. That second one has no switch: inside the school zone, an arrival or a departure is the thing the app is for. The third and fourth are set out below. A position nobody has updated for ninety seconds is removed from the map rather than left there looking current.
The third item is a limit rather than an exception, and it replaced one. Since 2026-08-30 a student's phone sends its position only while it is inside the school zone. The terms of that limit are:
- There is no switch for it, and no way to widen it.
- Outside that zone the phone sends no position at all, even with the app open.
- A guardian's phone has no school zone. Theirs is sent to the students they paired with, while their own app is open, as it always was — so a child can see a parent coming.
- During an alert the phone sends its position wherever it is. A limit on where the app shares a position must not become a limit on calling for help.
- No history is kept on either phone or on our server.
- A setting that shared a position all day, with the app closed, existed between 2026-08-29 and 2026-08-30. It was withdrawn with this change, and the switch that turned it on was removed because there is nothing left for it to turn off.
The fourth exception, and the only one you do not control. Since 2026-08-29, when somebody you paired with opens the app, your phone shares where it is with that person. The terms of it are:
- There is no switch for it, and any person you paired with can start it. Removing the pairing is the only way to stop it.
- It lasts about fifteen minutes at a time, renewed while they keep looking, and it ends by itself when they stop.
- It reaches only the person who is looking, and not the others you paired with.
- It applies whether or not the app is open on your phone.
- While it runs, your phone shows a notice saying so, and that notice cannot be swiped away. Nothing in the app removes it without also ending the sharing.
- It changes nothing else: the same cadence, the same sealing, and no history kept on either phone or on our server.
- It does not survive your phone restarting. Nobody sees you again until they open the app and ask again.
What we do not promise. That any of it arrives, that it is accurate, or that it is current. A phone with no signal, no location permission, a poor fix or a flat battery shows nothing or shows something vague. An empty map is not evidence that anyone is anywhere, and this app must not be relied on as a way of knowing where a child is. Clause 9 applies to a position exactly as it applies to an alert.
A question the app asks you
This was written here before it existed, and it exists now. It shipped on 12 September 2026; the paragraphs below said “is being built” until that day, and they are left standing rather than replaced so that anyone who read the earlier version can see what happened to it. When two phones agree that they heard gunfire, the app puts one question on the screen of each phone that reported hearing it: did you just hear gunfire? Fifteen seconds, yes or no.
Your answer leaves the phone. It goes to the people that phone is paired with, locked the way an alert is, and it carries the time you answered and nothing else — no sound, no words of yours, no position of its own. A warning says how many people answered yes, and that is what the answers are for.
Nobody has to answer, and answering nothing holds nothing back. A warning that has already been earned still goes out. Only an explicit no, from a phone that heard the sound, ever counts against one. Anyone who is running, hiding or hurt does not answer a question, and a system that needed them to would fail in the case it exists for.
One phone is asked at most once in any seven days. That is a limit on how often anyone can be interrupted, and it has a consequence worth stating plainly: most events ask nobody anything, so being asked nothing is not evidence that nothing happened.
What it cannot do
It cannot call the police, an ambulance or a school. It cannot summon help of any kind. It shows you your local emergency number, and it will never dial it for you.
It will sometimes be wrong
This app may warn you when nothing has happened, and it may stay silent when something has. A phone in a bag, a flat battery, a denied microphone permission, a school with no other phones running it, or simply a sound the app does not recognise will all produce silence.
Treat every alert as unconfirmed until you know more.
This app has never raised an alert from a real gunshot. It has been tested on recordings and on drills only. Everything published about how well it works, including on how it performs, is measured that way.
One limit is daily, and the platform forces it.
- Android will not let the app start listening again by itself in the background.
- The student's phone must be opened once each day, after the listening hours have begun, for it to listen that day.
- A day on which that does not happen is a day without protection.
- The app asks the student to open it when the school day starts.
- If that does not happen, the guardian is told.
Silence from this app is not evidence that nothing happened.
Do not rely on it alone
ShotDetect is not a substitute for any part of an emergency plan, and a school should not treat it as one. It is an extra signal, and an unreliable one.
Who may use it
Protection does not begin until a guardian has connected to the student's phone and accepted these terms, so a child never agrees to this alone.
That gate is enforced: a phone will not arm unless a guardian has accepted on it, so a student tapping through the disclaimer alone cannot open the microphone. This page said the opposite until 2026-08-18, describing a gap that had already been closed. What the app cannot do is check who is tapping, which is a different limitation and is stated on the screen that asks.
ShotDetect is for students aged 13 and over, and for adults. It is not offered to children under 13. These terms said until August 2026 that use by a child under 13 required verifiable parental consent, which implied it was available to them. It is not: the app reads a precise position and puts it into an unencrypted Bluetooth broadcast, and that is not something we are prepared to do on a younger child's phone.
The person who accepts these terms must be 18 or over and must be the student's parent or legal guardian. The account is theirs. A student does not accept these terms alone, and a student's phone does not listen until a guardian has accepted — either on the student's phone or by arming it from the guardian's own.
Since wording 0.21.0 the person accepting has to say so. The acceptance screen carries a statement — "I am 18 or over and this student's parent or guardian" — and acceptance is not recorded until it is ticked. That is a statement, not a check: no birthdate is asked for and none is stored, and the app still cannot see who is holding the phone. What it now has is a record of what the person tapping said they were.
A student aged 13 to 17 is still a minor. Raising the floor to 13 changes which rules apply to us; it does not make a 13-year-old able to agree to this for themselves. Under Philippine law a person is a minor until 18, and the consent for processing a minor's personal information has to come from their parent or legal guardian. The guardian's acceptance above is that consent. It is how we comply with the Data Privacy Act's treatment of minors, not a way around it.
Workplaces, and the police feed
The workplace and agency roles are not available in the version on Google Play; they appear on the first screen as "Not available in this version" and cannot be selected. What follows describes those roles so that these terms are complete.
A workplace can run the app over an office or a floor. Everything above about what the app does, what it cannot do and how often it is wrong applies there unchanged. Three things are different, and all three are in a separate in-app document with a version number of its own, so a workplace redraft never asks a family to accept anything.
Consent is the member's own, and refusing costs coverage and nothing else. A member of staff is an adult, so nobody accepts on their behalf. What refusing means is that the phone does not listen and is not one of the phones that can hear something. The roster shows it as not covered and shows nothing else about the person; it is not recorded as a fault, and no part of the app reports the choice to us.
A manager sees that you are covered. A manager never sees where you are. There is no routine position, no trail, no arrival note, no roster map, and no way for a manager's open app to start a phone publishing. A position moves only while a corroborated incident is open. Section 11a of the privacy policy is the whole of it.
A site's manager may offer its incidents to one named police agency, and no incident has ever been sent to one. The enrolment always has an end date, cannot run longer than a year, and can be ended at once. Five conditions all have to hold before anything reaches an agency, and the third of them is a person answering yes — the question in section 01b, which was built on 2026-09-12. This paragraph said until 2026-09-13 that the question was not built and that nothing could therefore reach an agency. Both halves have changed: the question exists, and a manager can enrol a site from the app itself. What has not changed is the sentence in bold above — no incident has ever been sent to any agency, and no alert of any kind has ever come from a real gunshot. The conditions and the payload are listed in section 11a of the privacy policy.
A workplace phone also keeps its site on the phone — the boundary, the floors, the zone names, the agreed hours and the surveyed position of each fixed listening device — and a manager's phone keeps the enrolment beside it. Section 07 of the privacy policy lists both, and section 11a says what the enrolment record deliberately does not hold. Neither exists on a family phone.
Two things this app will not do for a manager, and neither is a limitation we intend to remove. It will not dial an emergency number: section 02 applies to a manager exactly as it applies to a parent, and an automated call at this app's measured error rate would be an abuse of an emergency line before it was a feature. And it will not send an unconfirmed incident to an agency by any route, including a manager choosing to.
Calling emergency services
If you call emergency services after an alert, say that an app alerted you and that it is not confirmed. That matters: the people answering need to know what kind of report they are receiving.
Making a false report to emergency services is a criminal offence in most countries, including the Philippines.
Practice alerts
The app can run practice alerts so people know what a real one looks like. A practice alert is marked as practice on every screen it appears on, and it cannot open the emergency dialler — there is no path from a practice alert to summoning the police.
A practice alert does appear in the app's timeline, labelled as a drill, and the entries stay there after the practice ends. The timeline is deliberately append-only, so that someone reading it afterwards sees the whole sequence rather than a record wiped the moment the screen cleared. Because the timeline lives in memory only, it is gone when the app closes.
The screenshot of an alert on our home page, captioned "Guardian · alert", was produced by a practice alert. The app cannot currently produce that screen from real audio.
No guarantee of detection
We do not guarantee that the app will detect a gunshot, that it will detect one in time, or that it will tell the difference between a gunshot and another loud sound. It is a prototype and its accuracy in real buildings has not been established.
What has been measured, on recorded audio rather than in a building, is set out on how it performs, and the figures live there rather than in these terms so that they can be corrected as the detector changes instead of going stale inside a document somebody agreed to. In short, and this has not changed: the detector raises far more false alerts than its design target of about one per school per year, and it misses a meaningful share of real gunshots on microphones and recording equipment it was never trained on. Neither is good enough for anyone to rely on. We publish the numbers so that nobody has to discover them the hard way.
Delivery is not in our control
This clause used to begin "No warning reaches anyone out of Bluetooth range, today or in this version." That is no longer the case: since August 2026 a corroborated alert can be forwarded to a guardian you have paired with, wherever they are. What follows is what that does and does not promise.
All of it applies to the position sharing in clause 1a as well. A position that does not arrive, arrives late, or arrives stale is the same failure as an undelivered alert and is no more under our control. The app draws nothing where it has heard nothing, on purpose, but the absence of a dot tells you about the network and not about a person.
Between phones in Bluetooth range, whether a warning arrives depends on batteries, radio conditions, walls and distance, notification settings, and whether the phones involved are switched on, armed and nearby. How often delivery succeeds across a real building has not been measured.
Beyond Bluetooth range, delivery additionally depends on both phones having a working internet connection at the time, on the guardian's phone being permitted by its operating system to keep watching in the background, and on our relay being reachable. Mobile operating systems may stop background activity at any time, and we cannot prevent it. An alert that cannot be delivered within ninety minutes is discarded rather than delivered late, because a warning that arrives hours after the event invites action that is wrong.
Be aware of one operating-system limit in particular. An earlier version of these terms described a daily cap Android places on this kind of waiting; the app no longer runs in the mode that cap applies to. What remains is this: when Android stops the watcher on a guardian's phone — under memory or battery pressure, or after a restart — recent versions of Android may refuse to let the app start itself again from the background, particularly on a phone whose owner declined the battery-optimisation exemption the app asks for. The app books the earliest return the system permits, and the ninety minutes above is chosen so that an alert survives an interruption of that kind. It does not cover a phone that stays stopped: a guardian's phone that has been left closed for a long stretch may not be collecting, and an alert raised in that stretch can expire before it is fetched. Opening the app is the reliable way to know it is watching; the guardian's home screen shows when the connection was last confirmed.
Alerts sent beyond Bluetooth range are deliberately fewer. The detector must be substantially more confident before an alert is forwarded than before it is shown on a phone in the building. This is a trade, described in clause 1: it makes false alarms substantially rarer on the forwarded path at the cost of never forwarding a substantial share of the detections that would raise a local alert. The current figures are on how it performs. Silence is not evidence that nothing happened. This app must not be relied on as a means of knowing your child is safe.
None of the above is under our control, and we do not warrant delivery.
What we are responsible for
We are responsible for our own deliberate wrongdoing, and for anything the law where you live does not permit us to exclude — which, in many places, includes death or personal injury caused by negligence.
Nothing in these terms takes away a right you have under consumer law.
What we are not responsible for
Subject to clause 10, we are not responsible for harm arising from the app failing to detect something, warning you about something that did not happen, warning you late, or failing to reach you at all. Nor are we responsible for decisions taken in response to an alert.
Do not drive to the school
If you are a guardian and you receive an alert, do not drive to the school. You will arrive into a situation you cannot assess, in a vehicle that may obstruct the people who can help. Call, and wait to be told what is happening.
Governing law
These terms are governed by the laws of the Republic of the Philippines. This does not remove any protection you have under the consumer law of the country you live in.
Contact
Llyr Labs — contact@shotdetect.com. See also our Privacy Policy.