Skip to main content

Protecting data we hold

The Govt.nz app collects and stores as little user data as possible by limiting what is collected on backend systems, making additional data collection opt-in and applying strict security standards.

Limited user data is collected and stored

The app is designed to minimise the amount of user data stored by the app on backend systems. Where information is required (such as device data), it’s performed in a way that it is not linked to an individual person.

Services are opt-in

Any service that collects additional data is designed to be opt-in so users can choose what data is collected.

What data is collected

We may collect information when you use the app or communicate with us:

  • Read about the types of personal information we may collect, including device and usage data and contact information in our Privacy policy.
  • Data that enables the app to match an emergency alert to a location:
    • If you save a location in the app, this is done by setting a pin. This is not real-time information about your current location. The app cannot track your location.
    • When a location is pinned, the app generates a unique device ID to associate with that pin. Only the device ID and the location pin are stored in backend systems — no other information is linked to you. Device and location IDs cannot be directly tied back to an individual.
    • You do not need to save the exact location pin to receive an alert for that area. You can save a location nearby and the alerting service will still work.
    • If you do not enable location services in your device settings, you will not receive emergency alerts for your current location. If you do not enable location services in your device settings or save a location in the app, you will not receive emergency alerts at all — this is all under your control

How data is stored and collected

Where data is stored or collected, it must follow a set of security rules:

  • It’s encrypted at rest and in transit.
  • Decryption keys are held by the app, not the server, where possible.
  • Regular independent security reviews and technical testing are carried out. This includes code reviews and penetration testing, meeting Digital Identity Services Trust Framework (DISTF) security requirements.

Utility links and page information

Was this page helpful?
Thanks, do you want to tell us more?

Do not enter personal information. All fields are optional.

Last updated