Privacy Policy
Fafety is a personal safety check-in app. You set a recurring check-in interval;
if you miss one, your chosen contacts are alerted. This policy explains exactly what
data we collect, why, how it is protected, and your rights over it.
We keep this document in plain language — no legalese.
Short version: We collect only what the app needs to work.
We do not sell or share your data with anyone. Passwords are never stored in
readable form. GPS coordinates are encrypted before they touch our database.
1. Information We Collect
Account
- Name and email address — to create and identify your account and to send you security-related communications.
- Password — never stored in plain text. We store only a one-way cryptographic hash (bcrypt) that cannot be reversed to recover your password. We cannot read your password.
- Date of birth — to verify you meet the minimum age requirement (16+).
- Phone number (optional) — so contacts can find your account by phone number when you add them.
Check-in data
- Check-in timestamps — the date and time of each check-in you submit, used to calculate your overdue status.
- Check-in interval — the interval you have configured between required check-ins.
Location data
- GPS coordinates — only collected if you explicitly enable Location sharing in Settings. When enabled, your device uploads your coordinates so that approved contacts can see where you are if you miss a check-in.
- GPS data is never collected silently. The app requests location permission only after you opt in, and always shows a plain-language explanation before the system permission dialog.
- GPS records older than 7 days are automatically and permanently deleted.
Contacts
- Contact names and identifiers — the names, phone numbers, and/or email addresses of people you add as contacts in the app.
- Contact relationships — who you have approved to receive your alerts and view your location.
Device data
- Push notification token — a device-specific token issued by Google Firebase (Android) or Apple APNs (iOS), used to deliver check-in reminders and missed check-in alerts to your device. Tokens are rotated and stored per device. They are never sold or shared.
2. Why We Collect This Data
| Data | Why we need it |
| Account information | To identify you, secure your account, and let you sign in |
| Check-in timestamps & interval | To determine when you are overdue and trigger alerts to your contacts |
| GPS coordinates | So approved contacts can find you if you miss a check-in (opt-in only) |
| Contact names & identifiers | To know who to alert and how to reach them |
| Push notification token | To deliver timely alerts and reminders to your device |
We collect nothing beyond this list. We do not track browsing behaviour, device usage, or app analytics.
3. How Your Data Is Protected
-
Passwords — stored as a bcrypt hash only. bcrypt is a one-way function;
there is no mechanism, technical or otherwise, to recover your original password from
what we store.
-
GPS coordinates — encrypted with AES-256-GCM at the
application level before being written to the database. The encryption key is managed
separately from the data. Even if the database were compromised, raw coordinates could
not be read without the key.
-
Data in transit — all communication between your device and our servers
uses TLS 1.3. Unencrypted connections are rejected.
-
Database access — enforced row-level security policies ensure that each
user can only read and modify their own data. Our application database account has no
ability to alter the database schema.
-
Biometric data — if you use fingerprint or face recognition to confirm
check-ins, all biometric processing happens entirely on your device's secure hardware.
We never receive, transmit, or store any biometric template or result.
4. Who Can See Your Data
Your data is private by default. The only people who can see specific pieces of it are:
- You — you can see all of your own data.
- Contacts you explicitly approve — they can see your check-in status and, if you have enabled location sharing, your GPS coordinates when you are overdue. They cannot see your password, email address, date of birth, or any other account details.
We do not sell, rent, or share your personal information with any third party.
We use no third-party analytics services, advertising networks, or data brokers.
We may disclose information only if required by law or in response to a valid legal process.
5. Data Retention
- Account data — retained until you delete your account.
- GPS location data — automatically and permanently deleted after 7 days.
- Check-in history — automatically and permanently deleted after 7 days. Only your most recent check-ins are kept, solely to determine your current overdue status.
-
Account deletion — when you delete your account (Settings → Delete my account),
all your data is permanently removed: check-in history, GPS records, contact relationships,
alert history, and push tokens. This deletion is irreversible. Deletion cascades within
30 days in accordance with GDPR Article 17.
6. Your Rights
You have the right to:
- Delete your account and all associated data at any time — Settings → Delete my account.
- Opt out of location sharing at any time — Settings → Location sharing → Off.
7. Children
Fafety is not directed at children under 16. We do not knowingly collect personal data
from anyone under 16 without verified parental or guardian consent. If you believe we
have collected data from a minor without consent, please contact us and we will delete it.
8. Changes to This Policy
This Privacy Policy may be updated from time to time as the app evolves or legal
requirements change. When we make significant changes, we will notify you through
the app before the changes take effect. The date at the top of this page reflects
when it was last revised. Your continued use of Fafety after a change is posted
constitutes your acceptance of the updated policy.
Contact
Questions or concerns about this Privacy Policy or how we handle your data?
Please contact us:
Email: developer@fafety.com