SheSafe Privacy Policy

Effective date and last updated: 2026-09-01

This Privacy Policy explains how SheSafe collects, uses, discloses, retains, and protects personal information when you use the SheSafe mobile application, the SheSafe pages at boonts.com, invitation links, and related support channels (together, the "Service"). It also explains the choices and rights available to you.

SheSafe is operated by Roman Babunts, the individual App Store seller identified as the app provider on the applicable SheSafe App Store product page ("SheSafe", "we", "us", or "our"). Roman Babunts is the data controller for the processing described in this Policy and can be contacted at [email protected].

SheSafe is a personal safety coordination tool. It is not an emergency dispatch, law-enforcement, security-monitoring, medical, or rescue service and does not guarantee anyone's safety. In an immediate emergency, contact the appropriate local emergency service first.

1. Scope And Sources Of Information

This Policy applies to information that we receive:

This Policy does not govern a third party's independent handling of information after you leave the Service or share information outside the Service.

2. Information We Collect

Account, profile, and eligibility information

Trusted-circle, invitation, and relationship information

The Service does not read or upload your device address book in the current release. If you choose SMS, email, WhatsApp, Telegram, or another sharing app, your device and that third-party service handle the recipient information under their own terms.

Precise location, journey, and safety information

Location may continue to be collected and transmitted during a user-started active journey or SOS session when the app is in the background or the screen is locked, subject to your device permissions and operating-system restrictions. The current release is not designed to collect continuous location outside an active safety session.

Date Mode, journey context, and other user content

Do not include unnecessary sensitive information, names of alleged offenders or victims, contact details, health information, or other identifying information in a public incident description or journey note. Information marked "anonymous" may be hidden from other users while remaining linked internally to an account for security, moderation, duplicate prevention, and legal compliance.

Analytics, device, browser, and service-operation information

Google Analytics for Firebase mobile collection is disabled by default and is enabled only after you choose to share app analytics during onboarding or in Settings. The mobile analytics payload policy is designed to exclude account, journey, safety-event and other stable internal identifiers, names, email addresses, phone numbers, free text, street addresses, precise coordinates, trusted-circle graphs, and SOS content. Google may nevertheless receive a random app-instance identifier, IP address, device/app metadata, approximate network-derived region, and transport metadata needed to provide analytics.

Information stored only on your device

The personal SOS cancel PIN, tutorial state, permission-introduction state, legal-acceptance copy, scheduled local notifications, and undelivered SOS retry queue may be stored locally on your device. The current implementation does not send the digits of your cancel PIN to our server. Local data may remain until you clear app data or uninstall the app, subject to operating-system backups.

Data not collected by the current release

The current release does not intentionally collect or upload microphone audio, photos, video, payment-card data, or address-book contacts. It does not use precise location, trusted-circle relationships, journey notes, or SOS content for advertising. If a future release adds a new data category or materially new purpose, we will update this Policy and provide any notice or obtain any consent required before the new processing begins.

3. How Location And Safety Sharing Work

You start location sharing by starting an active journey, Date Mode session, or SOS flow. During that session, permitted trusted contacts may receive or view your current or last-known location, route or destination, venue and text context, ETA, alert level, check-in state, battery or sound state, connectivity, and relevant safety-event status.

Depending on the selected mode and configured timing, ignoring a check-in, tapping "Need Help", releasing an armed SOS control, using a duress flow, or losing connectivity for an extended period may create an SOS or disconnected event and disclose the last-known location to trusted contacts automatically. Routine reminders may be scheduled locally on the primary user's device, while remote server-side push delivery to trusted contacts is intended for SOS and related acknowledgement events in the current release. Product behavior may be limited by release configuration and platform capabilities.

A trusted contact can view, copy, screenshot, forward, or act on information they legitimately receive. We restrict access within the Service, but cannot control a recipient's device or independent use after disclosure. Remove a contact or end the session if you no longer want ongoing in-Service sharing; previously received copies may remain outside our control.

Location represents the device, not necessarily the person. It can be wrong, stale, unavailable, or misleading if a device is left behind, shared, offline, low on battery, or affected by GPS, network, operating-system, Focus/Do Not Disturb, background-processing, or permission settings.

4. Community Safety Map And External Safety Data

The safety map may combine user-submitted incident reports and confirmations with public or third-party street-lighting, map, and travel-advisory data. A submitted incident's location, category, severity, description, time, anonymous display state, and verification count may be visible to other users. Reporter and verifier account IDs may be retained internally as described in this Policy.

Map requests may send a map viewport or approximate geographic bounds, IP address, and device or request metadata to our backend or map providers. Basemap tiles may be requested from OpenFreeMap. Street-lighting queries may be served from Supabase or, if needed, sent to OpenStreetMap Overpass endpoints, including public endpoints operated by third parties.

"Verified" only means that a configured number of users submitted a confirmation; it does not mean that SheSafe, police, a government body, or an independent investigator confirmed an incident. Safety scores, lighting labels, risk zones, advisories, and incident markers may be incomplete, estimated, duplicated, outdated, user-generated, or incorrect. They are informational and are not safe-route recommendations or predictions that any place is safe or dangerous.

5. How And Why We Use Information

We use information to:

Where law requires a legal basis, the basis depends on the purpose and context:

If user-provided context incidentally reveals health, sexual-life, political, religious, or other specially protected information, we process it only to provide the requested safety workflow and under an additional condition required by applicable law, such as explicit consent or protection of vital interests. Please avoid submitting such information unless necessary.

We do not make solely automated decisions that produce legal or similarly significant effects. Automated check-in, timeout, connectivity, score, and SOS rules affect Service notifications and displays, not legal rights or official emergency decisions.

6. When We Disclose Information

Trusted contacts and other users

We disclose the relevant session and event information to users authorized for that journey, relationship, SOS event, or public map report. Public incident content may be shown to any user who can access the map.

Service providers

Depending on platform, region, and enabled configuration, providers may include:

These providers process information for us or independently under their terms and privacy notices. We require providers acting as our processors to protect personal information consistently with this Policy and applicable law.

Legal, security, and safety disclosures

We may preserve or disclose information when we reasonably believe it is necessary to comply with applicable law or valid legal process; investigate fraud, abuse, or a security incident; enforce our Terms; protect the rights, property, or safety of a user, SheSafe, or another person; or respond to a life-safety situation. We do not promise that a disclosure will be made, that a requester will respond, or that the Service will contact public emergency responders.

Business transfers

Information may be reviewed or transferred in connection with financing, due diligence, a merger, acquisition, reorganization, insolvency, or sale of all or part of the Service, subject to confidentiality and applicable law.

7. Analytics, Cookies, Advertising, And Sale/Sharing

Mobile product analytics are optional, pseudonymous, and PII-minimized. Google Analytics for Firebase collection starts only if you opt in and can be disabled again in Settings. Disabling it stops future app analytics collection and asks the SDK to reset its locally held app-instance analytics data. We do not set a Firebase user ID or send account IDs, precise location, journey or Date Mode text, trusted-circle data, safety-event IDs, or SOS content to analytics. Ad storage, ad-user-data use, ad personalization, Android Advertising ID, iOS IDFA, and cross-app tracking are disabled for the mobile integration. SheSafe does not request Apple's App Tracking Transparency permission for this analytics.

Apple and Google may separately produce store-level acquisition, installation, retention, session, crash, and quality statistics through App Store Connect and Google Play Console. Those platform statistics are governed by the user's device/store privacy choices and the platform provider's terms. Apple usage reports may be limited to users who chose to share diagnostics and usage data with developers.

The SheSafe website may use cookies, pixels, scripts, online identifiers, and similar technologies from Umami, Google, and Yandex for audience measurement, interaction analysis, advertising attribution or remarketing, and, where enabled, session replay. These providers may receive IP address, cookie or device identifiers, browser and device data, page URL, referrer, and interaction events. Use browser controls, content blockers, available provider opt-outs, or contact [email protected] to object or make an applicable opt-out request.

We do not sell personal information for money. Some laws may define disclosures of website identifiers to advertising or analytics providers as "sale", "sharing", or targeted advertising even when no money changes hands. Where such law applies, we will honor applicable opt-out rights and legally recognized preference signals to the extent required. SheSafe does not knowingly sell or share personal information of users under 18.

8. Retention And Deletion

We retain information only for as long as reasonably needed for the stated purposes, subject to law, security, fraud prevention, dispute handling, backup integrity, and protection of other users.

Current operational rules include:

Account deletion is designed to remove account-owned profile, trusted-contact, journey, context, check-in, invite, live-location, safety-event, delivery, and device-token records where technically and legally permitted. Deletion may not remove information lawfully retained for another user's records, public reports that have been de-identified from you, information another person copied, or records needed for security, fraud prevention, legal compliance, disputes, and backup integrity.

9. Your Choices And Privacy Rights

You can:

Revoking a permission or consent does not affect earlier lawful processing and may make safety features unavailable or unreliable. A local uninstall does not by itself delete server records; use the in-app deletion flow or contact us.

Depending on where you live, you may have rights to access, know, correct, delete, export or receive a portable copy, restrict processing, object, withdraw consent, opt out of sale/sharing/targeted advertising or certain profiling, appeal a request decision, and receive equal service without unlawful discrimination. You may also complain to a competent data-protection authority.

Submit a request to [email protected]. We may verify your identity and authority before acting. We may deny or limit a request where permitted, including where it would disclose another person's information, impair security or fraud prevention, conflict with law, or require deletion of a record another user is entitled to keep. Authorized agents may submit requests where applicable, subject to verification.

10. International Processing

We and our providers may process information in Serbia, the European Economic Area, the United States, and other countries where providers operate. Those countries may have different privacy and government-access laws. Where required, we rely on adequacy decisions, data-processing agreements, standard contractual clauses, the UK Addendum or IDTA, or other recognized safeguards and supplementary measures.

Availability of the Service in a country does not mean that data is stored in that country. A region-specific deployment, notice, or consent may apply where required.

11. Security And Incident Response

We use reasonable administrative, technical, and organizational safeguards, including authenticated access, PostgreSQL Row-Level Security, server-side authorization, restricted Realtime channels, PII-minimized push payloads, least-privilege access, event audit records, and transport encryption where supported.

No method of storage or transmission is completely secure, and we cannot guarantee confidentiality, availability, integrity, uninterrupted operation, or recovery. Keep your device, email account, sign-in session, and PIN secure; review trusted contacts; and notify [email protected] if you suspect misuse or unauthorized access. We will assess and notify affected people or authorities of a personal-data breach when applicable law requires.

12. Adults Only

The current release is intended only for people aged 18 or older and is not directed to children or teens. We do not knowingly permit an under-18 person to create an account. If we learn that an under-18 person provided personal information, we may suspend the account and delete or restrict the information as required or appropriate. Contact [email protected] if you believe this has occurred.

13. Changes To This Policy

We may update this Policy as the Service, providers, law, or security practices change. The posted "Last updated" date identifies the current version. Posting the revised Policy on the Service is our primary method of publication, and we do not promise individual notice for every editorial, clarifying, non-substantive, or user-beneficial change.

If a change is material, introduces a materially different purpose, or requires notice or consent under applicable law or platform policy, we will provide the required in-app, email, prominent, or other notice and obtain consent where required before the new processing begins. We will not apply a materially broader use retroactively to previously collected information where prohibited.

14. Contact

Controller and Service operator: Roman Babunts, trading as SheSafe, Serbia.

For privacy rights, account deletion, support, abuse reports, security incidents, or questions about this Policy, email [email protected].