SheSafe Privacy Policy
Effective date and last updated: 2026-09-01
This Privacy Policy explains how SheSafe collects, uses, discloses, retains, and protects personal information when you use the SheSafe mobile application, the SheSafe pages at boonts.com, invitation links, and related support channels (together, the "Service"). It also explains the choices and rights available to you.
SheSafe is operated by Roman Babunts, the individual App Store seller identified as the app provider on the applicable SheSafe App Store product page ("SheSafe", "we", "us", or "our"). Roman Babunts is the data controller for the processing described in this Policy and can be contacted at [email protected].
SheSafe is a personal safety coordination tool. It is not an emergency dispatch, law-enforcement, security-monitoring, medical, or rescue service and does not guarantee anyone's safety. In an immediate emergency, contact the appropriate local emergency service first.
1. Scope And Sources Of Information
This Policy applies to information that we receive:
- directly from you, including information entered in the app or sent to support;
- automatically from your device, browser, app, permissions, and use of the Service;
- from a trusted contact or another user who invites you, connects with you, receives your safety information, confirms an incident, or otherwise participates in a shared workflow;
- from authentication, hosting, push, maps, analytics, security, and support providers; and
- from public or licensed map, street-lighting, travel-advisory, and safety data sources.
This Policy does not govern a third party's independent handling of information after you leave the Service or share information outside the Service.
2. Information We Collect
Account, profile, and eligibility information
- Supabase or authentication-provider user ID, email address, display name, and authentication or verification metadata supplied by Apple, Google, or email sign-in;
- app account ID, account state, language, country or data-region setting where enabled; and
- age confirmation and versioned Terms and Privacy acceptance timestamps.
Trusted-circle, invitation, and relationship information
- trusted-contact relationships, roles, permissions, priority, membership, and block or removal state;
- invite codes and links, inviter and recipient identifiers, channel selected in the device share sheet, status, creation, expiry, redemption, and acceptance records; and
- records needed to determine which user may view, acknowledge, or act on a journey or safety event.
The Service does not read or upload your device address book in the current release. If you choose SMS, email, WhatsApp, Telegram, or another sharing app, your device and that third-party service handle the recipient information under their own terms.
Precise location, journey, and safety information
- precise or approximate device location, route points, origin, destination, venue, map bounds, last-known location, and location timestamps;
- journey type, Date Mode details, alert level, ETA, start and completion state, check-in schedule and responses, missed check-ins, heartbeat and connectivity state, and automatic expiry state;
- SOS type and source, including manual, timeout, missed-check-in, or duress escalation, timestamps, acknowledgement, resolution, and delivery status;
- battery level, sound or notification state, app state, last-online time, and other limited device telemetry used to show whether an active safety session may be degraded; and
- per-recipient event, outbox, retry, delivery, visibility, acknowledgement, escalation, failure, and audit records.
Location may continue to be collected and transmitted during a user-started active journey or SOS session when the app is in the background or the screen is locked, subject to your device permissions and operating-system restrictions. The current release is not designed to collect continuous location outside an active safety session.
Date Mode, journey context, and other user content
- destination or venue details and free-text notes that you choose to attach to a journey, Date Mode session, check-in, or safety event;
- incident reports, including the selected map point, category, severity, optional description, time, anonymous-display preference, and verification votes; and
- support messages and any information or attachments you choose to send to us.
Do not include unnecessary sensitive information, names of alleged offenders or victims, contact details, health information, or other identifying information in a public incident description or journey note. Information marked "anonymous" may be hidden from other users while remaining linked internally to an account for security, moderation, duplicate prevention, and legal compliance.
Analytics, device, browser, and service-operation information
- app version, platform, operating-system and User-Agent information, IP address, approximate network-derived region, language, browser or device type, referrer, screen views, session timestamps, a random app-instance identifier, and diagnostic or security logs;
- PII-minimized product events, such as onboarding steps, authentication method, journey or SOS actions, invite outcomes, safety-layer use, permission results, and account-deletion requests; and
- website interaction data, such as pages viewed, link clicks, scroll depth, cookie or online identifiers, advertising measurement, and, where enabled, session-replay or similar interaction data.
Google Analytics for Firebase mobile collection is disabled by default and is enabled only after you choose to share app analytics during onboarding or in Settings. The mobile analytics payload policy is designed to exclude account, journey, safety-event and other stable internal identifiers, names, email addresses, phone numbers, free text, street addresses, precise coordinates, trusted-circle graphs, and SOS content. Google may nevertheless receive a random app-instance identifier, IP address, device/app metadata, approximate network-derived region, and transport metadata needed to provide analytics.
Information stored only on your device
The personal SOS cancel PIN, tutorial state, permission-introduction state, legal-acceptance copy, scheduled local notifications, and undelivered SOS retry queue may be stored locally on your device. The current implementation does not send the digits of your cancel PIN to our server. Local data may remain until you clear app data or uninstall the app, subject to operating-system backups.
Data not collected by the current release
The current release does not intentionally collect or upload microphone audio, photos, video, payment-card data, or address-book contacts. It does not use precise location, trusted-circle relationships, journey notes, or SOS content for advertising. If a future release adds a new data category or materially new purpose, we will update this Policy and provide any notice or obtain any consent required before the new processing begins.
3. How Location And Safety Sharing Work
You start location sharing by starting an active journey, Date Mode session, or SOS flow. During that session, permitted trusted contacts may receive or view your current or last-known location, route or destination, venue and text context, ETA, alert level, check-in state, battery or sound state, connectivity, and relevant safety-event status.
Depending on the selected mode and configured timing, ignoring a check-in, tapping "Need Help", releasing an armed SOS control, using a duress flow, or losing connectivity for an extended period may create an SOS or disconnected event and disclose the last-known location to trusted contacts automatically. Routine reminders may be scheduled locally on the primary user's device, while remote server-side push delivery to trusted contacts is intended for SOS and related acknowledgement events in the current release. Product behavior may be limited by release configuration and platform capabilities.
A trusted contact can view, copy, screenshot, forward, or act on information they legitimately receive. We restrict access within the Service, but cannot control a recipient's device or independent use after disclosure. Remove a contact or end the session if you no longer want ongoing in-Service sharing; previously received copies may remain outside our control.
Location represents the device, not necessarily the person. It can be wrong, stale, unavailable, or misleading if a device is left behind, shared, offline, low on battery, or affected by GPS, network, operating-system, Focus/Do Not Disturb, background-processing, or permission settings.
4. Community Safety Map And External Safety Data
The safety map may combine user-submitted incident reports and confirmations with public or third-party street-lighting, map, and travel-advisory data. A submitted incident's location, category, severity, description, time, anonymous display state, and verification count may be visible to other users. Reporter and verifier account IDs may be retained internally as described in this Policy.
Map requests may send a map viewport or approximate geographic bounds, IP address, and device or request metadata to our backend or map providers. Basemap tiles may be requested from OpenFreeMap. Street-lighting queries may be served from Supabase or, if needed, sent to OpenStreetMap Overpass endpoints, including public endpoints operated by third parties.
"Verified" only means that a configured number of users submitted a confirmation; it does not mean that SheSafe, police, a government body, or an independent investigator confirmed an incident. Safety scores, lighting labels, risk zones, advisories, and incident markers may be incomplete, estimated, duplicated, outdated, user-generated, or incorrect. They are informational and are not safe-route recommendations or predictions that any place is safe or dangerous.
5. How And Why We Use Information
We use information to:
- create and authenticate accounts, provide onboarding, and record legal and age acceptance;
- operate trusted circles, invitations, active journeys, Date Mode, check-ins, local reminders, SOS, location sharing, emergency-number prompts, widgets, and recipient acknowledgement;
- display maps, street-lighting context, community incident reports, safety scores, and travel-advisory information;
- deliver PII-minimized push handoffs and fetch full event details only after authorized access;
- queue and retry safety events when connectivity is unavailable;
- prevent unauthorized access, stalking, coercive monitoring, spam, false reports, fraudulent SOS use, duplicate voting, and service disruption;
- moderate content, investigate reports, enforce the Terms, protect users and the public, and establish, exercise, or defend legal claims;
- provide support and process access, correction, export, deletion, objection, and other privacy requests;
- measure adoption and reliability, debug failures, test and improve features, and understand website and app use; and
- comply with law, app-store rules, binding requests, and safety or security obligations.
Where law requires a legal basis, the basis depends on the purpose and context:
- contract or steps requested before contract for account and core user-requested safety functionality;
- consent for device permissions, precise or background location, certain analytics or storage technologies, and processing that requires consent;
- legitimate interests in securing, operating, troubleshooting, improving, and preventing abuse of the Service, balanced against user rights;
- legal obligation for required records and lawful requests; and
- vital interests only in an exceptional situation where permitted and necessary to protect a person, without representing that SheSafe monitors or dispatches emergencies.
If user-provided context incidentally reveals health, sexual-life, political, religious, or other specially protected information, we process it only to provide the requested safety workflow and under an additional condition required by applicable law, such as explicit consent or protection of vital interests. Please avoid submitting such information unless necessary.
We do not make solely automated decisions that produce legal or similarly significant effects. Automated check-in, timeout, connectivity, score, and SOS rules affect Service notifications and displays, not legal rights or official emergency decisions.
6. When We Disclose Information
Trusted contacts and other users
We disclose the relevant session and event information to users authorized for that journey, relationship, SOS event, or public map report. Public incident content may be shown to any user who can access the map.
Service providers
Depending on platform, region, and enabled configuration, providers may include:
- Supabase for authentication, database, Realtime, Edge Functions, and authorization;
- Apple and Google for app distribution, sign-in, device services, APNs or FCM push delivery, aggregated store/acquisition analytics, and related platform operations;
- MapLibre software and OpenFreeMap, OpenStreetMap/Overpass operators, and public travel-advisory sources for map and safety context;
- Google Analytics for Firebase for consented, PII-minimized mobile product analytics on iOS and Android;
- Apple App Store Connect Analytics and Google Play Console analytics for store, acquisition, installation, retention, usage, and quality metrics made available by the relevant platform under its own privacy controls;
- self-hosted Umami for website analytics;
- Google Analytics and Google Ads, and Yandex Metrica/Webvisor, for website traffic, interaction, advertising measurement, and related analytics where enabled;
- Cloudflare and GitHub Pages for DNS, routing, security, hosting, and public pages; and
- Cloudflare Email Routing and Google email services for support.
These providers process information for us or independently under their terms and privacy notices. We require providers acting as our processors to protect personal information consistently with this Policy and applicable law.
Legal, security, and safety disclosures
We may preserve or disclose information when we reasonably believe it is necessary to comply with applicable law or valid legal process; investigate fraud, abuse, or a security incident; enforce our Terms; protect the rights, property, or safety of a user, SheSafe, or another person; or respond to a life-safety situation. We do not promise that a disclosure will be made, that a requester will respond, or that the Service will contact public emergency responders.
Business transfers
Information may be reviewed or transferred in connection with financing, due diligence, a merger, acquisition, reorganization, insolvency, or sale of all or part of the Service, subject to confidentiality and applicable law.
7. Analytics, Cookies, Advertising, And Sale/Sharing
Mobile product analytics are optional, pseudonymous, and PII-minimized. Google Analytics for Firebase collection starts only if you opt in and can be disabled again in Settings. Disabling it stops future app analytics collection and asks the SDK to reset its locally held app-instance analytics data. We do not set a Firebase user ID or send account IDs, precise location, journey or Date Mode text, trusted-circle data, safety-event IDs, or SOS content to analytics. Ad storage, ad-user-data use, ad personalization, Android Advertising ID, iOS IDFA, and cross-app tracking are disabled for the mobile integration. SheSafe does not request Apple's App Tracking Transparency permission for this analytics.
Apple and Google may separately produce store-level acquisition, installation, retention, session, crash, and quality statistics through App Store Connect and Google Play Console. Those platform statistics are governed by the user's device/store privacy choices and the platform provider's terms. Apple usage reports may be limited to users who chose to share diagnostics and usage data with developers.
The SheSafe website may use cookies, pixels, scripts, online identifiers, and similar technologies from Umami, Google, and Yandex for audience measurement, interaction analysis, advertising attribution or remarketing, and, where enabled, session replay. These providers may receive IP address, cookie or device identifiers, browser and device data, page URL, referrer, and interaction events. Use browser controls, content blockers, available provider opt-outs, or contact [email protected] to object or make an applicable opt-out request.
We do not sell personal information for money. Some laws may define disclosures of website identifiers to advertising or analytics providers as "sale", "sharing", or targeted advertising even when no money changes hands. Where such law applies, we will honor applicable opt-out rights and legally recognized preference signals to the extent required. SheSafe does not knowingly sell or share personal information of users under 18.
8. Retention And Deletion
We retain information only for as long as reasonably needed for the stated purposes, subject to law, security, fraud prevention, dispute handling, backup integrity, and protection of other users.
Current operational rules include:
- account, profile, and trusted-relationship records remain while the account or relationship is active and are deleted or de-identified after a valid account deletion request, subject to the exceptions below;
- invite codes expire after 24 hours and are single-use, although limited issuance, redemption, fraud, and audit records may remain temporarily;
- safety-event delivery and audit records expire after 30 days under the current production retention class;
- journey coordinates and destination address fields are nullified 30 days after journey creation, while non-location journey metadata may remain for history, statistics, security, or legal purposes;
- journey context notes and SOS incident records are deleted after 30 days;
- device push tokens are revoked or deleted on sign-out, account deletion, or invalidation where technically available;
- undelivered SOS events may remain in a local device retry queue until delivered, cleared, app data is removed, or the app is uninstalled;
- community incident reports may remain publicly available until removed, expired, found inaccurate, no longer useful, or deleted under an applicable request; internal reporter and verifier links may be retained longer for moderation, abuse prevention, and legal claims;
- identifiable analytics and operational logs are normally retained for no more than 24 months, and aggregated or de-identified statistics may be retained longer;
- ordinary support messages are normally deleted or archived within 180 days after resolution, while minimal privacy-request, dispute, fraud, or legal case records may be retained for up to 24 months or longer if law requires; and
- residual copies may remain for a limited period in encrypted or access-limited backups until overwritten under normal backup cycles.
Account deletion is designed to remove account-owned profile, trusted-contact, journey, context, check-in, invite, live-location, safety-event, delivery, and device-token records where technically and legally permitted. Deletion may not remove information lawfully retained for another user's records, public reports that have been de-identified from you, information another person copied, or records needed for security, fraud prevention, legal compliance, disputes, and backup integrity.
9. Your Choices And Privacy Rights
You can:
- decline or revoke location and notification permissions in device settings;
- end an active journey or SOS session and remove a trusted relationship;
- avoid submitting optional text or a community report;
- manage website cookies through your browser and available provider controls;
- enable or disable optional mobile product analytics in SheSafe Settings;
- sign out, request account deletion in Settings, or email [email protected]; and
- contact us to object to or ask about analytics where applicable.
Revoking a permission or consent does not affect earlier lawful processing and may make safety features unavailable or unreliable. A local uninstall does not by itself delete server records; use the in-app deletion flow or contact us.
Depending on where you live, you may have rights to access, know, correct, delete, export or receive a portable copy, restrict processing, object, withdraw consent, opt out of sale/sharing/targeted advertising or certain profiling, appeal a request decision, and receive equal service without unlawful discrimination. You may also complain to a competent data-protection authority.
Submit a request to [email protected]. We may verify your identity and authority before acting. We may deny or limit a request where permitted, including where it would disclose another person's information, impair security or fraud prevention, conflict with law, or require deletion of a record another user is entitled to keep. Authorized agents may submit requests where applicable, subject to verification.
10. International Processing
We and our providers may process information in Serbia, the European Economic Area, the United States, and other countries where providers operate. Those countries may have different privacy and government-access laws. Where required, we rely on adequacy decisions, data-processing agreements, standard contractual clauses, the UK Addendum or IDTA, or other recognized safeguards and supplementary measures.
Availability of the Service in a country does not mean that data is stored in that country. A region-specific deployment, notice, or consent may apply where required.
11. Security And Incident Response
We use reasonable administrative, technical, and organizational safeguards, including authenticated access, PostgreSQL Row-Level Security, server-side authorization, restricted Realtime channels, PII-minimized push payloads, least-privilege access, event audit records, and transport encryption where supported.
No method of storage or transmission is completely secure, and we cannot guarantee confidentiality, availability, integrity, uninterrupted operation, or recovery. Keep your device, email account, sign-in session, and PIN secure; review trusted contacts; and notify [email protected] if you suspect misuse or unauthorized access. We will assess and notify affected people or authorities of a personal-data breach when applicable law requires.
12. Adults Only
The current release is intended only for people aged 18 or older and is not directed to children or teens. We do not knowingly permit an under-18 person to create an account. If we learn that an under-18 person provided personal information, we may suspend the account and delete or restrict the information as required or appropriate. Contact [email protected] if you believe this has occurred.
13. Changes To This Policy
We may update this Policy as the Service, providers, law, or security practices change. The posted "Last updated" date identifies the current version. Posting the revised Policy on the Service is our primary method of publication, and we do not promise individual notice for every editorial, clarifying, non-substantive, or user-beneficial change.
If a change is material, introduces a materially different purpose, or requires notice or consent under applicable law or platform policy, we will provide the required in-app, email, prominent, or other notice and obtain consent where required before the new processing begins. We will not apply a materially broader use retroactively to previously collected information where prohibited.
14. Contact
Controller and Service operator: Roman Babunts, trading as SheSafe, Serbia.
For privacy rights, account deletion, support, abuse reports, security incidents, or questions about this Policy, email [email protected].