SafeTrace privacy policy
Last updated 2026-08-27
App: SafeTrace (com.safetrace.app) · Developer: Temy · Contact: support@safe-track.dev
Last updated: 2026-08-27
This is the whole policy. It is written for the person who actually uses SafeTrace: a parent or legal guardian keeping track of their own child. If something below is unclear, or you want a copy of what we hold, email privacy@safe-track.dev and a person will answer within 30 days.
We have tried to write only things that are true of the app you can install today. Where something is planned but not built, it says so.
1. Who we are
SafeTrace is built and run by Temy. We are the data controller for everything described here. Reach us at privacy@safe-track.dev.
2. What SafeTrace is for
You, the caregiver, create an account. You pair a GPS tracker that your child carries. The app shows you where that tracker is, lets you draw safe zones, and alerts you when the tracker leaves one.
The app is for the adult. The child does not have an account, does not sign in, and is never asked for anything.
3. What we collect
About you, the caregiver
| What | Why | Where it goes |
|---|---|---|
| Email address | It is your sign-in, and how we reach you about the account | Our server |
| Password | Sign-in. Stored only as a hash, never in readable form | Our server |
| Full name | So the account has a person on it | Our server |
| Mobile number | So we can send SMS alerts, and to pre-fill tracker setup | Our server |
| The date you accepted the Terms | So we can show what you agreed to, and when | Our server |
About the tracker your child carries
| What | Why | Where it goes |
|---|---|---|
| Location fixes (latitude, longitude, accuracy, time) | The whole point of the app: showing you where the tracker is and telling you when it leaves a safe zone | Our server |
| Battery level, online or offline, last-seen time | So you know whether to trust what the map is showing | Our server |
| The tracker's hardware identifier (IMEI) | It is how we know which tracker a position belongs to | Our server |
| The raw message the tracker sent | So a wrong position can be diagnosed later without asking you to reproduce it | Our server |
| Nearby WiFi and mobile-network identifiers, when the tracker cannot see satellites | Indoors a tracker often has no GPS fix. These can be turned into an approximate position | See section 6. Off by default |
This is precise location data, and it is tied to your account. We say so plainly because that is exactly what it is.
About your phone
| What | Why | Where it goes |
|---|---|---|
| A registration record for this phone: a public key generated inside the phone's secure hardware, plus the phone model | So the server knows which phones belong to your account and can send them alerts | Our server. The private half of the key never leaves the phone |
| A push-notification token | So an alert can reach your lock screen | Google's push service and our server. Not working today: the app ships with a placeholder push configuration, so alerts do not currently arrive |
What stays on your phone and is never sent to us
- The first name you give your child. It is stored in the app's own storage on that phone only. It is not in any message we send, not in any alert, and not on our servers. It is cleared when you log out.
- Your map preferences and the app's own settings.
What we never collect
- A child's date of birth, school, contacts, photos or messages.
- Anything for advertising or profiling. There is no advertising SDK and no analytics SDK in the app.
- We do not sell your data or a child's data to anyone, for any purpose, ever.
4. Children's privacy (COPPA)
SafeTrace collects location about a child. That is only lawful with a guardian's verified consent, so the consent check is built into the database itself rather than into a screen that could be skipped.
How it works. Before any child location can be collected, read or paired to your account, there must be a consent record on our servers that says a parent or legal guardian affirmed they are the parent or legal guardian, tied to the verified email address on the account. Without that record:
- a child's tracker cannot be paired to the account,
- location and battery rows for it cannot be read, and
- newly arriving location rows are refused at the point of storage.
All three checks run on the server. An app that skipped a consent screen would still be refused.
Withdrawing consent. You can withdraw at any time. Withdrawal stops collection immediately and erases the location and status history that consent covered. The record that consent was given and then withdrawn is kept, because that is the audit trail the rule exists to create; the data it covered is gone.
Email privacy@safe-track.dev to withdraw, or use the in-app control once it ships. The enforcement above is live on our servers today; the in-app consent and withdrawal screens are still being added.
A child's given name is never sent to us at all (section 3), so there is no child profile on our servers to withdraw, export or correct. There is a tracker, and the positions it reported.
5. How long we keep things
- Your account details: until you delete the account.
- Location and status history: until you delete the account, or withdraw consent, or ask us to clear it. We intend to hold no more than 90 days, and automatic clean-up is not built yet. We would rather say that than print a retention promise nothing enforces. Ask us at privacy@safe-track.dev and we will clear your history by hand.
- Consent records: kept as the audit trail described in section 4, without the data they covered.
6. Who else touches the data
We keep this list as short as we can.
| Who | What they get | Why |
|---|---|---|
| Our own servers | Everything in section 3 marked "our server" | We run the database and the sign-in service (Supabase: PostgreSQL, GoTrue, PostgREST) and the tracker ingest ourselves, on infrastructure we control. This is not a hosted third-party service, and no vendor holds a copy |
| Mapbox | Your phone's IP address and the part of the map you are looking at | Map tiles. Mapbox never receives your account, your child's name, or the tracker's position |
| Google Maps (Android) | The same kind of tile requests, on screens that use the Google map | Map display |
| Google Cloud Messaging (Firebase) | The push token for your phone, and the alert text, which names the safe zone and never a child | Delivering alerts to your lock screen. Not functional in the current build (section 3) |
| Google Geolocation API | Nearby WiFi and mobile-network identifiers the tracker reported, with no account or name attached | Turning an indoor scan into an approximate position. Off by default. It is a per-deployment setting that ships disabled, and while it is off no scan ever leaves our servers |
There are no other processors, no data brokers, and no advertising networks.
7. Deleting your account
In the app: Settings -> Account -> Delete account. You are signed out and this phone's copy is cleared straight away; your account and its history are erased from our servers within 30 days.
If you no longer have the app, email privacy@safe-track.dev from the address on the account.
The full detail of what is erased, what is kept and why, is on the account-deletion page.
8. Your rights
Email privacy@safe-track.dev to:
- get a copy of what we hold about you,
- correct something that is wrong,
- delete the account (or use the in-app path above),
- withdraw guardian consent, which stops collection about a child,
- ask us to clear location history without closing the account,
- complain about how we handled any of the above.
We answer within 30 days. We will check you are the account holder before we act, because "delete this account" and "send me everything you hold" are both requests we must not honour for a stranger.
9. Security
Everything between the app and our servers goes over HTTPS. Passwords are stored hashed. Isolation between families is enforced in the database itself, so one account's query cannot return another family's rows even if the app asked for them. The private half of your phone's registration key is generated in the phone's secure hardware and never leaves it.
We are a small team. We do not claim a certification we have not been through.
10. Changes to this policy
If we change this policy we will update the date at the top and, for anything that changes what we collect or who receives it, tell account holders by email before it takes effect.
11. Contact
support@safe-track.dev for anything about the app.
privacy@safe-track.dev for the requests in section 8: a copy of your data, correction, erasure, withdrawing consent, or a complaint.
Temy, developer of SafeTrace.