ZapSafe Privacy Policy

Effective Date: March 15, 2026 · Applies to ZapSafe v9 and above · Governing law: Digital Personal Data Protection Act, 2023 (India)

✅ Plain-Language Summary — What You Actually Need to Know

1. Who We Are

ZapSafe is developed and operated by [ZapSafe Technologies Pvt. Ltd.], registered in India. We are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act).

Data Protection Officer: [DPO Name] · dpo@zapsafe.app · [Address]

2. What Information We Collect

Information You Provide

DataWhat We CollectWhat We Do NOT Collect
Phone numberA one-way cryptographic hash (SHA-256). We cannot reverse this to your actual number.Your actual phone number in readable form
Home and work locationAn approximate area code (geohash) — accurate to roughly 50–100 metres. Not a precise address.Your exact street address or precise GPS coordinates of your home
Emergency contactsA one-way hash of each contact's phone number. Display name stored on your device only.Contact names, relationship, or any personal details about your contacts
Medical CardBlood type, allergies, medications — stored encrypted on your device. Shared with contacts and emergency services only during an active SOS.Medical history, insurance details, or any information beyond what you choose to enter

Information Generated During Use

DataWhere StoredWhen Deleted
GPS location trace (during active SOS only)Encrypted on our servers30 days after incident closes
Audio recordingsOn your device only — never sent to us30 days after incident, or when you delete
Video recordingsOn your device only — never sent to us30 days after incident, or when you delete
Motion sensor (IMU) logOn your device only — never sent to us30 days after incident, or when you delete
AI detection log (DCS scores)On your device only — never sent to us30 days after incident, or when you delete
SHA-256 file fingerprintsOn our servers (hashes only — we cannot reconstruct files from hashes)30 days after incident
Escalation log (who was notified and when)On our servers30 days after incident
Community heatmap contribution (opt-in only)On our servers — anonymised, no link to your identityPermanent (cannot be linked back to you)
Biometric data (blink liveness check)Processed on your device only — never stored anywhereDiscarded after each use

3. How We Use Your Information

We use your information only to provide the safety functions of ZapSafe. We do not use it for advertising, profiling, or any commercial purpose.

4. Who We Share Your Information With

RecipientWhat They ReceiveWhenBasis
Your emergency contactsYour GPS location, AI detection reason, battery level, Medical Card (via web link). DURESS flag if applicable.During active SOS onlyYour consent at setup — core function
Emergency services (112/999)GPS location, last 30 seconds of audio, Medical Card, AI confidence score, your photo if providedAutomatically at T+150s if no contact respondsVital interests — protecting your life
Law enforcementLegal evidence package — only when you choose to share it yourselfOnly when you tap "Share with Police"Your explicit consent at time of export
AWS (cloud provider)Encrypted GPS data, encrypted hashes, encrypted escalation logsDuring operationData processing agreement
Firebase/Apple (push notifications)Device push token and a notification identifier. Zero user content.During SOS alertsData processing agreement
We never sell your data. We never share your data with advertisers, data brokers, or any third party for commercial purposes. ZapSafe earns no revenue from your data.

5. What We Never Do

6. How Long We Keep Your Information

Data TypeRetention PeriodDeletion Method
GPS trace from SOS30 days after incident closesAutomated scheduled deletion job — DPDP compliance
SHA-256 evidence hashes30 days after incident closesAutomated deletion — user may extend via app
Escalation log30 days after incident closesAutomated deletion
Device registration recordUntil you deregister or delete your accountDELETE /auth/device/{id} — all data wiped within 72 hours
Trusted Circle session GPSDeleted immediately when session endsSynchronous deletion on session close
Heatmap contributionsPermanent — but anonymised, not linked to youCannot be individually deleted — anonymised on submission
On-device evidence files30 days — you can extend or delete manuallyControlled by you in the Evidence Vault

7. Your Rights Under the DPDP Act, 2023

As a Data Principal under India's Digital Personal Data Protection Act, you have the following rights:

8. Children's Privacy

ZapSafe is not directed at children under 18. We do not knowingly collect data from users under 18. If you believe a user under 18 has registered, please contact dpo@zapsafe.app and we will delete the account immediately.

9. How We Protect Your Information

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Board of India within 72 hours and notify you without undue delay.

10. How to Contact Us

PurposeContact
Privacy questions and data requestsdpo@zapsafe.app · Response within 48 hours
Security vulnerabilitiessecurity@zapsafe.app · Responsible disclosure
General supportsupport@zapsafe.app
Data Protection Officer[DPO Name] · dpo@zapsafe.app · [Address, India]
Data Protection Board of India (escalation)https://dpboard.gov.in (if grievance unresolved after 30 days)

This Privacy Policy may be updated from time to time. We will notify you of material changes via in-app notification at least 30 days before they take effect. Continued use of ZapSafe after that date constitutes acceptance of the updated policy.