ZapSafe Privacy Policy
✅ Plain-Language Summary — What You Actually Need to Know
- Your audio and video never leave your phone. All AI detection happens on your device. We never receive, store, or process your voice recordings or camera footage on our servers.
- Your evidence stays on your phone. The files are encrypted and locked by a PIN only you know. You choose if and when to share them with police.
- We only receive your GPS during an active SOS — so your emergency contacts and emergency services can find you. This is deleted 30 days after the incident.
- Your home and work location are stored as approximate area codes (geohashes), not precise addresses. We cannot see your exact home address.
- The app is completely free. We do not sell your data to advertisers. We do not show you ads.
- You can delete everything at any time. Go to Settings → Delete My Data and your account and all associated data will be erased.
1. Who We Are
ZapSafe is developed and operated by [ZapSafe Technologies Pvt. Ltd.], registered in India. We are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act).
Data Protection Officer: [DPO Name] · dpo@zapsafe.app · [Address]
2. What Information We Collect
Information You Provide
| Data | What We Collect | What We Do NOT Collect |
|---|---|---|
| Phone number | A one-way cryptographic hash (SHA-256). We cannot reverse this to your actual number. | Your actual phone number in readable form |
| Home and work location | An approximate area code (geohash) — accurate to roughly 50–100 metres. Not a precise address. | Your exact street address or precise GPS coordinates of your home |
| Emergency contacts | A one-way hash of each contact's phone number. Display name stored on your device only. | Contact names, relationship, or any personal details about your contacts |
| Medical Card | Blood type, allergies, medications — stored encrypted on your device. Shared with contacts and emergency services only during an active SOS. | Medical history, insurance details, or any information beyond what you choose to enter |
Information Generated During Use
| Data | Where Stored | When Deleted |
|---|---|---|
| GPS location trace (during active SOS only) | Encrypted on our servers | 30 days after incident closes |
| Audio recordings | On your device only — never sent to us | 30 days after incident, or when you delete |
| Video recordings | On your device only — never sent to us | 30 days after incident, or when you delete |
| Motion sensor (IMU) log | On your device only — never sent to us | 30 days after incident, or when you delete |
| AI detection log (DCS scores) | On your device only — never sent to us | 30 days after incident, or when you delete |
| SHA-256 file fingerprints | On our servers (hashes only — we cannot reconstruct files from hashes) | 30 days after incident |
| Escalation log (who was notified and when) | On our servers | 30 days after incident |
| Community heatmap contribution (opt-in only) | On our servers — anonymised, no link to your identity | Permanent (cannot be linked back to you) |
| Biometric data (blink liveness check) | Processed on your device only — never stored anywhere | Discarded after each use |
3. How We Use Your Information
We use your information only to provide the safety functions of ZapSafe. We do not use it for advertising, profiling, or any commercial purpose.
- GPS during SOS: To show your emergency contacts where you are and to transmit your location to emergency services when 112 is auto-dialled.
- File fingerprints (SHA-256): To provide court-admissible proof that your evidence files have not been altered since capture.
- Escalation log: To orchestrate the notification chain and provide an audit trail for post-incident review.
- Heatmap data (opt-in only): To show other users which areas have had reported incidents, so they can take precautions.
- Device registration data: To associate push notification tokens with your device so we can deliver SOS alerts to your contacts.
4. Who We Share Your Information With
| Recipient | What They Receive | When | Basis |
|---|---|---|---|
| Your emergency contacts | Your GPS location, AI detection reason, battery level, Medical Card (via web link). DURESS flag if applicable. | During active SOS only | Your consent at setup — core function |
| Emergency services (112/999) | GPS location, last 30 seconds of audio, Medical Card, AI confidence score, your photo if provided | Automatically at T+150s if no contact responds | Vital interests — protecting your life |
| Law enforcement | Legal evidence package — only when you choose to share it yourself | Only when you tap "Share with Police" | Your explicit consent at time of export |
| AWS (cloud provider) | Encrypted GPS data, encrypted hashes, encrypted escalation logs | During operation | Data processing agreement |
| Firebase/Apple (push notifications) | Device push token and a notification identifier. Zero user content. | During SOS alerts | Data processing agreement |
5. What We Never Do
- We never receive, store, or process your audio or video recordings on our servers.
- We never share your data with advertisers or data brokers.
- We never use your data to train AI models without your explicit opt-in consent.
- We never store your precise home or work address — only an approximate area code.
- We never access your biometric data — it is processed and discarded entirely on your device.
- We never share your data with government agencies unless required by a lawful court order — and we will notify you to the extent legally permitted.
- We never show you advertisements.
- We never require payment or a subscription to access any safety feature.
6. How Long We Keep Your Information
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| GPS trace from SOS | 30 days after incident closes | Automated scheduled deletion job — DPDP compliance |
| SHA-256 evidence hashes | 30 days after incident closes | Automated deletion — user may extend via app |
| Escalation log | 30 days after incident closes | Automated deletion |
| Device registration record | Until you deregister or delete your account | DELETE /auth/device/{id} — all data wiped within 72 hours |
| Trusted Circle session GPS | Deleted immediately when session ends | Synchronous deletion on session close |
| Heatmap contributions | Permanent — but anonymised, not linked to you | Cannot be individually deleted — anonymised on submission |
| On-device evidence files | 30 days — you can extend or delete manually | Controlled by you in the Evidence Vault |
7. Your Rights Under the DPDP Act, 2023
As a Data Principal under India's Digital Personal Data Protection Act, you have the following rights:
- Right to Access (s.11): View all data we hold about you — go to Settings → My Data.
- Right to Correction (s.12): Correct any inaccurate information — edit in the app directly.
- Right to Erasure (s.13): Delete all your data — Settings → Delete My Account. Cloud data erased within 72 hours. On-device data erased immediately.
- Right to Grievance Redressal (s.14): Contact dpo@zapsafe.app. We will respond within 48 hours and resolve within 30 days. If unresolved, you may escalate to the Data Protection Board of India.
- Right to Nominate (s.14): Nominate a trusted person to exercise your rights if you become incapacitated — set in Tier 1 contact settings.
- Right to Withdraw Consent: Withdraw consent for any optional processing at any time via Settings. Withdrawal does not affect the lawfulness of processing before withdrawal.
8. Children's Privacy
ZapSafe is not directed at children under 18. We do not knowingly collect data from users under 18. If you believe a user under 18 has registered, please contact dpo@zapsafe.app and we will delete the account immediately.
9. How We Protect Your Information
- All data in transit is encrypted with TLS 1.3.
- All data at rest in our cloud is encrypted with AES-256 using AWS KMS.
- Access to production data is restricted to a minimum number of engineers, logged, and audited.
- We conduct annual third-party security audits and penetration tests.
- We maintain a responsible disclosure programme — security@zapsafe.app.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Board of India within 72 hours and notify you without undue delay.
10. How to Contact Us
| Purpose | Contact |
|---|---|
| Privacy questions and data requests | dpo@zapsafe.app · Response within 48 hours |
| Security vulnerabilities | security@zapsafe.app · Responsible disclosure |
| General support | support@zapsafe.app |
| Data Protection Officer | [DPO Name] · dpo@zapsafe.app · [Address, India] |
| Data Protection Board of India (escalation) | https://dpboard.gov.in (if grievance unresolved after 30 days) |
This Privacy Policy may be updated from time to time. We will notify you of material changes via in-app notification at least 30 days before they take effect. Continued use of ZapSafe after that date constitutes acceptance of the updated policy.