Privacy Policy

Introduction & Our Commitment

RewindSafe ("we", "us", "our") is built on a privacy-first foundation. Our guiding principle is that your personal-safety data belongs to you — not to advertisers, not to governments, and not to us — unless you explicitly choose to share it, or unless a consensual guardian arrangement makes a guardian the data owner.

This Privacy Policy explains what we collect, why, how we use and protect it, who may process it, how long we keep it, and what rights you have. It applies to the RewindSafe mobile app, the associated web services (including these legal pages), and communications with us. It supplements and is incorporated into our Terms of Service.

Information We Collect

Information you provide

  • Account identity: An email address and profile name when you sign in via Google, Apple, or a passwordless email link. We never receive or store an OAuth password. If you never sign in, only a local anonymous device identity exists.
  • Safety contacts: Names and contact details of the people you designate as emergency contacts, partners, or guardians. Stored locally and, on Pro plans, synced to your personal cloud space.
  • Places, terrains & journeys: Names, coordinates, and rules for the safe/unsafe places, terrains, and monitored routes you configure.

Data the app generates to keep you safe

  • Audio: The core function. Audio is encrypted on-device before any storage or transmission. On the Free tier it never leaves your device.
  • Multi-layer evidence telemetry: For context around an event, the app may capture a synchronized frame that can include precise location/GPS, motion/accelerometer & orientation, altitude/barometric pressure, temperature, device state (battery, network, thermal), and an on-device AI risk score. Which layers are captured depends on your plan and your per-layer privacy settings.
  • On-device AI analysis: Audio may be analysed locally by an on-device model to estimate a distress/risk score and detect sound patterns. This analysis runs on your device; raw audio is not sent to us for analysis.
  • Event & safety metadata: Timestamps, event type (Save/Panic), trigger source (manual, check-in, risk fusion, geofence, etc.), broadcast mode (local/live), duration, journey/challenge linkage, and device-generated identifiers used to organise your evidence.
  • Audit logs: A log of significant actions (account changes, linkage events, exports) for your own transparency.

Technical & diagnostic data

  • Device identifier: An anonymised, app-specific device ID linking your local data to your account. We do not collect IMEI, UDID, or permanent hardware identifiers.
  • Crash & performance diagnostics: Anonymised stability and performance data, stripped of personal identifiers before transmission.
  • Product analytics: Aggregate, anonymised feature-usage data to guide development. We do not build individual behavioural profiles and do not use this data for advertising.

Device Permissions We Request

RewindSafe only requests the permissions its safety features need, and degrades gracefully if you decline:

  • Microphone — required for the audio buffer and panic recording.
  • Location (including background) — for place/terrain monitoring, journey/route deviation alerts, and attaching location to a panic event. You can limit or disable this; doing so disables the location-dependent features.
  • Motion & fitness sensors — for fall/impact and movement context in the evidence frame and risk scoring.
  • Notifications — for check-in prompts, guardian/contact alerts, and status.
  • Bluetooth — only for short-range, proximity-based device pairing when you link with a contact in person.
  • Camera — only when you choose live (video) panic streaming.

You can review and change these at any time in your device's system settings; many can also be toggled per-layer inside the app.

How We Use Your Information

We use the information we collect to:

  • Provide the Service: authenticate you, sync your data across your devices (Pro), enable guard/ward, partner, and observer linkages, and deliver notifications.
  • Power safety features: run the rolling buffer, process Save/Panic, perform on-device AI distress detection and risk fusion, drive check-ins and the dead-man's-switch, route real-time alerts and (in live mode) audio/video to your designated contacts or guardian, and preserve the integrity of your evidence.
  • Improve the Service: analyse anonymised usage and crash data to fix bugs and build features.
  • Comply with the law: respond to valid legal process and enforce our Terms.
  • Support you: answer your requests and send service-related messages.

We do not use your data to serve advertisements, and we do not sell, rent, or trade your personal data for commercial purposes.

Legal Bases for Processing (GDPR & Similar Frameworks)

Where applicable, we process personal data on these bases:

  • Contractual necessity — to provide what you requested (account, cloud sync, linkages).
  • Legitimate interests — security, fraud prevention, and anonymised analytics that do not override your fundamental rights.
  • Consent — for optional, permission-gated features such as location, microphone, motion sensors, and push notifications. You may withdraw consent at any time via device or in-app settings.
  • Vital interests / legal obligation — to protect you or another person in a safety emergency, or where processing is required by law.

Data Storage, Security & Encryption

Security is part of RewindSafe's architecture, not an afterthought:

  • On-device encryption: Audio and sensitive telemetry are encrypted at rest using authenticated AES-256 encryption. Encryption keys are held in your device's secure key storage and are not transmitted to us.
  • Per-event & end-to-end keys: Evidence is protected with per-event keys; when you share an event with a contact or guardian, access is granted by wrapping keys for that specific recipient, so only intended parties can decrypt it. Keys are rotated when access is revoked.
  • In-transit encryption: All communication with our servers uses TLS 1.2 or higher; live panic streams use encrypted real-time transport.
  • Cloud storage: Pro cloud data is stored on Google Cloud / Firebase infrastructure, which holds SOC 2, ISO 27001, and similar certifications.
  • Access controls: Internal access is least-privilege; no employee has routine access to user audio.
  • Breach notification: If a breach affects your personal data, we will notify you and the relevant authorities within the timeframes required by law (typically 72 hours under GDPR).

Guard / Ward Data Relationships

The guard/ward feature involves a specific, transparent data-ownership arrangement:

  • When a Ward links to a Guard, the Guard account becomes the data owner for that ward's synced recordings and events, stored in the Guard's cloud space.
  • The ward device always shows a persistent "monitored by [guardian]" indicator while a linkage is active, and a distinct indicator when the guardian is actively viewing a live feed.
  • Ward-initiated unlinking carries a deliberate revocation delay during which the guardian is notified and the ward's panic functionality stays fully active — a safeguard against a ward being coerced into revoking. Guardians, as data owner and sponsor, may remove a ward immediately.
  • On unlinking, ward data already captured remains in the guardian's cloud unless the guardian deletes it.

This is designed to protect minors and vulnerable people who rely on a trusted adult. RewindSafe does not facilitate or endorse use of this feature for covert surveillance, and the ward is always shown that monitoring is active.

Partner & Observer Relationships

Beyond guard/ward, RewindSafe supports symmetric, consent-based safety links:

  • Partners: Two Pro users may form a mutual peer-safety link. Each side independently configures, via an explicit consent step, exactly which data categories (e.g. location, panic events) they share with the other; sharing is bilateral and revocable.
  • Observers: A guardian may assign observers who help watch a ward. Observers receive only the access the guardian grants, reached through the guardian relationship.

Every linkage requires an explicit in-app consent step that summarises what will be shared before it is created.

Data Sharing & Third Parties

We share your information only in these limited circumstances:

  • Processors acting for us: Firebase / Google Cloud (infrastructure and storage), RevenueCat (subscription management), OneSignal (push notifications), PostHog (anonymised product analytics), and Google Cloud Translation (used once, server-side, to translate these legal pages — not your personal data). These providers process data under data-processing agreements and may not use it for their own purposes.
  • Your designated recipients: When you trigger a live panic or share an event, the relevant audio/telemetry is delivered to the specific contacts or guardian you have linked — end-to-end protected to those recipients.
  • Legal process: Where required by a valid court order, subpoena, warrant, or other lawful process; we will notify you where legally permitted.
  • Safety emergencies: Where we have a good-faith belief that disclosure is necessary to prevent imminent harm.
  • Business transfers: In a merger, acquisition, or asset sale, with notice before your data becomes subject to a different policy.

We never share your audio, telemetry, location, or safety contacts with advertisers or data brokers.

Data Retention

We keep data for the minimum period needed to provide the Service:

  • Recordings & evidence: On Free, stored locally until you delete them or uninstall. On Pro, cloud-synced events follow your configured retention; un-saved buffers are short-lived, and deleting an event cascade-deletes its audio, telemetry, clips, and encryption keys.
  • Account data: Kept for the life of your account plus up to 30 days after deletion (to allow recovery from accidental deletion).
  • Audit logs: Retained locally for a limited period; cloud audit logs (Pro) for a defined retention window.
  • Anonymised analytics: Retained in aggregate, non-identifiable form for a limited period.

When you delete your account, we permanently delete the associated personal data within 30 days, except where retention is required by law or legitimate legal process.

Your Rights & Choices

Depending on where you live, you may have the rights to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your personal data ("right to be forgotten").
  • Port your data in a machine-readable format.
  • Object to or restrict certain processing.
  • Withdraw consent at any time, without affecting prior lawful processing.
  • Complain to your supervisory authority (e.g. the ICO in the UK, CNIL in France, or your local equivalent).

Much of this is available directly in-app (export, delete account, per-layer toggles). To exercise any right, contact privacy@rewindsafe.app; we respond within 30 days or the period required by your jurisdiction.

Children's Privacy

RewindSafe takes children's privacy extremely seriously. Children under 13 may not create accounts independently. Children aged 13–17 may use the Service as a Ward under a Guard (parent or legal guardian) who has accepted these Terms and this Policy on their behalf.

We do not knowingly collect personal data from children under 13 without verifiable parental consent. If you believe we have done so, contact privacy@rewindsafe.app and we will delete it promptly.

International Data Transfers

RewindSafe serves users globally, so your data may be processed in a country other than your own. We use appropriate safeguards for such transfers, including Standard Contractual Clauses (or equivalent mechanisms) for transfers from the EEA, UK, or Switzerland, and rely on our cloud provider's contractual data-protection commitments.

Changes to This Policy

We may update this Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes we will update the "Last Updated" date, notify you in-app, and — for changes that affect your rights — seek your renewed consent. Continued use after changes take effect constitutes acceptance of the revised Policy.

Contact Us

For any question, concern, or request about this Policy or your data:

RewindSafe Privacy Team
Privacy: privacy@rewindsafe.app
Legal: legal@rewindsafe.app
Support: support@rewindsafe.app

We aim to respond to privacy enquiries within 5 business days and to work with you toward a fair resolution.