Privacy Policy
Last updated: 8 August 2026
SafeZone is built so that as little as possible accumulates about you: there is no user account, no email address, no free-text fields and no photos. This policy describes which data is nevertheless processed when you use the “SafeZone” app, why, for how long — and what rights you have.
1. Controller
ESBM-Solutions UG (haftungsbeschränkt) i. Gr.
Ditfurthstraße 48
33611 Bielefeld, Germany
Email: support@esbm-solutions.com
2. Hosting
Our servers are operated by Hetzner Online GmbH (Germany) and managed via Coolify; the server location is Frankfurt am Main. They run the app’s API (api.safezone.esbm-solutions.com) and the PostgreSQL database. A data processing agreement is in place with Hetzner. Report data is not outsourced to any external database or cloud provider.
3. Use without an account
SafeZone has no registration and no sign-in. We collect neither an email address nor a name, phone number or password, and the app is not linked to any social login.
So that reporting limits, confirmation limits and abuse protection can work at all, the app creates a random device identifier the first time you use it. That identifier is stored in your device’s encrypted system storage and is kept on our server only as a cryptographic hash (SHA-256). It contains no information about you, your device or your connection and is not linked to any advertising identifier. If you delete the app you lose access to that identifier; reinstalling creates a new one.
4. Which data we process
- Device identifier (as a hash) and an internal trust score derived from it, based on how often your reports were confirmed by others or expired unconfirmed. Purpose: abuse protection and weighting of the map.
- Reports — we store only: the chosen category (e.g. robbery, violence, aggressive group, harassment, drug scene, pickpocketing, feeling unsafe, dark area), optional attributes from fixed lists (group size, behaviour, mobility), the location of the reported incident as a coordinate, the time of the report, optionally the stated time of the incident, the link to your device identifier and, where applicable, the link to a previous report of the same incident. There are no free-text fields, no photo or video uploads and no fields for names or descriptions of people.
- Confirmations — if you confirm someone else’s report, we store the report, your device identifier and the time.
- Your device location when reporting — transmitted together with the report but not stored. It is used only for the immediate plausibility check that the reported location is no more than 500 metres away from you. After the check it is discarded.
- Location queries — to load the map, warnings and nearby help the app sends your position to our API. These queries are neither logged nor stored: our server is configured so that neither the request URL containing the coordinates nor the IP address is written to log files.
- IP address — used briefly in memory as a counter when a new device identifier is created, so that identifiers cannot be created without limit. It is not stored in the database and not logged, and expires after 24 hours at the latest or when the service restarts.
- Settings (language, warning categories, warning radius, subscription status) — remain solely on your device.
5. Location data in detail
In the foreground (while you are using the app) we use your location to centre the map on you, to place and verify your report and to find help nearby.
In the background we use your location only if you explicitly enable warnings and grant the “always allow” permission. In that case the app loads the current areas within your chosen radius (500 m to 5 km) and monitors up to 18 zones of 200 metres radius each on your device. If you enter such a zone, the app creates the notification itself. We do not keep a server-side movement profile, and your location is not continuously transmitted for this purpose. You can switch warnings off at any time in the app settings or in your device’s system settings.
6. Notifications
Warnings are local notifications triggered by your own device. We do not send push messages through a push service, we store no push token, and we are technically unable to message you individually.
7. Reports and other people’s data
A report describes a situation at a place, not a person. That is exactly why the app has no input fields for names, descriptions or photos: no identifying information about third parties should be created in the first place. Please do not use SafeZone to follow, observe or tag individual people — our terms of use prohibit this.
8. Purposes and legal bases
| Purpose | Legal basis (Art. 6(1) GDPR) |
|---|---|
| Providing the map, reports, confirmations and nearby help | (b) — performance of the contract of use |
| Abuse protection: reporting and confirmation limits, plausibility check, trust score, IP counter during registration | (f) — legitimate interest in a reliable map with little abuse |
| Warnings (background location and notifications) | (a) — your consent, revocable at any time |
| Non-personalised advertising to finance free use | (f) — legitimate interest in financing the service |
| Handling and managing subscriptions | (b) — performance of the subscription contract |
9. Recipients and processors
| Service | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the API and database | Germany |
| Google AdMob (Google Ireland Ltd.) | Ad banner on the map screen (only without a subscription) | Ireland / USA |
| RevenueCat, Inc. | Technical management of subscriptions | USA |
| Apple / Google Play | Distribution of the app, processing of purchases | Ireland / USA |
Beyond that we use no analytics, tracking, crash-reporting or AI services. In particular, SafeZone uses no Sentry, no OpenAI and no external database service.
10. Advertising
Without a subscription we show an ad banner — exclusively on the map screen. No advertising appears in the reporting, help, onboarding or settings areas.
Ads are currently served on a non-personalised basis only. Google AdMob processes technical information about the device and the ad request as well as a coarse location (region) derived from the IP address, in order to deliver ads, cap their frequency and prevent fraud. We do not pass any reports, device identifiers or precise locations to AdMob.
Should we offer personalised advertising in the future, we will first obtain your consent through Google’s consent dialog (User Messaging Platform), and on iOS additionally through Apple’s App Tracking Transparency (ATT). Without consent, advertising remains non-personalised. With a subscription, no advertising is loaded at all.
11. Subscriptions
The “Ad-free” and “Supporter” subscriptions are purchased through the Apple App Store or Google Play; your contractual partner for the purchase is Apple or Google. The technical management (checking which subscription is active) is handled by RevenueCat. This creates an anonymous app identifier, the store’s purchase and transaction identifiers and the subscription status. We receive no payment data such as credit card numbers or billing addresses. The privacy policies of Apple and Google apply in addition. The subscription status is stored on your device and is not linked to your reports.
12. Retention
- Reports are permanently deleted no later than 90 days after they arrive. Before that they are condensed into an anonymous monthly statistic containing only category, month, count and a coarse cell of the map grid (H3, resolution 9, roughly 0.1 km²) — without coordinates and without any link to a device identifier.
- A report stays visible on the map for far less time: depending on the category it expires automatically after five times its decay period, which — counted from the last confirmation — is between roughly 10 hours (e.g. violence, feeling unsafe) and around 60 hours (drug scene). Persistent conditions such as “dark area” stay visible until deletion after 90 days.
- Confirmations are deleted together with the report they belong to.
- Device identifiers (hash and trust score) are retained for as long as they are needed for abuse protection. You can delete yours yourself at any time — in the app under Settings → My data; it happens immediately, together with your reports and confirmations. Alternatively we delete it on request by email — see Delete account & data.
- Location queries and IP addresses are never stored in the first place.
13. Transfers to third countries
Google AdMob and RevenueCat process data (also) in the USA. Transfers are based on the EU standard contractual clauses or an adequacy decision (EU-US Data Privacy Framework), where applicable. Your reports and location queries do not leave Germany.
14. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Consent you have given — for instance to warnings — can be withdrawn at any time with effect for the future by switching them off in the app. You also have the right to lodge a complaint with a data protection supervisory authority.
You can exercise your right to erasure (Art. 17 GDPR) without going through us at all: in the app under Settings → My data, “Delete my data” removes all your reports, all your confirmations and your device identifier from our servers immediately and irreversibly. The same screen also shows you your device identifier.
A practical note for every other kind of request: because we deliberately store no contact details, we can only match a request to your data if you tell us your device identifier. Without that link we cannot provide information or carry out a targeted deletion — this is not a refusal but a consequence of data minimisation (Art. 11 GDPR).
15. Contact for privacy matters
For questions or to exercise your rights, contact: support@esbm-solutions.com.
Note: This text is a carefully prepared draft and does not constitute legal advice. We recommend having it reviewed by a lawyer before the official app launch.