SafeZone
Support

Privacy Policy

Last updated: 8 August 2026

SafeZone is built so that as little as possible accumulates about you: there is no user account, no email address, no free-text fields and no photos. This policy describes which data is nevertheless processed when you use the “SafeZone” app, why, for how long — and what rights you have.

1. Controller

ESBM-Solutions UG (haftungsbeschränkt) i. Gr.
Ditfurthstraße 48
33611 Bielefeld, Germany
Email: support@esbm-solutions.com

2. Hosting

Our servers are operated by Hetzner Online GmbH (Germany) and managed via Coolify; the server location is Frankfurt am Main. They run the app’s API (api.safezone.esbm-solutions.com) and the PostgreSQL database. A data processing agreement is in place with Hetzner. Report data is not outsourced to any external database or cloud provider.

3. Use without an account

SafeZone has no registration and no sign-in. We collect neither an email address nor a name, phone number or password, and the app is not linked to any social login.

So that reporting limits, confirmation limits and abuse protection can work at all, the app creates a random device identifier the first time you use it. That identifier is stored in your device’s encrypted system storage and is kept on our server only as a cryptographic hash (SHA-256). It contains no information about you, your device or your connection and is not linked to any advertising identifier. If you delete the app you lose access to that identifier; reinstalling creates a new one.

4. Which data we process

5. Location data in detail

In the foreground (while you are using the app) we use your location to centre the map on you, to place and verify your report and to find help nearby.

In the background we use your location only if you explicitly enable warnings and grant the “always allow” permission. In that case the app loads the current areas within your chosen radius (500 m to 5 km) and monitors up to 18 zones of 200 metres radius each on your device. If you enter such a zone, the app creates the notification itself. We do not keep a server-side movement profile, and your location is not continuously transmitted for this purpose. You can switch warnings off at any time in the app settings or in your device’s system settings.

6. Notifications

Warnings are local notifications triggered by your own device. We do not send push messages through a push service, we store no push token, and we are technically unable to message you individually.

7. Reports and other people’s data

A report describes a situation at a place, not a person. That is exactly why the app has no input fields for names, descriptions or photos: no identifying information about third parties should be created in the first place. Please do not use SafeZone to follow, observe or tag individual people — our terms of use prohibit this.

8. Purposes and legal bases

PurposeLegal basis (Art. 6(1) GDPR)
Providing the map, reports, confirmations and nearby help(b) — performance of the contract of use
Abuse protection: reporting and confirmation limits, plausibility check, trust score, IP counter during registration(f) — legitimate interest in a reliable map with little abuse
Warnings (background location and notifications)(a) — your consent, revocable at any time
Non-personalised advertising to finance free use(f) — legitimate interest in financing the service
Handling and managing subscriptions(b) — performance of the subscription contract

9. Recipients and processors

ServicePurposeLocation
Hetzner Online GmbHHosting of the API and databaseGermany
Google AdMob (Google Ireland Ltd.)Ad banner on the map screen (only without a subscription)Ireland / USA
RevenueCat, Inc.Technical management of subscriptionsUSA
Apple / Google PlayDistribution of the app, processing of purchasesIreland / USA

Beyond that we use no analytics, tracking, crash-reporting or AI services. In particular, SafeZone uses no Sentry, no OpenAI and no external database service.

10. Advertising

Without a subscription we show an ad banner — exclusively on the map screen. No advertising appears in the reporting, help, onboarding or settings areas.

Ads are currently served on a non-personalised basis only. Google AdMob processes technical information about the device and the ad request as well as a coarse location (region) derived from the IP address, in order to deliver ads, cap their frequency and prevent fraud. We do not pass any reports, device identifiers or precise locations to AdMob.

Should we offer personalised advertising in the future, we will first obtain your consent through Google’s consent dialog (User Messaging Platform), and on iOS additionally through Apple’s App Tracking Transparency (ATT). Without consent, advertising remains non-personalised. With a subscription, no advertising is loaded at all.

11. Subscriptions

The “Ad-free” and “Supporter” subscriptions are purchased through the Apple App Store or Google Play; your contractual partner for the purchase is Apple or Google. The technical management (checking which subscription is active) is handled by RevenueCat. This creates an anonymous app identifier, the store’s purchase and transaction identifiers and the subscription status. We receive no payment data such as credit card numbers or billing addresses. The privacy policies of Apple and Google apply in addition. The subscription status is stored on your device and is not linked to your reports.

12. Retention

13. Transfers to third countries

Google AdMob and RevenueCat process data (also) in the USA. Transfers are based on the EU standard contractual clauses or an adequacy decision (EU-US Data Privacy Framework), where applicable. Your reports and location queries do not leave Germany.

14. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Consent you have given — for instance to warnings — can be withdrawn at any time with effect for the future by switching them off in the app. You also have the right to lodge a complaint with a data protection supervisory authority.

You can exercise your right to erasure (Art. 17 GDPR) without going through us at all: in the app under Settings → My data, “Delete my data” removes all your reports, all your confirmations and your device identifier from our servers immediately and irreversibly. The same screen also shows you your device identifier.

A practical note for every other kind of request: because we deliberately store no contact details, we can only match a request to your data if you tell us your device identifier. Without that link we cannot provide information or carry out a targeted deletion — this is not a refusal but a consequence of data minimisation (Art. 11 GDPR).

15. Contact for privacy matters

For questions or to exercise your rights, contact: support@esbm-solutions.com.

Note: This text is a carefully prepared draft and does not constitute legal advice. We recommend having it reviewed by a lawyer before the official app launch.