What we store, what we cannot read, and what never leaves your phone.
The short version. What you write down, where you were, your recordings and your photos are encrypted on your phone before they are sent anywhere. We hold no key that opens any of it. We cannot read your record, and neither can the company that stores it for us.
We do not sell anything, show adverts, or run analytics or trackers of any kind. There is no third-party script on this site.
The phone numbers of the people you add are never sent to us at all. They stay on your device.
Last updated: 6 August 2026.
Your record is encrypted with a key generated on your own device. Every entry gets its own key, and that key is sealed separately to you and to each person in your circle. What reaches our database is unreadable text and sealed keys. There is no master key, and no key on our side that opens anything.
That covers what you write, your check-in state, your location when you share it, your voice recordings and your photos.
This is a deliberate limit on us, and it has a consequence you should know about: if you lose your key and your recovery passphrase, we cannot recover your record. Nobody can. That is the trade for us not being able to read it.
| What | Why | Can we read it? |
|---|---|---|
| An account identifier | To know which record is yours | Yes |
| Your email address — optional | Only if you give it, so we can reach you. You can clear it at any time | Yes |
| The name you choose to be called | So your friends know who the alert is from | Yes |
| Your public key, and the public key of each person in your circle | To seal entries so your circle can open them | Yes — public keys are meant to be public |
| Invite and watch links | To connect you to your circle and to show them your timer | Yes |
| Timestamps and check-in status | To know when a timer has run out and who to tell | Yes |
| Your entries, locations, recordings and photos | They are your record | No — encrypted |
The phone numbers of your circle. When you add someone by number, that number is used on your device to open WhatsApp with a message ready to send. It is not uploaded and we never hold it. We do not contact the people you add — you do, from your own phone.
Your private key. It is generated on your device and stays there. If you set a recovery passphrase, the key is wrapped with it before it is stored, so the passphrase never reaches us either.
YesSafe asks for your location only at the moment you raise an alarm or check in. It takes a single reading and stops. There is no background tracking, no location history, and nothing is collected while you are not using it. If you refuse the permission, everything else still works — your circle is told, just without a map.
The reading is encrypted before it is sent, so it is readable only by you and the circle you chose.
Severe-weather warnings are a separate thing and do not use your location at all: we send the coordinates of the city you picked from a list, never yours.
Recording is something you start. Audio and images are encrypted on your device before they are uploaded, and are stored as unreadable files. They are opened only by you or your circle, on your devices.
There are no advertising or tracking cookies, and no third-party cookies. We set two, both strictly necessary:
| Name | What it does |
|---|---|
help_sid | Keeps you signed in. Signed, and readable only by the server |
help_mode | Remembers which version of the guide to show you |
Your browser also keeps a few settings on your own device, which we never receive: whether you allowed the microphone, whether a check-in is running, and your usual timer length.
| Who | What for | What they can read |
|---|---|---|
| Supabase | Database and encrypted file storage | Only the unencrypted items in the table above. Not your record |
| Fly.io | Runs the website | Ordinary web request logs |
| Cloudflare | Delivers the site and protects it from attack | Ordinary web request logs |
| US National Weather Service | Severe-weather warnings | The coordinates of a city on our list — never yours |
When you tap to open WhatsApp, a map, or a helpline's website, you are leaving YesSafe and that service's own privacy policy applies. We do not send them anything about you.
We do not sell or share your personal information. We do not show adverts or work with advertising networks. We do not run analytics, tracking pixels, session recording or fingerprinting. We do not build a profile of you. We do not use your data to train anything.
Wherever you live, you can ask us to show you what we hold, correct it, delete it, or send you a copy. You can delete your record from inside the app. If you are in the UK or EU, the UK GDPR and GDPR give you those rights and the right to complain to your data protection authority — in the UK, the Information Commissioner's Office. If you are in California, the CCPA and CPRA give you the right to know, delete, correct, and opt out of sale or sharing; we do not sell or share, so there is nothing to opt out of, and we will never treat you differently for asking.
Remember the limit above: we can delete your encrypted record, but we cannot show you its contents, because we cannot read them.
Your record is kept until you delete it. There is no automatic expiry: we do not quietly bin things after a year.
Deleting works differently here than in most apps, on purpose. When you delete an entry it disappears from your view immediately — that is the part that matters if someone is standing over you telling you to get rid of it. But the entry itself is kept for seven more days. During those seven days you can put it back, and the people in your circle can still read it. After that it is gone for good.
There is no "delete it properly now" button, anywhere. That is not an oversight. That button is the one an attacker would press, and the seven days exist so that a deletion made under pressure is survivable. For the same reason, your circle is told when something is deleted — at most once a day. A deletion you did not make is the loudest thing this app can do.
You can delete your whole record and your account. The same seven-day window applies. If you want it gone sooner than that, write to us and we will do it by hand — but understand that we are removing a safety net, so we will check it is really you asking.
Your data is stored in the United States. The website runs on Fly.io in Virginia, and your record is stored by Supabase on Amazon Web Services in Northern Virginia.
If you are in the UK or the EU, that means your data is transferred to the United States. We rely on the UK and EU Standard Contractual Clauses for that transfer, which are the terms our providers publish and operate under.
YesSafe is for people aged 16 and over. We do not knowingly create records for anyone younger. If you believe a child under 16 has a record here, write to us and we will remove it.
The guide itself — the cities, the emergency numbers, the things to watch for — is open to anyone, with no account and no age check, and it stays that way. A page that tells you which number to ring should not ask how old you are first.
If we change this policy we will change the date at the top. If a change affects what we collect or who sees it, we will tell you in the app before it takes effect.
YesSafe is run by XFactorAi LLC, which is the data controller for everything described on this page.
XFactorAi LLC
7345 W Sand Lake Rd, Ste 210 – Office 4812
Orlando, FL 32819
United States
To ask what we hold, to correct it, to get a copy, or to have it deleted, write to [email protected]. A person reads it. We will answer within 30 days, which is what the UK and EU rules require, and usually much sooner.
If you are in the UK or the EU and you are not happy with how we answer, you can complain to your own data protection authority — in the UK that is the Information Commissioner's Office.