What we store, what we cannot read, and what never leaves your phone.
The short version. What you write down, where you were, your recordings and your photos are encrypted on your phone before they are sent anywhere. We hold no key that opens any of it. We cannot read your record, and neither can the company that stores it for us.
We do not sell anything, show adverts, or run analytics or trackers of any kind. There is no third-party script on this site.
If you add someone by mobile number, we store that number. The warning your circle gets is sent by our server, not by your phone, so the number has to be somewhere the server can read it. See The people you add, below.
Last updated: 11 August 2026.
Your record is encrypted with a key generated on your own device. Every entry gets its own key, and that key is sealed separately to you and to each person in your circle. What reaches our database is unreadable text and sealed keys. There is no master key, and no key on our side that opens anything.
That covers what you write, your check-in state, your location when you share it, your voice recordings and your photos.
This is a deliberate limit on us, and it has a consequence you should know about: if you lose your key and your recovery passphrase, we cannot recover your record. Nobody can. That is the trade for us not being able to read it.
| What | Why | Can we read it? |
|---|---|---|
| An account identifier | To know which record is yours | Yes |
| Your email address — optional | Only if you give it, so we can reach you. You can clear it at any time | Yes |
| The name you choose to be called | So your friends know who the alert is from | Yes |
| For each person in your circle: the name you give them, their email address, and their mobile number if you added them by one | So the alarm can be addressed to them. Our server sends it, so our server has to hold what to send it to | Yes |
| Your public key, and the public key of each person in your circle | To seal entries so your circle can open them | Yes — public keys are meant to be public |
| Invite and watch links | To connect you to your circle and to show them your timer | Yes |
| Timestamps and check-in status | To know when a timer has run out and who to tell | Yes |
| Your entries, recordings and photos | They are your record | No — encrypted |
| The coordinates of an alarm you raise | So the email to your circle can show them where you are | Yes — this one is not encrypted. See Location, below. |
We hold their phone number, and we are the ones who contact them. When you add someone by mobile, the number is saved with their place in your circle. When a check-in runs out, it is copied into the queue of people to warn, and a job on our servers sends from that queue. Their email address, if you gave one, works the same way. We would rather write this down than have you learn it from a friend who got a message you did not send.
It is stored because the warning is written and sent by our database, which is the part of this that is awake at 2am when your timer runs out. A number that only your phone knows is a number nobody can be reached at once your phone is in someone else's pocket — which is the night this was built for.
What does happen on your phone: the invitation. When you add someone and tap to send it, the message is written on your device and you send it yourself, from your own WhatsApp. We are not in that conversation.
Today the warning goes by email only. There is no text service behind this yet, so a friend you added by number alone is somebody you can reach and we cannot. We are telling you that here for the same reason the app tells you on their card: believing someone will be warned when they will not is the one way this product could make you less safe.
We do not sell these numbers, share them, or use them for anything but reaching your circle for you. Removing someone stops us contacting them. It does not by itself erase the number we hold — write to us if you want that done.
Your private key. It is generated on your device and stays there. If you set a recovery passphrase, the key is wrapped with it before it is stored, so the passphrase never reaches us either.
YesSafe asks for your location only at the moment you raise an alarm or check in. It takes a single reading and stops. There is no background tracking, no location history, and nothing is collected while you are not using it. If you refuse the permission, everything else still works — your circle is told, just without a map.
The reading is encrypted before it is sent, so it is readable only by you and the circle you chose.
When you raise an alarm, the coordinates of that alarm are also stored unencrypted, so that they can be put into the email your circle receives.
This is a deliberate trade and we would rather explain it than bury it. The email that warns your friends is written by our database, which holds no key to anything of yours. That means a location it can show them cannot also be encrypted. Without this, a friend opens the alert at 2am, finds a link, and discovers she needs an account and a key before she can learn where you are — which is the exact moment the whole thing was built for, and the exact moment it would fail you.
What this does not change: who you were with, the car, where you were going, your notes, your recordings and your photographs stay encrypted and unreadable to us. Somebody who obtained our database could see that an alarm was raised and where. They could not see a word of what you wrote.
It happens only when you press an alarm button. An ordinary check-in never stores a plain location, and nothing is ever recorded in the background.
In Settings you can choose between sending your position once when you press — which is what happens unless you say otherwise — and keeping it going while the alarm is live, which adds a new position about every 45 seconds so the people you chose can see which way you are going rather than only where you already were.
Even then: it only runs while the app is open, it stops the moment you say you are safe, and it stops if you close the app. We do not ask for background location permission and we do not intend to — which means we genuinely cannot follow you when you are not looking at this. Those positions are stored the same way as the alarm's own: readable by your circle, deleted with the entry, gone at six months.
Severe-weather warnings are a separate thing and do not use your location at all: we send the coordinates of the city you picked from a list, never yours.
Recording is something you start. Audio and images are encrypted on your device before they are uploaded, and are stored as unreadable files. They are opened only by you or your circle, on your devices.
There are no advertising or tracking cookies, and no third-party cookies. We set two, both strictly necessary:
| Name | What it does |
|---|---|
help_sid | Keeps you signed in. Signed, and readable only by the server |
help_mode | Remembers which version of the guide to show you |
Your browser also keeps a few settings on your own device, which we never receive: whether you allowed the microphone, whether a check-in is running, and your usual timer length.
| Who | What for | What they can read |
|---|---|---|
| Supabase | Database and encrypted file storage | Only the unencrypted items in the table above. Not your record |
| Resend | Sends the emails — the warning to your circle, the nudge to you, and invitations | The address it is going to, the name you chose, when the alarm was raised, and for an alarm the coordinates and a map link. Not your record |
| Twilio | Text messages. Set up, and never used — there is no working account behind it and no text has ever been sent by us | Nothing, so far. If we switch it on it would be the mobile number and the words of the warning |
| Apple and Google, for notifications | Would put the alert on a phone's lock screen. Never used — nobody has ever switched it on, and inside our iPhone app it cannot work at all | Nothing, so far. If it were switched on they would carry the alert to the phone, the way any app's notification arrives |
| Fly.io | Runs the website | Ordinary web request logs |
| Cloudflare | Delivers the site and protects it from attack | Ordinary web request logs |
| US National Weather Service | Severe-weather warnings | The coordinates of a city on our list — never yours |
Twilio and the notification services are on this list because they are wired up, not because they are working. Today the only warning that goes out is the email. We would rather name a company that has been given nothing than leave it off and have to add it later. If either ever starts carrying your data, this page says so before it does.
When you tap to open WhatsApp, a map, or a helpline's website, you are leaving YesSafe and that service's own privacy policy applies. We do not send them anything about you.
We do not sell or share your personal information. We do not show adverts or work with advertising networks. We do not run analytics, tracking pixels, session recording or fingerprinting. We do not build a profile of you. We do not use your data to train anything.
Wherever you live, you can ask us to show you what we hold, correct it, delete it, or send you a copy. You can delete your record from inside the app. If you are in the UK or EU, the UK GDPR and GDPR give you those rights and the right to complain to your data protection authority — in the UK, the Information Commissioner's Office. If you are in California, the CCPA and CPRA give you the right to know, delete, correct, and opt out of sale or sharing; we do not sell or share, so there is nothing to opt out of, and we will never treat you differently for asking.
Remember the limit above: we can delete your encrypted record, but we cannot show you its contents, because we cannot read them.
Every entry is deleted six months after you make it. The date is set by the database the moment the entry is written, and a job every night deletes everything that has reached it — the entry, its keys, and any recording or photograph attached to it. Editing an entry does not restart the clock, and nothing in the app can push the date back. The app shows you the date each entry disappears, so you are never left finding out by going to look for something that is no longer there.
Messages are deleted three months after they are sent — sooner than entries, on purpose. An entry is a record you made in case something happened, and it stays useful for a while. A message is a conversation. Anything you attached to it — a photograph, a recording — goes at the same moment, from the same nightly job, and the same rule applies: nothing in the app can push the date back, for you or for the person you sent it to.
Your account itself does not expire. Your name, your email address if you gave one, and your circle stay until you delete them.
Deleting works differently here than in most apps, on purpose. When you delete an entry it disappears from your view immediately — that is the part that matters if someone is standing over you telling you to get rid of it. But the entry itself is kept for seven more days. During those seven days you can put it back, and the people in your circle can still read it. After that it is gone for good.
There is no "delete it properly now" button, anywhere. That is not an oversight. That button is the one an attacker would press, and the seven days exist so that a deletion made under pressure is survivable. For the same reason, your circle is told when something is deleted — at most once a day. A deletion you did not make is the loudest thing this app can do.
You can delete your whole record and your account. The same seven-day window applies. If you want it gone sooner than that, write to us and we will do it by hand — but understand that we are removing a safety net, so we will check it is really you asking.
Your data is stored in the United States. The website runs on Fly.io in Virginia, and your record is stored by Supabase on Amazon Web Services in Northern Virginia.
If you are in the UK or the EU, that means your data is transferred to the United States. We rely on the UK and EU Standard Contractual Clauses for that transfer, which are the terms our providers publish and operate under.
YesSafe is for people aged 16 and over. We do not knowingly create records for anyone younger. If you believe a child under 16 has a record here, write to us and we will remove it.
The guide itself — the cities, the emergency numbers, the things to watch for — is open to anyone, with no account and no age check, and it stays that way. A page that tells you which number to ring should not ask how old you are first.
If we change this policy we will change the date at the top. If a change affects what we collect or who sees it, we will tell you in the app before it takes effect.
YesSafe is run by XFactorAi LLC, which is the data controller for everything described on this page.
XFactorAi LLC
7345 W Sand Lake Rd, Ste 210 – Office 4812
Orlando, FL 32819
United States
To ask what we hold, to correct it, to get a copy, or to have it deleted, write to [email protected]. A person reads it. We will answer within 30 days, which is what the UK and EU rules require, and usually much sooner.
If you are in the UK or the EU and you are not happy with how we answer, you can complain to your own data protection authority — in the UK that is the Information Commissioner's Office.