Safe Check-In ("we", "us") operates this personal-safety check-in service. Contact us about privacy at hello@safecheckin.org.
| Data | Why |
|---|---|
| Your email address | To create and secure your account and sign you in. |
| Password (hashed) and, if enabled, two-factor secret (encrypted) | To protect your account. We never store your password in readable form. |
| Trusted contacts' details (name, phone, email) and your relationship label | So we can alert the people you choose if you miss a check-in. |
| Your check-ins and schedules | To know when to expect you and when to alert your contacts. |
| Optional location | Only if you turn it on, to share your last known location with your contacts during an alert. You control retention and can delete it. |
| Push subscription topic | To deliver notifications to your device. |
| Billing details (via Stripe) | To take payment for paid plans. We do not store full card numbers; Stripe handles card data. |
| Security logs (sign-in attempts, audit events, IP at the time) | To protect accounts and provide a tamper-evident history of safety events. |
We use your information only to run the Service: to schedule and record check-ins, to send reminders and alerts through your chosen channels, to secure your account, to take payment, and to support you. We do not sell your data or use it for advertising.
When you add a trusted contact, we ask them to confirm they accept receiving safety alerts before we send them. You must only add people who have agreed. A contact can decline, and we will not send them alerts unless they have accepted.
We share the minimum needed with providers that help run the Service. They process data on our behalf under their own terms:
| Provider | Purpose |
|---|---|
| Twilio (incl. SendGrid) | SMS, voice calls, and email alerts |
| ntfy (self-hosted, with Apple/Google push relays) | Push notifications to your device |
| Stripe | Payment processing for paid plans |
| Cloudflare | DNS, security, and content delivery |
| Cloud hosting provider | Running the application and database |
Data is stored on our server and may be processed by the providers above, some of which operate overseas. We take reasonable steps to ensure overseas recipients handle your data consistently with the Australian Privacy Principles.
We protect your data with encryption in transit (HTTPS), hashed passwords, encrypted two-factor and location secrets, access controls that isolate each account's data, and append-only security logs. No system is perfectly secure, but we design for the sensitivity of this data.
We keep your data while your account is active. You can delete contacts, location data, and your account. When you delete your account we remove or de-identify your personal data, except where we must keep limited records for legal, security, or billing reasons (for example, tamper-evident safety logs and payment records).
Under the Australian Privacy Principles you can ask to access or correct your personal information, and ask us to delete it. Email hello@safecheckin.org and we will respond within a reasonable time.
The Service is not intended for children under 16. We do not knowingly collect their data.
If a breach likely to cause serious harm occurs, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
If you are not satisfied with our response to a privacy concern, you can contact the OAIC at oaic.gov.au.
We may update this policy. Material changes will be notified through the Service.