YesSafe

Privacy

What we store, what we cannot read, and what never leaves your phone.

The short version. What you write down, where you were, your recordings and your photos are encrypted on your phone before they are sent anywhere. We hold no key that opens any of it. We cannot read your record, and neither can the company that stores it for us.

We do not sell anything, show adverts, or run analytics or trackers of any kind. There is no third-party script on this site.

The phone numbers of the people you add are never sent to us at all. They stay on your device.

Last updated: 6 August 2026.

What we cannot see

Your record is encrypted with a key generated on your own device. Every entry gets its own key, and that key is sealed separately to you and to each person in your circle. What reaches our database is unreadable text and sealed keys. There is no master key, and no key on our side that opens anything.

That covers what you write, your check-in state, your location when you share it, your voice recordings and your photos.

This is a deliberate limit on us, and it has a consequence you should know about: if you lose your key and your recovery passphrase, we cannot recover your record. Nobody can. That is the trade for us not being able to read it.

What we store

WhatWhyCan we read it?
An account identifierTo know which record is yoursYes
Your email address — optionalOnly if you give it, so we can reach you. You can clear it at any timeYes
The name you choose to be calledSo your friends know who the alert is fromYes
Your public key, and the public key of each person in your circle To seal entries so your circle can open themYes — public keys are meant to be public
Invite and watch linksTo connect you to your circle and to show them your timerYes
Timestamps and check-in statusTo know when a timer has run out and who to tellYes
Your entries, locations, recordings and photosThey are your recordNo — encrypted

What never leaves your phone

The phone numbers of your circle. When you add someone by number, that number is used on your device to open WhatsApp with a message ready to send. It is not uploaded and we never hold it. We do not contact the people you add — you do, from your own phone.

Your private key. It is generated on your device and stays there. If you set a recovery passphrase, the key is wrapped with it before it is stored, so the passphrase never reaches us either.

Location

YesSafe asks for your location only at the moment you raise an alarm or check in. It takes a single reading and stops. There is no background tracking, no location history, and nothing is collected while you are not using it. If you refuse the permission, everything else still works — your circle is told, just without a map.

The reading is encrypted before it is sent, so it is readable only by you and the circle you chose.

Severe-weather warnings are a separate thing and do not use your location at all: we send the coordinates of the city you picked from a list, never yours.

Recordings and photos

Recording is something you start. Audio and images are encrypted on your device before they are uploaded, and are stored as unreadable files. They are opened only by you or your circle, on your devices.

Cookies and what is kept in your browser

There are no advertising or tracking cookies, and no third-party cookies. We set two, both strictly necessary:

NameWhat it does
help_sidKeeps you signed in. Signed, and readable only by the server
help_modeRemembers which version of the guide to show you

Your browser also keeps a few settings on your own device, which we never receive: whether you allowed the microphone, whether a check-in is running, and your usual timer length.

Who else touches your data

WhoWhat forWhat they can read
SupabaseDatabase and encrypted file storage Only the unencrypted items in the table above. Not your record
Fly.ioRuns the websiteOrdinary web request logs
CloudflareDelivers the site and protects it from attack Ordinary web request logs
US National Weather ServiceSevere-weather warnings The coordinates of a city on our list — never yours

When you tap to open WhatsApp, a map, or a helpline's website, you are leaving YesSafe and that service's own privacy policy applies. We do not send them anything about you.

What we never do

We do not sell or share your personal information. We do not show adverts or work with advertising networks. We do not run analytics, tracking pixels, session recording or fingerprinting. We do not build a profile of you. We do not use your data to train anything.

Your rights

Wherever you live, you can ask us to show you what we hold, correct it, delete it, or send you a copy. You can delete your record from inside the app. If you are in the UK or EU, the UK GDPR and GDPR give you those rights and the right to complain to your data protection authority — in the UK, the Information Commissioner's Office. If you are in California, the CCPA and CPRA give you the right to know, delete, correct, and opt out of sale or sharing; we do not sell or share, so there is nothing to opt out of, and we will never treat you differently for asking.

Remember the limit above: we can delete your encrypted record, but we cannot show you its contents, because we cannot read them.

Keeping it, and getting rid of it

Your record is kept until you delete it. There is no automatic expiry: we do not quietly bin things after a year.

Deleting works differently here than in most apps, on purpose. When you delete an entry it disappears from your view immediately — that is the part that matters if someone is standing over you telling you to get rid of it. But the entry itself is kept for seven more days. During those seven days you can put it back, and the people in your circle can still read it. After that it is gone for good.

There is no "delete it properly now" button, anywhere. That is not an oversight. That button is the one an attacker would press, and the seven days exist so that a deletion made under pressure is survivable. For the same reason, your circle is told when something is deleted — at most once a day. A deletion you did not make is the loudest thing this app can do.

You can delete your whole record and your account. The same seven-day window applies. If you want it gone sooner than that, write to us and we will do it by hand — but understand that we are removing a safety net, so we will check it is really you asking.

Where your data is

Your data is stored in the United States. The website runs on Fly.io in Virginia, and your record is stored by Supabase on Amazon Web Services in Northern Virginia.

If you are in the UK or the EU, that means your data is transferred to the United States. We rely on the UK and EU Standard Contractual Clauses for that transfer, which are the terms our providers publish and operate under.

Age

YesSafe is for people aged 16 and over. We do not knowingly create records for anyone younger. If you believe a child under 16 has a record here, write to us and we will remove it.

The guide itself — the cities, the emergency numbers, the things to watch for — is open to anyone, with no account and no age check, and it stays that way. A page that tells you which number to ring should not ask how old you are first.

Changes

If we change this policy we will change the date at the top. If a change affects what we collect or who sees it, we will tell you in the app before it takes effect.

Contact

YesSafe is run by XFactorAi LLC, which is the data controller for everything described on this page.

XFactorAi LLC
7345 W Sand Lake Rd, Ste 210 – Office 4812
Orlando, FL 32819
United States

To ask what we hold, to correct it, to get a copy, or to have it deleted, write to [email protected]. A person reads it. We will answer within 30 days, which is what the UK and EU rules require, and usually much sooner.

If you are in the UK or the EU and you are not happy with how we answer, you can complain to your own data protection authority — in the UK that is the Information Commissioner's Office.