YOUR DATA · YOUR CONTROLS

Your data stays in your hands.

SafeCity's most important privacy interface is the set of controls that lets you inspect, correct, limit, and erase what the app keeps.

On-device firstYou set retentionErase any time
SAFE CITY · PRIVACY CENTERYour data
LOCAL

CURRENT STATEYou are in control

Incident history30 days
Learned baselineOptional
Cloud safety profileNone
Erase this installation
EVIDENCEAES-GCM
CLOUD PROFILENot created

DIRECT CONTROLS

Six ways to stay in charge.

Most SafeCity data lives only on the device, so the fastest rights controls live there too.

HistoryIncidentsPermissionsConsent

See what is stored

History and Settings expose incidents, contacts, permissions, consent state, retention, and learned-baseline controls.

01
ContactsSettingsPreferencesOn device

Correct your details

Update or remove emergency contacts and change protection settings directly on the device.

02
IncidentsEvidenceImmediateEncrypted

Delete an incident

Remove individual incidents and their encrypted evidence before the selected retention period ends.

03
LearningRoutineResetLocal only

Clear the baseline

Erase optional learned routine aggregates without deleting contacts or incident history.

04
1–90 days30-day defaultExpiryYour choice

Choose retention

Set local incident retention from 1 to 90 days, with 30 days as the current default.

05
ConsentContactsIncidentsFull reset

Withdraw and erase

Stop monitoring and erase this installation’s SafeCity personal data through one confirmed Settings flow.

06

DATA LIFECYCLE

From a passing signal to deliberate erasure.

Different data deserves different lifetimes. Ordinary inference should be fleeting; a confirmed incident should be encrypted and remain only as long as you choose.

01

Created

A short signal exists in memory or a setting is entered by you.

02

Protected

Durable metadata uses SQLCipher; confirmed evidence uses AES-GCM.

03

Used

Local safety states, history, and user-requested actions use the minimum relevant data.

04

Expired

Volatile windows disappear quickly; incidents follow your selected retention.

05

Erased

Delete one record, clear optional learning, or withdraw consent and erase the installation.

WITHDRAWAL

One confirmed action stops processing and resets this installation.

SettingsLegal & dataWithdraw

In the app, use Settings → Legal and your data → Withdraw consent and erase data. Monitoring stops and SafeCity removes contacts, sessions, incidents, locations, queued anonymous reports, consent records, optional learned profiles, and encrypted evidence from the installation.

FORMAL REQUESTS

Some rights need an operator.

Access summaries, grievance handling, nomination, or questions about external recipients require a verified support process.

Pre-release statusThe final Data Fiduciary, Privacy Contact, and Grievance Officer must be published before distribution.

FULL DETAILS

Read the itemised Privacy Notice.

See every data category, purpose, recipient, retention rule, and safeguard in the complete notice.