Operator identity, grievance contact, final app behavior, and qualified Indian legal review must be completed before public distribution.
01
Data Fiduciary and contact details
A production deployment must publish the legal name, registered address, privacy contact, Grievance Officer, grievance email, and applicable postal address of the person or organisation that determines why and how SafeCity personal data is processed.
SafeCity must not be publicly distributed until these details are complete and operational.
02
Scope
This notice applies to the SafeCity mobile app and personal data processed for monitoring, SOS, evidence, support, privacy-rights, and security functions. It does not govern a mobile operating system, telecom carrier, SMS app, mapping provider, or emergency service acting for its own purposes; those parties provide their own notices.
03
Personal data, purposes, and retention
| Personal data | Purpose | Where handled | Retention |
|---|---|---|---|
| Emergency-contact name and phone | Prepare an SOS message to a person you choose | Encrypted device database | Until removed, consent withdrawal, or app-data erasure |
| Short microphone windows and rolling 15-second tail | Detect possible distress; preserve pre-alert audio only after confirmed SOS | Volatile device memory; bundled model | Windows are discarded; tail is discarded unless encrypted as evidence |
| Voice trigger and limited threat phrase labels | Hands-free SOS and limited local phrase checking | Bundled on-device keyword model | Ordinary labels are transient; confirmed incident factors follow incident retention |
| Motion features | Detect fall or struggle patterns and reduce false alarms | Calculated in volatile device memory | Ordinary windows are discarded; incident factors follow incident retention |
| Optional behavior baseline | Use unusual movement, speed, or coarse area only as supporting evidence | Bounded aggregate profiles in encrypted device storage | Deleted when disabled, cleared, consent is withdrawn, or app data is erased |
| Coordinates and accuracy | Incident location, Safety Navigator, route requests, viewed maps, and optional coarse routine cell | Encrypted device record and relevant public map providers | Overwritten or erased locally; external providers apply their own retention |
| Optional coarse community-risk contribution | Create crowd-thresholded anonymous risk zones | Approximate 500 m cell before transport | Unsent queue and accepted aggregate input: up to 30 days |
| Incident metadata and feedback | Display history, explain the alert, and support deletion | Encrypted device database | User-selected 1–90 days; default 30 days |
| Confirmed incident evidence | Preserve a user-authorised incident record | AES-GCM encrypted app-private files | Same as incident; earlier deletion available |
| Consent and legal versions | Record choices and notice shown | Encrypted device database | Until withdrawal or app-data erasure |
SafeCity does not collect a contact list, advertising identifier, account password, payment data, or continuous video. The repository contains no advertising SDK, data sale, or targeted-advertising flow.
04
Purposes, consent, and current pre-release variance
The intended production basis for monitoring audio, motion, location, optional behavior baselining, incident evidence, and associated identifiers is free, specific, informed, unconditional, and unambiguous consent through clear affirmative action. Operating-system permissions are separate controls.
The current prototype does not yet fully meet that intended design: onboarding requires all listed permissions and combines several purposes. Production must split optional processing, default optional features off, and correct map disclosures before relying on this consent model.
Emergency-contact details are voluntarily provided to prepare an SOS message. You should inform the contact. SafeCity does not silently send the message; the system composer requires you to press Send.
05
Processors, recipients, and disclosures
Personal data may be handled by the following parties:
- Mobile operating-system provider: permissions, protected keys, notifications, camera, microphone, motion, and location.
- SMS and telecom providers and chosen recipients: message content and included location after you press Send.
- External mapping applications: coordinates when you deliberately open or share a map link.
- OpenStreetMap Overpass endpoints: exact current coordinates when Safety Navigator requests nearby places and lighting.
- OpenStreetMap routing: exact origin and destination when you request a walking route.
- CARTO: viewed map-tile area and ordinary network metadata.
- SafeCity anonymous-risk aggregation: only after separate opt-in, an approximate 500 m cell, hourly bucket, trigger category, and rotating deduplication token.
- Authorities: only where disclosure is legally required and documented by the production operator.
No SafeCity-hosted evidence upload, cloud monitoring inference, advertising SDK, or analytics SDK exists in this repository.
06
Cross-border processing
Supported inference stays inside the phone. Operating-system, SMS, telecom, and mapping providers may process data outside India under their own arrangements. Before production, the operator must inventory each transfer, comply with applicable restrictions or localisation rules, and publish countries and safeguards. Raw monitoring audio must not be moved to an unreviewed remote service without a new data-flow, security, notice, processor, and consent review.
07
Retention and erasure
- Ordinary monitoring windows and inference results remain in volatile memory and are discarded.
- The rolling 15-second tail is discarded when monitoring stops unless a confirmed SOS encrypts it as evidence.
- Optional behavior profiles are bounded encrypted aggregates and are deleted when the feature is disabled or cleared.
- Incidents and evidence follow the 1–90 day period selected in Settings, with earlier deletion available.
- Contacts and consent records remain until removed, consent is withdrawn, or app data is erased.
- Queued anonymous-risk reports and accepted aggregate input are retained no more than 30 days.
- Longer retention is permitted only where law requires it and the operator documents and segregates the record.
08
Security safeguards
The current architecture includes:
- SQLCipher encryption for durable mobile metadata;
- random 256-bit database and evidence keys in platform-protected storage;
- AES-GCM encryption for incident evidence;
- app-private files and deletion of temporary plaintext capture files;
- in-memory monitoring audio with no inference network request or audio cache;
- an app-bundled model and local fusion rules;
- bounded local retention and individual/bulk erasure;
- coarse-cell conversion, rotating tokens, and minimum crowd thresholds for optional risk zones.
Production still requires secure signing, dependency and model provenance review, key lifecycle controls, vulnerability management, incident response, and periodic mobile security testing.
09
Personal-data breaches
The production Data Fiduciary must maintain an incident-response process that can notify affected people without delay, explain likely impact and protective steps, notify the Data Protection Board of India as applicable, provide required details within the prescribed period, and investigate and prevent recurrence. A named 24×7 operational owner must be published before release.
10
Your rights and grievance redressal
Subject to applicable law, you may:
- request a summary of personal data and processing activity;
- request applicable identities of other fiduciaries and processors;
- correct, complete, or update personal data;
- erase data no longer required by purpose or law;
- withdraw consent as easily as it was given;
- raise a grievance; and
- nominate another person to exercise rights after death or incapacity.
Local access, correction, and erasure controls are described on the Data Rights page. The operator must publish and staff a verified request and grievance process before public distribution. Do not send unencrypted incident evidence through ordinary email.
11
Withdrawal of consent
Use Settings → Legal and your data → Withdraw consent and erase data. SafeCity stops monitoring and deletes this installation's contacts, sessions, incidents, locations, queued anonymous reports, anonymous secret, consent records, optional learned profiles, and encrypted evidence, then returns to onboarding. Withdrawal does not affect lawful earlier processing or retention required by law.
12
Children
This build is restricted to people aged 18 or older and does not implement verifiable parental consent. It must not be offered to a child until qualified counsel reviews the use case and the operator implements the required parental-consent, due-diligence, child-wellbeing, tracking, and behavioral-monitoring safeguards.
13
Language and accessibility
Production consent and notices must be clear, accessible, and available in the language choices required by applicable law. The app includes English, Hindi, and Bengali interface strings, but professionally translated legal notices and accessibility testing remain release work.
14
Changes to this notice
The version and effective date appear above. If a change materially alters personal-data categories, purposes, recipients, or choice, SafeCity must present the updated notice and obtain fresh consent before the new processing begins. Product and legal teams must keep the app, website, store disclosures, and actual deployment aligned.
15
Legal framework for this draft
This deployment template was prepared for readiness under India's Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025. It is not legal advice or a compliance conclusion.