TRUST CENTER · NO VAGUE PROMISES

Built to help. Honest about where it stops.

Safety technology earns trust by being specific: about what it does, what leaves the phone, what can fail, and what still depends on you.

IMPORTANTDo not use SafeCity as your only way to obtain urgent help.

OUR SAFETY CHARTER

Four rules before any feature.

These principles shape product decisions, safety copy, and the way every alert is bounded.

01

Assist, never guarantee

SafeCity is not an emergency dispatcher, monitored alarm, medical device, police service, or proof that an incident occurred.

02

Explain the decision

Visible factors, tiered states, and model-version records make an alert reviewable instead of presenting a mystery score.

03

Minimize by architecture

Short-lived signals, bounded local state, encrypted evidence, and user-chosen retention reduce the amount of sensitive data that exists.

04

Require agreement

Single-modality events and behavior deviation cannot ordinarily trigger automatic SOS. Independent evidence must agree.
YAMNet Lite
Keyword model
Motion rules
ON-DEVICETemporal fusion

MODEL, NOT MAGIC

Broad sound classes, narrow safety rules.

YAMNet is a general environmental-sound classifier, not a purpose-trained personal-safety model. Its scores are evidence—not calibrated emergency probabilities. Deterministic motion, reviewed suppressors, and confirmation rules keep that distinction visible.

521

AudioSet classes in the pretrained taxonomy

0

Valid production accuracy claims today

2

Independent modalities for ordinary auto-SOS

KNOWN LIMITATIONS

What SafeCity may miss or misread.

These are product constraints, not footnotes. Validation across people, languages, devices, and real environments is still required.

01

Played media may still resemble real distress.

02

Quiet coercion or medical events may produce no detectable audio or motion.

03

Phone position, cases, clothing, room noise, and device hardware change signal quality.

04

Mobile operating systems can stop background work after force-quit, low power, or vendor restrictions.

05

A model-load failure disables pretrained audio inference and leaves reduced fallback behavior.

06

Thresholds are pilot defaults and have not been validated on a representative field dataset.

07

Keyword recognition varies by language, accent, volume, distance, and background sound.

08

Routine changes, travel, shift work, or GPS drift can look unusual to an adaptive baseline.

WHERE DATA GOES

A data path you can actually read.

Core inference stays on-device. Map and messaging features invoke outside providers only for the action they perform.

Audio & motion inferenceYour phone

Volatile windows; no SafeCity cloud inference request.

LOCAL
Incident metadata & evidenceYour phone

SQLCipher metadata and AES-GCM files in app-private storage.

ENCRYPTED
Nearby place lookupOverpass endpoint

Exact current coordinates when Safety Navigator opens.

EXTERNAL
Selected walking routeOpenStreetMap routing

Exact origin and destination when a route is requested.

EXTERNAL
Viewed map tilesCARTO

Viewed area and ordinary network metadata.

EXTERNAL
Optional community riskSafeCity aggregation

Approximate 500 m cell, hourly bucket, category, rotating token.

OPT-IN

PLATFORM REALITY

Background protection is not the same everywhere.

Mobile platforms control what happens after an app leaves the screen. SafeCity reports degraded coverage because hiding that difference would be a safety bug.

ANDROID

Native foreground-service handoff

Background rules can continue keyword, conditioned-audio, fall, and violent-motion checks, subject to OS and vendor restrictions.

iOS · CURRENT PROTOTYPE

No equivalent continuous background monitoring

The React audio and motion loop stops when the current iOS app is no longer active. This is a known platform gap.

YOUR INFORMATION

Control should be a screen, not a slogan.

See the choices built into local storage, retention, correction, erasure, and consent withdrawal.