Legal
Privacy Policy
SafeOutside is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact safeguarding@safeoutside.co.uk and we will remove it.
What we collect
To provide the SafeOutside service we collect and store the following information:
- Account data — username, optional nickname, email address, and an encrypted (hashed) password
- Location data — your GPS coordinates only at the moment you check in or send a report, and optionally a what3words address. We do not collect your location in the background or while the app is closed.
- Activity data — session names and times, check-in statuses and timestamps, and the area reports and messages you send to your network
- Device data — a push-notification token used to deliver safety alerts to your device, and (optionally) your device battery level at check-in so your network can see if your phone is running low. We also record which version of the app you are running, whether it is the iOS or Android app, and when you last opened it, so we know who is on an out-of-date version and can support you properly.
- Preferences — your notification level for each network, any temporary pause, and whether you have said you are taking part in a particular session
- Club membership (if you join a club) — which club you belong to. So that they can administer the membership, your club’s organisers can see your username, nickname, email address, join date, which plan you are on, and which version of the app you last used and when. They can also send you a password-reset email. They cannot see your password.
Organisers have no special access to your location or check-in history. However, an organiser who is a member of the same network as you sees your live status and check-in locations exactly as any other member of that network does — that comes from sharing a network, not from running the club. - Subscription data — the plan you are on and its renewal date. If you subscribe in the app, we store the subscription status reported by Apple or Google. If a club subscribes on the web, we store Stripe’s customer and subscription references for that club. We never see or store your card details.
- Emergency contacts (Pro) — if you add emergency contacts, we store the name and phone number you provide for each (maximum three). You confirm you have that person's permission. Phone numbers are encrypted at rest and are used only to send an SOS text if you trigger a danger alert. SOS text alerts are subject to fair-use limits (a monthly cap and a short cooldown between repeat alerts) and are a supplementary notification only — never a substitute for the emergency services. You can remove a contact at any time; a contact can also ask to be removed by emailing support@safeoutside.co.uk.
How we use it
Your data is used solely to provide the SafeOutside service:
- Your location, status, reports and messages are shown to the members of your network so they know you are safe during an active session
- Check-in history is retained to provide activity logs and, in serious incidents, to help you or your contacts provide information to emergency services
- Your email address is used for account management, safety notifications, and password resets
- Push tokens are used only to deliver safety alerts relating to your own network
- Emergency-contact phone numbers (Pro) are used only to send an SOS text message, with your location, to those contacts when you trigger a danger alert
- Your notification preferences decide which routine updates you receive. They never suppress an emergency alert
- App version and last-opened date are used to tell whether you need an update and to diagnose problems you report — never to build a profile of you
- Subscription references are used to confirm what your account is entitled to, and to process renewals and cancellations
We do not sell your data, and we do not use it for advertising, analytics profiling, or any third-party commercial purpose.
Service providers
We use a small number of trusted third parties to operate the service. They process data only on our behalf and only as needed:
- what3words — when a what3words address is used, your coordinates are sent to what3words to convert them into a 3-word address
- Brevo — delivers our emails (verification, password reset, and safety report/alert emails) and, for Pro users, sends SOS text messages (SMS) to your emergency contacts
- Expo / Google Firebase Cloud Messaging — deliver push notifications to your device
- Apple and Google — process in-app subscription purchases. Your payment is handled entirely by the app store; we receive only the resulting subscription status
- RevenueCat — reconciles those app-store subscriptions and tells our server which plan an account is on. It receives your SafeOutside account reference, not your name or email
- Stripe — processes club subscription payments made on our website. Card details are entered on Stripe’s own hosted checkout and never reach our servers; we store only Stripe’s references for the club and the billing contact’s email
Data retention and deletion
Your account data is retained for as long as your account is active. You can permanently delete your account and personal data at any time:
- In the app: open Account → Delete Account and confirm with your password
- On the web: see safeoutside.co.uk/delete-account
- By email: contact support@safeoutside.co.uk from your registered email address
Deletion removes your profile, check-ins, reports, messages, sessions you created, emergency contacts, and push token. If you created a group that still has other members, ownership is passed to another member so their data is not lost. We may retain limited anonymised operational logs where required for security or legal reasons; these do not identify you.
Security
Passwords are hashed using bcrypt and never stored in plain text. Emergency-contact phone numbers are encrypted at rest (AES-256-GCM) and are only decrypted at the moment an SOS text is sent. All data in transit is encrypted via HTTPS/WSS. Access to the server and database is restricted and authenticated.
Your rights
You have the right to access, correct, or delete your personal data at any time. Use the in-app deletion option above, or contact support@safeoutside.co.uk.
Last updated August 2026. This policy may be updated from time to time.