Privacy Policy
Effective 14 September 2026 · Applies to the SafeSupply mobile app and safesupply.site
The short version: the free tier collects no personal information at all. The scanner never uploads photos. Location is city-level only. Buddy sessions self-delete within 24 hours. Your journal is encrypted so we can't read it. We never sell data, and there are no advertising SDKs in the app.
1. Who we are
SafeSupply is operated by Jason Decaux trading as Indrevo (ABN 21 979 134 918), based in New South Wales, Australia ("we", "us"). We are the data controller for the personal information described in this policy. Contact: admin@safesupply.site.
2. What we collect — and what we deliberately don't
Free tier (anonymous)
- No account is required. We do not collect your name, email address, phone number or any government identifier.
- Region — you select or allow the app to determine your city-level region so alerts are relevant. We never collect or store GPS coordinates.
- Anonymous device token — a random push-notification token (Firebase Cloud Messaging) so alerts can reach your device. It is not linked to your identity.
Premium tier
- Account email — used for sign-in and account recovery only.
- Subscription status — purchases are processed entirely by Google Play or the Apple App Store. We never see or store your card details; we receive only an anonymised entitlement token via RevenueCat.
Feature-specific data
- Pill scanner: photos are processed exclusively on your device by an embedded recognition model. Photos are never transmitted to our servers or any third party, and we cannot access them.
- Buddy timer: the session details you enter (schedule, chosen contact, optional note) are stored only for the life of the session and are automatically and permanently deleted within 24 hours.
- Distress alerts (SOS): this is the only feature that ever uses precise location, and only at the moment you trigger it. When you hold the SOS button, your GPS position, optional note and live location updates are delivered to the crew contacts you selected — no one else. Delivery passes through our push infrastructure encrypted in transit; if your device has no data connection, the app instead sends the SOS by SMS directly from your phone to your crew — device to device, never touching our servers. SOS data is never used for any other purpose, and everything we relay (locations, notes, delivery records) is permanently deleted within 24 hours of the session ending.
- Journal: entries are encrypted at rest using keys derived from your credentials. We do not hold the keys and cannot decrypt your entries.
- Community reports: if you submit a report, all metadata (device identifiers, timestamps beyond the date, location beyond region) is stripped before storage.
Diagnostics
- Crash reports (Sentry) — technical crash data such as device model, OS version and stack traces, used solely to fix defects. Crash reports are scrubbed of user content.
- Aggregate usage counts — e.g. how many devices in a region received an alert. Aggregated, never per-person profiles.
This website
- The site sets no tracking cookies and runs no analytics scripts.
- If you submit the support or account-deletion form, we receive what you type plus the submission time, delivered via our hosting provider (Netlify) to our support inbox.
3. Why we process it (legal bases)
| Purpose | Data | Basis (GDPR Art. 6) |
|---|---|---|
| Delivering regional alerts | Region, push token | Performance of contract / legitimate interests |
| Premium account & billing | Email, entitlement token | Performance of contract |
| Buddy timer alerts | Session data (ephemeral) | Performance of contract |
| Fixing crashes | Diagnostics | Legitimate interests |
| Answering support requests | What you send us | Legitimate interests / consent |
| Legal compliance | Records as required | Legal obligation |
In Australia we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). In California, the categories above are the only categories collected; we do not "sell" or "share" personal information as defined by the CCPA/CPRA.
4. Retention
| Data | Kept for |
|---|---|
| Buddy-timer sessions | Maximum 24 hours, then permanently deleted |
| Push token | Until the app is uninstalled or token rotates |
| Premium account | Until you delete your account |
| Journal entries | Until you delete them or your account |
| Crash reports | 90 days |
| Support correspondence | 24 months |
5. Who we share with (sub-processors)
- Google Firebase (authentication, database, push notifications) — Google LLC.
- RevenueCat (subscription entitlement management).
- Sentry (crash reporting).
- Netlify (website hosting and form delivery).
- Google Play / Apple App Store (payments — governed by their own policies).
These providers process data on our instructions under their standard data-processing terms. Some are located outside Australia and the EEA (primarily the United States); transfers rely on Standard Contractual Clauses or equivalent safeguards. We never share data with advertisers or data brokers, and we do not sell personal information — ever.
We may disclose information if required by law. Because of the app's data-minimisation design, in most cases there is very little we could disclose: no scanner photos, no GPS trails, no readable journals, no session history older than 24 hours.
6. Your rights
Depending on where you live, you have rights to access, correct, export and delete your personal information, to object to or restrict processing, and to withdraw consent. You can exercise them:
- In the app: Settings → Privacy (export, correction, journal wipe, account deletion).
- On this site: safesupply.site/delete-account.
- By email: admin@safesupply.site.
We respond within 30 days. If you're unsatisfied, you can complain to your local authority — in Australia, the Office of the Australian Information Commissioner (OAIC); in the EU/UK, your data protection authority.
7. Security & breach notification
Data in transit is protected with TLS; data at rest is encrypted. Journal encryption keys are derived from your credentials and are not held by us. Access to production systems is restricted and logged. If a data breach occurs that is likely to result in serious harm, we will notify affected users and the relevant authority in line with the Australian Notifiable Data Breaches scheme and, where applicable, the GDPR's 72-hour requirement.
8. Age
SafeSupply is rated 17+ and is not directed at anyone under 17. We do not knowingly collect personal information from anyone under 17; if we learn we have, we will delete it.
9. Changes
We'll post any changes to this policy here and update the effective date. Material changes will be flagged in the app before they take effect.
Questions? admin@safesupply.site