Skip to main content

Privacy Policy

Last updated: July 20, 2026

1. Controller

The controller for SafelyShare account and service data is:

  • [Counsel review required: legal entity name]
  • [Counsel review required: registered business address]
  • Privacy: [Counsel review required: privacy email]
  • Telephone: [Counsel review required: telephone number]

2. Safe files and keys

Selected safe files are encrypted with AES-256-GCM on the sender's device and transferred over a local connection to the recipient's device. The SafelyShare application server does not receive or store those files. It stores account and safe metadata, the recipient public key, and a wrapped safe key so the timelock can release it when due. The recipient private key remains encrypted in device secure storage.

3. Data we process

  • Account identity, verified email state, password hash, preferences, roles, and account history.
  • Device identifiers, push tokens, heartbeat times, sessions, IP/request data, and security logs.
  • Safe metadata, timelock settings, extension events, recipients, public keys, and wrapped keys—but not safe-file contents.
  • Plan, trial eligibility, billing source, product, status, renewal and grace dates, provider customer/transaction/subscription identifiers, refunds, disputes, and audited support overrides. SafelyShare does not receive full card details from Mollie, Apple, or Google.
  • Family membership, roles, invitation email addresses, hashed invitation tokens, acceptance/expiry events, and management actions.
  • Support correspondence and billing/service notifications.

4. Why we process it

  • Contract: authenticate users; operate safes, timelocks, subscriptions, Families, trials, grace, support, and required service messages.
  • Legal obligation: accounting, tax records, lawful requests, and consumer-rights administration.
  • Legitimate interests: secure the service, prevent fraud and duplicate purchase binding, troubleshoot faults, and keep minimal evidence of administrative actions. These interests are balanced against user rights.
  • Consent: only where specifically requested, such as optional marketing or device permissions that legally require it; consent can be withdrawn.

5. Families and invitations

Family members see each other's display names and roles. Owners also see member email addresses and pending invitations. Family membership never exposes safes, files, keys, recipients, or activity. Invitation addresses come from an owner; the first invitation message identifies that source, provides this notice, and supports decline. Pending invitation tokens expire after seven days and are irreversibly invalidated when used, revoked, resent, or expired. The expired invitation record is deleted 30 days after expiry.

6. Payments and service providers

Mollie processes website payments as an independent controller under its own privacy statement. Apple and Google independently process store accounts and payment methods; SafelyShare receives signed transaction, subscription, renewal, refund, and status data needed to provide access. SafelyShare shares only the identifiers and transaction context needed for payment, verification, support, fraud prevention, and legal compliance.

  • Hosting/database: [Counsel review required: hosting vendor and region]
  • Email delivery: [Counsel review required: email vendor and region]
  • Support: [Counsel review required: support vendor and region]
  • Payments and stores: Mollie, Apple App Store, and Google Play
  • Push delivery: Apple Push Notification service and Firebase Cloud Messaging
  • Language suggestion: country.is receives the browser IP once per tab session when no language preference is stored and returns a country code; SafelyShare does not retain it.

7. International transfers

Some providers may process data outside the European Economic Area. The applicable countries, adequacy decisions, standard contractual clauses, and means to obtain safeguards must be confirmed before launch: [Counsel review required: international-transfer safeguards].

8. Automated entitlement decisions

The entitlement engine uses verified provider events, paid-through dates, manual cancellation, payment failure, refund/revocation, Family membership, and time to activate, continue, grace, restore, or end Pro. Failed automatic renewal keeps Pro for one calendar month; manual cancellation and refunds do not. This is contract administration, not advertising profiling. Contact support if a provider record or result is wrong; an audited manual override may be applied.

9. Device-only recovery

When Pro ends, the mobile app may store automatic-extension choices in an encrypted device-local file protected by an account/device key. SafelyShare cannot read or recover this file. The app tries to restore it when Pro returns on the same installation and device. After reinstalling, clearing app data, or changing devices, the app can no longer access or decrypt the recovery file.

10. Retention and deletion

  • Active account, Family, subscription, and safe metadata is kept while needed to provide the service. Account deletion removes active account records and owned safes, subject to the exceptions below.
  • Payment and tax records, including the provider transaction identifiers required for accounting and purchase ownership, are kept through ten years after the end of the calendar year in which the transaction occurred.
  • Expired invitation records are deleted 30 days after expiry.
  • Family management audit records are kept for two years after the recorded action.
  • Operational and security event payloads are kept for 30 days.
  • Backups are kept for 30 days.
  • Support and withdrawal-case personal data is kept for two years after the case is closed.

Limited records may remain where required by law or necessary for legal claims. Deleted data may remain in protected backups until normal expiry and is not restored to active systems except for disaster recovery.

11. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing and complain to the Autoriteit Persoonsgegevens or your local authority. Contact [Counsel review required: privacy email]. Mandatory financial records and data needed for legal claims may not be immediately erasable.

12. Children, security, and changes

SafelyShare is for users aged 16 or older. Every subscription purchaser and Family owner must be 18 or older. SafelyShare uses encryption, TLS, password hashing, access controls, signed provider data, and least-privilege administration, but no system is risk-free. Material privacy changes are notified when required; the updated date is shown above.