Privacy Policy
SafeLeo handles where you are and who you trust. This page explains exactly what we collect, who can see it, and what you can make us do about it — in plain language, without the parts that only exist to protect us.
Effective
1. Who we are
SafeLeo is a personal safety app operating in Kenya. For the purposes of the Data Protection Act, 2019, SafeLeo is the data controller for the personal data described here — we decide what is collected and why.
You can reach us at hello@safeleo.app about anything on this page, including requests to see, correct or delete your data.
2. The short version
- Your location is visible only to people you added to your Circle. There is no public map and no browsing of other users.
- We keep one current location per person, not a history of everywhere you have been.
- Safety alerts you post are visible to people nearby. You choose whether the location on them is exact or approximate.
- We do not sell your data, and we do not run advertising.
- You can delete your account from the app. Deleting it removes your location, your Circle links and your account record.
3. What we collect
Account
- Email address
- Required. It is how you sign in — we send a six-digit code rather than asking you to keep a password.
- Name and profile picture
- Optional. Only used so people in your Circle recognise you rather than a row of email addresses.
Location
- Your current location
- A single point with an accuracy figure, updated while you are sharing and overwritten each time. We do not build a location history from it.
- Locations attached to alerts
- The coordinates of a safety report. You choose exact or approximate when you post; approximate is deliberately coarser so a report cannot pinpoint your doorstep.
- Locations attached to an SOS
- Coordinates, accuracy and a place label at the moment you press. An SOS never waits for a GPS fix — if there is no location, the alarm still goes out without one.
- Places you watch
- Areas you ask to be alerted about, with the radius you chose. These are usually meaningful places — a home, a school — so we treat them as sensitively as live location.
Your Circle
- Who follows whom
- The links between you and the people you added, along with the invite codes used to create them and pending requests in either direction.
- What each person may see
- Separate switches for live location and last known location, held per link rather than globally, so you can share differently with different people.
Content you create
- Alerts
- Category, type, severity, an optional description and optional photos, plus the area name derived from the coordinates.
- Confirmations
- When you confirm someone else’s alert, we record that you did — it is how a real report rises above a mistaken one.
- Feedback and course activity
- Anything you send us, and which safety course chapters and quizzes you have completed.
Technical
- Device and push token
- An identifier from Apple or Google that lets us deliver notifications, plus the platform and when it was last used. It cannot be used to read anything on your device.
- IP address
- Recorded when you request a sign-in code and when a session is created. Used to rate-limit sign-in attempts and to work out which country you are in so we show you local content. We do not use it to track you between sessions.
- Sign-in codes and sessions
- Sign-in codes and session tokens are stored hashed, never in a form we could read back or reuse.
4. Why we use it
Under the Data Protection Act we have to have a lawful basis for each use. Ours are:
- To perform our contract with you — showing your Circle where you are, delivering alerts, sending an SOS, keeping you signed in. Without these the app does not function.
- Your consent — location sharing itself. You grant it in the app and in your device settings, and you can withdraw it in either place at any time.
- Our legitimate interests — keeping the service secure and working: rate-limiting sign-ins, detecting abuse, fixing crashes. We use the least data that achieves this.
- Legal obligation — where we are required to retain or disclose something by Kenyan law.
We do not use your data for advertising, we do not sell it, and we do not share it with data brokers.
5. Who can see your location
This is the part most people actually want to know, so it is explicit.
- Only people in your Circle, and only those you have granted the relevant permission. Each link carries its own switches for live and last-known location.
- Nobody else using SafeLeo. There is no directory, no public map, and no way to look up another person.
- Not us, casually. Our team does not browse user locations. Access to production data is limited to what is needed to operate and debug the service.
- Alerts are different by design. A safety report is shown to people near where it happened — that is its purpose. It carries the location you chose, at the precision you chose, and it is not labelled with your name.
Withdrawing a permission stops future sharing. It does not retract a location someone has already seen, in the same way a message cannot be unread.
6. Who else touches your data
We use other companies to run the service. They process data on our instructions and may not use it for their own purposes.
- Google Cloud
- Hosting and the database, in the Johannesburg region.
- Firebase Cloud Messaging (Google)
- Delivers push notifications and alerts to your device.
- Cloudflare
- Serves this website, protects and routes traffic to our API, and stores photos attached to alerts.
- Brevo
- Sends sign-in codes and service email.
- Google Maps Platform
- Place search and the names of areas shown in the app.
- Google Gemini
- Produces the written summary of an area’s safety from alerts already in the system. It receives the alert content, not your identity.
- Sentry
- Reports crashes and errors so we can fix them.
We may also disclose data where we are legally required to, or where it is necessary to protect someone’s life or safety.
7. Where it is stored
Our servers and database are in Johannesburg, South Africa — the closest region to Kenya, chosen so the app responds quickly here. Some of the processors above operate elsewhere.
This means your data is transferred outside Kenya. Under sections 48 to 50 of the Data Protection Act we do that on the basis of appropriate safeguards: contractual data-protection terms with each processor, encryption in transit, and limits on what each one receives. You may ask us for details of these safeguards.
8. How long we keep it
- Your current location
- One record per person, overwritten each update. Deleted with your account.
- Alerts
- Alerts expire on their own — a report about a temporary hazard stops being shown once it stops being true.
- Sign-in codes
- Valid for ten minutes, then unusable.
- Sessions
- Expire on their own, and immediately when you sign out.
- Account data
- Kept while your account exists. When you delete it, your location, Circle links, devices and account record go with it.
We may retain limited records for longer where the law requires it, or where they are needed to resolve a dispute.
9. Your rights
Under the Data Protection Act, 2019 you have the right to:
- Be told how your data is being used — this page.
- Get a copy of the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data deleted, subject to any legal obligation to keep it.
- Object to processing, and to withdraw consent for location sharing.
- Receive your data in a portable form.
Email hello@safeleo.app and we will respond within the statutory timeframe. We may ask you to confirm your identity first — we are not going to hand someone else your location history because they asked nicely.
If you are not satisfied with our response you may complain to the Office of the Data Protection Commissioner.
10. Security
- Traffic between your device and our servers is encrypted.
- Sign-in codes and session tokens are stored hashed, so a copy of our database would not let anyone sign in as you.
- Our servers accept no direct inbound connections from the internet — all traffic arrives through a protected tunnel.
- Access to production data is restricted and logged.
No system is perfectly secure. If a breach affects your rights and freedoms we will notify you and the Data Protection Commissioner as the Act requires.
11. Children
SafeLeo is not intended for children under 18 signing up on their own. A parent or guardian may add a child to their Circle, and by doing so confirms they are entitled to consent on that child’s behalf. If you believe a child has created an account without that consent, contact us and we will remove it.
12. Changes
We will update this page when what we do changes. The effective date at the top always reflects the current version. If a change materially affects how your data is handled, we will tell you in the app or by email rather than quietly editing this page.
13. Contact us
Questions, requests, or complaints: hello@safeleo.app. We would much rather hear from you directly than have you find out something here surprised you.