SafeCircle
Privacy Policy
Last updated August 23, 2026
SafeCircle helps authorized household members share deliberate, time-bounded check-ins. Tribal Ventures LLC is the controller; contact support@tribalventuresgroup.com.
Information processed
- Firebase Authentication identifiers and the explicit Core identity link;
- Core user and household membership identifiers used for authorization;
- check-in status, category, expiry, lifecycle timestamps, subject, and record version;
- acknowledgement identity and timestamp;
- notification consent, quiet hours, time zone, and preference version;
- identity-linked APNs or FCM destination tokens and bounded device metadata; and
- App Check results, request identifiers, rate-limit state, sanitized audits, and operational diagnostics needed for security and reliability.
SafeCircle does not collect or track location. It does not process health records or perform emergency monitoring, automatic emergency detection, escalation, dispatch, or contact with 911, police, or EMS. It does not use these data for advertising, sale, or cross-app tracking.
Use and disclosure
Data is used to authenticate users, enforce household isolation and revocation, provide check-in functionality, apply notification choices, deliver optional generic notifications, prevent abuse, diagnose failures, and protect the service. Authorized household members receive only service-mediated data allowed by current membership. Firebase/Google and Apple process limited information as infrastructure and notification-delivery providers. SafeCircle does not disclose data to advertisers or data brokers.
Notification privacy
Notification tokens are linked server-side to the Core user and are not anonymous. Lock-screen payloads are generic and contain only opaque routing data. Authoritative content is retrieved after authentication, App Check, explicit identity linking, and current household authorization. Notification delivery is optional and not guaranteed.
Security
The client cannot access authoritative Firestore records directly. Requests require Firebase Authentication and App Check. The service resolves identity and household membership server-side, applies revocation and rate limits, and avoids logging credentials, tokens, private request or response bodies, notification text, or raw provider errors.
Retention
- Terminal check-ins, acknowledgements, and sanitized security audits: up to 90 days.
- Terminal notification outbox records and operational diagnostics: up to 30 days.
- Invalid or superseded notification destinations: deleted within seven days.
- Preferences, identity links, and memberships: while active, then deleted or de-identified within 30 days of an accepted deletion request.
- Backups: the applicable period plus no more than 30 days for rotation.
Exceptional security holds must be documented, access-restricted, and time-bounded.
Choices, access, and deletion
Members can disable notification consent and quiet hours without deleting membership. A verified deletion request may cover SafeCircle records, membership, notification preferences and destinations, and the shared Core identity/account. Revocation immediately blocks future household access while the request is processed. See account and data deletion.
Children and changes
No child-directed use or guardian/dependent model is approved for V1. Material policy changes require updated notice and, where appropriate, renewed consent.
