Privacy Policy

Last updated: 3 August 2026

Safeinest helps parents and carers keep children a little safer online. This policy explains, in plain English, what personal information we collect, why we collect it, how we protect it, and the choices you have. It applies to our two iPhone apps (the Parent app and the Kids app) and our marketing website.

Our starting principle is simple: collect as little as possible. Where we can use a nickname instead of a name, or an age instead of a birthday, we do. Where Apple stops third-party apps from seeing something (like the contents of your child's messages), we don't try to work around it — and we won't pretend we can.

A note on the honest limits of iPhone: Safeinest uses Apple's Screen Time (Family Controls) to apply the rules a parent sets. This is cooperative — it enforces and reports, but it is not absolute, and Screen Time can be switched off in iOS Settings. A Screen Time passcode set by the parent is what makes restrictions stick.

Who we are (data controller and contact)

Safeinest is the 'data controller' for the personal information described in this policy. That means we decide what is collected and why, and we are responsible for looking after it.

Safeinest is operated by JETMEAWAY LTD, registered in England and Wales. If you need our company number, registered address or ICO registration number — for example to make a data-protection request — email us and we will give them to you.

For any privacy question, or to make a request about your data, contact us at hello@safeinest.com.

If we appoint a Data Protection Officer or a UK GDPR representative, we will name them here.

What data we collect

Guardian (parent) email — to create your account, sign you in, and send important service messages about your account or the app.

Child alias — a nickname you choose, not the child's legal name.

Child age — the age you choose (1 to 17), not a date of birth. We store the age only, never the birthday.

Device pairing identifiers — the codes and IDs that link a parent account to a specific child device, so the rules you set reach the right phone.

Basic device status — operational signals such as whether Screen Time permission is switched on, whether the device is online, and when rules were last applied. This tells you the app is working; it is not the content of anything.

Family message text — the messages you and your child send each other inside Safeinest, encrypted at rest. We keep the most recent messages in a conversation, and nothing at all from any other app.

Location — only when you switch Live location on for a specific child. Their phone sends its position while that setting is on, and we keep the most recent fix, encrypted, with the time it was taken. If you also switch on the 24-hour trail for that child, we keep up to one day of those positions so you can see the journey between places; anything older is deleted automatically. Switching either setting off stops the sharing and deletes what was stored.

Safe zones — the places you choose (a label, a centre point and a radius) and whether the child's phone is currently inside or outside each one, so we can tell you when they arrive or leave.

Voice-call set-up data — the technical details needed to connect a call between the two phones. Calls are never recorded and never pass through us; the set-up records are deleted after about a day.

Redacted safety-alert snippets — this applies only to a possible future Android feature. Nothing produces these today on any platform, and on iPhone nothing ever can. If it ships, we would keep only a short, masked preview, never the full message or conversation.

Push notification token — so we can deliver alerts and reminders to your phone.

Minimal technical logs — limited records we need to keep the service secure, diagnose faults, and prevent abuse.

Crash reports — when something in the app goes wrong, we collect the technical details of the fault (what broke, the app version, the device model) together with the internal ID numbers needed to trace it. Nobody in a family is named in one. See 'Third parties and processors' below.

What we do NOT collect

We do not read messages on iPhone. Not iMessage, not WhatsApp, not any other app. Apple does not allow third-party apps to do this, and we do not attempt it. Message monitoring is only possible on Android and is a future feature, not something Safeinest does on iPhone today.

We do not collect browsing history.

We do not collect the child's legal name or date of birth — an alias and an age only.

We do not read your contacts, photos, or camera roll. We do not read messages, browsing or app activity in any other app on the phone, and we do not collect how long each app was used — Apple keeps those figures on the child's own device.

We do not build a long-term picture of where a child has been. We collect location only while you have Live location switched on for a specific child, and by default we keep just the single most recent position. A trail of the last 24 hours is kept only if you switch that on as well, and it deletes itself as it ages — see 'What data we collect' above.

We do not record voice calls.

We do not build advertising profiles, and we do not sell your data or your child's data to anyone. Ever.

Our lawful bases (UK GDPR)

Under the UK GDPR we must have a lawful basis for each use of personal data. We rely on:

Contract — to provide the app to you, the guardian, once you create an account and pair a device.

Legitimate interests — to keep the service secure, reliable, and free from abuse. We balance this against everyone's privacy, and we give the child's privacy particular weight.

Consent — for anything genuinely optional (for example, certain notifications). Where we rely on consent, you can withdraw it at any time.

Legal obligation — where the law requires us to keep or disclose certain information.

Because a child's data is involved, we take extra care with these choices and keep them under review.

The Children's Code (Age Appropriate Design Code)

Safeinest is designed around the ICO's Age Appropriate Design Code, also called the Children's Code, and the wider UK GDPR duty to protect children's data.

In practice this means: data minimisation is the default; we use an age instead of a date of birth and an alias instead of a name; privacy-preserving settings are on by default, so live location is off until you switch it on for a child; the Kids app tells your child plainly what is happening rather than hiding it; and we do not profile children or use 'nudge' techniques to push them (or you) into sharing more.

We do not use children's data for marketing, advertising, or any purpose beyond keeping the family-safety features working.

How we use your data

To pair a parent account with a child device and deliver the rules you set — app-category allow/block, bedtime and school windows, timed blocks, focus presets, block-now, approved extra time, and the 'lock app removal' intent.

To carry family messages, voice calls and SOS alerts between you and your child.

To show you your child's latest location, to tell you when they arrive at or leave a safe zone you have drawn, and — if you switch the 24-hour trail on — to show you the journey between those places. Only while you have Live location switched on for that child.

To send you alerts and reminders — for example that a phone has disconnected, that Screen Time has been switched off, that fewer apps are covered than before, or that a phone has not been heard from for two days.

To keep accounts secure and prevent misuse.

To provide support when you contact us.

To fix faults and improve the reliability of the service.

We do not use your data — or your child's — for advertising or profiling.

Encryption at rest and security

We protect data in transit using HTTPS/TLS, and we encrypt personal data at rest.

We limit who can access data to those who need it, use access controls, and keep technical logs to spot and respond to problems.

We honestly can't promise that any online service is perfectly secure. What we can promise is that we minimise what we hold in the first place, protect what we do hold, and tell you promptly if a breach ever puts your data at risk (and notify the ICO where the law requires).

How long we keep data, and deletion

We keep account data (such as your email, the child alias, age, and pairing links) only while your account is active.

When you remove a child or close your account, we delete the associated personal data — their rules, family messages and stored location — at that point, except where we must keep a limited record to meet a legal obligation.

Live location is a single stored position that is overwritten each time a new one arrives, and is cleared when you switch the setting off. The optional 24-hour trail holds at most one day of positions: older ones are deleted automatically, and switching the trail off — or switching Live location off — deletes the whole trail immediately. Voice-call set-up records are deleted after about a day. Crash reports are kept for 90 days.

Technical logs are kept for a short period for security and troubleshooting, then deleted.

You can ask us to delete your data sooner — see 'Your rights' below.

Children's rights and the parent's role

Safeinest is set up and controlled by a parent or carer, who acts on the child's behalf and makes the settings decisions.

Children have their own data protection rights too. We keep the child's footprint deliberately small, and the Kids app shows plain, honest messages — for example, when a parent has asked that apps not be removed, the child sees a 'please ask first' note rather than a silent block.

We encourage parents to talk with their child about what Safeinest does, in an age-appropriate way. If a child (or a parent on their behalf) wants to know what data relates to them or wants it deleted, contact us and we will help.

Your data-subject rights

Under UK GDPR you have the right to: access your data; correct it if it's wrong; have it erased; restrict or object to how we use it; ask for a copy to reuse elsewhere (portability); and withdraw any consent you gave.

To exercise any of these, email hello@safeinest.com. We may need to confirm your identity so we don't hand data to the wrong person.

We aim to respond within one month. There's normally no charge. If a request is exceptionally complex, we'll tell you and keep you updated.

Third parties and processors

We use a small number of trusted suppliers ('processors') to run the service. These typically include:

Cloud hosting — to run our backend and store data securely.

Push notification delivery — Apple Push Notification service, and Firebase Cloud Messaging, to send alerts to your device.

Crash and error reporting — Sentry, hosted in the EU (Germany). When the apps or our backend hit a fault, we send the technical details of what went wrong: the error, the stack trace, the app version and device model, and the internal ID numbers of the account, child record or device involved. We strip out anything that could name a family before it is sent — no email addresses, no sign-in details, no message text, no location, no pairing codes. Crash reports are kept for 90 days and then deleted automatically.

Any processor is bound by a contract to protect your data, use it only on our instructions, and keep it secure.

We do not sell your data, and we do not share it with third parties for their own marketing.

International transfers

We aim to keep data within the UK or the European Economic Area where we can.

Some suppliers (for example, push-notification infrastructure) may process data outside the UK. Where that happens, we make sure appropriate safeguards are in place — such as a UK 'adequacy' decision, the UK International Data Transfer Agreement, or Standard Contractual Clauses with the UK Addendum.

Our crash reporting (Sentry) is set to store data in the European Economic Area, in Germany, which is covered by a UK adequacy decision.

You can ask us for more detail on where your data goes and how it's protected.

Cookies and the website

The Safeinest apps do not use advertising or tracking cookies.

Our marketing website is kept deliberately minimal. It uses only essential cookies needed to make the site work; any non-essential cookies (if we ever add them) will ask for your consent first, and you can decline.

We do not use cookies to build advertising profiles.

Changes to this policy

We may update this policy as the product evolves or the law changes.

When we do, we'll change the 'Last updated' date at the top. If a change is significant, we'll take reasonable steps to tell you — for example, an in-app notice or an email — before it takes effect.

How to complain (the ICO)

If you're unhappy about how we've handled your data, please contact us first at hello@safeinest.com so we can try to put it right.

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO).

ICO website: ico.org.uk. Helpline: 0303 123 1113. Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.