Privacy Policy

Last Updated: September 2, 2026

1. Introduction

Welcome to Safety N3T by Mikolonia Mobile ("we," "us," or "our"). We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and services.

By using Safety N3T, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our app.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Display name, email address, username, and optional profile photo
  • Location Data: Your verified residential address(es) and real-time geographic location when you enable location sharing
  • Communications: Messages, posts, comments, and media you share within the app
  • Payment Information: Billing details processed securely through our payment providers (see Section 5)
  • Profile Information: Optional bio, profession, interests, and contact preferences
  • Verification Data: Information used to verify your residence (location history patterns)

2.2 Information Collected Automatically

  • Device Information: Device type, operating system version, unique device identifiers, and app version
  • Usage Data: Features used, interactions, timestamps, and session duration
  • Location Data: GPS coordinates when location services are enabled (foreground and background with your permission)
  • Log Data: IP address, access times, and error logs for troubleshooting
  • Push Notification Tokens: Device tokens for delivering notifications

2.3 Sensitive Data

We may collect the following sensitive data only with your explicit consent:

  • Precise Location: Real-time GPS location for safety features, community map, and residence verification
  • Biometric Data: Face ID or Touch ID authentication (processed locally on your device, never transmitted to our servers)
  • Voice Data: Voice messages and speech-to-text for accessibility features
  • Camera and Photos: Images and videos you choose to share

2.4 Profile Photos and Face Data

What face data we collect: If you choose to upload a profile photo, we collect the profile photo image and limited non-biometric safety signals derived from that image, such as whether a human face appears to be present, whether the image appears to match a public figure or celebrity, and whether the image may be similar to profile photos associated with previously banned accounts. We do not collect Face ID or Touch ID data, raw facial landmarks, face geometry, faceprints, biometric templates, or biometric identifiers.

How we use it: We use profile-photo face analysis only for account integrity and community safety: to help confirm that profile photos represent a real person, reduce impersonation of celebrities or public figures, detect attempts by banned users to re-register, and enforce our Terms of Service. We do not use face data for advertising, tracking, profiling, emotion recognition, identity verification against government IDs, or third-party AI training.

Third-party processing and storage: Profile photos may be sent to Google Cloud Vision for automated face and web/celebrity detection. Google processes the image as our service provider for this safety check. Profile photos are stored in Google Firebase Storage, and only high-level validation results and non-biometric safety records are stored in Google Firestore. We do not store the raw Google Cloud Vision response or raw face landmark data.

Consent (BIPA, Texas CUBI, Washington MHMDA): Profile-photo face analysis is an opt-in feature everywhere. It is OFF by default for every new account regardless of where you live. You must explicitly turn on the "Face validation" toggle in Privacy Settings → Data & consent before Safety N3T will send any image bytes to Google Cloud Vision or compute image fingerprints for ban-evasion checks. If the toggle is off, no profile-photo bytes leave your device, no image fingerprints are computed for you, and no comparison against banned-user photos takes place.

What we actually store, in plain terms: We do not store face templates, faceprints, biometric identifiers, or facial-landmark coordinates. On banned-user records, we store a small "perceptual hash" of each historical profile photo — a 1024-bit whole-image fingerprint that identifies same-or-near-duplicate images, not the underlying face. Perceptual hashes are used only to flag potential re-registrations by banned users for admin review; they are not shared with, sold to, or licensed to any third party for advertising, training, profiling, or identity verification.

Retention: For regular users, profile photos and related validation results are retained while the account is active and are deleted within 30 days after account deletion, subject to legal, security, or backup requirements described in Section 11. For users banned for safety or Terms violations, profile photos and related non-biometric safety records — including the perceptual hashes described above — are retained for up to 365 days under an automated Firestore TTL policy, then destroyed. Pending ban-evasion match candidates are also retired automatically after 365 days.

Revocation: Turning off the Face validation toggle at any time (a) immediately stops any future profile-photo bytes from being sent to Google Cloud Vision, (b) immediately stops any image-fingerprint comparison against banned-user photos, and (c) deletes your own pending ban-evasion match candidates from our database. Non-biometric account-integrity data (the boolean "profile photo validated" flag on your account) remains until account deletion.

3. How We Use Your Information

We use your information for the following purposes:

  • Core Services: Provide, maintain, and improve Safety N3T features
  • Community Connection: Connect you with verified neighbors in your community
  • Safety Features: Enable S.O.S. alerts, Inner Circle location sharing, and emergency notifications
  • Residence Verification: Verify your address through location pattern analysis
  • Communications: Send important alerts, notifications, and service updates
  • Payments: Process subscriptions and marketplace transactions
  • Security: Detect and prevent fraud, abuse, and unauthorized access
  • Improvement: Analyze usage patterns to improve app functionality (aggregated, non-identifying data only)

3.1 What We Do NOT Use Your Data For

  • We do NOT sell your personal data to advertisers or data brokers
  • We do NOT build behavioral profiles for targeted advertising
  • We do NOT track you across other apps or websites
  • We do NOT use algorithms designed for mass manipulation of opinions
  • We do NOT share your data with third-party AI systems for training purposes

4. Location Data

Location data is central to Safety N3T's functionality. Here's exactly how we use it:

4.1 Types of Location Access

  • Foreground Location: Used when the app is open for the community map, nearby alerts, and navigation
  • Background Location: Used only when you enable specific features:
    • Inner Circle location sharing (share your location with trusted contacts)
    • Residence verification (overnight location patterns to verify your address)
    • S.O.S. emergency alerts (send your location during emergencies)

4.2 Location Data Controls

  • You can disable background location at any time in Settings → Privacy → Location Sharing
  • You can enable "Defensive Mode" to become invisible to everyone except your Inner Circle
  • You can delete your location history at any time using the button in Settings → Privacy → Delete Location History

How live location sharing is enforced: Your live location is shared only with Inner Circle members who have also added you to their Inner Circle. This is enforced by Safety N3T's server-side access controls on the live_locations record for your account, not just by app UI. Administrators retain access for safety and moderation purposes. Location history is stored under a separate policy described in Section 4.3, but third-party access to your location history now follows the same live-location sharing list: only the Inner Circle members who can currently see your live location can read your location history, and administrators retain access for safety and moderation purposes.

Periodic sharing review: Every 90 days, Safety N3T prompts you in-app to review the Inner Circle members who can see your live location, so you can pause or remove anyone who no longer needs access.

4.3 Location Data Retention

Why we store location history on our servers: Location history is a core safety feature. If you go missing, your location history must be accessible to help locate you—if it were stored only on your device, that data would be lost along with you. Your Inner Circle and, in emergencies, authorities can access your location history to assist in your recovery.

Location history is retained on our servers for the duration of your account. You can delete it at any time from the Privacy settings. Upon account deletion, location history is deleted within 30 days.

Location Permission Note: Please select "While Using the App" when prompted for location access. Safety N3T does not require "Always Allow" location access for any of its features.

5. Third-Party Services

We use the following third-party services to operate Safety N3T. Each provider is contractually obligated to protect your data and use it only for the purposes we specify:

Service Provider Purpose Data Shared
Backend & Database Google Firebase (Firestore, Auth, Storage, Functions) User authentication, data storage, cloud functions Account data, messages, media, usage data
Maps Google Maps (Android/Web), Apple MapKit (iOS) Community map, location display, geocoding Location coordinates, map interactions
Payments Stripe Subscription and marketplace payments Payment card details (processed by Stripe, not stored by us)
Payments PayPal Alternative payment method PayPal account email (processed by PayPal)
Payments Apple Pay iOS payment method Tokenized payment data (processed by Apple)
Push Notifications Firebase Cloud Messaging (FCM), Apple Push Notification Service (APNs) Deliver alerts and notifications Device tokens, notification content
Video/Voice Calls Agora Real-time communication for calls Call metadata (calls are not recorded)
Text Recognition Google ML Kit (on-device) OCR for document scanning None (processed entirely on-device)
Profile Photo Safety Checks Google Cloud Vision Face presence detection and celebrity/public-figure impersonation checks for profile photos Profile photo image for automated safety analysis; raw responses and facial landmarks are not stored by Safety N3T
Email Resend Transactional emails (verification, receipts) Email address, email content
URL Safety Checks Google Web Risk Server-side lookups on user-submitted links to detect malware, phishing, and other unsafe URLs URLs submitted for classification (no account identifiers are attached to the lookup)
AI Inference — Generative Text Google Gemini (Generative Language API) On-demand generation of assistant responses in features that explicitly invoke AI User-submitted prompt text for that request only (no long-term account profile is sent)
AI Inference — Generative Text Anthropic (Claude) On-demand generation of assistant responses in features that explicitly invoke AI User-submitted prompt text for that request only
AI Inference — Generative Text and Vision OpenAI On-demand generation of assistant responses, and vision-based analysis of images the user submits to AI features User-submitted prompt text and image references for that request only
AI Inference — Search Augmentation Perplexity On-demand retrieval-augmented answers in features that explicitly invoke web-search AI User-submitted query text for that request only
AI Inference — Hosted Models Hugging Face Inference On-demand inference against hosted open-source models User-submitted prompt text for that request only
Subscription Management RevenueCat Managing in-app subscription state across App Store and Google Play Store purchase tokens, subscription status, anonymized account identifier
Payouts to Sellers and Service Providers Payoneer Sending payouts to marketplace sellers, service suppliers, and verified professionals Payee name, payout destination details required by Payoneer, and payout amount (payout method details are processed by Payoneer)
Video Embed Metadata YouTube Data API / oEmbed Enriching user-shared YouTube video links with title, thumbnail, and channel metadata YouTube video ID or URL submitted by the user (no account identifiers are attached to the lookup)
Video Embed Metadata Twitch Helix / OAuth Enriching user-shared Twitch links with stream/clip metadata; OAuth is used only when the user chooses to connect a Twitch account Twitch video/clip/channel identifier submitted by the user; for OAuth, the Twitch account identifier the user authorises

AI inference — inference only, not training: When you use a feature that explicitly invokes an AI provider listed above (Google Gemini, Anthropic, OpenAI, Perplexity, Hugging Face Inference), the text you submit for that request — and, for the OpenAI vision path, references to any image you submit to that feature — is transmitted to the named provider for inference only. This is consistent with the commitment in Section 3.1: we do not send your data to third-party AI systems to train their models, and we do not authorise the listed AI providers to use your submissions to train their models. Each AI request carries only the prompt for that request; we do not attach a long-term profile of your account or your community activity.

URL and video-ID enrichment lookups: When you submit a link, Safety N3T may look it up with Google Web Risk to check whether the URL is known to be unsafe. When you share a YouTube or Twitch link, Safety N3T may look up the corresponding video/clip identifier with the YouTube Data API/oEmbed endpoint or the Twitch Helix API to fetch public metadata (title, thumbnail, channel/stream information). These lookups send the URL or video identifier only; no account identifiers are attached to the lookup itself.

Third-Party Data Protection: All third-party providers listed above are required to provide the same or greater protection of your data as described in this Privacy Policy. We do not share your data with any third parties for advertising or marketing purposes.

6. End-to-End Encryption

Safety N3T uses end-to-end encryption (E2EE) for private communications:

6.1 What IS Encrypted (E2EE)

  • Private direct messages between users
  • Media shared in private conversations (photos, videos, voice messages)
  • Password-protected chat threads

For E2EE content, only you and your recipient can read the messages. We cannot access this content, even if legally compelled.

6.2 What is NOT End-to-End Encrypted

  • Public posts and comments in community feeds
  • Group chats (encrypted in transit, but accessible for moderation)
  • Profile information and public data
  • Marketplace listings

This content is encrypted in transit (TLS) and at rest, but may be accessed for content moderation or legal compliance.

7. App Tracking Transparency

We do NOT track you.

Safety N3T does not:

  • Track your activity across other companies' apps or websites
  • Use advertising identifiers (IDFA) for tracking
  • Share data with data brokers
  • Build profiles for targeted advertising

Therefore, Safety N3T does not request App Tracking Transparency permission because we have nothing to track.

8. Data Sharing

We do not sell your personal information. Ever.

We may share information only in these limited circumstances:

  • With Your Consent: When you explicitly choose to share (e.g., sharing location with Inner Circle)
  • Community Members: Your public profile information is visible to other users in your verified communities
  • Service Providers: Third parties listed in Section 5, solely to operate our services
  • Legal Requirements: When required by valid legal process (court order, subpoena). We will notify you unless legally prohibited
  • Safety: To prevent imminent harm to individuals or respond to emergency situations

9. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in Transit: All data transmitted between your device and our servers uses TLS 1.3
  • Encryption at Rest: Data stored on our servers is encrypted using AES-256
  • End-to-End Encryption: Private messages use RSA-2048 + AES-256 encryption
  • Secure Storage: Sensitive data on your device is stored in iOS Keychain / Android Keystore
  • Access Controls: Strict internal access controls and audit logging
  • Regular Audits: Periodic security assessments and penetration testing

While no system is 100% secure, we continuously work to protect your data using best practices.

10. Your Rights and Choices

You have the following rights regarding your personal data:

10.1 Access and Portability

  • View Your Data: Access your personal information in Settings → Privacy → My Data
  • Export Your Data: Download a copy of your data in a portable format

10.2 Correction and Deletion

  • Correct Data: Update inaccurate information in your profile settings
  • Delete Account: Request complete deletion in Settings → Account → Delete Account
  • Deletion Timeline: Upon request, we will delete your personal data within 30 days, except where retention is required by law

10.3 Consent Management

  • Location: Manage in Settings → Privacy → Location Sharing
  • Notifications: Manage in Settings → Notifications
  • Marketing: Opt-out of promotional communications in Settings → Notifications

10.4 How to Exercise Your Rights

You can exercise most rights directly in the app. For requests we cannot fulfill in-app, contact us at contact@mikoloniamobile.com. We will respond within 30 days.

11. Data Retention

We retain your data according to the following schedule:

  • Account Data: Retained while your account is active, deleted within 30 days of account deletion request
  • Messages: Retained until you delete them, or 30 days after account deletion
  • Location Data: Location history is retained on our servers for the duration of your account (this is a safety feature—see Section 4.3)
  • Profile Photos and Face Data: Retained while your account is active and deleted within 30 days after account deletion, except where retention is required for legal, security, fraud-prevention, safety, backup, or banned-user enforcement reasons described in Section 11.2
  • Transaction Records: Retained for 7 years as required by financial regulations
  • Security Logs: Retained for 90 days for fraud prevention
  • Backup Data: Deleted within 90 days of account deletion

Reconciliation of 30-day and 90-day windows: The 30-day retention window in this section and the deletion timeline in Section 10.2 apply to live production data. Encrypted disaster-recovery backups roll off on the 90-day schedule listed above; residual copies of your data can therefore persist in cold backups for up to 90 days after the live-data purge completes. Restored data from such a backup is re-purged before being returned to production.

11.1 Operational Diagnostic and Location Retention (Draft — pending counsel review)

The following server-side retention windows are enforced automatically by Firestore Time-to-Live (TTL) policies on an expires_at timestamp written on each record. When a record's expires_at passes, Firestore deletes it without further action from us or from you.

  • Diagnostic Logs (app-side troubleshooting events, location-pipeline traces): retained for 90 days from the time of the event. IP addresses are stripped from diagnostic payloads before they are written; only coarse debugging metadata is kept.
  • App-Exit Diagnostics (Android OS kill reasons captured on next app start): retained for 90 days from upload.
  • Session Logs (login, device rebind, and other security-relevant events, including the IP address captured server-side for fraud review): retained for 90 days from the event. Frozen historical snapshots created during suspected log-wiping attacks inherit the same 90-day window.
  • Raw Background Location History (individual GPS points collected while location sharing is enabled): retained for 24 hours from capture — stricter than the 30-day maximum described in Section 4.3. The account-lifetime retention referenced in Section 4.3 applies only to the derived summaries surfaced to your Inner Circle, not to the raw point stream.

Note: This subsection describes the current technical retention configuration and is being finalised in coordination with legal counsel. If the wording here conflicts with any other retention statement in this policy, the shorter window applies.

11.2 Banned User Data Retention

To protect our communities from users who have been banned for violations of our Terms of Service (such as harassment, fraud, or abusive behavior), we retain certain data from banned accounts indefinitely:

  • Profile Photos: All profile photos uploaded by banned users are retained to help identify attempts to create new accounts
  • Verified Residence Information: Address verification data from banned users is retained
  • Device Identifiers: Device IDs associated with banned accounts are retained
  • Email Addresses: Email addresses used by banned accounts are retained on our blacklist

Legal Basis: This retention is based on our legitimate interest in protecting community safety and preventing banned users from circumventing their bans (GDPR Article 6(1)(f), CCPA business purpose exception). When a new user joins a community, their profile photo may be compared against photos from users who were previously banned from that community to detect potential ban evasion.

Important: This data is only retained for users who have been banned for violating our Terms of Service. Regular users who delete their accounts have their data removed according to our standard deletion schedule.

12. Children's Privacy

Safety N3T is intended only for users 18 and older, and we do not knowingly collect personal information from anyone under 18. No child accounts can be created in Safety N3T today, and none of the features described elsewhere in this Policy operate on data collected from children.

We plan to build a separate companion app for children called Safety N3T Jr. in the future. Safety N3T Jr. has not been built or released; before it launches it will have its own children's privacy notice and its own verifiable parental-consent process, and children's data will not be collected under this Policy.

If you believe someone under 18 is using Safety N3T, please contact us at contact@mikoloniamobile.com and we will remove that account.

13. International Data Transfers

Safety N3T operates globally. Your data may be transferred to and processed in countries other than your own, including the United States where our servers are located.

When we transfer data internationally, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Data processing agreements with all third-party providers
  • Compliance with applicable data protection laws

The specific transfer mechanism in place for each processor listed in Section 5 (for example the applicable Standard Contractual Clauses module or an equivalent safeguard, and the corresponding data processing agreement) is available on request. Contact us at contact@mikoloniamobile.com to receive the current per-vendor list.

14. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request disclosure of personal information collected, used, and shared
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell personal information, so this right does not apply
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

To exercise these rights, contact us at contact@mikoloniamobile.com or use the in-app privacy controls.

15. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

  • Legal Basis: We process your data based on: (a) your consent, (b) contract performance, (c) legal obligations, or (d) legitimate interests
  • Right to Access: Obtain a copy of your personal data
  • Right to Rectification: Correct inaccurate personal data
  • Right to Erasure: Request deletion of your personal data
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time

Data Controller: Mikolonia Mobile is the data controller for your personal data.

To exercise these rights or file a complaint, contact us at contact@mikoloniamobile.com. You also have the right to lodge a complaint with your local data protection authority.

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes:

  • We will notify you via push notification and/or email
  • We will update the "Last Updated" date at the top of this policy
  • We will provide a summary of changes
  • For material changes, we may require you to re-acknowledge the policy

Continued use of Safety N3T after changes constitutes acceptance of the updated policy.

17. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Email: contact@mikoloniamobile.com

Company: Mikolonia Mobile

We aim to respond to all inquiries within 30 days.