Legal information

Privacy Policy

This policy explains in practical terms how BeSafe uses information in the iOS app and on be-safe.app.

Effective since August 8, 2026

1. Introduction

This policy covers the BeSafe – SOS Safety App for iOS and the be-safe.app website. BeSafe is published by Hugo Bertin, who is the controller for the processing described below where it is carried out by BeSafe.

It describes the behaviour observed in the available source code for versions 1.2 and 1.3. The version 1.2 binary distributed through the App Store was not available for independent verification of its native implementation. Where the sources differ, this policy identifies the version concerned and describes the broadest potential processing.

BeSafe is a personal safety assistance app. It complements existing safety measures and does not replace emergency services. Users remain in control of sensitive feature activation and the permissions granted in iOS.

2. Data and information used by BeSafe

In the source code examined, BeSafe works without an online account and without a BeSafe server configured to receive app content. The information below is mainly created or entered by the user and retained in the app’s local storage on the iPhone.

BeSafe does not include advertising tools, audience analytics or cross-app tracking. Some information nevertheless leaves the device when the user requests an Apple service, displays a map, sends a message, opens an external link or contacts support. Those cases are explained in the following sections.

Processing needed for requested app features is based on providing the service selected by the user. Microphone and location remain subject to the user’s choice and iOS permissions. Handling support requests and protecting the website rely on the legitimate interests of responding, operating the service and preventing abuse, together with applicable legal obligations where relevant.

  • Local profile: first name or nickname and last name entered in the app; no BeSafe email address or password is required.
  • Safety settings: primary and backup phrases, language, durations, preferences, scenarios, optional destinations and the state of features used.
  • Trusted contacts: name, phone number, prepared message and recipient selection.
  • Audio: temporary microphone stream used to detect a phrase, recordings created after a trigger and related metadata.
  • Location: one-time position requested to prepare a message or trip, accuracy and capture time.
  • Local history and diagnostics: dates, durations, timer or trip outcome, recipient count and technical events needed for operation. In version 1.2, a local log may also contain coordinates captured while preparing a message; this log is not automatically sent to BeSafe.
  • Subscription: product identifier, displayed price, StoreKit-verified result and locally retained Premium status.
  • Support and website: sender email address, subject, content and usual metadata of an email voluntarily sent to support, together with technical request data processed by the website host.

3. Microphone and audio

The microphone is used when the user enables voice protection, starts a guided test or requests a recording. Voice protection that has already been enabled may continue listening for the safety phrase when the app moves into the background; it stops when the user disables protection or iOS interrupts the audio session.

In the version 1.3 source code examined, phrase detection takes place on the iPhone using a Whisper model bundled with the app. Earlier versions may use a different implementation based on iOS audio or recognition components. The available code does not configure a BeSafe server to receive the voice stream. Apple may process information if an Apple system service is used, under its own rules.

The audio and text fragments needed for detection are handled during the active session and are not retained as a conversation history. Local technical events may nevertheless indicate the state of phrase detection or the audio session.

After detecting the safety phrase, or following a manual action where the feature permits it, BeSafe may start a separate recording. Users can withdraw Microphone permission at any time in iOS Settings; the relevant features will then be unable to work normally.

4. Location

BeSafe requests foreground location permission only after a visible user action. The request may appear when protection is enabled even though no coordinate is read at that stage. A position is actually read only to prepare a message or save a one-time trip position. The app does not implement permanent tracking, background location monitoring or geofencing.

To prepare an SOS message, a one-time position is obtained and inserted into the message draft as Apple Maps and Google Maps links. It is not recorded in BeSafe history for that action. For Safe Trip, a one-time position may be retained locally during the trip if the user enables the option; it can be removed, and it is deleted from the trip details when the trip is closed.

In the version 1.2 source code, coordinates used to prepare the message may also appear in a diagnostic log local to the iPhone. BeSafe does not automatically receive that log. The version 1.3 source code examined no longer records coordinate values in that application log.

The map preview uses Apple mapping services. Apple may process the precise coordinate and technical information needed to display the map. The privacy manifest of the mapping component bundled with version 1.3 declares collection of precise location for app functionality, without linking it to identity or using it for tracking. If the user or a recipient opens an Apple Maps or Google Maps link, the selected service receives the coordinate contained in the link under its own privacy rules.

5. Trusted contacts

Trusted contacts are entered manually in BeSafe. The source code examined does not access the iPhone address book. The contact’s name, phone number, prepared message and selection remain stored locally until they are edited or deleted.

When preparing a message, BeSafe opens the iOS Messages composer with recipients and text pre-filled. BeSafe cannot send the SMS silently or guarantee delivery: the user must review the content and confirm sending. Apple, the mobile carrier and recipients then process the message through their own services. In a group conversation, recipients may see the other phone numbers; BeSafe displays a confirmation before opening a group message.

Users must provide only contact details they are authorised to use and should inform their trusted contacts about the intended use where necessary.

6. Recordings

Audio files are created in the app’s local folder and appear in history with their date and duration. BeSafe does not upload them to a BeSafe server or automatically transmit them to a contact or support.

Where the History screen and its controls are available in the version and plan being used, users can listen to a recording, delete it individually or request deletion of all recordings. Deletion removes the local history entry and requests deletion of the corresponding file. A file deletion error may leave an orphaned local copy until the app’s data is cleared.

Depending on iPhone settings, app data may be included in an iCloud backup or device backup managed by Apple. BeSafe does not control those possible copies; users must manage them through Apple backup settings.

7. App Store subscriptions and purchases

BeSafe Premium purchases are processed by Apple using StoreKit. BeSafe asks Apple for the product list, displayed prices and verified entitlement status to activate or restore Premium. The app retains Premium status and its last update time locally.

BeSafe receives no card number, Apple Account password or full payment details. Apple is responsible for handling payment, purchase history and the Apple Account under its own terms.

Subscriptions are managed and cancelled through the Apple Account used for the purchase. Deleting BeSafe does not automatically cancel a subscription.

8. Apple services and other providers

BeSafe uses iOS components for the microphone, location, Maps, Messages, phone calls, local notifications, alarms, Live Activities and StoreKit. These services may process the information needed for the requested feature under Apple’s terms.

Google receives a coordinate only when a Google Maps link containing that coordinate is opened. The be-safe.app website is hosted by Vercel: to deliver and secure pages, Vercel processes information including IP address, date, requested URL, browser type, location information derived from the IP address and technical logs. BeSafe has enabled no user account, form, advertising or audience analytics on this website.

Emails sent to support@be-safe.app are processed by BeSafe’s email provider. Depending on their organisation and the selected service, Apple, Google, Vercel or the email provider may process information in countries outside the European Economic Area. The applicable conditions and safeguards depend on the provider and are described in its privacy documents and the rules applicable to it.

9. Data retention and deletion

BeSafe uses retention periods determined by each feature and places the main deletion controls in the user’s hands. Because BeSafe has no server copy of local app content, support cannot view or remotely erase information that exists only on the iPhone.

  • Profile, contacts, messages, phrases, settings and scenarios: retained locally while configured; they can be edited and, where the interface provides a control, deleted.
  • Voice detection stream: handled during the active session and then discarded; no conversation transcript is added to history. Local technical events may remain subject to iOS log management.
  • Audio recordings: retained until deleted from history where that control is available, or until the app’s data is erased.
  • Trip position: retained during the active trip until removed or the trip is explicitly closed; becoming overdue alone does not close the trip. Completed history does not retain coordinates.
  • Timer and trip histories: retained locally until the relevant item or history is deleted.
  • Drafts and sent SMS: retained by Messages, carriers and recipients according to their settings and obligations.
  • Local Premium status: retained until the next update or until app data is erased; Apple retains its own purchase data under its rules.
  • Support emails: retained for as long as needed to handle the request, prevent abuse and meet any evidence or retention obligations. The exact period depends on the nature of the request and applicable obligations; emails are deleted when no longer needed.
  • Website logs: retained by Vercel according to the plan and retention periods applicable to its service; BeSafe operates no additional analytics or profiling log.

10. Security

Local data is isolated in the app’s storage by iOS. In version 1.3, the active safety phrase configuration is stored in the iOS Keychain with protection restricted to that device; an older migrated copy may nevertheless remain in local storage. Version 1.2 keeps its phrase in the app’s local storage. Having no BeSafe server for recordings, contacts and positions reduces transmission and remote exposure.

Security also depends on the iPhone passcode, iCloud settings, access to the Apple Account and people who can access the device. No storage or transmission method can guarantee absolute security.

11. Children

BeSafe is not designed to create child accounts or knowingly collect children’s information on a BeSafe server. The App Store page shows a 9+ rating, which is a content rating and not permission to process information without any supervision that may be required.

A minor should use BeSafe with a parent or legal guardian’s involvement where required by law or the circumstances, especially before saving contacts, using the microphone, sharing a location or making a purchase.

12. Changes to this policy

This policy may change to reflect a new BeSafe version, a provider change or a legal requirement. The current version is published on this page with its update date. If a material change requires a new choice, BeSafe will provide appropriate notice in the app, on the website or when the relevant feature is used.

13. Contact and rights

Controller: Hugo Bertin, 253 rue du Maquis de l’Oisans, 38750 Huez, France.

For questions about this policy or to exercise, where the conditions apply, your rights of access, rectification, erasure, restriction, objection or portability regarding information held by BeSafe, contact the address below. Describe your request without sending unnecessary recordings, locations, phone numbers or other sensitive information.

For information that exists only on your iPhone, use the app’s edit or deletion controls and iOS Settings. You may also lodge a complaint with the CNIL or the data protection authority responsible for your country.

support@be-safe.app

14. Last updated

Last updated: August 8, 2026. This version replaces the BeSafe policy previously published on Notion.